An ACI engineer is implementing a Layer 3 Out inside the Cisco ACI fabric that must meet these requirements:The data center core switch must be connected to one of the leaf switches with a single 1G link.The routes must be exchanged using a link-state routing protocol that supports hierarchical network design.The data center core switch interface must be using 802.1Q tagging, and each VLAN will be configured witha dedicated IP address.Which set of steps accomplishes this goals?
Answer(s): D
Option D is correct because the scenario requires a link-state protocol that supports hierarchical network design for L3 Out in ACI, and OSPF is the appropriate protocol policy for external routed connections with an area of 0 in ACI External Routed domains. A) and B) identical incorrect options claim EIGRP policy but EIGRP is not a standard in ACI for L3Out with OSPF hierarchical design. C) BGP policy with AS 0 is invalid for this L3Out use case and does not align with the required hierarchical link-state design. D) correctly specifies OSPF with area 0 to meet the requirements.
An engineer is in the process of discovering a new Cisco ACI fabric consisting of two spines and four leaf switches. The discovery of leaf 1 has just been completed. Which two nodes are expected to be discovered next? (Choose two.)
Answer(s): C,E
Option C is correct because initial fabric discovery progresses from the first leaf to discover its neighboring spine nodes, establishing control-plane connectivity with spine devices. In a two-spine, four-leaf ACI fabric, after leaf 1, the two spines (spine 1 and spine 2) are discovered next to form the fabric’s backbone before full leaf-to-leaf or leaf-to-leaf spine adjacencies are completed. Option E is correct for the same reason: the second spine (spine 2) is discovered next to spine 1 to complete the spine pair for the fabric’s control plane. Incorrect — A, B, D describe other leaves; discovery of additional leaves typically follows spine discovery, not preceding it. Incorrect — Leaf 2, leaf 4, and any order of their discovery is contingent on spine readiness, not required immediately after leaf 1.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/GSG/ b_APIC_Getting_Started_Guide_Rel_2_x/b_APIC_Getting_Started_Guide_Rel_2_x_chapter_0100.pdf
A bridge domain for an EPG called "Web Servers" must be created in the Cisco APIC. The configuration must meet these requirements:Only traffic to known MAC addresses must be allowed to reduce noise.The multicast traffic must be limited to the ports that are participating in multicast routing.The endpoints within the bridge domain must be kept in the endpoint table for 20 minutes without anyupdates.Which set of steps configures the bridge domain that satisfies the requirements?
Answer(s): B
Option BA) Incorrect — L2 Unknown Unicast should be set to Hardware Proxy is not the mechanism for enforcing explicit known-MAC filtering or controlling multicast behavior in this scenario.B) Correct — Setting L2 Unknown Unicast to Hardware Proxy aligns with restricting traffic to known MAC addresses and leverages APIC/BD policies to constrain unknown traffic, meeting noise reduction while preserving endpoint learn/aging semantics.C) Incorrect — Multicast Destination Flooding to Flood in BD does not address known-MAC enforcement or endpoint aging requirements; it governs multicast flood behavior only.D) Incorrect — ARP Flooding checkbox is unrelated to controlling unknown unicast, endpoint retention, or multicast port-eligibility in this context.
An engineer is troubleshooting fabric discovery in a newly deployed Cisco ACI fabric and analyzes this output:Which ACI fabric address is assigned to interface lo1023?
Answer(s): C
Option C is correct because lo1023 is shown as a fabric tunnel endpoint in the ACI fabric discovery output, which identifies the ACI fabric IP addressing for inter-node control-plane and data-path encapsulation within the fabric. Incorrect — A) VXLAN tunnel endpoint refers to endpoint for VXLAN encapsulated traffic but not the fabric discovery address specifically. Incorrect — B) Physical tunnel endpoint is not a standard ACI term for fabric discovery addressing. Incorrect — D) Dynamic tunnel endpoint is not a defined ACI construct for fabric discovery addressing.
The company's Cisco ACI fabric hosts multiple customer tenants. To meet a service level agreement, the company is constantly monitoring the Cisco ACI environment. Syslog is one of the methods used for monitoring. Only events related to leaf and spine environmental information without specific customer data should be logged. To which ACI object must the configuration be applied to meet these requirements?
Option D is correct because fabric policies in Cisco ACI govern global fabric behavior, including environmental logging settings at the fabric level, which apply across tenants and do not expose specific tenant data. This aligns with logging leaf/spine environmental information without per-tenant data.A) infra tenant — Incorrect — infra is an internal tenant for fabric infrastructure objects, but environmental logging scope at the fabric level is not restricted to infra tenant data and requires fabric-wide policy.B) access policy — Incorrect — access policies control contract and endpoint access behavior, not fabric-wide environmental logging configuration.C) switch profile — Incorrect — switch profiles configure switch-level features and policies, but the question requires a fabric-wide logging scope independent of individual switches.
