Use Free 300-620 Exam Questions that Stimulates Actual EXAM [Q105-Q130]

Share

Use Free 300-620 Exam Questions that Stimulates Actual EXAM

Get 100% Real 300-620 Free Online Practice Test


To pass the Cisco 300-620 certification exam, candidates must have a strong understanding of network protocols, routing and switching technologies, and virtualization concepts. They should also have experience with Cisco ACI, including its architecture, policies, and integration with other technologies. Implementing Cisco Application Centric Infrastructure certification exam consists of multiple-choice questions that assess candidates' knowledge of these topics.


Cisco 300-620 certification exam is an important benchmark for IT professionals who specialize in data center infrastructure management. Implementing Cisco Application Centric Infrastructure certification validates the skills and knowledge required to deploy and manage ACI infrastructure, which is one of the most widely used technologies in modern data centers. With the Cisco 300-620 certification, candidates can demonstrate their ability to design, implement, and manage ACI infrastructure, and they can differentiate themselves from other IT professionals in the field. Implementing Cisco Application Centric Infrastructure certification provides a strong foundation for IT professionals who want to advance their careers in data center infrastructure management and is highly regarded by employers in the industry.

 

NEW QUESTION # 105
Refer to the exhibit. An administrator configures inter-VRF route leaking between Production:vrf- prod and Non-Production:vrf-nonprod. However, the route in the Non-Production:vrf-nonprod VRF to the production tenant is missing. Which action resolves the VRF route leaking issue?

  • A. Export the contract from provider to consumer tenant.
  • B. Enable the Shared between VRFs option for the BD subnet in the production VRF.
  • C. Enable the Shared between VRFs option for the EPG subnet in the non-production VRF.
  • D. Change the contract scope to Global.

Answer: B


NEW QUESTION # 106
An ACI administrator notices a change in the behavior of the fabric. Which action must be taken to determine if a human intervention introduced the change?

  • A. Inspect event records in the APIC UI to see all actions performed by users.
  • B. Inspect the output of show command history in the APIC CLI.
  • C. Inspect /var/log/audit_messages on the APIC to see a record of all user actions.
  • D. Inspect audit logs in the APIC UI to see all user events.

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/all/faults/guide/b_APIC_F aults_Errors/b_IFC_Faults_Errors_chapter_010.html


NEW QUESTION # 107
Refer to the exhibit.

An engineer must implement the inter-tenant service graph. Which set of actions must be taken to accomplish this goal?

  • A. * Define the contract in the provider tenant and export it to the consumer tenant.
    * Define the L4-L7 device, service graph template, and ASA bridge domains in the provider tenant.
  • B. * Define the contract in the provider tenant and export it to the provider tenant.
    * Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant.
  • C. * Define the contract in the provider tenant and export it to the consumer tenant.
    * Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant.
  • D. * Define the contract in the provider tenant and export it to the provider tenant.
    * Define the L4-L7 device, service graph template, and ASA bridge domains in the consumer tenant.

Answer: A


NEW QUESTION # 108
Refer to the exhibit.

An engineer is integrating a VMware vCenter with Cisco ACI VMM domain configuration. ACI creates port-group names with the format of "Tenant | Application | EPG". Which configuration option is used to generate port groups with names formatted as "Tenant=Application=EPG"?

  • A. enable tag collection
  • B. virtual switch name
  • C. delimiter
  • D. security domains

Answer: C

Explanation:
In the Cisco ACI VMM domain configuration, to generate port groups with names formatted as "Tenant=Application=EPG", the configuration option used is delimiter. The delimiter is a character that separates the elements of the port-group name. By changing the delimiter setting to "=", the port-group names will be generated with the desired format.


NEW QUESTION # 109
An engineer needs to avoid loops in the ACI network and needs an ACI leaf switch to error- disable an interface if the interface receives an ACI-generated packet. Which action meets these requirements?

  • A. Enable the Loop Indication by MCP event in the Error Disabled Recovery Policy.
  • B. Change the default administrative state of the global MCP Instance Policy.
  • C. Set Rogue EP Control in the Endpoint Controls Policy.
  • D. Uncheck the Loop Protection Action check box in MCP Instance Policy.

