{"id":23908,"date":"2026-09-28T11:07:03","date_gmt":"2026-09-28T11:07:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23908"},"modified":"2026-09-28T11:07:03","modified_gmt":"2026-09-28T11:07:03","slug":"cisco-ccnp-data-center-300-635-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-data-center-300-635-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-635-exam-dumps\"><b>Cisco CCNP Data Center 300-635 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 221.<\/b><\/p>\n<p><b>Which Cisco ACI object is used to define a group of endpoints that share the same policy requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint Group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Bridge Domain only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Contract Filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Fabric Node<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Endpoint Group, or EPG, is a logical collection of endpoints that share common policy requirements within Cisco ACI. Endpoints in the same EPG are typically associated with similar application roles or security requirements. Communication between EPGs is controlled through contracts. An EPG is usually created within an Application Profile and associated with a Bridge Domain for network connectivity. Bridge Domains provide forwarding context, while filters describe traffic characteristics used by contracts. Understanding how EPGs fit into the ACI object model is important for API-driven automation because EPGs are represented as managed objects that can be created, queried, and modified programmatically.<\/span><\/p>\n<p><b>Question 222.<\/b><\/p>\n<p><b>Which Cisco ACI object provides the Layer 2 forwarding domain used by one or more EPGs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Contract<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Bridge Domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Tenant only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Filter only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Bridge Domain provides the Layer 2 forwarding context in Cisco ACI. EPGs are associated with Bridge Domains, which can also contain subnet configuration and connect to a Layer 3 routing context through a VRF. Bridge Domains include settings for flooding, endpoint learning, and routing behavior. Contracts define communication policy, while filters specify traffic characteristics. In automation workflows, Bridge Domains are often created before EPGs so the required forwarding structure already exists when the application policy is deployed.<\/span><\/p>\n<p><b>Question 223.<\/b><\/p>\n<p><b>Which ACI object provides the Layer 3 routing context for Bridge Domains?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Contract<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> VRF<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical Domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VRF provides the Layer 3 routing context in Cisco ACI. One or more Bridge Domains can be associated with the same VRF while remaining distinct Layer 2 domains. This allows ACI to separate forwarding contexts and maintain routing isolation between tenants or applications. Application Profiles organize EPGs, contracts regulate communication, and physical domains associate policy with physical infrastructure. Automation scripts commonly create or identify the VRF before creating dependent Bridge Domains and application objects.<\/span><\/p>\n<p><b>Question 224.<\/b><\/p>\n<p><b>Which ACI construct defines permitted communication between EPGs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN Pool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Interface Profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Physical Domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Contract<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Contracts define communication policy between Endpoint Groups in Cisco ACI. One EPG can provide a contract while another consumes it. Contract subjects reference filters that describe allowed protocols, ports, or other traffic characteristics. This application-centric approach allows communication policy to be expressed in terms of logical endpoint relationships rather than only IP addresses. VLAN pools and interface profiles serve access-policy functions, while physical domains connect policy constructs to physical infrastructure. Contracts are frequently created and associated programmatically through APIC APIs.<\/span><\/p>\n<p><b>Question 225.<\/b><\/p>\n<p><b>Which ACI object defines traffic-matching criteria such as TCP destination port 443?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Tenant<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Bridge Domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Application Profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An ACI filter defines traffic characteristics such as protocol, source or destination port, and EtherType. Filters are referenced by contract subjects to describe which traffic should be permitted or processed between EPGs. For example, a filter may match TCP destination port 443 for HTTPS traffic. Tenants, Bridge Domains, and Application Profiles provide broader structural functions. In automated deployments, filters can be standardized and reused to ensure consistent application policy across environments.<\/span><\/p>\n<p><b>Question 226.<\/b><\/p>\n<p><b>Which Cisco ACI object groups EPGs that belong to the same application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VRF<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Application Profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> VLAN Pool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Interface Selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Application Profile logically groups Endpoint Groups associated with an application. For example, a three-tier application might have separate web, application, and database EPGs contained within one Application Profile. Contracts then control communication between those groups. VRFs provide routing context, while VLAN pools and interface selectors are associated with fabric access policy. Application Profiles are represented as managed objects in APIC and can be deployed consistently through REST APIs, SDKs, Ansible, or Terraform.<\/span><\/p>\n<p><b>Question 227.<\/b><\/p>\n<p><b>Which APIC API query should an automation script use when it knows the exact distinguished name of an ACI object?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Class query only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS lookup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Distinguished-name query<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP query<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A distinguished-name query is appropriate when the script knows the exact DN of the managed object it wants to retrieve. The DN uniquely identifies the object&#8217;s position in the ACI management information tree. A class query is more appropriate when the automation needs to retrieve multiple objects of the same managed-object class. DNS and ARP are unrelated to APIC&#8217;s object model. DN-based retrieval is useful when modifying or validating a specific object because it avoids returning unrelated records.<\/span><\/p>\n<p><b>Question 228.