An engineer must configure SNMP inside a Cisco ACI fabric. The engineer has created an SNMP Policy, called SNMP-policy and an SNMP Monitoring Group called SNMP-group1 that contains five trap receivers. Which configuration set completes the configuration?
-
A
Permit OOB management traffic using UDP port 161. Associate client group policy with the OOB management EPG.
-
B
Edit oobbrc to permit traffic using UDP port 16. Associate the client group policy to SNMP-group1.
-
C
Create an OOB management contract. Include the SNMP server in the OOB management EPG.
-
D
Allow all OOB management traffic. Configure three trap receivers on SNMP-group1.
Reveal answer details
Close answer details
Correct answerA
Explanation1) Ports 161 and 162 2) Fabric Policies > Policies > Pod > SNMP > default > Client Group Policies > Create SNMP Client Group
Profile > define Name and select Associated Management EPG
Question 2
Multiple choice
Refer to the exhibit.   A syslog service was configured to capture different faults and events from a Cisco ACI tenant. The Cisco ACI fabric is missing any OOB capability. After some time, the administrator noticed that the syslog messages were not present on the APIC. Which two actions complete the configuration? (Choose two.)
-
A
Change forwarding facility to local1.
-
B
Ping the syslog server from the APIC.
-
C
Reconfigure the UDP port settings.
-
D
Change the minimum severity levels.
-
E
Set the management EPG to default.
Reveal answer details
Close answer details
Correct answersC, D
ExplanationUDP Port 514 When using Inband management for your ACI Fabric, the Inband management EPG DOES require the specific UDP Port 514 (Syslog) to be enabled. The severity level is set to Alert which is level 1. This would exclude levels 2-7.
Refer to the exhibit.  A customer is deploying a WAN with these requirements: 1. Routers 1 and 2 must receive only routes 192.168.11.0/24 and 192.168.21.0/24 from the Cisco ACI fabric. 2. Reachability to the WAN users must be permitted only for the servers that are located in vrf_prod. Which settings must be configured to meet these objectives?
-
A
Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF. Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet.
-
B
Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF. Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG.
-
C
Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally. Configure the subnet 192.168.31.0/24 as Private to VRF. Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG.
-
D
Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally. Configure the subnet 192.168.31.0/24 as Private to VRF. Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet.
Reveal answer details
Close answer details
An engineer configures SNMP for an ACI fabric and created an SNMP Monitoring Destination Group called snmp_dgroup1. Snmp_dgroup1 is configured with the server hostname and community password. An SNMP policy called snmp_podpolicy1 is configured to enable SNMP and add an SNMP Client Group Profile called snmp_clgroup1. Snmp_podpolicy1 is associated the default pod profile via a pod policy group named pod1. Which configuration set must the engineer enable to complete the SNMP configuration?
-
A
Configure the OOB management contract to permit UDP 162. Associate snmp_dgroup1 with the OOB management EPG.
-
B
Configure an SNMP management contract to permit all traffic. Associate snmp_podpolicy1 with an SNMP pod profile.
-
C
Configure an SNMP management contract to permit UDP 162. Associate the SNMP Source to snmp_clgroup1.
-
D
Configure the OOB management contract to permit all traffic. Associate snmp_clgroup1 with the SNMP management EPG.
Reveal answer details
Close answer details
An engineer plans to integrate a Cisco ACI fabric with VMware vCenter DVS. Which set of actions must the engineer take to ensure a successful integration?
-
A
Set a vCenter controller named ACI-VMware-Integration and select Read Only Access mode.
-
B
Set a vCenter controller named ACI-VMware-Integration and select Read Write Access mode.
-
C
Set a virtual switch named ACI-VMware-Integration and select Read Write Access mode.
-
D
Set a virtual switch named ACI-VMware-Integration and select Read Only Access mode.
Reveal answer details
Close answer details
A Cisco ACI fabric with many dual-homed servers connected through VPC pairs must be upgraded with minimal traffic impact. Which upgrade preparation step is recommended for the leaf switches?
-
A
place all leaf switches in one maintenance group
-
B
divide leaf switches into two or more maintenance groups
-
C
upgrade all APICs after the leafs
-
D
disable VPC before the upgrade
Reveal answer details
Close answer details
Correct answerB
ExplanationThe correct answer is B because dividing leaf switches into two or more maintenance groups minimizes traffic impact in environments with VPC-connected endpoints. Option A is incorrect because upgrading all leafs together increases risk and disruption. Option C is incorrect because leaf grouping, not APIC sequencing alone, is the key preparation step described. Option D is incorrect because disabling VPC is not the recommended approach for minimizing impact during the upgrade.
A network engineer must integrate VMware vCenter cluster with Cisco ACI. The requirement is for the management traffic of the hypervisors and VM controllers to use the virtual switch associated with the Cisco Application Policy. The EPG called "Vmware-MGMT" with VLAN 300 has been created for this purpose. Which set of steps must be taken to complete the configuration?
-
A
Add VLAN 300 with static allocation to the VLAN POOL that is used for VMM integration. Attach the VMM domain to the target EPG with resolution preprovision, mode static, untagged access VLAN, and Port-Encap 300.