Answer: B

Explanation:
MisCabling Protocol (MCP) detects loops from external sources (i.e., misbehaving servers, external networking equipment running STP, etc.) and will err-disable the interface on which ACI receives its own packet. Enabling this feature is a best practice, and it should be enabled globally and on all interfaces, regardless of the end device.
For MCP to be enabled, you need to have it enabled globally and on a per-interface basis. While MCP is enabled on all interfaces by default, it is not turned "on" until you also enable it globally.
The global configuration knob for MCP can be enabled by configuring the global settings here:
Fabric > Access Policies > Global Policies > MCP Instance Policy default.
https://www.cisco.com/c/dam/en/us/solutions/collateral/data-center-virtualization/application- centric-infrastructure/aci-guide-using-mcp-mis-cabling-protocol.pdf


NEW QUESTION # 110
Which type of port is used for in-band management within ACI fabric?

  • A. spine switch port
  • B. leaf access port
  • C. APIC console port
  • D. management port

Answer: B


NEW QUESTION # 111
An engineer is extending EPG connectivity to an external network. The external network houses the Layer 3 gateway and other end hosts. Which ACI bridge domain configuration should be used?

  • A. Forwarding: Custom
    L2 Unknown Unicast: Hardware Proxy L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Enabled
  • B. Forwarding: Custom
    L2 Unknown Unicast: Flood
    L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Disabled
  • C. Forwarding: Custom
    L2 Unknown Unicast: Hardware Proxy L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Disabled
  • D. Forwarding: Custom
    L2 Unknown Unicast: Flood
    L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Enabled

Answer: A

Explanation:
When extending EPG connectivity to an external network that houses the Layer 3 gateway and other end hosts, the ACI bridge domain configuration should use Forwarding: Custom, L2 Unknown Unicast: Hardware Proxy, L3 Unknown Multicast Flooding: Flood, Multi Destination Flooding: Flood in BD, and ARP Flooding: Enabled23. This configuration ensures that unknown unicast traffic is handled efficiently while still allowing ARP flooding, which is necessary for the ACI fabric to learn about endpoints on the external network23.


NEW QUESTION # 112
Refer to the exhibit.

Refer to the exhibit. An engineer configures an L3Out but receives the error presented. Which action clears the fault?

  • A. Create a custom QoS policy.
  • B. Acknowledge the QoS-related error.
  • C. Set the QoS policy to Level 3.
  • D. Associate a custom QoS class.

Answer: A

Explanation:
When configuring an L3Out in Cisco ACI and encountering a QoS-related error, creating a custom QoS policy is often necessary to clear the fault. This involves defining a QoS policy that meets the specific requirements of the L3Out configuration and applying it to the relevant interfaces or globally within the fabric. The custom QoS policy should be designed to prioritize traffic appropriately and ensure that the necessary QoS settings are in place for the L3Out connections1.
Reference:
Cisco ACI L3Out Configuration Examples1


NEW QUESTION # 113
A packet is routed between two endpoints on different Cisco ACI leaf switches. Which VXLAN VNID is applied to the packet?

  • A. FD
  • B. BD
  • C. EPG
  • D. VRF

Answer: D


NEW QUESTION # 114
Which tenant is used when configuring in-band management IP addresses for Cisco APICs, leaf nodes, and spine nodes?

  • A. mgmt
  • B. default
  • C. common
  • D. infra

Answer: D


NEW QUESTION # 115
An engineer needs to deploy a leaf access port policy group in ACI Fabric to support the following requirements:
* Control the amount of application data flowing into the system
* Allow the newly connected device to auto-negotiate link speed with the leaf switch Which two ACI policies must be configured to achieve these requirements? (Choose two.)

  • A. ingress control plane policing policy
  • B. slow drain policy
  • C. link level policy
  • D. L2 interface policy
  • E. ingress data plane policing policy

Answer: C,E

Explanation:
Explanation

Slow Drain handles FCoE packets that are causing traffic congestion on ACI fabric. So, it is wrong.
Ingress control plane is wrong, because the request is for "application data flowing".
L2 interface policy is concerned about QinQ and VLAN scope.


NEW QUESTION # 116
Refer to the exhibit.

Refer to the exhibit. The EPG-100 must be extended to the vCenter as a port group with a tagged VLAN ID of 100. Which set of actions accomplishes this goal?

  • A. Define a dynamic VLAN range (from 100-200) under a VLAN pool that is associated with the dc1vdev domain.
    Associate the dc2vcdev domain with EPG and select these settings:
    Untagged VLAN Access: selected
    VLAN Mode: Static with Encap: 100
  • B. Define a dynamic VLAN range (from 100-200) under a VLAN pool that is associated with the del vdev domain.
    Associate the dc1vcdev domain with EPG and select these settings:
    Untagged VLAN Access: unselected
    VLAN Mode: Static with Encap: 100
  • C. Define a static VLAN range (from 100-200) under a VLAN pool that is associated with the dc1vcdev domain.
    Associate the dc1vcdev domain with EPG and select these settings:
    Untagged VLAN Access: unselected
    VLAN Mode: Static with Encap: 100
  • D. Define a static VLAN range (from 100-200) under a VLAN pool that is associated with the dc1vcdev domain.
    Associate the dc2vcdev domain with EPG and select these settings:
    Untagged VLAN Access: selected
    VLAN Mode: Static with Encap: 100

Answer: A


NEW QUESTION # 117
Which method does the Cisco ACI fabric use to load-balance multidestination traffic?

