300-620 Exam Details

  • Exam Code
    :300-620
  • Exam Name
    :Implementing Cisco Application Centric Infrastructure (DCACI)
  • Certification
    :CCNP Data Center
  • Vendor
    :Cisco
  • Total Questions
    :388 Q&As
  • Last Updated
    :May 29, 2026

Cisco 300-620 Online Questions & Answers

  • Question 201:

    Refer to the exhibit.

    An engineer must disable the communication between the two backup servers in the backup EPG. Which action accomplishes this goal?

    A. Set Preferred Group Member to Excluded.
    B. Set the physical domain to None.
    C. Set a different static binding for the encap VLAN.
    D. Set Intra EPG Isolation to Enforced.

  • Question 202:

    An engineer must advertise a bridge domain subnet out of the ACI fabric to an OSPF neighbor. Which two configuration steps are required? (Choose two.)

    A. Add External Subnet for External EPG flag under External EPG
    B. Configure Subnet scope to Advertised Externally
    C. Configure the Subnet under the EPG level
    D. Create Route Control Profile with the export direction under External EPG
    E. Add L3Out profile to the bridge domain using Associated L3Outs section

  • Question 203:

    As part of a migration, legacy non-ACI switches must be connected to the Cisco ACI fabric. All non-ACI switches run per-VLAN RSTP. After the non-ACI switches are connected to Cisco ACI, the STP convergence caused a microloop and significant CPU spike on all switches. Which configuration on the interfaces of the external switches that face the Cisco ACI fabric resolves the problem?

    A. BPDU guard
    B. aggressive STP timers
    C. BPDU filtering
    D. STP type link shared

  • Question 204:

    A design requires a single APIC cluster to manage multiple pods that are part of one logical Cisco ACI fabric. Which ACI Anywhere architecture matches this requirement?

    A. Multi-Site
    B. Multi-Pod
    C. Remote Leaf
    D. service graph

  • Question 205:

    How is broadcast forwarded in Cisco ACI Multi-Pod after ARP flooding is enabled?

    A. Ingress replication is used on the spines to forward broadcast frames in the IPN infrastructure.
    B. Within a pod, the ingress leaf switch floods the broadcast frame on all fabric ports.
    C. Broadcast frames are forwarded inside the pod and across the IPN using the multicast address that is associated to the bridge domain.
    D. For the specific bridge domain, all spines forward the broadcast frames to IPN routers.

  • Question 206:

    What is a requirement for Cisco ACI IPN to manage multidestination traffic?

    A. pervasive gateway
    B. unicast routing
    C. anycast gateway
    D. multicast routing

  • Question 207:

    Which service graph option creates a permit entry for the traffic from the provider EPG to the provider connector of the PBR node?

    A. direct connect
    B. promiscuous mode
    C. single context aware
    D. share encap

  • Question 208:

    A network engineer is configuring syslogs in the Cisco ACI environment with these requirements:

    All message severities must be logged except for debugging messages.

    Messages must be compliant with RFC 5424 format.

    Logs must be saved only in a file on the APIC.

    Which settings must be used in the Syslog Monitoring Destination Group to meet these requirements?

    A. Format: ACI Local File Destination Admin State: Enabled Severity: Notifications Console Destination Admin State: Disabled
    B. Format: NX-OS Local File Destination Admin State: Disabled Severity: Emergencies Console Destination Admin State: Enabled
    C. Format: NX-OS Local File Destination Admin State: Disabled Severity: Alerts Console Destination Admin State: Enabled
    D. Format: ACI Local File Destination Admin State: Enabled Severity: Information Console Destination Admin State: Disabled

  • Question 209:

    An engineer must configure a new local user inside a Cisco ACI. The new user must meet these criteria:

    1.

    Must be provided with complete read-only access to the tenant.

    2.

    Must be permitted to create and delete EPGs within a specific tenant.

    3.

    Must not be allowed to modify any other objects within that tenant.

    The tenant and security domain association is already in place. Which configuration set configures the new tenant?

    A. Create a new role with tenant-admin privilege. Create the local user and assign it to the tenant-security domain. Add the tenant-security domain to the role admin with access privilege type Read. Add the tenant-security domain to the new role with access privilege type Write.
    B. Create a new role with tenant-epg privilege. Create the local user and assign it to the tenant-security domain. Add the tenant-security domain to the role read-all with access privilege type Read. Add the tenant-security domain to the new role with access privilege type Write.
    C. Create a new role with tenant-connectivity privilege. Create the local user and assign it to the tenant-security domain. Add the tenant-security domain to the role access-admin with access privilege type Read. Add the tenant-security domain to the new role with access privilege type Write.
    D. Create a new role with tenant-security privilege. Create the local user and assign it to the tenant-security domain. Add the tenant-security domain to the role tenant-admin with access privilege type Read. Add the tenant-security domain to the new role with access privilege type Write.

  • Question 210:

    Refer to the exhibit.

    An engineer must implement the inter-tenant service graph. Which set of actions must be taken to accomplish this goal?

    A. Define the contract in the provider tenant and export it to the consumer tenant. Define the L4-L7 device, service graph template, and ASA bridge domains in the provider tenant.
    B. Define the contract in the provider tenant and export it to the consumer tenant. Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant.
    C. Define the contract in the provider tenant and export it to the provider tenant. Define the L4-L7 device and service graph template in the provider tenant and the ASA bridge domains in the consumer tenant.
    D. Define the contract in the provider tenant and export it to the provider tenant. Define the L4-L7 device, service graph template, and ASA bridge domains in the consumer tenant.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-620 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.