Refer to the exhibit. A client is configuring a new Cisco ACI fabric. All VLANs will be extended during the migration phase using the VPC connections on leaf switches 3, 4 and leaf switches 5, 6 toward the legacy network. The migration phase has these requirements:The legacy switches must be able to transfer BPDUs through the ACI fabric.If the legacy switches fail to break a loop, Cisco ACI must break the loop.Which group settings must be configured on VPC interface policy groups ipg_vpc-legacy_1 and ipg_vpc- legacy_2 to meet these requirements?
Answer(s): A
Option A is correct because MCP (MAC Pinning Control) must be enabled to allow the legacy switches to forward BPDUs through the ACI fabric via VPC without mislearning or loop protection interference. Enabling MCP ensures consistent MAC pinning behavior across the VPC peers, which helps preserve BPDU traversal while still allowing ACI to detect and break loops if a legacy device creates one.B, C, D are incorrect because they imply different MCP states or configurations that do not provide the required balance of BPDU forwarding and loop protection in the migration scenario. Specifically, enabling MCP is the necessary condition to support stable BPDU passthrough in VPC legacy connections.
A Cisco ACI fabric is connected to an external Cisco Catalyst switch. Which set of actions must be taken for Cisco ACI leaf and spine switches to be managed from the management port?
Option D is correct because managing ACI leaf/spine from the management port requires exposing the default/common contract via the out-of-band (OOB) EPG, enabling management-plane access independent of tenant networks. A) and C) incorrectly reference the external management network under tenant mgmt/common, which is not the standard approach for OOB management in this scenario. B) incorrectly uses the default/mgmt contract by the OOB EPG alone, but the key requirement is the default/common contract, not default/mgmt, when using the management port for out-of-band access. E and F are not present in the question.
A Cisco ACI fabric contains a tenant called Prod. User_1 must have write access to tenant Prod and full access to the fabric access policy. Which set of actions must be taken to meet these requirements?
Option D is correct because assigning User_1 to the security domain ensures they inherit the necessary RBAC permissions scoped to that domain, granting them write access to the Prod tenant and full access to the fabric access policy via domain-level authorization in ACI RBAC.A) Incorrect — Associating User_1 to the tenant Prod only grants tenant scope, not the required RBAC or fabric-access-policy domain linkage to enforce write and full access across the fabric.B) Incorrect — Associating to the distinguished name of the fabric access policy confers policy-level access, but does not establish the necessary domain RBAC or tenant-scoped permissions for User_1.C) Incorrect — Directly associating to the fabric access policy yields policy-level permissions but bypasses the security-domain RBAC linkage needed for proper Tenant and Fabric policy enforcement.
Share your comments for Cisco 300-620 exam with other users:
thank you for providing the q bank
true quesstions
i can´t believe ms asks things like this, seems to be only marketing material.
hi, could you please add the last update of ns0-527
question #3 refers to vnet4 and vnet5. however, there is no vnet5 listed in the case study (testlet 2).
sometimes it may be good some times it may be
qs 4 answer seems wrong- please check
very detailed explanation !
the interactive nature of the test engine application makes the preparation process less boring.
very useful.
complete question dump should be made available for practice.
i just passed my first exam. i got 2 exam dumps as part of the 50% sale. my second exam is under work. once i write that exam i report my result. but so far i am confident.
nice create dewey stefen
i just wrote this exam and it is still valid. the questions are exactly the same but there are about 4 or 5 questions that are answered incorrectly. so watch out for those. best of luck with your exam.
passed my exam today. this is a good start to 2023.
great sharing
very helpful
thanks.. very helpful
i registered for 1z0-1047-23 but dumps qre available for 1z0-1047-22. help me with this...
please upload oracle 1z0-1110-22 exam pdf
becoming interesting on the logical part of the cdbs and pdbs
some of the answers are incorrect, i would be wary of using this until an admin goes back and reviews all the answers
question # 267: federated operating model is also correct.
its helpful alot.
the questiosn from this braindumps are same as in the real exam. my passing mark was 84%.
it is an exam that measures your understanding of cloud computing resources provided by aws. these resources are aligned under 6 categories: storage, compute, database, infrastructure, pricing and network. with all of the services and typees of services under each category
good and very useful
i cleared the az-104 exam by scoring 930/1000 on the exam. it was all possible due to this platform as it provides premium quality service. thank you!
easy questions
could you please upload ad0-127 dumps
good content
understanding about joins
please upload oracle cloud infrastructure 2023 foundations associate exam braindumps. thank you.