  • A. spanning trees
  • B. shortest-path trees
  • C. forwarding tag trees
  • D. PIM routing

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_010010.html


NEW QUESTION # 118
An engineer must perform a Cisco ACI fabric upgrade that minimizes the impact on user traffic and allows only permitted users to perform an upgrade.
Which two configuration steps should be taken to meet these requirements?

  • A. Divide switches into two or more maintenance groups.
  • B. Divide Cisco APIC controllers into two or more maintenance groups.
  • C. Grant tenant-ext-admin access to a user who performs an upgrade
  • D. Grant the fabric administrator role to a user who performs an upgrade.
  • E. Combine all switches into an upgrade group.

Answer: A,D


NEW QUESTION # 119
An engineer is implementing a Cisco ACI data center network that includes Cisco Nexus 2000 Series 10G fabric extenders. Which physical topology is supported?
A)

B)

C)

D)

  • A. Option C
  • B. Option D
  • C. Option B
  • D. Option A

Answer: D


NEW QUESTION # 120
Which attribute should be configured for each user to enable RADIUS for external authentication in Cisco ACI?

  • A. cisco-auth-features
  • B. cisco-security domain
  • C. cisco-av-pair
  • D. cisco-aci-role

Answer: C

Explanation:
The attribute that should be configured for each user to enable RADIUS for external authentication in Cisco ACI is cisco-av-pair. This attribute allows for the assignment of roles and permissions to users authenticated via RADIUS.


NEW QUESTION # 121
A network engineer must integrate VMware vCenter cluster with Cisco ACI. The requirement is for the management traffic of the hypervisors and VM controllers to use the virtual switch associated with the Cisco Application Policy. The EPG called "Vmware-MGMT" with VLAN 300 has been created for this purpose. Which set of steps must be taken to complete the configuration?

  • A. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
    Associate the target EPG with the VMM domain with default settings.
  • B. Add VLAN 300 with static allocation to the VLAN POOL that is used for VMM integration.
    Attach the VMM domain to the target EPG with resolution preprovision, mode static, untagged access VLAN, and Port-Encap 300.
  • C. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
    Create a static binding in the target EPG toward VMware hypervisors with VLAN 300, untagged access VLAN, and Untagged 802.1P mode.
  • D. Associate the target EPG with the VMM domain with default settings.
    Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.

Answer: C

Explanation:
To integrate the VMware vCenter cluster with Cisco ACI and ensure that the management traffic of the hypervisors and VM controllers uses the virtual switch associated with the Cisco Application Policy, the following steps must be taken:
Enable Infrastructure VLAN on AAEP used toward VMware hypervisors: This step involves enabling the infrastructure VLAN on the Attachable Access Entity Profile (AAEP) that is used for the VMware hypervisors. This VLAN is used for carrying infrastructure traffic such as management, vMotion, and fault tolerance.
Create a static binding in the target EPG toward VMware hypervisors with VLAN 300: This step involves creating a static binding in the "Vmware-MGMT" EPG for the VMware hypervisors with VLAN 300, setting it as an untagged access VLAN, and using Untagged 802.1P mode. This ensures that the management traffic is correctly tagged and associated with the appropriate EPG.
Reference:
Cisco ACI Fabric Hardware Installation Guide
Cisco ACI Troubleshooting Guide
Cisco ACI Multi-Site Architecture White Paper
Cisco ACI Virtual Machine Manager (VMM) Integration White Paper


NEW QUESTION # 122
An application team tells the Cisco ACI network administrator that it wants to monitor the statistics of the unicast and BUM traffic that are seen in a certain EPG. Which statement describes the collection statistics?

  • A. Cisco ACI does not capture statistics at the EPG level. Only statistics that pass through ACI contracts can be monitored.
  • B. EPG statistics can be collected only for VMM domains. If a physical domain exists, statistics are not collected.
  • C. The collection of statistics is enabled on the EPG level by enabling the statistics for unicast and BUM traffic.
  • D. All EPGs in the Cisco ACI tenant object must be enabled for statistics to be collected.