<\/b><\/p>\n<p><b>What is the main benefit of using an APIC class query instead of repeatedly querying many individual distinguished names?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It bypasses authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It disables object hierarchy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It converts JSON to CLI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It can retrieve multiple objects of the same class efficiently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A class query can retrieve multiple managed objects belonging to the same class in one operation. This is useful for inventory collection, compliance analysis, and bulk inspection of objects such as EPGs, Bridge Domains, or contracts. Query filters can further narrow the returned results. Repeatedly querying individual distinguished names may generate unnecessary API traffic and increase execution time. Class queries still require appropriate authentication and do not alter the underlying ACI hierarchy.<\/span><\/p>\n<p><b>Question 229.<\/b><\/p>\n<p><b>Which Cisco UCS construct can define server identity, boot configuration, network settings, and firmware policies independently of physical hardware?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ACI Contract<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Nexus Port Channel<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> VRF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cisco UCS Service Profile defines a server&#8217;s logical identity and operational configuration independently of a specific physical server. It can include UUID information, MAC address assignments, boot order, firmware policies, network interfaces, storage connectivity, and other settings. This policy-driven design makes server replacement and provisioning more consistent. Contracts and VRFs belong to networking environments, while a Nexus port channel aggregates physical links. Service Profiles are especially valuable for automation because they can be created from templates and associated with servers programmatically.<\/span><\/p>\n<p><b>Question 230.<\/b><\/p>\n<p><b>Which Cisco UCS capability allows multiple Service Profiles to inherit a common standardized configuration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN trunk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Service Profile template<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP table<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Syslog server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Service Profile template provides a reusable standardized definition from which multiple Service Profiles can be created. This helps ensure that server configurations remain consistent and reduces manual configuration effort. Templates can include policy references and other common server settings. Depending on the template type, derived profiles may remain associated with the template for future updates. VLAN trunks, ARP tables, and Syslog servers serve unrelated functions. Template-based provisioning is well suited to large-scale server automation.<\/span><\/p>\n<p><b>Question 231.<\/b><\/p>\n<p><b>Which Cisco tool provides PowerShell cmdlets for automating UCS infrastructure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cisco UCS PowerTool<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Wireshark<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> EEM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ansible Vault<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco UCS PowerTool provides PowerShell cmdlets that enable administrators to automate UCS management tasks. Engineers can connect to UCS environments, retrieve inventory, manage policies, create or modify Service Profiles, and perform repetitive operations through scripts. PowerTool is particularly useful in organizations that already use PowerShell extensively. Wireshark performs packet analysis, EEM provides event-driven device automation, and Ansible Vault protects secrets. PowerTool exposes UCS management functionality in a form that integrates naturally with PowerShell workflows.<\/span><\/p>\n<p><b>Question 232.<\/b><\/p>\n<p><b>Which Cisco UCS automation approach provides Python classes for interacting with UCS managed objects?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SNMP traps only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Cisco UCS Python SDK<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> FTP scripts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ICMP automation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Cisco UCS Python SDK provides Python classes and methods that represent UCS managed objects and simplify programmatic interaction with UCS Manager. Developers can use it to query inventory, create policies, configure Service Profiles, and manage other UCS resources. The SDK abstracts much of the underlying XML API complexity while retaining access to the UCS object model. SNMP traps primarily provide notifications, while FTP and ICMP do not provide equivalent UCS configuration capabilities.<\/span><\/p>\n<p><b>Question 233.<\/b><\/p>\n<p><b>Which Cisco Intersight feature allows automation clients to retrieve only objects that match specified criteria?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Packet capture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> STP convergence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> LACP negotiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Filtering allows an Intersight API client to request only resources that match specific properties such as model, status, organization, or name. This reduces response size and processing overhead, particularly in large infrastructure environments. Without filtering, a script might retrieve thousands of records and discard most of them locally. Packet capture, STP, and LACP are unrelated to API data selection. Efficient filtering improves both performance and clarity in automation workflows.<\/span><\/p>\n<p><b>Question 234.<\/b><\/p>\n<p><b>Which API technique must an automation script implement if Intersight returns a large collection in multiple result sets?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS recursion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Pagination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP suppression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pagination divides large API result sets into smaller groups of records. The client must request subsequent pages using the mechanism supported by the API, such as offsets, limits, page values, or continuation tokens. If pagination is ignored, the script may work with an incomplete inventory and make incorrect decisions. DNS, routing, and ARP functions are unrelated to REST API pagination. Good automation should continue processing pages until the required dataset has been retrieved fully.<\/span><\/p>\n<p><b>Question 235.<\/b><\/p>\n<p><b>Which Ansible feature is best suited to dynamically generate Nexus configuration text using device-specific variables?