A customer implements RBAC on a Cisco APIC using a Windows RADIUS server that is configured with network control policies. The APIC configuration is as follows: Tenant = TenantX Security Domain = TenantX-SD User = X
The customer requires User X to have access to TenantX only, without any extra privilege in the Cisco ACI fabric domain. Which Cisco AV pair must be implemented on the RADIUS server to meet these requirement?
A. shell:domains = TenantX-SD/fabric-admin/,common//read-all B. shell:domains = TenantX-SD/tenant-admin C. shell:domains = TenantX-SD/tenant-ext-admin/,common//read-all D. shell:domains = TenantX-SD/tenant-admin/,common//read-all
D. shell:domains = TenantX-SD/tenant-admin/,common//read-all
When Cisco ACI connects to an outside Layers 2 network, where does the ACI fabric flood the STP BPDU frame?
A. within the bridge domain B. within the APIC C. within the access encap VLAN D. between all the spine and leaf switches
C. within the access encap VLAN
Explanation/Reference:
The ACI fabric is an IP-based fabric that implements an integrated overlay, allowing any subnet to be placed anywhere in the fabric and supports a fabric-wide mobility domain for virtualized workloads. STP is not required within the ACI fabric and leaf. The spine and APIC don't run STP instances.
When connecting to an outside layer 2 network, the ACI fabric floods the STP BPDU frame within the boundary of the EPG. External switches are expected to break any potential loop upon receiving the flooded BPDU from the ACI fabric. Figure 69 depicts this process.
Question 283:
Refer to the exhibit.
A network engineer must configure a Cisco ACI fabric for the External Bridged network to communicate with L3Out. Which action accomplishes this goal?
A. Consume Test_Contract-APP-WEB from CCDM_EPG. B. Provide Test_Contract-DB-APP to MSPKAL. C. Provide Test_Contract-APP-WEB to MSP_EPG. D. Consume Test_Contract-DB-APP from Presentation. E. Consume Test_Contract-DB-APP from Presentation.
A. Consume Test_Contract-APP-WEB from CCDM_EPG.
Question 284:
Which endpoint learning operation is completed on the ingress leaf switch when traffic is received from a Layer 3 Out?
A. The source MAC address of the traffic is learned as a local endpoint. B. The source MAC address of the traffic is learned as a remote endpoint. C. The source IP address of the traffic is learned as a remote endpoint. D. The source IP address of the traffic is learned as a local endpoint.
A. The source MAC address of the traffic is learned as a local endpoint.
Question 285:
A network engineer demonstrates Cisco ACI to a customer. One of the test cases is to validate a disaster recovery event by resetting the ACI fabric to factory and then restoring the fabric to the state it was in before the event. Which setting must be enabled on ACI to export all configuration parameters that are necessary to meet these requirements?
A. enabled AES encryption B. generated a tech-support file C. encrypted export destination D. enabled JSON format export
A. enabled AES encryption
Explanation/Reference:
AES encryption may be optional for backup but is required for the use case of restoring a factory-fresh install to a fully working environment.
Question 286:
Refer to the exhibit.
A network engineer must configure a user tenant to raise the error shown when configuring a new EPG. Which action accomplishes this goal?
A. From Access Policies, set Exceed Action to Fail Transaction Action. B. From Fabric Policies, set Exceed Action to Fail Transaction Action. C. From Access Policies, set Exceed Action to Raise Fault Action. D. From Fabric Policies, set Exceed Action to Raise Fault Action.
B. From Fabric Policies, set Exceed Action to Fail Transaction Action.
Question 287:
A customer must deploy three Cisco ACI based data centers. Each site must be separated from the others. Which characteristic of Cisco ACI Multi-Pod makes it unsuitable for this deployment?
A. creates a virtual pod in the remote location B. requires all pods to share the same Cisco APIC cluster C. has distance and scale limitations D. places leaf switches in the remote site that belong to the same fabric as at the headquarters site
B. requires all pods to share the same Cisco APIC cluster
Explanation/Reference:
The Cisco® Application Centric Infrastructure (Cisco ACI™) Multi-Pod solution is an evolution of the stretched-fabric use case. Multiple pods provide intensive fault isolation in the control plane along with infrastructure cabling flexibility. As the name indicates, it connects multiple Cisco Application Policy Infrastructure Controller (APIC) pods using a Layer 3 interpod network (IPN).
Note: Pod spine switches cannot be connected back to back. IPN supports only Open Shortest Path First (OSPF) connectivity between the IPN and the spine switches. Though each pod consists of its own spine and leaf switches, all the pods reside within the same fabric and are managed by a single APIC cluster. This approach provides a single management and policy domain across all pods for end-to-end policy enforcement. In the data plane, the Multi-Pod solution uses Multiprotocol Border Gateway Protocol (MP-BGP) Ethernet Virtual Private Network (EVPN) connectivity over the IPN between the spine switches from each pod for communication using Virtual Extensible LAN (VXLAN) encapsulation.
Question 288:
A fabric engineer is defining a bridge domain for an application segment. Which Cisco ACI logical construct provides the Layer 2 forwarding context for attached EPGs?
A. tenant B. VRF C. bridge domain D. application profile
C. bridge domain
Explanation
The correct answer is C because a bridge domain is the Layer 2 forwarding construct in Cisco ACI and is associated with EPGs for endpoint communication. Option A is incorrect because a tenant is an administrative container. Option B is incorrect because a VRF provides Layer 3 routing isolation, not Layer 2 forwarding. Option D is incorrect because an application profile groups EPGs logically but does not forward traffic.
Question 289:
Refer to the exhibit.
An engineer plans to upgrade the Cisco ACI fabric. Leaf1 and Leaf2 are deployed in a VPC. The fabric is peering with R1 using BGP protocol.
Which two actions upgrade the fabric nondisruptively? (Choose two.)
A. Configure the Graceful upgrade option. B. Disable the BGP neighborship between Cisco ACI fabric and R1. C. Enable the Graceful Insertion and Removal option. D. Configure one maintenance group for every leaf. E. Create one update group for all spines.
A. Configure the Graceful upgrade option. C. Enable the Graceful Insertion and Removal option. E. Create one update group for all spines.
Question 290:
A network engineer must optimize a Cisco ACI multi-pod deployment. Both pods are using the same pod policy group. The customer requirement is to avoid inter-pod traffic loss in case of planned or unplanned spine reload. Which action accomplishes this goal?
A. Configure the COOP type as compatible in COOP Group Policy. B. Configure MACsec in the MACsec Fabric Interface Policy. C. Configure a lower IS-IS metric for redistributed routes in ISIS Policy. D. Configure all spines as Route Reflectors in the BGP Route Reflector Policy.
C. Configure a lower IS-IS metric for redistributed routes in ISIS Policy.
Explanation/Reference:
This ensures that when new spine switch is introduced (booting up), or during upgrades/reboot of spine, the spine is not in the forwarding path to external destinations until the full configuration of the spine is completed and the default metric
is changed to the lower metric (recommended to 32, default 63).
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cisco exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 300-620 exam preparations
and Cisco certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.