Cisco Implementing Application Centric Infrastructure (DCACI) 300-620 Dumps in PDF

Free Cisco 300-620 Real Questions (page: 24)

Which resolution immediacy setting allows a policy to be downloaded to the Cisco ACI leaf switch software regardless of CDP/LLDP neighborship?

  1. Expedite
  2. Immediate
  3. Pre-Provision
  4. On Demand

Answer(s): C

Explanation:

The Pre-Provision resolution mode causes the policy to be sent straight to the leaf's software database immediately - without waiting for CDP/LLDP discovery - whereas On-Demand holds off until a neighbor is detected.



Refer to the exhibit.





A Cisco ACI fabric has four access policy groups. The VPC reciprocal protection group has been defined. The N9K1 trunks VLANs 10-20 to ACI leaf switches. Which policy group must be associated with Eth1/1 and Eth1/2 to complete the deployment?

  1. PEGRKAL12_PolGrp
  2. PEGRMET12_PolGrp
  3. PEGRKIF11_PolGrp
  4. PEGRPAL11_PolGrp

Answer(s): B

Explanation:

The fabric links from N9K1 to two separate ACI leaves form a VPC-style multi-node port channel. You must use the policy group with lagT = node (PEGRMET12_PolGrp) so that both Eth1/1 and Eth1/2 are treated as one portchannel across leaf1 and leaf2.



Which function does spine switch perform in the Cisco ACI fabric?

  1. It connects to classic Ethernet devices in the multitier topology.
  2. It decapsulates VXLAN packets received from leaf switches.
  3. It stores all the entries of endpoints-to-VTEP mapping.
  4. It bridges tenant packets for applying network policies.

Answer(s): B

Explanation:

In an ACI fabric the spine's role is purely L3 - it terminates the VXLANGPE tunnels from the leaves, removes the outer VXLAN header (decapsulation), routes the packet to the correct leaf, then re-encapsulates it for onward delivery. The leaf switches handle bridging and policy enforcement, and neither store the full endpoint- to-VTEP mapping nor connect directly to traditional Ethernet devices.



Refer to the exhibit.



A company deployed Cisco ACI and plans to migrate the first servers to the Cisco ACI fabric. The current network setup experiences a small number of silent hosts. What is the Cisco recommended bridge domain configuration to support the network topology presented?

  1. Unicast Routing: Disabled
    L2 Unknown Unicast: Flood
  2. Unicast Routing: Enabled
    L2 Unknown Unicast: Hw Proxy
  3. ARP Flooding: Enabled
    Multi Destination Flooding: Flood in BD
  4. ARP Flooding: Disabled
    L3 Unknown Multicast Flooding: Flood

Answer(s): B

Explanation:

When you extend an existing L3-switched network into ACI and keep the original SVI as the gateway, enabling Unicast Routing on the bridge domain lets the fabric advertise its host routes back to that SVI. Setting L2 Unknown Unicast to HW Proxy ensures the spine/leaf fabric will proxy ARP and unknown-unicast MAC requests for those migrated servers so that "silent" hosts are reachable without flooding.



An EPG is associated with a VMM domain. Which option must be set to allow the bridge domain and the VRF of the EPG to be instantiated on all leaf switches that discovered the ESXi host?

  1. Immediate Resolution immediacy
  2. On-Demand Resolution immediacy
  3. On-Demand Deployment immediacy
  4. Immediate Deployment immediacy

Answer(s): C

Explanation:

Setting the EPG's Deployment immediacy to On-Demand ensures that the bridge domain and VRF are only pushed down to - and instantiated on - the leaf switches that actually see the ESXi host, rather than all leaves up front.



On which endpoint type is the host tracking feature performed in the Cisco ACI fabric?

  1. local endpoint
  2. bounce entry endpoint
  3. on-peer endpoint
  4. remote endpoint

Answer(s): D

Explanation:

The host-tracking feature in ACI issues ARP/ND probes only for remote endpoints (those learned via unicast routing), in order to verify ongoing reachability. It does not run against purely local, bounce, or on-peer endpoint types.



A Cisco ACI fabric has detected EP1 with IP address 192.168.1.1 to MAC M1 on interface Eth1/1. The fabric is designed so that when EP1 is down, a new EP2 receives the same IP address with a different MAC M2 on the same interface Eth1/1. Which two features must be enabled to meet this requirement? (Choose two.)

  1. ARP Flooding
  2. L3 Unknown Multicast Optimized Flood
  3. L2 Unknown Unicast Hardware Proxy
  4. GARP Based Detection
  5. EPG Flood in Encapsulation

Answer(s): A,D

Explanation:

ARP Flooding must be enabled on the Bridge Domain so that gratuitous ARPs from the replacement host actually flood through the fabric (otherwise the leafs' default proxy behavior would swallow them).
GARP-Based Detection uses those flooded gratuitous ARP frames to detect the IP/MAC change and promptly clear the old endpoint entry when the new host comes up on the same port.