-
B
Associate the target EPG with the VMM domain with default settings. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
-
C
Enable Infrastructure VLAN on AAEP used toward VMware hypervisors. Associate the target EPG with the VMM domain with default settings.
-
D
Enable Infrastructure VLAN on AAEP used toward VMware hypervisors. Create a static binding in the target EPG toward VMware hypervisors with VLAN 300, untagged access VLAN, and Untagged 802.1P mode.
Reveal answer details
Close answer details
A customer must deploy three Cisco ACI based data centers. Each site must be separated from the others. Which characteristic of Cisco ACI Multi-Pod makes it unsuitable for this deployment?
-
A
creates a virtual pod in the remote location
-
B
requires all pods to share the same Cisco APIC cluster
-
C
has distance and scale limitations
-
D
places leaf switches in the remote site that belong to the same fabric as at the headquarters site
Reveal answer details
Close answer details
Correct answerB
ExplanationThe Cisco® Application Centric Infrastructure (Cisco ACI™) Multi-Pod solution is an evolution of the stretched-fabric use case. Multiple pods provide intensive fault isolation in the control plane along with infrastructure cabling flexibility. As the name indicates, it connects multiple Cisco Application Policy Infrastructure Controller (APIC) pods using a Layer 3 interpod network (IPN). Note: Pod spine switches cannot be connected back to back. IPN supports only Open Shortest Path First (OSPF) connectivity between the IPN and the spine switches. Though each pod consists of its own spine and leaf switches, all the pods reside within the same fabric and are managed by a single APIC cluster. This approach provides a single management and policy domain across all pods for end-to-end policy enforcement. In the data plane, the Multi-Pod solution uses Multiprotocol Border Gateway Protocol (MP-BGP) Ethernet Virtual Private Network (EVPN) connectivity over the IPN between the spine switches from each pod for communication using Virtual Extensible LAN (VXLAN) encapsulation.
Refer to the exhibit.  A tenant is configured with a single L3Out and a single-homed link to the core router called Core-1. An engineer must add a second link to the L3Out that connects to the Core-2 router. Which action allows traffic from Core-2 to BL-1002 to have the same connectivity as the traffic from Core-1 to BL-1001?
-
A
Add a second OSPF interface profile to the logical interface profile.
-
B
Add a second interface to the external domain to the existing L3Out.
-
C
Add a second path to the logical interface profile of the existing L3Out.
-
D
Add a second subnet to the external EPG to the existing L3Out.
Reveal answer details
Close answer details
Question 10
Single choice
Refer to the exhibit.  An application called App_1 is hosted on the server called S1. A silent host application, App_2, is hosted on S2. Both applications use the same VLAN encapsulation. Which action forces Cisco ACI fabric to learn App_2 on ACI leaf 2?
-
A
Set Unicast Routing to Hardware Proxy.
-
B
Set L2 Unknown Unicast to Flood.
-
C
Set L3 Unknown Multicast to Optimized flood.
-
D
Set Multi-Destination Flooding to Drop.
Reveal answer details
Close answer details
Question 11
Single choice
Refer to the exhibit.  A load balancer is connected to the Cisco ACI fabric using a single interface. The load balancer is performing source and destination NAT. A service graph is configured on the Cisco ACI. Which action must be taken to allow traffic from host A to pass through the load balancer before reaching host B?
-
A
Apply PBR on contract between the load balancer and application EPGs.
-
B
Disable unicast routing on the bridge domain BD_2.
-
C
Configure limit IP learning to subnet on BD_3.
-
D
Set the default gateway for host B on the load balancer.
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739971.html
Question 12
Single choice
Refer to the exhibit.  A network engineer must configure a user tenant to raise the error shown when configuring a new EPG. Which action accomplishes this goal?
-
A
From Access Policies, set Exceed Action to Fail Transaction Action.
-
B
From Fabric Policies, set Exceed Action to Fail Transaction Action.
-
C
From Access Policies, set Exceed Action to Raise Fault Action.
-
D
From Fabric Policies, set Exceed Action to Raise Fault Action.
Reveal answer details
Close answer details
Question 13
Multiple choice
An engineer must perform a Cisco ACI fabric upgrade that minimizes the impact on user traffic and allows only permitted users to perform an upgrade. Which two configuration steps should be taken to meet these requirements? (Choose two.)
-
A
Grant tenant-ext-admin access to a user who performs an upgrade
-
B
Divide Cisco APIC controllers into two or more maintenance groups
-
C
Combine all switches into an upgrade group
-
D
Grant the fabric administrator role to a user who performs an upgrade
-
E
Divide switches into two or more maintenance groups
Reveal answer details
Close answer details
Question 14
Single choice
Refer to the exhibit.  An engineer created a local user named User on Cisco ACI. The engineer must configure the fabric so that the User can access only common and PROD tenants. Which set of actions accomplishes the goal?
-
A
Add security domain "mgmt." to User. Associate security domain "mgmt." under PROD tenant.
-
B
Add security domain "Tenant" to User. Associate security domain "Tenant" under PROD tenant.
-
C
Add security domain "all" to User. Associate security domain "all" under PROD tenant
-
D
Add security domain "common" to User. Associate security domain "common" under PROD tenant.
