[May-2025] 100% Guarantee Download 300-620 Exam Dumps PDF Q&A
Kickstart your Career with Real Updated Questions
Cisco 300-620 exam covers various topics, including ACI fabric infrastructure, policies, access policies, endpoint groups, application profiles, and service graphs. Candidates are required to have a deep understanding of these concepts, as well as hands-on experience with the ACI platform. 300-620 exam consists of multiple-choice questions, simulation questions, and drag-and-drop questions, and it lasts for 90 minutes.
Achieving the Cisco 300-620 certification demonstrates an IT professional's expertise in implementing Cisco ACI solutions and validates their ability to design and manage complex data center environments. Implementing Cisco Application Centric Infrastructure certification is ideal for network administrators, network architects, and data center engineers who want to enhance their skills and advance their careers in the networking industry. The Cisco 300-620 exam is a comprehensive and challenging certification that requires thorough preparation and practical experience in ACI environments.
NEW QUESTION # 20
Which class of ACI object is presented in this output?
- A. Endpoint
- B. Tenant
- C. Contract
- D. Bridge Domain
Answer: B
Explanation:
In Cisco ACI, the object classes are used to categorize different types of managed objects within the ACI model. The output presented is indicative of a Tenant class object. Tenants in ACI are a top-level container for application policies, essentially providing a unit of isolation from other tenants. Each tenant can contain its own application policies, services, and network policies, and they are separate from other tenants to ensure multi-tenancy1.
Reference:
Cisco ACI Policy Model Guide1
Object Renaming in Cisco ACI - Cisco2
Application Centric Infrastructure (ACI) REST API Guide - Cisco DevNet
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/openstack/ACI-Installation-Guide-for-Red-Hat-Using-OSP13-Director/m-configuring-ironic-for-openstack.html
NEW QUESTION # 21
An engineer configured Layer 2 extension from the ACI fabric and changed the Layer 2 unknown unicast policy from Flood to Hardware Proxy. How does this change affect the flooding of the L2 unknown unicast traffic?
- A. It is forwarded to one of the spines to perform as a spine proxy.
- B. It is forwarded to one of the APICs to perform as a proxy.
- C. It is flooded within the whole fabric.
- D. It is dropped by the leaf when the destination endpoint is not present in the endpoint table.
Answer: A
NEW QUESTION # 22
Which two statements regarding ACI Multi-Site are true? (Choose two.)
- A. Routers in the Inter-Site network must run OSPF, DHCP relay, and MP-BGP.
- B. ACI Multi-Site is a solution that supports a dedicated APIC cluster per site.
- C. The Multi-Site orchestrator must be directly attached to one ACI leaf.
- D. ACI Multi-Site is a solution that allows one APIC cluster to manage multiple ACI sites.
- E. The Inter-Site network routers should run OSPF to establish peering with the spines.
Answer: B,E
NEW QUESTION # 23
What do Pods use to allow Pod-to-Pod communication in a Cisco ACI Multi-Pod environment?
- A. over Layer 3 Out connectivity via border leafs
- B. over Layer 3 directly connected back-to-back spines
- C. over Layer 3 IPN connectivity via border leafs
- D. over Layer 3 IPN connectivity via spines
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/w
NEW QUESTION # 24
Refer to the exhibit.
Refer to the exhibit. What must be configured in the service graph to redirect HTTP traffic between the EPG client and EPG server to go through the Cisco ASA firewall?
- A. permit-all contract filter
- B. contract with no filter
- C. precise filter to allow only HTTP traffic
- D. contract filter to allow ARP and HTTP.
Answer: D
NEW QUESTION # 25
Refer to the exhibit.
Which two objects are created as a result of the configuration? (Choose two.)
- A. application profile
- B. VRF
- C. endpoint group
- D. bridge domain
- E. attachable AEP
Answer: B,D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/rest_cfg/2_1_x/ b_Cisco_APIC_REST_API_Configuration_Guide/ b_Cisco_APIC_REST_API_Configuration_Guide_chapter_01110.html
NEW QUESTION # 26
Refer to the exhibit.
Which two configurations enable inter-VRF communication? (Choose two.)
- A. Enable Advertise Externally under the subnet scope.
- B. Export the contract and import as a contract interface.
- C. Set the subnet scope to Shared Between VRFs.
- D. Change the subject scope to VRF.
- E. Change the contract scope to Tenant.
