Prepare For Realistic 300-620 Dumps PDF - 100% Passing Guarantee [Q108-Q129]

Share

Prepare For Realistic 300-620 Dumps PDF - 100% Passing Guarantee

Check the Available 300-620 Exam Dumps with 391 Q's

NEW QUESTION # 108
An engineer is in the process of discovering a new Cisco ACI fabric consisting of two spines and four leaf switches. The discovery of leaf 1 has just been completed. Which two nodes are expected to be discovered next? (Choose two.)

  • A. spine 1
  • B. spine 2
  • C. leaf 4
  • D. leaf 3
  • E. leaf 2

Answer: A,B


NEW QUESTION # 109
What must be enabled in the bridge domain to have the endpoint table learn the IP addresses of endpoints?

  • A. GARP based detection
  • B. L2 unknown unicast: flood
  • C. subnet scope
  • D. unicast routing

Answer: D


NEW QUESTION # 110
An engineer implements a configuration backup on the Cisco APIC. The backup job must meet these requirements:
- The backup must transfer the encrypted data to the remote server.
- The transfer must be resumed if the connection is interrupted
Which configuration set meets these requirements?

  • A. Select protocol HTTP in Create Remote Location.
    Choose JSON format in Configuration Export Policy.
  • B. Select protocol SFTP in Create Remote Location.
    Choose XML format in Configuration Export Policy.
  • C. Select protocol TFTP in Create Remote Location.
    Choose JSON format in Configuration Export Policy.
  • D. Select protocol FTP in Create Remote Location.
    Choose XML format in Configuration Export Policy.

Answer: B


NEW QUESTION # 111
Refer to the exhibit. All nodes in the Cisco ACI fabric have been statically assigned out-of-band management IP addresses in the 10.100.180.0/24 range. An engineer is attempting to SSH into Leaf101 using a laptop with an IP address of 10.101.180.100/24. Which configuration change must be performed to allow the engineer to SSH using the laptop?

  • A. Select the default QoS Class policy.
  • B. Add a contract filter to oobbrc-default that allows SSH.
  • C. Change the Leaf101 IP address to 10.101.180.101.
  • D. Change the allowed subnets.

Answer: D


NEW QUESTION # 112
Drag and drop the Cisco ACI filter entry options from the left onto the correct categories on the right indicating what are required or optional parameters.

Answer:

Explanation:


NEW QUESTION # 113
An engineer must configure a Layer 3 connection to the WAN router. The hosts in production VRF must access WAN subnets. The engineer associates EPGs in the production VRF with the external routed domain. Which action completes the task?

  • A. Configure the Export Route Control Subnet scope for the external EPG.
  • B. Configure the External Subnets for the External EPG scope for the external EPG.
  • C. Configure the Import Route Control Subnet scope for the external EPG.
  • D. Configure the Shared Route Control Subnet scope for the external EPG.

Answer: B


NEW QUESTION # 114
An engineer is implementing an out-of-band (OOB) management access for the Cisco ACI fabric. The secure access must meet these requirements:
* Only GUI and secure shell must be allowed to access the management interfaces of the ACIs.
* The only IP ranges that must be permitted to connect the fabric will be 10.10.10.0724 and 192.168.15.0/24.
Which configuration set meets these requirements?

  • A. Set up static IPs on the management interfaces from the required IP range. Add the required subnets to the external network instance profile.
  • B. Implement HTTPS and SSH protocol filters in the OOB contract. Add the required subnets to the external network instance profile.
  • C. Create an out-of-band EPG in the external management entity. Associate the management profile with the OOB contract.
  • D. Create an out-of-band EPG in the common tenant. Associate the external network instance profile with the OOB contract.