Reveal answer details
Close answer details
Question 15
Single choice
An engineer is extending an EPG out of the ACI fabric using static path binding. Which statement about the endpoints is true?
-
A
Endpoints must connect directly to the ACI leaf port.
-
B
External endpoints are in a different bridge domain than the endpoints in the fabric.
-
C
Endpoint learning encompasses the MAC address only.
-
D
External endpoints are in the same EPG as the directly attached endpoints.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe user can extend an EPG beyond an ACI leaf by statically assigning a leaf port (along with a VLAN ID) to an EPG. After doing so, all the traffic received on this leaf port with the configured VLAN ID will be mapped to the EPG and the configured policy for this EPG will be enforced. The endpoints need not be directly connected to the ACI leaf port. They can be behind a layer 2 network as long as the VLAN associated with the EPG is enabled within the layer 2 network that connects the remote endpoint to the ACI fabric.
Question 16
Single choice
A data center administrator is upgrading an ACI fabric. There are 3 APIC controllers in the fabric and all the servers are dual-homed to pairs of leaf switches configured in VPC mode. How should the fabric be upgraded to minimize possible traffic impact during the upgrade?
-
A
1. Create two maintenance groups for the APIC controllers: VPC left and VPC right. 2. Upgrade the first group of controllers. 3. Upgrade the second group of controllers. 4. Upgrade the leaf switches.
-
B
1. Create two maintenance groups for APIC controllers: VPC left and VPC right. 2. Upgrade the leaf switches. 3. Upgrade the first group of controllers. 4. Upgrade the second group of controllers.
-
C
1. Create two maintenance groups for the leaf switches: VPC left and VPC right. 2. Upgrade the APIC controllers. 3. Upgrade the first group of leaf switches. 4. Upgrade the second group of leaf switches.
-
D
1. Create two maintenance groups for the leaf switches: VPC left and VPC right. 2. Upgrade the first group of switches. 3. Upgrade the second group of switches. 4. Upgrade the APIC controllers.
Reveal answer details
Close answer details
Correct answerC
ExplanationRecommended by Cisco TAC and the Cisco Consultant that was helping us upgrade ACI to upgrade the APIC first and than the Fabric with Minimum of two groups VPC1 and VPC2.
Question 17
Single choice
Refer to the exhibit.  An engineer configured this node control policy and these ACI objects: 1. leaf policy group named ACI_Leaf_PolGrp. 2. leaf switches profile named ACI_Leaf_NodeProf. 3. node control policy named ACI_Pal_Node_Ctrl. Which association set must be used to apply ACI_Pal_Node_Ctrl on Node-2001?
-
A
SWNFV1ACIPAL to ACI_Leaf_PolGrp ACI_Leaf_PolGrp to ACI_Leaf_NodeProf SWNFV1ACIPAL to Node-2001
-
B
ACI_Pal_Node_Ctrl to SWNFV1ACIPAL ACI_Leaf_PolGrp to Node-2001 ACI_Pal_Node_Ctrl to ACI_Leaf_NodeProf
-
C
ACI_Pal_Node_Ctrl to ACI_Leaf_PolGrp ACI_Leaf_PolGrp to Node-2001 SWNFV1ACIPAL to ACI_Leaf_NodeProf
-
D
ACI_Pal_Node_Ctrl to ACI_Leaf_PolGrp ACI_Pal_Node_Ctrl to Node-2001 SWNFV1ACIPAL to ACI Leaf PolGrp
Reveal answer details
Close answer details
Question 18
Multiple choice
Refer to the exhibit.  Which two objects are created as a result of the configuration? (Choose two.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answersC, E
ExplanationConfigure the tenant, VRF, and bridge domain. This example configures tenant t1 with VRF v1 and bridge domain bd1. The tenant, VRF, and BD are not yet deployed. Example: <fvTenant name="t1">
<fvCtx name="v1"/>
<fvBD name="bd1">
<fvRsCtx tnFvCtxName="v1"/>
<fvSubnet ip="44.44.44.1/24" scope="public"/>
<fvRsBDToOut tnL3extOutName="l3out1"/>
</fvBD>/>
</fvTenant>
Question 19
Single choice
As part of a migration, legacy non-ACI switches must be connected to the Cisco ACI fabric. All non-ACI switches run per-VLAN RSTP. After the non-ACI switches are connected to Cisco ACI, the STP convergence caused a microloop and significant CPU spike on all switches. Which configuration on the interfaces of the external switches that face the Cisco ACI fabric resolves the problem?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
A Cisco ACI fabric is integrated with VMware VDS. The fabric must apply a security policy to check the integrity of traffic out of the network adapter. Which action must be taken to drop the packet when the ESXi host discovers a mismatch between the actual source MAC address transmitted by the guest operating system and the effective MAC address of the virtual machine adapter?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
What is the result of the pcEnPref flag configured on the epg-App_EPG? 
-
A
Any configuration changes to the private network are validated.
-
B
Access control rules for the L3Out network are applied.
-
C
Access control rules for the private network are applied.
-
D
Any changes to the underlying EPG objects are forbidden.