Answer: A,B
NEW QUESTION # 27
An engineer is configuring a VRF for a tenant named Cisco. Drag and drop the child objects on the left onto the correct containers on the right for this configuration.
Answer:
Explanation:
NEW QUESTION # 28
An endpoint called EP1 is connected to Cisco ACI compute leaf1. The engineer must replace EP1 with EP2 on the same leaf switch. Which set of actions forces all remote leaves to delete EP1 before timer expiration?
- A. Set L2 Unknown Unicast to Flood.
Select Clear remote IP entries. - B. Set L2 Unknown Unicast to Flood.
Select Clear remote MAC entries. - C. Set L2 Unknown Unicast to Hardware proxy.
Select Clear remote MAC entries. - D. Set L2 Unknown Unicast to Hardware Proxy.
Select Clear remote IP entries.
Answer: B
Explanation:
When the bridge domain has L2 Unknown Unicast set to Flood, if an endpoint is deleted the system deletes it from both the local leaf switches as well as the remote leaf switches where the bridge domain is deployed, by selecting Clear Remote MAC Entries. Without this feature, the remote leaf continues to have this endpoint learned until the timer expires.
NEW QUESTION # 29
Which action sets Layer 2 loop migration in an ACI Fabric with a Layer 2 Out configured?
- A. Enable MCP on the ACI fabric.
- B. Disable STP in the external network.
- C. Disable STP on the ACI fabric.
- D. Enable STP on the ACI fabric.
Answer: A
Explanation:
To set Layer 2 loop migration in an ACI Fabric with a Layer 2 Out configured, MCP (Misconfiguration Protocol) must be enabled on the ACI fabric56. MCP helps to prevent Layer 2 loops by detecting misconfigurations that could potentially cause loops56.
NEW QUESTION # 30
A Solutions Architect is asked to design two data centers based on Cisco ACI technology that can extend L2/ L3, VXLAN, and network policy across locations. ACI Multi-Pod has been selected. Which two requirements must be considered in this design? (Choose two.)
- A. A single APIC Cluster is required in a Multi-Pod design. It is important to place the APIC Controllers in different locations in order to maximize redundancy and reliability.
- B. ACI Multi-Pod requires an IP Network supporting PIM-Bidir.
- C. ACI underlay protocols, i.e. COOP, IS-IS and MP-BGP, spans across pods. Create QoS policies to make sure those protocols have higher priority.
- D. Multi-Pod requires multiple APIC Controller Clusters, one per pod. Make sure those clusters can communicate to each other through a highly available connection.
- E. ACI Multi-Pod does not support Firewall Clusters across Pods. Firewall Clusters should always be local.
Answer: C,D
Explanation:
Section: ACI Anywhere
NEW QUESTION # 31
On which two interface types should a user configure storm control to protect against broadcast traffic? (Choose two.)
- A. endpoint-facing trunk interface
- B. port channel on a single leaf switch
- C. all interfaces on the leaf switches in the fabric
- D. fabric uplink interfaces on the leaf switches
- E. APIC facing interfaces
Answer: A,B
Explanation:
Typically, a fabric administrator configures storm control in fabric access policies on the following interfaces:
A regular trunk interface.
A direct port channel on a single leaf switch.
A virtual port channel (a port channel on two leaf switches).
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2- x/L2_config/b_Cisco_APIC_Layer_2_Configuration_Guide/ b_Cisco_APIC_Layer_2_Configuration_Guide_chapter_01010.html
NEW QUESTION # 32
Which two types of interfaces are supported on border leaf switches to connect to an external router? (Choose two.)
- A. FEX host interface
- B. out of band interface
- C. subinterface with VXLAN tagging
- D. Switch Virtual Interface
- E. subinterface with 802.1Q tagging
Answer: D,E
NEW QUESTION # 33 
Refer to the exhibit. An engineer is integrating a VMware vCenter with Cisco ACI VMM domain configuration.
ACI creates port-group names with the format of "Tenant | Application | EPG". Which configuration option is used to generate port groups with names formatted as "Tenant=Application=EPG"?
- A. virtual switch name
- B. delimiter
- C. enable tag collection
- D. security domains
Answer: A
Explanation:
Section: Integrations
NEW QUESTION # 34
Refer to the exhibit.
Refer to the exhibit. A Cisco ACI fabric displays this fault. Which set of actions modifies the event to be displayed as a warning in the future?
