An organization has encountered many STP-related issues in the past due to failed hardware components.They are in the process of long-term migration to a newly deployed ACI fabric. Senior engineers are worried that spanning-tree loops in the existing network may be extended to the ACI fabric. Which feature must be enabled on the ACI leaf ports to protect the fabric from spanning-tree loops?
Answer(s): B
Option B is correct because per-VLAN MCP (Minimum Control Plane) on ACI leaf ports protects the fabric from spanning-tree loops by enforcing per-VLAN control, preventing legacy STP-induced loops from propagating into the fabric during migration. Incorrect — A) BPDU Guard: protects against rogue BPDU on access ports but does not specifically guard against STP loops entering the fabric from multiple VLANs; not the dedicated ACI mechanism for loop prevention. Incorrect — C) Storm Control: limits traffic rate to prevent broadcast/mlood storms, not designed to stop STP loops or control plane loops. Incorrect — D) BPDU Filter: suppresses BPDU transmission/processing on a port, but can disrupt legitimate topology signals and isn’t the recommended per-VLAN protection for fabric loops.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/aci-fundamentals/Cisco- ACI-Fundamentals-401/Cisco-ACI-Fundamentals-401_chapter_0101.html
A network engineer must design a method to allow the Cisco ACI to redirect traffic to the firewalls. Only traffic that matches specific L4-L7 policy rules should be redirected. The load must be distributed across multiple firewalls to scale the performance horizontally. Which action must be taken to meet these requirements?
Answer(s): D
Option D) Correct — Implement ACI Service Graph with Symmetric PBR. Symmetric PBR ensures bidirectional policy enforcement and consistent redirection of traffic that matches L4-L7 rules, enabling scalable distribution across multiple firewalls via service graph. It preserves policy symmetry for both directions and supports distributed firewall architectures.A) Incorrect — Unidirectional PBR only redirects traffic in one direction, not suitable for bidirectional flows required for symmetric policy enforcement.B) Incorrect — GIPo (Generic Ingress Policy object) is not the standard mechanism to define symmetric, per-flow service chaining with L4-L7 matching in a service graph.C) Incorrect — Two Nodes with GIPo does not specify symmetric PBR behavior and may not guarantee proper distribution across multiple firewalls.
An engineer created two interface protocol policies called Pol_CDP40275332 and Pol_LLDP46783451. The policies must be used together in a single policy. Which ACI object must be used?
Answer(s): A
Option A is correct because interface policy groups are the ACI construct that aggregates related interface policies (such as two interface protocol policies) to be applied together as a single policy group within an interface policy configuration. This matches the requirement to use Pol_CDP40275332 and Pol_LLDP46783451 together in a single logical unit.B) Incorrect — switch policy group is used to group switch-related policies, not interface protocols.C) Incorrect — switch profile defines device-wide switch settings, not per-interface protocol policies.D) Incorrect — interface profile binds physical interfaces to interface policy groups, but does not itself house the combination of protocol policies.
What is the minimum number of APICs does Cisco recommend to deploy in a production cluster?
Option B is correct because Cisco recommends a minimum of three APICs in a production ACI cluster to provide quorum, fault tolerance, and continuous controller availability.A) Incorrect — A single APIC does not provide quorum or HA; no protection against APIC failure.C) Incorrect — Four APICs are supported; however, three is the minimum and is the recommended baseline for production.D) Incorrect — Five APICs exceed the minimum requirement and are not specified as the baseline recommendation for production.
Refer to the exhibit. An engineer must implement the inter-tenant service graph. Which set of actions must be taken to accomplish this goal?
Option A is correct because inter-tenant service graphs in ACI require defining the L4–L7 device, service graph template, and ASA bridge domains in the provider (service graph consumer) tenant, then exporting the contract to the consumer tenant. Incorrect options: B and C place L4–L7 device/service graph/ASA bridge domains in the wrong tenants, which violates the provider-export model for inter-tenant service graphs. D incorrectly requires all elements in the consumer tenant, which reverses the governance model; contracts are defined in the provider and exported to the consumer.
All workloads in VLAN 1001 have been migrated into EPG-1001. The requirement is to move the gateway address for VLAN 1001 from the core outside the Cisco ACI fabric into the Cisco ACI fabric. The endpoints in EPG-1001 must route traffic to endpoints in other EPGs and minimize flooded traffic in the fabric. Which configuration set is needed on the bridge domain to meet these requirements?