Reveal answer details
Close answer details
Question 22
Single choice
Which switch type is discovered first in the Cisco ACI fabric discovery process?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Single choice
An engineer configured a bridge domain with the hardware-proxy option for Layer 2 unknown unicast traffic. What occurs in this configuration?
-
A
The leaf switch drops the Layer 2 unknown unicast packet if it is unable to find the MAC address in the local forwarding tables.
-
B
The Layer 2 unknown hardware proxy lacks support of the topology change notification.
-
C
The leaf switch forwards the Layers 2 unknown unicast packets to all other leaf switches if it is unable to find the MAC address in its local forwarding tables.
-
D
The spine switch drops the Layer 2 unknown unicast packet if it is unable to find the MAC address in the COOP database.
Reveal answer details
Close answer details
Correct answerD
ExplanationWhen using hardware-proxy, you should consider enabling unicast routing and defining a subnet on the bridge domain. This is because with hardware-proxy on, if a MAC address has been aged out in the spine switch-proxy, traffic destined to this MAC address is dropped. References: https://www.cisco.com/c/en/us/td/docs/dcn/whitepapers/cisco-application-centric-infrastructure-design-guide.html#Usinghardwareproxytoreduceflooding
Question 24
Single choice
An engineer must limit management access to the Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?
-
A
policy in the management tenant
-
B
ACL on the console interface
-
C
ACL on the management interface of the APIC
-
D
policy on the management VLAN
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/cli/nx/cfg/b_APIC_NXOS_CLI_User_Guide/b_APIC_NXOS_CLI_User_Guide_chapter_01000.html
Question 25
Single choice
A customer migrates a legacy environment to Cisco ACI. A Layer 2 trunk is configured to interconnect the two environments. The customer also builds ACI fabric in an application-centric mode. Which feature should be enabled in the bridge domain to reduce instability during the migration?
-
A
Set Multi-Destination Flooding to Flood in BD.
-
B
Enable Flood in Encapsulation.
-
C
Set Multi-Destination Flooding to Flood in Encapsulation.
-
D
Disable Endpoint Dataplane Learning
Reveal answer details
Close answer details
Correct answerC
ExplanationQuite a few engineers have asked whether multiple EPGs associated with a single bridge domain can be extended to non-ACI switches outside a fabric. The answer is yes. Among the options for Multi Destination Flooding, administrators can choose Flood in Encapsulation at the bridge domain level to isolate flooding to each associated EPG. In the context of migrations, the use case many proponents of this feature have in mind is to consolidate multiple VLANs and subnets into a small number of bridge domains.
Question 26
Single choice
An engineer has set the VMM resolution immediacy to pre-provision in a Cisco ACI environment. No Cisco Discovery Protocol neighborship has been formed between the hypervisors and the ACI fabric leaf nodes. How does this affect the download policies to the leaf switches?
-
A
No policies are downloaded because LLDP is the only supported discovery protocol.
-
B
Policies are downloaded when the hypervisor host is connected to the VMM VDS.
-
C
Policies are downloaded to the ACI leaf switch regardless of Cisco Discovery Protocol neighborship.
-
D
No policies are downloaded because there is no discovery protocol neighborship.
Reveal answer details
Close answer details
Correct answerC
ExplanationPre-provision-Specifies that a policy (for example, VLAN, VXLAN binding, contracts, or filters) is downloaded to a leaf switch even before a VM controller is attached to the virtual switch (for example, VMware VDS). This pre-provisions the configuration on the switch. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_01011.html
Question 27
Single choice
A Cisco ACI fabric is configured with these objects: login domain named Domain_1 TACACS+ provider group named Tacacs_ProvGro TACACS+ server IP 10.43.145.1 Which action set allows users to log in to Cisco APIC using TACACS user credentials without setting the domain to Domain_1 for each login?
-
A
Add IP 10.43.145.1 under Tacacs_ProvGro. Associate Tacacs_ProvGro to Domain_1. Set realm to TACACS+ under default AAA authentication.
-
B
Add IP 10.43.145.1 under default AAA authentication. Associate Tacacs_ProvGro to Domain_1. Set realm to local under Tacacs_ProvGro.
-
C
Add IP 10.43.145.1 under Tacacs_ProvGro. Associate Tacacs_ProvGro to default AAA authentication. Set realm to TACACS+ under default AAA authentication.
-
D
Add IP 10.43.145.1 under Domain_1. Associate Tacacs_ProvGro to Domain_1. Set realm to local under default AAA authentication.
Reveal answer details
Close answer details
Question 28
Single choice
Refer to the exhibit.  An engineer is migrating legacy servers into the Cisco ACI environment. The requirement is to ensure that all endpoints and MAC addresses are learned properly in legacy and Cisco ACI switches. Which configuration set must be configured under the bridge domain called bd_360 to accomplish this goal?
-
A
L2 Unknown Unicast: Hardware Proxy ARP Flooding: Disabled
-
B
L2 Unknown Unicast: Flood - ARP Flooding: Enabled
-
C
L2 Unknown Unicast: Hardware Proxy ARP Flooding: Enabled
-
D
L2 Unknown Unicast: Flood - ARP Flooding: Disabled
Reveal answer details
Close answer details
Correct answerB
ExplanationARP HW proxy is not suited for this scenario as the routing is outside ACI
Question 29
Multiple choice
An engineer must add new servers to a Cisco ACI cluster and configure ports to accept the new servers. The existing servers are dual-homed to Leaf101 and Leaf102 using ports 1-3 and an interface policy group called cluster1_ifpg. The new servers must use ports 1 and 2 on Leaf103 and Leaf104. Which two actions must be taken to enable the ports with the same configuration as the existing servers in the cluster? (Choose two.)