Answer: B

Explanation:
The engineer is implementing out-of-band (OOB) management access for the Cisco ACI fabric with the following requirements:
Only GUI (HTTPS) and Secure Shell (SSH) must be allowed to access the management interfaces.
Only IP ranges 10.10.10.0/24 and 192.168.15.0/24 must be permitted to connect.
This requires configuring access control and restricting IP ranges for OOB management.
Requirement Analysis
OOB management in ACI is typically handled via the Management Tenant (mgmt) and an OOB contract to define allowed protocols and sources.
The external network instance profile defines the permitted IP ranges for external access.
Option Evaluation
A . Implement HTTPS and SSH protocol filters in the OOB contract. Add the required subnets to the external network instance profile:
An OOB contract can specify allowed protocols (HTTPS on port 443 and SSH on port 22) to restrict access to GUI and SSH only. Adding the subnets 10.10.10.0/24 and 192.168.15.0/24 to the external network instance profile limits the source IP ranges, meeting both requirements.
Reference:
B . Create an out-of-band EPG in the external management entity. Associate the management profile with the OOB contract:
This approach creates an EPG for OOB management, but it does not specify protocol filters (HTTPS/SSH) or IP range restrictions. The management profile alone does not enforce these requirements.
C . Set up static IPs on the management interfaces from the required IP range. Add the required subnets to the external network instance profile:
Assigning static IPs to management interfaces is a configuration step, but it does not enforce protocol restrictions (HTTPS/SSH) or limit source IP ranges via a contract. This is incomplete.
D . Create an out-of-band EPG in the common tenant. Associate the external network instance profile with the OOB contract:
The common tenant can host an OOB EPG, but this option lacks explicit protocol filtering (HTTPS/SSH) and relies on the external network instance profile, which may not fully address the GUI/SSH restriction.
Final Answer Justification
A is correct because it directly addresses both requirements: using an OOB contract to filter HTTPS and SSH protocols and adding the specified subnets to the external network instance profile to restrict IP ranges.
Primary Cisco Reference:
Cisco APIC Management Tenant Configuration Guide, "OOB Management Access." Cisco ACI Security Guide, "Contract-Based Access Control."


NEW QUESTION # 115
Refer to the exhibit.

When the subnet is configured on a bridge domain, on which physical devices is the gateway IP address configured?

  • A. only spine switches where the bridge domain of the tenant is present
  • B. all leaf switches and all spine nodes
  • C. only leaf switches where the bridge domain of the tenant is present
  • D. all border leaf nodes where the bridge domain of the tenant is present

Answer: C

Explanation:
In Cisco Application Centric Infrastructure (ACI), when a subnet is configured on a bridge domain, the gateway IP address is configured on the leaf switches where the bridge domain of the tenant is present. This configuration allows for localized routing within the fabric, providing efficient east-west traffic handling without requiring traffic to traverse up to the spine nodes unless necessary for north-south routing or policy enforcement.
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_0111.html


NEW QUESTION # 116
Regarding the MTU value of MP-BGP EVPN control plane packets in Cisco ACI, which statement about communication between spine nodes in different sites is true?

  • A. By default, spine nodes generate 1500-bytes packets to exchange endpoints routing information. As a result, the Inter-Site network should be able to carry 1800-bytes packets.
  • B. By default, spine nodes generate 1500-bytes packets to exchange endpoints routing information. As a result, the Inter-Site network should be able to carry 1500-bytes packets.
  • C. By default, spine nodes generate 9000-bytes packets to exchange endpoints routing information. As a result, the Inter-Site network should be able to carry 9100-bytes packets.
  • D. By default, spine nodes generate 9000-bytes packets to exchange endpoints routing information. As a result, the Inter-Site network should be able to carry 9000-bytes packets.

Answer: C


NEW QUESTION # 117
An organization has encountered many STP-related issues in the past due to failed hardware components. They are in the process of long-term migration to a newly deployed ACI fabric. Senior engineers are worried that spanning-tree loops in the existing network may be extended to the ACI fabric. Which feature must be enabled on the ACI leaf ports to protect the fabric from spanning-tree loops?

  • A. Storm Control
  • B. BPDU Guard
  • C. BPDU Filter
  • D. per-VLANMCP

Answer: B

Explanation:
o protect the ACI fabric from spanning-tree loops, the feature that must be enabled on the ACI leaf ports is BPDU Guard


NEW QUESTION # 118
Refer to the exhibit A Cisco ACI fabric is using out-of-band management connectivity.
The APIC must access a routable host with an IP address of 192.168.11.2.
Which action accomplishes this goal?

  • A. Modify the Pod Profile to use the default Management Access Policy
  • B. Add a Fabric Access Policy to allow management connections.
  • C. Change the switch APIC Connectivity Preference to in-band management
  • D. Remove the in-band management address from the APIC.

Answer: D


NEW QUESTION # 119
A customer must deploy three Cisco ACI based data centers. Each site must be separated from the others. Which characteristic of Cisco ACI Multi-Pod makes it unsuitable for this deployment?