Answer: C

Explanation:

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1- x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_01011.html


NEW QUESTION # 123
What are two PBR characteristics of the Cisco ACI Active-Active Across Pods deployment mode in Cisco ACI Multi-Pod design? (Choose two.)

  • A. This mode causes the traffic to flow asymmetrically.
  • B. Traffic is dynamically redirected to the firewall that owns the connection.
  • C. Deployment occurs in go-to mode only.
  • D. Deployment occurs in transparent mode.
  • E. The connection state is unsynchronized.

Answer: B,C


NEW QUESTION # 124
In the context of VMM, which protocol between ACI leaf and compute hosts ensures that the policies are pushed to the leaf switches for immediate and on demand resolution immediacy?

  • A. LLDP
  • B. STP
  • C. VXLAN
  • D. ISIS

Answer: C


NEW QUESTION # 125
A customer migrates a legacy environment to Cisco ACI. A Layer 2 trunk is configured to interconnect the two environments. The customer also builds ACI fabric in an application-centric mode.
Which feature should be enabled in the bridge domain to reduce instability during the migration?

  • A. Disable Endpoint Dataplane Learning
  • B. Set Multi-Destination Flooding to Flood in BD.
  • C. Enable Flood in Encapsulation.
  • D. Set Multi-Destination Flooding to Flood in Encapsulation.

Answer: D

Explanation:
IMPORTANT In a single BD with Multiple EPGs, each EPG is defined by a different VLAN encapsulation. IF those VLANs extend into you legacy non-ACI network, then (by default) these frames will leak from one VLAN to another - which is probably NOT what you want, which is why there is a Multi-Destination Flooding option to Flood in Encapsulation - to prevent leakage from one EPG to another - but again, this may break some protocols. But before setting your BD to Flood in Encapsulation re-read the IF statement above.


NEW QUESTION # 126
An engineer is implementing an out-of-band (OOB) management access for the Cisco ACI fabric.
The secure access must meet these requirements:
- Only GUI and secure shell must be allowed to access the management
interfaces of the ACIs.
- The only IP ranges that must be permitted to connect the fabric will
be 10.10.10.0/24 and 192.168.15.0/24.
Which configuration set meets these requirements?

  • A. Create an out-of-band EPG in the common tenant.
    Associate the external network instance profile with the OOB contract.
  • B. Create an out-of-band EPG in the external management entity.
    Associate the management profile with the OOB contract.
  • C. Implement HTTPS and SSH protocol filters in the OOB contract.
    Add the required subnets to the external network instance profile.
  • D. Set up static IPs on the management interfaces from the required IP range.
    Add the required subnets to the external network instance profile.

Answer: C


NEW QUESTION # 127
Refer to the exhibit.

Refer to the exhibit. New e-commerce software is deployed on Cisco ACI fabric. The environment must meet these requirements:
The overall number of contracts must be reduced by reusing the existing contracts within a VRF when possible.
The e-commerce software must communicate only with software EPGs that are part of the same ANP.
The e-commerce software must be prevented from communicating with applications in different ANPs.
Which scope must be selected to meet these requirements?

  • A. Tenant
  • B. Endpoint Group
  • C. Global
  • D. Application Profile

Answer: D


NEW QUESTION # 128
What represents the unique identifier of an ACI object?

  • A. management information tree
  • B. application programming interface
  • C. universal resource identifier (URI)
  • D. distinguished name

Answer: C

Explanation:
The unique identifier of an ACI object is represented by the universal resource identifier (URI)2.


NEW QUESTION # 129
An engineer has set the VMM resolution immediacy to pre-provision in a Cisco ACI environment. No Cisco Discovery Protocol neighborship has been formed between the hypervisors and the ACI fabric leaf nodes. How does this affect the download policies to the leaf switches?

  • A. No policies are downloaded because there is no discovery protocol neighborship.
  • B. Policies are downloaded when the hypervisor host is connected to the VMM VDS.
  • C. No policies are downloaded because LLDP is the only supported discovery protocol.
  • D. Policies are downloaded to the ACI leaf switch regardless of Cisco Discovery Protocol neighborship.

Answer: D


NEW QUESTION # 130
......

BEST Verified Cisco 300-620 Exam Questions (2026) : https://www.braindumpspass.com/Cisco/300-620-practice-exam-dumps.html

The Best Practice Test Preparation for the 300-620 Certification Exam: https://drive.google.com/open?id=1agC3sg4T2h3ndztDO6h4slaLWPSNpQ62