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Jinja2 template<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Fact cache only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Callback plugin<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Inventory file only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jinja2 templates generate text dynamically using variables, loops, and conditionals. A single template can produce different Nexus configurations based on device-specific values such as hostnames, interfaces, VLANs, or IP addresses. This improves consistency and reduces duplicated configuration. Inventory can store variables, but the template performs the actual rendering. Callback plugins affect Ansible execution output, and fact caches store gathered information. Templates are particularly valuable when the desired end result is structured CLI configuration.<\/span><\/p>\n<p><b>Question 236.<\/b><\/p>\n<p><b>Which Ansible keyword allows a task to run only if a condition is satisfied?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> notify<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> loop<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> when<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">when<\/span><span style=\"font-weight: 400;\"> keyword provides conditional execution in Ansible. It allows a task to run only when a Boolean expression evaluates as true. For example, a task may execute only when a queried VLAN does not already exist or when the target platform matches a required device type. <\/span><span style=\"font-weight: 400;\">register<\/span><span style=\"font-weight: 400;\"> stores task results, <\/span><span style=\"font-weight: 400;\">loop<\/span><span style=\"font-weight: 400;\"> repeats a task, and <\/span><span style=\"font-weight: 400;\">notify<\/span><span style=\"font-weight: 400;\"> triggers handlers. Conditions make playbooks more flexible and help reduce unnecessary changes.<\/span><\/p>\n<p><b>Question 237.<\/b><\/p>\n<p><b>Which Terraform command should an engineer use first to see whether a configuration would create, modify, or destroy resources?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">terraform plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b> <span style=\"font-weight: 400;\">terraform destroy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b> <span style=\"font-weight: 400;\">terraform state rm<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b> <span style=\"font-weight: 400;\">terraform output<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">terraform plan<\/span><span style=\"font-weight: 400;\"> shows the proposed difference between the current known state and the declared desired configuration. It identifies which resources would be created, updated, replaced, or destroyed. Reviewing this output is an important safeguard before production deployment. <\/span><span style=\"font-weight: 400;\">terraform destroy<\/span><span style=\"font-weight: 400;\"> removes resources, while state-management and output commands serve different purposes. In mature workflows, plans can be stored and reviewed through CI\/CD systems before <\/span><span style=\"font-weight: 400;\">terraform apply<\/span><span style=\"font-weight: 400;\"> is authorized.<\/span><\/p>\n<p><b>Question 238.<\/b><\/p>\n<p><b>Which Terraform feature allows reusable infrastructure logic to be packaged and called from multiple configurations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> State lock only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Module<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Output variable only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backend only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Terraform module packages a collection of resources and supporting logic into a reusable component. A module can accept input variables and expose outputs, allowing teams to standardize common infrastructure patterns while still supporting environment-specific values. This reduces duplicated code and improves consistency. Backends store state, while state locking controls concurrent changes. Outputs expose selected values but do not package reusable infrastructure logic. Well-designed modules are a fundamental part of scalable infrastructure-as-code practices.<\/span><\/p>\n<p><b>Question 239.<\/b><\/p>\n<p><b>Which NETCONF operation retrieves only configuration data from a selected datastore?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">&lt;get-config&gt;<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b> <span style=\"font-weight: 400;\">&lt;commit&gt;<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b> <span style=\"font-weight: 400;\">&lt;lock&gt;<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b> <span style=\"font-weight: 400;\">&lt;close-session&gt;<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The NETCONF <\/span><span style=\"font-weight: 400;\">&lt;get-config&gt;<\/span><span style=\"font-weight: 400;\"> operation retrieves configuration data from a selected datastore such as running or candidate, depending on device support. It differs from <\/span><span style=\"font-weight: 400;\">&lt;get&gt;<\/span><span style=\"font-weight: 400;\">, which can retrieve both configuration and operational state information. Filters can be used to limit the response. <\/span><span style=\"font-weight: 400;\">&lt;commit&gt;<\/span><span style=\"font-weight: 400;\"> activates candidate changes, <\/span><span style=\"font-weight: 400;\">&lt;lock&gt;<\/span><span style=\"font-weight: 400;\"> reserves a datastore, and <\/span><span style=\"font-weight: 400;\">&lt;close-session&gt;<\/span><span style=\"font-weight: 400;\"> ends the NETCONF session. Choosing the correct retrieval operation helps automation obtain only the information needed for the task.<\/span><\/p>\n<p><b>Question 240.<\/b><\/p>\n<p><b>A team wants infrastructure changes to be tested automatically, reviewed, and deployed to production only after all required checks pass. Which approach is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Run scripts directly from personal laptops<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable version control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use a CI\/CD pipeline with testing, policy checks, and approval gates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store production passwords directly in the repository<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CI\/CD pipeline can enforce a controlled promotion process for infrastructure automation. Early stages can perform syntax validation, linting, unit tests, integration tests, security checks, and policy validation. High-impact production changes can then require peer review or explicit approval before deployment. This creates a repeatable and auditable workflow while reducing the risk of untested changes. Direct execution from personal workstations lacks consistent controls, and storing credentials in source code creates unnecessary security exposure.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps &nbsp; Question 221. Which Cisco ACI object is used to define a group of endpoints that share the same policy requirements? Endpoint Group 2. Bridge Domain only 3. Contract Filter 4. Fabric Node Correct Answer: 1 Explanation: An Endpoint Group, or EPG, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23908"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23908"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23908\/revisions"}],"predecessor-version":[{"id":23909,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23908\/revisions\/23909"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}