  • A. requires all pods to share the same Cisco APIC cluster
  • B. places leaf switches in the remote site that belong to the same fabric as at the headquarters site
  • C. creates a virtual pod in the remote location
  • D. has distance and scale limitations

Answer: A

Explanation:
The characteristic of Cisco ACI Multi-Pod that makes it unsuitable for deploying three separate data centers is that it requires all pods to share the same Cisco APIC cluster. In a Multi-Pod deployment, all the pods are part of the same fabric and are managed by a single APIC cluster, which means that they are not completely isolated from each other.


NEW QUESTION # 120
The company ESXi infrastructure is hosted on the Cisco UCS-B Blade Servers. The company decided to take advantage of ACI VMM integration to enable consistent enforcement of policies across virtual and physical workloads. The requirement is to prevent the packet loss between the distributed virtual switch and the ACI fabric. Which setting must be implemented on a vSwitch policy to accomplish this goal?

  • A. LACP
  • B. MAC Pinning
  • C. LLDP
  • D. Static Channel

Answer: B

Explanation:
Configure the vSwitch Policies on APIC for UCS B
... ... ...
Along with this, the only supported load balancing mechanism when UCS B series is used is Route Based on Originating Virtual Port.
If you configure a mac-pinning policy, it programs the port groups to use this mechanism. This is very important in order to prevent packet loss.
Reference:
https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/application-policy- infrastructure-controller-apic/118965-config-vmm-aci-ucs-00.html


NEW QUESTION # 121
A Cisco ACI environment consists of multiple silent hosts that are often relocated between leaf switches. When the host is relocated, the bridge domain takes more than a few seconds to relearn the host's new location. The requirement is to minimize the relocation impact and make the ACI fabric relearn the new location of the host faster. Which action must be taken to meet these requirements?

  • A. Configure ARP Flooding to Enabled.
  • B. Set Unicast Routing to Enabled.
  • C. Set L2 Unknown Unicast to Hardware Proxy.
  • D. Configure IP Data-Plane Learning to No.

Answer: D


NEW QUESTION # 122
A Cisco ACI fabric with an ARP packet must ensure detection of silent hosts with an ARP packet.
The current bridge domain is configured with hardware proxy and unicast routing. Which step must be taken on the bridge domain to complete the configuration?

  • A. Enable Flood in the bridge domain for Multi Destination Flooding.
  • B. Enable ARP Flooding in the bridge domain.
  • C. Set Optimized Flood for L3 Unknown Multicast.
  • D. Set L2 Unknown Unicast to Flood.

Answer: B


NEW QUESTION # 123
An engineer is implementing a Cisco ACI environment that consists of more than 20 servers. Two of the servers support only Cisco Discovery Protocol with no order link discovery protocol. The engineer wants the servers to be discovered automatically by the Cisco ACI fabric when connected. Which action must be taken to meet this requirement?

  • A. Configure a lower order policy group that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
  • B. Configure a higher order interface policy that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
  • C. Create an override policy that enables Cisco Discovery Protocol after LLDP is enabled in the default policy group.
  • D. Create an interface profile for the interface that disables LLDP on the desired switch that is referenced by the interface policy group.

Answer: B


NEW QUESTION # 124
Which components must be configured for the BGP Route Reflector policy to take effect?

  • A. leaf fabric interface overrides and profiles
  • B. access policies and profiles
  • C. pod policy groups and profiles
  • D. spine fabric interface overrides and profiles

Answer: C


NEW QUESTION # 125
What represents the unique identifier of an ACI object?

  • A. distinguished name
  • B. universal resource identifier (URI)
  • C. application programming interface
  • D. management information tree

Answer: A


NEW QUESTION # 126
An engineer is configuring ACI VMM domain integration with Cisco UCS-B Series. Which type of port channel policy must be configured in the vSwitch policy?

  • A. LACP Passive
  • B. MAC Pinning-Physical-NIC-load
  • C. MAC Pinning
  • D. LACP Active

Answer: C


NEW QUESTION # 127
Which method does the Cisco ACI fabric use to load-balance multidestination traffic?

  • A. shortest-path trees
  • B. PIM routing
  • C. spanning trees
  • D. forwarding tag trees

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci- fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_010010.html


NEW QUESTION # 128
Drag and drop the Cisco ACI filter entry options from the left onto the correct categories on the right indicating what are required or optional parameters.

Answer:

Explanation:

Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/ b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_01000.html


NEW QUESTION # 129
......

Download 300-620 Exam Dumps Questions to get 100% Success: https://www.pass4leader.com/Cisco/300-620-exam.html

100% Accurate Answers! 300-620 Actual Real Exam Questions: https://drive.google.com/open?id=1Myu29YneepypeSV3O0IjCRdju9zVoAtT