-
A
Attach interface selectors to leaf profiles Leaf103 and Leaf104.
-
B
Use interface selector for cluster1_infpg.
-
C
Connect with interface selector using a new AEP.
-
D
Configure interface selector using a new interface policy group.
-
E
Select ports 1 and 2 using interface selectors.
Reveal answer details
Close answer details
Question 30
Single choice
Refer to the exhibit.  An engineer migrates a legacy data center to a new Cisco ACI fabric. The new deployment must raise a fault if a Layer 2 loop is detected from the external networking devices. Due to the large number of workloads still running on the legacy network, the interconnection links must not be disabled. The engineer has already enabled the MCP globally. Which configuration completes the configuration?
-
A
Disable Loop Protection Action on MCP global policy.
-
B
Enable MCP in the interconnection links.
-
C
Configure MCP on all the legacy extended VLANs.
-
D
Implement MCP PDU per VLAN on the legacy-facing interfaces.
Reveal answer details
Close answer details
Question 31
Multiple choice
Which two components are essential parts of a Cisco ACI Virtual Machine Manager (VMM) domain policy configuration? (Choose two.)
-
A
Layer 3 outside interface association
-
B
-
C
-
D
-
E
IP address pool association
Reveal answer details
Close answer details
Correct answersC, D
ExplanationReferences: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_01011.html
Question 32
Single choice
A Cisco ACI environment is configured to integrate with a vCenter environment using the VMM domain name west_coast_VMM. Within the ACI environment, only tenant west_coast has EPGs associated with west_coast_VMM. This deployment is new, so these EPGs currently do not have any members. A systems engineer is setting up vCenter, creates a VDS named west-coast-VMM, and deletes the VDS named west_coast_VMM. The systems engineer creates the necessary port groups that correspond with the EPGs, but when VMs are connected to the port groups, they cannot ping their gateway. Which action establishes connectivity?
-
A
Associate the EPGs to west-coast-VMM.
-
B
Rename the VDS to west_coast_VMM.
-
C
Use the EPG encap-VLAN on the port groups.
-
D
Disconnect Cisco APIC connectivity from vCenter.
Reveal answer details
Close answer details
Question 33
Single choice
Which Cisco APIC configuration prevents a remote network that is not configured on the bridge domain from being learned by the fabric?
-
A
enable Limit IP Learning to Subnet
-
B
-
C
enable IP Data-plane Learning
-
D
enable ARP Flooding to BD
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739989.html
Question 34
Single choice
The Application team reports that a previously existing port group has disappeared from vCenter. An engineer confirms that the VMM domain association for the EPG is no longer present. Which action determines which user is responsible for the change?
-
A
Check the EPG audit logs for the "deletion" action and compare the affected object and user.
-
B
Evaluate the potential faults that are raised for that EPG.
-
C
Examine the health score and drill down to an object that affects the EPG combined score.
-
D
Inspect the server logs to see who was logging in to the APIC during the last few hours.
Reveal answer details
Close answer details
Question 35
Single choice
What is the name of the automatically configured VLAN 3600 presented during Cisco ACI fabric discovery? 
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
How does Cisco ACI manage the old endpoint information on the original leaf switch after an endpoint moves between two Cisco ACI leaf switches?
-
A
A bounce entry is created by COOP communication instead of data plane learning.
-
B
A remote endpoint is created to represent the endpoint on another leaf.
-
C
Cisco APIC deletes an endpoint after receiving GARP packets from the new leaf.
-
D
The spine switch pushes all endpoint database entries to all leaf switches.
Reveal answer details
Close answer details
Correct answerA
Explanationhttps://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739989.html#Endpointmovementandbounceentries
Question 37
Single choice
A company's virtualization is hosted on a Nutanix infrastructure. The company has an Application Centric Infrastructure virtual machine manager (VMM) integration with a Nutanix cluster. The existing mapping uses IP address management (IPAM) settings to enable the DHCP within Nutanix to allocate IP addresses. The company wants to change the settings of the EPG-10 VMM to EPG association and remove the DHCP functionality as it is not required. Which process accomplishes this goal?
-
A
Shutdown remaining VMs in the EPG-10. Disable IPAM functionality on VMM to EPG association. Remove subnet association with the VMs NIC on the Nutanix cluster. Re-attach the VMs NIC back to the subnet EPG-10 on the Nutanix cluster. Power on the VMs.
-
B
Shutdown remaining VMs in the EPG-10. Remove subnet association with the VMs NIC on the Nutanix cluster. Remove VMM association from EPG-10. Re-associate VMM to EPG-10 with IPAM enabled and DHCP server override. Re-attach the VMs NIC back to the subnet EPG-10 on the Nutanix cluster. Power on the VMs.
