[UPDATED 2025] Read 300-620 Study Guide Cover to Cover as Literally [Q23-Q45]

Share

[UPDATED 2025] Read 300-620 Study Guide Cover to Cover as Literally

100% Real & Accurate 300-620 Questions and Answers with Free and Fast Updates


To pass the Cisco 300-620 exam, candidates must have a solid understanding of networking fundamentals, as well as hands-on experience in designing, deploying, and troubleshooting ACI solutions. 300-620 exam consists of multiple-choice and simulation questions that test the candidate's ability to analyze complex scenarios and apply their knowledge to solve practical problems.

 

NEW QUESTION # 23
Which two protocols are used for fabric discovery in ACI? (Choose two.)

  • A. CDP
  • B. OSPF
  • C. ISIS
  • D. DHCP
  • E. LLDP

Answer: C,E

Explanation:
The two protocols used for fabric discovery in Cisco ACI are LLDP (Link Layer Discovery Protocol) and ISIS (Intermediate System to Intermediate System). LLDP is used for neighbor discovery on the data link layer, while ISIS is a routing protocol used for reachability between the TEP IPs (VTEPs) within the ACI fabric23.


NEW QUESTION # 24
What represents the unique identifier of an ACI object?

  • A. application programming interface
  • B. distinguished name
  • C. universal resource identifier (URI)
  • D. management information tree

Answer: B

Explanation:
Reference:
https://www.slideshare.net/CiscoDevNet/introduction-to-aci-apis


NEW QUESTION # 25
Which class of ACI object is presented in this output?

  • A. Tenant
  • B. Bridge Domain
  • C. Endpoint
  • D. Contract

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/openstack/ACI-Installation-Guide-for-Red-Hat-Using-OSP13-Director/m-configuring-ironic-for-openstack.html


NEW QUESTION # 26
What must be enabled in the bridge domain to have the endpoint table learn the IP addresses of endpoints?

  • A. GARP based detection
  • B. unicast routing
  • C. L2 unknown unicast: flood
  • D. subnet scope

Answer: B

Explanation:
To have the endpoint table learn the IP addresses of endpoints in a bridge domain, unicast routing must be enabled1. This allows the bridge domain to learn the IP addresses of endpoints through the data plane1.


NEW QUESTION # 27
Drag and drop the Cisco ACI filter entry options from the left onto the correct categories on the right indicating what are required or optional parameters.

Answer:

Explanation:


NEW QUESTION # 28
A Cisco ACI fabric is connected to an external Cisco Catalyst switch. Which set of actions must be taken for Cisco ACI leaf and spine switches to be managed from the management port?

  • A. Provide default/common contract by external management network under tenant mgmt.
    Consume default/common contract by out-of-band EPG.
  • B. Provide default/common contract by out-of-band EPG.
    Consume default/common contract by external management network under tenant mgmt.
  • C. Provide default/mgmt contract by external management network under tenant common.
    Consume default/mgmt contract by out-of-band EPG.
  • D. Provide default/mgmt contract by out-of-band EPG.
    Consume default/mgmt contract by external management network under tenant common.

Answer: B

Explanation:
https://www.cisco.com/c/dam/en/us/solutions/collateral/data-center-virtualization/application- centric-infrastructure/aci-guide-configuring-out-of-band-access-for-your-fabric.pdf


NEW QUESTION # 29
Refer to the exhibit.

Which two components should be configured as route reflectors in the ACI fabric? (Choose two.)

  • A. Spine1
  • B. Leaf2
  • C. Leaf1
  • D. apic1
  • E. apic2
  • F. Spine2

Answer: A,F


NEW QUESTION # 30
An engineer is implementing a Cisco ACI environment that consists of more than 20 servers. Two of the servers support only Cisco Discovery Protocol with no order link discovery protocol. The engineer wants the servers to be discovered automatically by the Cisco ACI fabric when connected. Which action must be taken to meet this requirement?

  • A. Configure a lower order policy group that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
  • B. Configure a higher order interface policy that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
  • C. Create an override policy that enables Cisco Discovery Protocol after LLDP is enabled in the default policy group.
  • D. Create an interface profile for the interface that disables LLDP on the desired switch that is referenced by the interface policy group.