- A. Navigate to the ACI Fault tab.
Create a new record. - B. Navigate to the ACI Events tab.
Change the severity level. - C. Navigate to the ACI Fault tab.
Change the severity level. - D. Navigate to the ACI Events tab.
Create a new record.
Answer: B
NEW QUESTION # 35
How is broadcast forwarded in Cisco ACI Multi-Pod after ARP flooding is enabled?
- A. Broadcast frames are forwarded inside the pod and across the IPN using the multicast address that is associated to the bridge domain.
- B. For the specific bridge domain, all spines forward the broadcast frames to IPN routers.
- C. Ingress replication is used on the spines to forward broadcast frames in the IPN infrastructure.
- D. Within a pod, the ingress leaf switch floods the broadcast frame on all fabric ports.
Answer: A
Explanation:
After ARP flooding is enabled in Cisco ACI Multi-Pod, broadcast frames are forwarded within the pod and across the Inter-Pod Network (IPN) using the multicast address associated with the bridge domain. If the setting is 'Flood', the leaf switch floods to the Group IP (GIPo) multicast group allocated for the bridge domain, ensuring that both local and remote pods receive a flooded copy
NEW QUESTION # 36
Refer to the exhibit. A customer must back up the current Cisco ACl configuration securely to the remote location using encryption and authentication. The backup job must run once per day. The customer s security policy mandates that any sensitive information including passwords, must not be exported from the device. Which set of steps meets these requirements?
- A. Export destination using SCP protocol.
Disable Global AES Encryption. - B. Export destination using FTP protocol.
Use XML format. - C. Export destination using SCP protocol.
Use XML format. - D. Export destination using FTP protocol.
Disable Global AES Encryption.
Answer: A
NEW QUESTION # 37
A network engineer configures the Cisco ACI fabric to connect to vCenter with these requirements:
Port groups must be automatically created on the distributed virtual switch.
Port groups must use the VLAN allocation in the range between 20-30.
The deployment must optimize the CAM space on the leaf switches.
Which set of actions meets these criteria?
- A. Create a dynamic VLAN pool with the VLAN range of 20-30.
Create a physical domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to On Demand. - B. Create a static VLAN pool with the VLAN range of 20-30.
Create a physical domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to Immediate. - C. Create a dynamic VLAN pool with the VLAN range of 20-30.
Create a VMM domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to On Demand. - D. Create a static VLAN pool with the VLAN range of 20-30.
Create a VMM domain and associate it with the VLAN pool.
Create the EPG and associate the domain.
Set the deployment immediacy to Immediate.
Answer: C
NEW QUESTION # 38
A situation causes a fault to be raised on the APIC. The ACI administrator does not want that fault to be raised because it is not directly relevant to the environment. Which action should the administrator take to prevent the fault from appearing?
- A. Under System -> Faults, right-click on the fault and select Acknowledge Fault so that acknowledged faults will immediately disappear.
- B. Create a new global health score policy that ignores specific faults as identified by their unique fault code.
- C. Under System -> Faults, right-click on the fault and select Ignore Fault to create a fault severity assignment policy that hides the fault.
- D. Create a stats threshold policy with both rising and falling thresholds defined so that the critical severity threshold matches the squelched threshold.
Answer: C
NEW QUESTION # 39
When a pre-provision immediacy is used, when is the policy downloaded to the Cisco ACI leaf switch?
- A. The policy is programmed in the hardware policy CAM when the policy is downloaded in the leaf software.
- B. The policy is downloaded and programmed in the hardware policy CAM when the change is implemented on the Cisco APIC.
- C. The policy is downloaded to the associated leaf switch software when the ESXi host is attached to a DVS.
- D. The policy is programmed in the hardware policy CAM when the first packet is received through the data path.
Answer: B
NEW QUESTION # 40
A network engineer must allow secure access to the Cisco ACl out-of-band (OOB) management only from external subnets 10 0 0024 and 192.168 20 G'25. Which configuration set accomplishes this goal?
- A. Option C
- B. Option A
- C. Option B
- D. Option D
Answer: A
Explanation:
To enable the APIC in a Cisco ACI fabric using out-of-band management connectivity to access a routable host with an IP address of 192.168.11.2, you need to add a Fabric Access Policy that allows management connections. This involves configuring a contract that will be consumed and provided to your OOB devices. The contract will let the system know what traffic is allowed. In this case, you will use the default/common contract to permit any traffic. This is necessary because the APIC needs to be able to send traffic to and receive traffic from the management network1.