-
C
Shutdown remaining VMs in the EPG-10. Remove DHCP server override option from VMM to EPG association. Remove subnet association with the VMs NIC on the Nutanix cluster. Re-attach the VMs NIC back to the subnet EPG-10 on the Nutanix cluster. Power on the VMs.
-
D
Shutdown remaining VMs in the EPG-10. Remove subnet association with the VMs NIC on the Nutanix cluster. Remove VMM association from EPG-10. Re-associate VMM to EPG-10 with IPAM option disabled. Re-attach the VMs NIC back to the subnet EPG-10 on the Nutanix cluster. Power on the VMs.
Reveal answer details
Close answer details
Question 38
Single choice
An engineer must attach an ESXi host to the Cisco ACI fabric. The host is connected to Leaf 1 and has its gateway IP address 10.10.10.254/24 configured inside the ACI fabric. A new firewall is attached to Leaf 2 and mapped to the same EPG and BD as the ESXi host. The engineer must migrate the gateway of the ESXi host to the firewall. Which configuration set accomplishes this goal?
-
A
Disable unicast routing. Configure IP address 10.10.10.254/24 on the ACI BD.
-
B
Disable unicast routing. Define IP address 10.10.10.254/24 on the firewall.
-
C
Enable unicast routing. Configure IP address 10.10.10.254/24 on the ACI EPG.
-
D
Enable unicast routing. Set IP address 10.10.10.254/24 on the firewall.
Reveal answer details
Close answer details
Question 39
Multiple choice
Which two settings are available in a Cisco ACI contract? (Choose two.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 40
Multiple choice
What two actions should be taken to deploy a new Cisco ACI Multi-Pod setup? (Choose two.)
-
A
Configure MP-BGP on IPN routers that face the Cisco ACI spines.
-
B
Connect all spines to the IPN.
-
C
Configure anycast RP for the underlying multicast protocol
-
D
Configure the TEP pool of the new pod to be routable across the IPN.
-
E
Increase interface MTU for all IPN routers to support VXLAN traffic.
Reveal answer details
Close answer details
Correct answersD, E
Explanationhttps://www.wwt.com/article/cisco-aci-multi-site-vs-multi-pod
Question 41
Single choice
The company's Cisco ACI fabric hosts multiple customer tenants. To meet a service level agreement, the company is constantly monitoring the Cisco ACI environment. Syslog is one of the methods used for monitoring. Only events related to leaf and spine environmental information without specific customer data should be logged. To which ACI object must the configuration be applied to meet these requirements?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 42
Single choice
A network team must extend an EPG outside the ACI fabric toward a connected Layer 2 network. Which action accomplishes this requirement most directly?
-
A
create a route control profile
-
B
statically bind a leaf port and VLAN to the EPG
-
C
configure a BGP route reflector
-
D
enable shared route control subnet
Reveal answer details
Close answer details
Correct answerB
ExplanationThe correct answer is B because statically binding a leaf port and VLAN to an EPG extends that EPG to an external Layer 2 segment while enforcing the EPG policy. Option A is incorrect because a route control profile applies to Layer 3 route policy. Option C is incorrect because a BGP route reflector is for control-plane route distribution. Option D is incorrect because shared route control subnet is an L3Out subnet scope, not an EPG extension mechanism.
Question 43
Single choice
An engineer must securely export Cisco APIC configuration snapshots to a secure, offsite location. The exported configuration must be transferred using an encrypted tunnel and encoded with a platform- agnostic data format that provides namespace support. Which configuration set must be used?
-
A
Policy: Export Policy Protocol: TLS Format: JSON
-
B
Policy: Import Policy Protocol: TLS Format: XML
-
C
Policy: Import Policy Protocol: SCP Format: JSON
-
D
Policy: Export Policy Protocol: SCP Format: XML
Reveal answer details
Close answer details
Question 44
Single choice
An engineer must implement user activity tracking in the Cisco ACI with a solution that meets these requirements: 1. All user activity that is related to the Cisco ACI infrastructure hardware must be tracked. 2. All audit logs with severity level 5 and below must be collected and exported. 3. Logs must be exported to a Security Information and Event Management (SIEM) appliance. Which set of steps must be taken?
-
A
Create a Syslog Monitoring Destination Group with a remote destination of the SIEM device. Create a Tenant-level Syslog Source under the Monitoring section of the Tenant Tab. Select Audit Logs and a severity level of Warning,
-
B
Create a Syslog Monitoring Destination Group with a Local File destination. Create an Access-level Syslog Source under the Monitoring section of the Fabric Tab. Select Fault Logs and a severity level of Notification.
-
C
Create a Syslog Monitoring Destination Group with a remote destination of the SIEM device. Create a Fabric-level Syslog Source under the Monitoring section of the Fabric Tab. Select Audit Logs and a severity level of Notification.
-
D
Create a Syslog Monitoring Destination Group with Console Destination. Create a System-level Syslog Source under the Monitoring section of the System Tab. Select Session Logs and a severity level of Warning.