Option D is correct because enabling Hardware Proxy allows the bridge domain to route traffic to external gateways within the fabric, effectively moving the gateway address into the fabric and preventing undirected flooding. This aligns with the requirement to route traffic between EPGs and minimize flooded traffic.A) Enable Flood is incorrect because enabling flood would increase broadcast/flood traffic within the fabric, contrary to minimizing flooded traffic.B) Disable Local IP Learning is incorrect because it does not address gateway placement or inter-EPG routing behavior required to keep traffic within the fabric.C) Disable ARP Flood is incorrect because, while it reduces ARP floods, it does not facilitate gateway relocation into the fabric or efficient inter-EPG routing.
An engineer must advertise a bridge domain subnet out of the ACI fabric to an OSPF neighbor. Which two configuration steps are required? (Choose two.)
Answer(s): B,E
Option B is correct because advertising a bridge-domain subnet to OSPF requires configuring the Subnet scope to Advertised Externally so that the subnet is exported to external routing protocols. Option E is correct because associating an L3Out with the bridge domain enables external routing reachability and allows the BD subnet to be advertised via the chosen L3Out to OSPF.A) Incorrect — External Subnet for External EPG flag under External EPG is not a required step for advertising a BD subnet to OSPF.C) Incorrect — Subnet is configured at the EPG/BD level, not as a separate EPG-level subnet alone, and this option does not ensure advertisement.D) Incorrect — Route Control Profile with export direction under External EPG is not the standard mechanism to advertise BD subnets via OSPF.
An engineer must connect a new host to port on Leaf 101. A Cisco ACI fabric has an MCP policy configured but experiences excessive Layer 2 loops. The engineer wants the Cisco ACI fabric to detect and prevent Layer 2 loops in the fabric. Which set of actions accomplishes these goals?
Option D is correct because enabling MCP globally ensures L2 loop detection and prevention across the entire fabric, applying MCP behavior at the fabric level for all interfaces, which is required to stop loops triggered by a new host connection. Options A, B, and C: A and B (Enable MCP locally) imply per-device or per-attachment-point enabling, which would not uniformly detect/prevent fabric-wide loops. C (Enable MCP globally) is the same as D in this context, but the wording must match the given correct option label, which is D; if D differs in meaning from C, it would be incorrect. INSUFFICIENT_KNOWLEDGE
Share your comments for Cisco 300-620 exam with other users:
good need more
sample questions seems good
huawei is ok
good one nice
please continue
this exam dumps just did the job. i donot want to ruffle your feathers but your exam dumps and mock test engine is amazing.
nice questions
the explanation are really helpful
just passed my exam yesterday on my first attempt. these dumps were extremely helpful in passing first time. the questions were very, very similar to these questions!
cosmos db is paas not saas
what is the percentage of common questions in gcp exam compared to 197 dump questions? are they 100% matching with real gcp exam?
not able to see questions
by far one of the best sites for free questions. i have pass 2 exams with the help of this website.
excellent question bank.
it really helped
excelent material
the new versoin of this exam which i downloaded has all the latest questions from the exam. i only saw 3 new questions in the exam which was not in this dump.
question 8 - can cloudtrail be used for storing jobs? based on aws - aws cloudtrail is used for governance, compliance and investigating api usage across all of our aws accounts. every action that is taken by a user or script is an api call so this is logged to [aws] cloudtrail. something seems incorrect here.
question 13 tda - c01 answer : quick table calculation -> percentage of total , compute using table down
pls share teh dump
question 44 answer is user risk
please post the questions for preparation
thanks for the questions
please reopen it now ..its really urgent
these practice exam questions were exactly what i needed. the variety of questions and the realistic exam-like environment they created helped me assess my strengths and weaknesses. i felt more confident and well-prepared on exam day, and i owe it to this exam dumps!
thank u it very instructuf
its helpful?
is this dump still valid???
question 205 answer is b
question 39, should be answer b, directions stated is being sudneted from /21 to a /23. a /23 has 512 ips so 510 hosts. and can make 4 subnets out of the /21
beautiful test engine software and very helpful. questions are same as in the real exam. i passed my paper.
the questions are exactly the same in real exam. just make sure not to answer all them correct or else they suspect you are cheating.
question: 78 the right answer i think is d not a
very helpful