An engineer is configuring ACI VMM domain integration with Cisco UCS-B Series. Which type of port channel policy must be configured in the vSwitch policy?
A. LACP Active B. MAC Pinning C. LACP Passive D. MAC Pinning-Physical-NIC-load
Which ACI import mode processes each managed object individually and skips the invalid MO?
A. replace B. atomic C. best-effort D. merge
C. best-effort
Question 193:
Refer to the exhibit.
An engineer created a local user named User on Cisco ACI. The engineer must configure the fabric so that the User can access only common and PROD tenants.
Which set of actions accomplishes the goal?
A. Add security domain “mgmt.” to User. Associate security domain “mgmt.” under PROD tenant. B. Add security domain “Tenant” to User. Associate security domain “Tenant” under PROD tenant. C. Add security domain “all” to User. Associate security domain “all” under PROD tenant D. Add security domain “common” to User. Associate security domain “common” under PROD tenant.
B. Add security domain “Tenant” to User. Associate security domain “Tenant” under PROD tenant.
Explanation/Reference:
Question 194:
Refer to the exhibit.
An engineer is implementing Cisco ACI ?VMware vCenter integration for a blade server that lacks support of bonding. Which port channel mode results in "route based on originating virtual port" on the VMware VDS?
A. Static Channel ?Mode On B. MAC Pinning-Physical-NIC-load C. LACP Passive D. MAC Pinning+ E. LACP Active
An endpoint called EP1 is connected to Cisco ACI compute leaf1. The engineer must replace EP1 with EP2 on the same leaf switch. Which set of actions forces all remote leaves to delete EP1 before timer expiration?
A. Set L2 Unknown Unicast to Hardware proxy. Select Clear remote MAC entries. B. Set L2 Unknown Unicast to Flood. Select Clear remote MAC entries. C. Set L2 Unknown Unicast to Hardware Proxy. Select Clear remote IP entries. D. Set L2 Unknown Unicast to Flood. Select Clear remote IP entries.
B. Set L2 Unknown Unicast to Flood. Select Clear remote MAC entries.
Explanation/Reference:
When the bridge domain has L2 Unknown Unicast set to Flood, if an endpoint is deleted the system deletes it from both the local leaf switches as well as the remote leaf switches where the bridge domain is deployed, by selecting Clear Remote MAC Entries. Without this feature, the remote leaf continues to have this endpoint learned until the timer expires. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/L2_config/b_Cisco_APIC_Layer_2_Configuration_Guide/b_Cisco_APIC_Layer_2_Configuration_Guide_chapter_010.html#:~:text=When%20the%20bridge,the% 20timer%20expires.
Question 196:
DRAG DROP
Refer to the exhibit.
A Cisco ACI fabric is newly deployed, and the security team requires more visibility of all inter EPG traffic flows. All traffic in a VRF must be forwarded to an existing firewall pair. During failover, the standby firewall must continue to use the same IP and MAC as the primary firewall. Drag and drop the steps from the left into the implementation order on the right to configure the service graph that meets the requirements. (Not all steps are used.)
Create a service bridge domain and a layer 4 to layer 7 device within one cluster interface.
Question 197:
Which two IP address types are available for transport over the ISN when they are configured from Cisco ACI Multi-Site Orchestrator? (Choose two.)
A. Management IP of APICs B. Management IP of the MSO Node C. Anycast Overlay Multicast TEP D. MP-BGP EVPN Router-ID E. Common Pervasive Gateway
C. Anycast Overlay Multicast TEP D. MP-BGP EVPN Router-ID
Explanation/Reference:
As shown in Figure 60, the EVPN-RID, O-UTEP, and O-MTEP addresses are the only prefixes that must be exchanged across sites to enable the intersite EVPN control plane and the VXLAN data plane. Consequently, they are the only prefixes that should be learned in the ISN routing domain. This implies that those IP addresses must be globally routable across the ISN, which should normally not be a problem, because they are independent of the original TEP pools associated to each fabric and assigned separately on Cisco Nexus Dashboard Orchestrator at the time of Multi-Site deployment.
Question 198:
What is MP-BGP used for in Cisco ACI fabric?
A. MP-BGP VPNv4 AF is used as protocol on L3Out between a border leaf and an external router B. MP-BGP Layer 2 VPN EVPN AF is used to propagate L3Out routes that are received from a border leaf C. MP-BGP VPNv4 AF is used to propagate L3Out routes that are received from a border leaf to the fabric D. MP-BGP VPNv4 AF is used between spines in an ACI Multi-Pod fabric to propagate the endpoint
C. MP-BGP VPNv4 AF is used to propagate L3Out routes that are received from a border leaf to the fabric
An engineer must perform a Cisco ACI fabric upgrade that minimizes the impact on user traffic and allows only permitted users to perform an upgrade. Which two configuration steps should be taken to meet these requirements? (Choose two.)
A. Grant tenant-ext-admin access to a user who performs an upgrade B. Divide Cisco APIC controllers into two or more maintenance groups C. Combine all switches into an upgrade group D. Grant the fabric administrator role to a user who performs an upgrade E. Divide switches into two or more maintenance groups
D. Grant the fabric administrator role to a user who performs an upgrade E. Divide switches into two or more maintenance groups
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cisco exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 300-620 exam preparations
and Cisco certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.