Refer to the exhibit.



An engineer migrates a legacy data center to a new Cisco ACI fabric. The new deployment must raise a fault if a Layer 2 loop is detected from the external networking devices. Due to the large number of workloads still running on the legacy network, the interconnection links must not be disabled. The engineer has already enabled the MCP globally. Which configuration completes the configuration?

  1. Disable Loop Protection Action on MCP global policy.
  2. Enable MCP in the interconnection links.
  3. Configure MCP on all the legacy extended VLANs.
  4. Implement MCP PDU per VLAN on the legacy-facing interfaces.

Answer(s): D

Explanation:

By default, Mis-Cabling Protocol (MCP) BPDUs are only sent in the native VLAN. To detect loops in the other VLANs carried across your legacy trunk, you must enable per-VLAN MCP so that an MCP PDU is transmitted in each VLAN on those interfaces; this raises the loopdetection fault without disabling the ports.



Share your comments for Cisco 300-620 exam with other users:

N
Naveed
8/28/2023 2:48:00 AM

good questions with simple explanation

C
cert
9/24/2023 4:53:00 PM

admin guide (windows) respond to malicious causality chains. when the cortex xdr agent identifies a remote network connection that attempts to perform malicious activity—such as encrypting endpoint files—the agent can automatically block the ip address to close all existing communication and block new connections from this ip address to the endpoint. when cortex xdrblocks an ip address per endpoint, that address remains blocked throughout all agent profiles and policies, including any host-firewall policy rules. you can view the list of all blocked ip addresses per endpoint from the action center, as well as unblock them to re-enable communication as appropriate. this module is supported with cortex xdr agent 7.3.0 and later. select the action mode to take when the cortex xdr agent detects remote malicious causality chains: enabled (default)—terminate connection and block ip address of the remote connection. disabled—do not block remote ip addresses. to allow specific and known s

Y
Yves
8/29/2023 8:46:00 PM

very inciting

M
Miguel
10/16/2023 11:18:00 AM

question 5, it seems a instead of d, because: - care plan = case - patient = person account - product = product2;

B
Byset
9/25/2023 12:49:00 AM

it look like real one

D
Debabrata Das
8/28/2023 8:42:00 AM

i am taking oracle fcc certification test next two days, pls share question dumps

N
nITA KALE
8/22/2023 1:57:00 AM

i need dumps

C
CV
9/9/2023 1:54:00 PM

its time to comptia sec+

S
SkepticReader
8/1/2023 8:51:00 AM

question 35 has an answer for a different question. i believe the answer is "a" because it shut off the firewall. "0" in registry data means that its false (aka off).

N
Nabin
10/16/2023 4:58:00 AM

helpful content

B
Blessious Phiri
8/15/2023 3:19:00 PM

oracle 19c is complex db

S
Sreenivas
10/24/2023 12:59:00 AM

helpful for practice

L
Liz
9/11/2022 11:27:00 PM

support team is fast and deeply knowledgeable. i appreciate that a lot.

N
Namrata
7/15/2023 2:22:00 AM

helpful questions

L
lipsa
11/8/2023 12:54:00 PM

thanks for question

E
Eli
6/18/2023 11:27:00 PM

the software is provided for free so this is a big change. all other sites are charging for that. also that fucking examtopic site that says free is not free at all. you are hit with a pay-wall.

O
open2exam
10/29/2023 1:14:00 PM

i need exam questions nca 6.5 any help please ?

G
Gerald
9/11/2023 12:22:00 PM

just took the comptia cybersecurity analyst (cysa+) - wished id seeing this before my exam

R
ryo
9/10/2023 2:27:00 PM

very helpful

J
Jamshed
6/20/2023 4:32:00 AM

i need this exam

R
Roberto Capra
6/14/2023 12:04:00 PM

nice questions... are these questions the same of the exam?

S
Synt
5/23/2023 9:33:00 PM

need to view

V
Vey
5/27/2023 12:06:00 AM

highly appreciate for your sharing.

T
Tshepang
8/18/2023 4:41:00 AM

kindly share this dump. thank you

J
Jay
9/26/2023 8:00:00 AM

link plz for download

L
Leo
10/30/2023 1:11:00 PM

data quality oecd

B
Blessious Phiri
8/13/2023 9:35:00 AM

rman is one good recovery technology

D
DiligentSam
9/30/2023 10:26:00 AM

need it thx

V
Vani
8/10/2023 8:11:00 PM

good questions

F
Fares
9/11/2023 5:00:00 AM

good one nice revision

L
Lingaraj
10/26/2023 1:27:00 AM

i love this thank you i need

M
Muhammad Rawish Siddiqui
12/5/2023 12:38:00 PM

question # 142: data governance is not one of the deliverables in the document and content management context diagram.

A
al
6/7/2023 10:25:00 AM

most answers not correct here

B
Bano
1/19/2024 2:29:00 AM

what % of questions do we get in the real exam?

AI Tutor 👋 I’m here to help!