Answer: C

Explanation:
To ensure that servers supporting only Cisco Discovery Protocol are discovered automatically by the Cisco ACI fabric when connected, the action that must be taken is to Create an override policy that enables Cisco Discovery Protocol after LLDP is enabled in the default policy group


NEW QUESTION # 31
Regarding the MTU value of MP-BGP EVPN control plane packets in Cisco ACI, which statement about communication between spine nodes in different sites is true?

  • A. By default, spine nodes generate 9000-bytes packets to exchange endpoints routing information.
    As a result, the Inter-Site network should be able to carry 9000-bytes packets.
  • B. By default, spine nodes generate 1500-bytes packets to exchange endpoints routing information.
    As a result, the Inter-Site network should be able to carry 1500-bytes packets.
  • C. By default, spine nodes generate 9000-bytes packets to exchange endpoints routing information.
    As a result, the Inter-Site network should be able to carry 9100-bytes packets.
  • D. By default, spine nodes generate 1500-bytes packets to exchange endpoints routing information.
    As a result, the Inter-Site network should be able to carry 1800-bytes packets.

Answer: C

Explanation:
Maximum transmission unit (MTU) of Multiprotocol Border Gateway Protocol (MP-BGP) Ethernet Virtual Private Network (EVPN) control plane communication between spine nodes in different sites - By default, the spine nodes generate 9000-byte packets to exchange endpoint routing information. If that default value is not modified, the Inter Site Network (ISN) must support an MTU size of at least 9100 bytes. In order to tune the default value, modify the corresponding system settings in each APIC domain.


NEW QUESTION # 32
Refer to the exhibit.

A systems engineer is implementing the Cisco ACI fabric. However, the Server2 information is missing from the Leaf 101 endpoint table and the COOP database of the spine. The requirement is for the bridge domain configuration to enforce the ACI fabric to forward the unicast packets generated by Server1 destined to Server2. Which action must be taken to meet these requirements?

  • A. Enable ARP Flooding
  • B. Set IP Data-Plane Learning to No
  • C. Set L2 Unknown Unicast to Flood
  • D. Enable Unicast Routing

Answer: C

Explanation:
Both servers are in the same subnet. ARP flooding is out if we read the article in the link. Also unicast routing is not needed.
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739989.html


NEW QUESTION # 33
Refer to the exhibit.

A network engineer must improve the configuration backup process and the configuration restore process. The current ACI solution is integrated with VMMs and third-y.. L4-L7 devices. The process requires that no additional information be re-entered when importing the configuration for a fully-functional state. Which configuration configures the port policy?

  • A. Create target DNs for all tenants.
  • B. Configure a local snapshot.
  • C. Enable the Global AES Encryption Setting.
  • D. Select the JSON data format to be used when exporting

Answer: C

Explanation:
Enabling AES encryption ensures that sensitive data, such as credentials for VMMs and third-party integrations, is securely encrypted in the backup file. This is essential for a fully functional restore without requiring re-entry of sensitive details.


NEW QUESTION # 34
What happens to the traffic flow when the Cisco ACI fabric has a stale endpoint entry for the destination endpoint?

  • A. The leaf switch drops the traffic that is destined to the endpoint.
  • B. The leaf switch sends the traffic to the wrong destination leaf.
  • C. The leaf switch floods the traffic to the endpoint throughout the fabric.
  • D. The leaf switch does not learn the source endpoint through data plane learning.

Answer: A

Explanation:
Section: ACI Packet Forwarding
Explanation/Reference:
https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2019/pdf/BRKACI-2641.pdf


NEW QUESTION # 35
What is a characteristic of a Cisco ACI Multi-Pod?

  • A. It manages the configuration of different Cisco ACI pods using a single common Cisco APIC cluster.
  • B. Spines use BGP peering with IPN to send out the TEP pool prefix for the local pod.
  • C. It eliminates the need to deploy multicast in the Layer 3 network that interconnects the pods.
  • D. A VPNv4 address family is used to exchange endpoint information between spines.