Reveal answer details
Close answer details
Correct answerC
ExplanationFabric > Fabric > Policies > Monitoring > default > Callhome/Smart Callhome/SNMP/Syslog/TACACs uni/fabric/monfab-default Create Syslog Source Provide a name for this source (i.e., FabricDefaultSyslog) Select the Minimum Syslog Severity Level (default is warning; we have changed this to information) Select the categories of messages to source (default is faults; we have selected all categories) Select the Destination Syslog Server (this is the server we previously defined) https://unofficialaciguide.com/2018/08/11/configuring-syslog-for-aci/
Question 45
Single choice
Which endpoint type is used when the entries are pushed down from the COOP database of the spine switches to the ACI leaf switches?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
Refer to the exhibit.  An engineer must divert the traffic between VM-1 and VM-2 by using a Multi-Node service graph. The solution should prevent an insufficient number of available Layer 4 to Layer 7 devices in the first cluster. Which configuration set accomplishes this goal?
-
A
PBR node tracking tracking threshold with action bypass symmetric PBR resilient hashing
-
B
PBR node tracking tracking threshold with action permit unidirectional PBR resilient hashing
-
C
PBR node tracking tracking threshold with action permit symmetric PBR resilient hashing
-
D
PBR node tracking tracking threshold with action deny symmetric PBR unidirectional PBR
Reveal answer details
Close answer details
Correct answerC
Explanation1. PBR node tracking: This allows PBR to track the status of the Layer 4 to Layer 7 devices in the service graph. 2. Tracking threshold with action permit: This sets the threshold for device availability and permits traffic redirection to the available devices. 3. Symmetric PBR: This ensures that both inbound and outbound traffic is redirected through the same set of Layer 4 to Layer 7 devices in the service graph. 4. Resilient hashing: This load-balancing algorithm ensures that traffic is distributed evenly across all available devices, preventing any one device from becoming overloaded.
Question 47
Single choice
Which type of policy configures the suppression of faults that are generated from a port being down?
-
A
fault lifecycle assignment
-
B
event lifecycle assignment
-
C
fault severity assignment
-
D
event severity assignment
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/all/faults/guide/b_APIC_Faults_Errors/b_IFC_Faults_Errors_chapter_01.html
Question 48
Single choice
Refer to the exhibit.  The external subnet and internal EPG1 must communicate with each other, and the L3Out traffic must leak into the VRF named "VF1". Which configuration set accomplishes these goals?
-
A
Export Route Control Subnet Import Route Control Subnet Aggregate Shared Routes
-
B
External Subnets for External EPG Shared Route Control Subnet Shared Security Import Subnet
-
C
External Subnets for External EPG Import Route Control Subnet Shared Route Control Subnet
-
D
Export Route Control Subnet Shared Security Import Subnet Aggregate Shared Routes
Reveal answer details
Close answer details
Question 49
Multiple choice
An engineer must advertise a bridge domain subnet out of the ACI fabric to an OSPF neighbor. Which two configuration steps are required? (Choose two.)
-
A
Add External Subnet for External EPG flag under External EPG
-
B
Configure Subnet scope to Advertised Externally
-
C
Configure the Subnet under the EPG level
-
D
Create Route Control Profile with the export direction under External EPG
-
E
Add L3Out profile to the bridge domain using Associated L3Outs section
Reveal answer details
Close answer details
Correct answersB, E
Explanationhttps://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/guide-c07-743150.html#3AdvertiseinternalroutesBDsubnetstoexternaldevices The key points here are as follows: 1. Mark a BD subnet with an "Advertised Externally" scope. 2. Associate the BD with the L3Out(s) that need(s) to advertise the BD subnet to the outside.
Question 50
Single choice
A bridge domain for a new endpoint group in the Cisco ACI fabric must meet these requirements: 1. The bridge domain must function as the default gateway for the subnet so that routing remains within the Cisco ACI fabric. 2. ARP requests must be managed via Layer 3 unicast packets or be dropped to reduce excessive broadcast traffic. 3. The impact of misconfigured virtual machines must be kept to a minimum by preventing IP addresses outside of the configured subnet from being routed. Which set of actions must be taken?
-
A
Disable ARP Flooding. Enable Limit IP Learning to Subnet. Enable Unicast Routing on the bridge domain and configure a subnet.
-
B
Enable Limit IP Learning to Subnet. Enable Unicast Routing on the bridge domain and configure a subnet. Set Multi-Destination Flooding to Flood in BD.
-
C
Set Endpoint Retention Policy to default. Enable ARP Flooding. Enable Unicast Routing on the bridge domain and configure a subnet.
-
D
Enable Unicast Routing on the bridge domain and configure a subnet. Set L2 Unknown Unicast to Flood. Disable Endpoint Retention Policy.
Reveal answer details
Close answer details
Correct answerA
ExplanationUnicast Routing: If this setting is enabled and a subnet address is configured, the fabric provides the default gateway function and routes the traffic. Enabling unicast routing also instructs the mapping database to learn the endpoint IP-to-VTEP mapping for this bridge domain. The IP learning is not dependent upon having a subnet configured under the bridge domain. Limit IP Learning To Subnet: Prevents the local IP endpoint from being learned outside the subnets configured on the bridge domain. Prevents mis-learning of IP addresses that may not belong to the fabric. ARP Flood is off: ARP Request is handled as L3 Unicast
Question 51
Single choice
An engineer configures a Cisco ACI Multi-Pod for disaster recovery. Which action should be taken for the new nodes to be discoverable by the existing Cisco APICs?