Reference:
ACI: Configuring Out-of-Band (OOB) Access for Your Fabric - Cisco1
Troubleshoot ACI Management and Core Services - In-band and Out-of-band Management - Cisco2
NEW QUESTION # 41
An engineer must securely export Cisco APIC configuration snapshots to a secure, offsite location The exported configuration must be transferred using an encrypted tunnel and encoded with a platform-agnostic data format that provides namespace support Which configuration set must be used?
- A. Option A
- B. Option D
- C. Option C
- D. Option B
Answer: D
Explanation:
To securely export Cisco APIC configuration snapshots to a secure, offsite location using an encrypted tunnel and a platform-agnostic data format that provides namespace support, the following configuration set must be used:
Choose a Platform-Agnostic Data Format: Export the configuration in a data format like JSON or XML, which are platform-agnostic and support namespaces1.
Use an Encrypted Tunnel: Transfer the configuration snapshot over a secure protocol such as SFTP or SCP, which provides an encrypted tunnel for the data transfer1.
Schedule the Export: Set up a scheduled export of the configuration in the Cisco APIC to occur at regular intervals, ensuring the process is automated1.
Enable Encryption: Make sure the configuration export policy includes encryption settings. Cisco APIC supports AES-256 encryption for securing exported configuration files2.
Verify Namespace Support: Ensure that the chosen data format and the method of export support the use of namespaces, which are essential for organizing elements and attributes in XML documents1.
By following these steps and choosing Option B, the engineer can meet the requirements for securely exporting Cisco APIC configuration snapshots to an offsite location.
NEW QUESTION # 42
Refer to the exhibit. A company decided to decrease its routing footprint and remove RT-2 and RT-3 devices from its data center. Because of that, the exit point must be created from all the tenants by using the common tenant. Which two configuration tasks must be completed to meet these requirements? (Choose two.)
- A. Export contract Ctr-2 into the tenant TN-1 and attach it as a consumer to all the EPGs in the tenant TN-1.
- B. Change contract Ctr-3 scope to Global, consume it by all EPGs, and flag all subnets with flag Shared between VRFs.
- C. Update the L3Out ExtEPG subnet in the common tenant with flag Shared Route Control Subnet and Aggregate Shared Routes.
- D. Mark all subnets with flag Shared between VRFs and attach contract Ctr-3 as a provider to all the EPGs.
- E. Move subnets from all the bridge domains to the EPG level and mark them with flag Shared between VRFs.
Answer: B,C
NEW QUESTION # 43
An engineer is troubleshooting fabric discovery in a newly deployed Cisco ACI fabric and analyzes this output:
Which ACI fabric address is assigned to interface lo1023?
- A. Fabric tunnel endpoint
- B. VXLAN tunnel endpoint
- C. Physical tunnel endpoint
- D. Dynamic tunnel endpoint
Answer: A
Explanation:
In Cisco ACI, the interface lo1023 is assigned as a fabric tunnel endpoint (FTEP). This is a pervasive address found on every leaf and it's always the same. It is used mostly for AVS (Application Virtual Switch) when the infra VXLAN is extended out of the fabric1. The FTEP is crucial for the internal operation of the fabric, particularly for scenarios where the infrastructure VXLAN needs to be extended outside of the ACI fabric.
Reference:
Default IP interfaces on Fabric nodes - Cisco Community1
NEW QUESTION # 44
Which setting prevents the learning of Endpoint IP addresses whose subnet does not match the bridge domain subnet?
- A. "Limit IP learning to subnet" setting within the EPG.
- B. "Limit IP learning to subnet" setting within the bridge domain.
- C. "Limit IP learning to network" setting within the EPG.
- D. "Limit IP learning to network" setting within the bridge domain.
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/L2_config/ b_Cisco_APIC_Layer_2_Configuration_Guide/ b_Cisco_APIC_Layer_2_Configuration_Guide_chapter_010.html
NEW QUESTION # 45
......
Earn Quick And Easy Success With 300-620 Dumps: https://www.trainingdump.com/Cisco/300-620-practice-exam-dumps.html
Top-Class 300-620 Question Answers Study Guide: https://drive.google.com/open?id=1QduGrpPUKmgVZ-l5BrislIE4Ru69Zaf7