-
A
Configure IGMPv3 on the interfaces of IPN routers that face the Cisco ACI spine.
-
B
Enable subinterfaces with dot1q tagging on all links between the IPN routers.
-
C
Enable DHCP relay on all links that are connected to Cisco ACI spines on IPN devices.
-
D
Configure BGP as the underlay protocol in IPN.
Reveal answer details
Close answer details
Correct answerA
ExplanationDHCP relay support: One of the nice functionalities offered by the ACI Multi-Pod solution is the capability of allowing auto-provisioning of configuration for all the ACI devices deployed in remote Pods. This allows those remote Pods to join the Multi-Pod fabric with zero-touch configuration, as it normally happens to ACI nodes part of the same fabric (Pod).
Question 52
Single choice
Which component provides Cisco ACI fabric with Layer 2 and Layer 3 connectivity across pods and physical locations?
-
A
-
B
-
C
-
D
Cisco APIC control cluster
Reveal answer details
Close answer details
Question 53
Single choice
A Cisco ACI fabric must detect all silent endpoints for the Layer 3 bridge domain. Which actions accomplish this goal?
-
A
Enable Unicast Routing. Disable ARP Flooding.
-
B
Disable Unicast Routing. Enable L2 Unknown Unicast Hardware Proxy.
-
C
Enable Unicast Routing. Enable ARP Flooding.
-
D
Disable Unicast Routing. Enable L2 Unknown Unicast Flood.
Reveal answer details
Close answer details
Question 54
Single choice
Which type of MP-BGP address family is used to exchange MAC and IP address endpoint information between spines in two separate pods?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
Which resolution immediacy setting allows a policy to be downloaded to the Cisco ACI leaf switch software regardless of CDP/LLDP neighborship?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Multiple choice
Refer to the exhibit.  An engineer is deploying a Cisco ACI fabric with an L2Out to external switches. The Cisco ACI fabric has just been deployed and follows the default forwarding behavior. Which two actions accomplish a loop free topology? (Choose two.)
-
A
Add ports Eth1/1 and Eth1/2 to the LACP port channel.
-
B
Enable MCP on the ports between the leafs and spine switches.
-
C
Disconnect the link between Leaf3 and Leaf4.
-
D
Implement LLDP on ports Eth1/1 and Eth1/2 on Leaf2.
-
E
Configure BPDU guard on Catalyst switch ports.
Reveal answer details
Close answer details
Question 57
Single choice
A company is running a multi-pod environment across two data centers and wants to expand to co-locations. Which solution extends the application centric infrastructure (ACI) policy with minimum investment?
-
A
dedicated equipment for a new site in a multi-site deployment
-
B
dedicated equipment to extend the existing multi-pod
-
C
dedicated equipment for a dedicated ACI fabric
-
D
new leaf switches to be used in a remote-leaf architecture
Reveal answer details
Close answer details
Question 58
Single choice
In a Cisco ACI fabric, an endpoint moves between two leaf switches during a virtual machine migration. Which action does Cisco ACI take to minimize the impact to traffic during this event?
-
A
A new leaf switch updates a COOP database on the spine, which causes the old leaf switch to install a bounce entry.
-
B
A new leaf switch sends a COOP message to the Cisco APIC cluster to populate a new location of the endpoint.
-
C
A new leaf switch sends a COOP message directly to the old leaf switch to update it with new information about the endpoint move.
-
D
A new leaf switch floods GARP to every other leaf switch in the fabric, which advertises a new endpoint location to the fabric.
Reveal answer details
Close answer details
Correct answerA
ExplanationThere are several scenarios in which an endpoint moves between two Cisco ACI leaf switches, such as a failover event or a virtual machine migration in a hypervisor environment. Cisco ACI data-plane endpoint learning detects these events quickly and updates the Cisco ACI endpoint database on a new leaf. In addition to data-plane learning, Cisco ACI uses bounce entries to manage the old endpoint information on the original leaf. When a new local endpoint is detected on a leaf, the leaf updates the COOP database on spine switches with its new local endpoint. If the COOP database has already learned the same endpoint from another leaf, COOP will recognize this event as an endpoint move and report this move to the original leaf that contained the old endpoint information. The old leaf that receives this notification will delete its old endpoint entry and create a bounce entry, which will point to the new leaf. A bounce entry is basically a remote endpoint created by COOP communication instead of data-plane learning.
Question 59
Single choice
An engineer configured Layer 2 extension from the ACI fabric and changed the Layer 2 unknown unicast policy from Flood to Hardware Proxy. How does this change affect the flooding of the L2 unknown unicast traffic?
-
A
It is forwarded to one of the spines to perform as a spine proxy.
-
B
It is flooded within the whole fabric.
-
C
It is dropped by the leaf when the destination endpoint is not present in the endpoint table.
-
D
It is forwarded to one of the APICs to perform as a proxy.
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/L2_config/b_Cisco_APIC_Layer_2_Configuration_Guide/ b_Cisco_APIC_Layer_2_Configuration_Guide_chapter_010.html
|