Answer: A


NEW QUESTION # 36
An engineer must limit management access to me Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?

  • A. policy In the management tenant
  • B. ACL on the management interface of the APIC
  • C. policy on the management VLAN
  • D. ACL on the console interface
    https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_0111.html

Answer: A


NEW QUESTION # 37
When does the Cisco ACI leaf learn a source IP or MAC as a remote endpoint?

  • A. When VXLAN traffic arrives on a leaf fabric port from the spine and outer source IP is in the Layer 3 Out EPG subnet range.
  • B. When VXLAN traffic arrives on a leaf fabric port from the spine and inner source IP is in the Layer 3 Out EPG subnet range.
  • C. When VXLAN traffic arrives on a leaf fabric port from the spine and outer source IP is in the bridge domain subnets range.
  • D. When VXLAN traffic arrives on a leaf fabric port from the spine and inner source IP is in the bridge domain subnets range.

Answer: D


NEW QUESTION # 38
Refer to the exhibit.

Refer to the exhibit. The external subnet and internal EPG1 must communicate with each other, and the L3Out traffic must leak into the VRF named "VF1". Which configuration set accomplishes these goals?

  • A. Export Route Control Subnet
    Shared Security Import Subnet
    Aggregate Shared Routes
  • B. Export Route Control Subnet
    Import Route Control Subnet
    Aggregate Shared Routes
  • C. External Subnets for External EPG
    Import Route Control Subnet
    Shared Route Control Subnet
  • D. External Subnets for External EPG
    Shared Route Control Subnet
    Shared Security Import Subnet

Answer: D

Explanation:
To enable communication between the external subnet and internal EPG1, and to allow L3Out traffic to leak into the VRF named "VF1", the following configuration set should be used:
External Subnets for External EPG: This configuration defines the subnets that are external to the ACI fabric but need to be reachable from within the fabric. It is necessary to specify which subnets are to be considered part of the L3Out1.
Shared Route Control Subnet: This setting allows the subnets to be shared across different VRFs, enabling communication between EPGs that are in different tenants but within the same VRF1.
Shared Security Import Subnet: This configuration ensures that the security policies (contracts) associated with the shared subnets are also imported, allowing for the necessary traffic to flow between the internal and external endpoints1.
By applying this configuration set, the external subnet and internal EPG1 will be able to communicate, and the L3Out traffic will be properly leaked into the designated VRF, meeting the specified goals.
Reference:
ACI Inter VRF/Tenant Route Leaking Configuration Example1


NEW QUESTION # 39
The engineer notices frequent MAC and IP address moves between different leaf switch ports.
Which action prevents this problem from occurring?

  • A. Enable endpoint loop protection.
  • B. Disable IP bridge domain enforcement.
  • C. Enable rogue endpoint control.
  • D. Disable enforce subnet check.

Answer: A

Explanation:
enabling endpoint loop protection can prevent frequent MAC and IP address moves between different leaf switch ports.


NEW QUESTION # 40
A data center administrator is upgrading an ACI fabric. There are 3 APIC controllers in the fabric and all the servers are dual-homed to pairs of leaf switches configured in VPC mode. How should the fabric be upgraded to minimize possible traffic impact during the upgrade?

  • A. 1. Create two maintenance groups for the leaf switches: VPC left and VPC right.
    2. Upgrade the APIC controllers.
    3. Upgrade the first group of leaf switches.
    4. Upgrade the second group of leaf switches.
  • B. 1. Create two maintenance groups for the leaf switches: VPC left and VPC right.
    2. Upgrade the first group of switches.
    3. Upgrade the second group of switches.
    4. Upgrade the APIC controllers.
  • C. 1. Create two maintenance groups for APIC controllers: VPC left and VPC right.
    2. Upgrade the leaf switches.
    3. Upgrade the first group of controllers.
    4. Upgrade the second group of controllers.
  • D. 1. Create two maintenance groups for the APIC controllers: VPC left and VPC right.
    2. Upgrade the first group of controllers.
    3. Upgrade the second group of controllers.
    4. Upgrade the leaf switches.

Answer: B


NEW QUESTION # 41
An administrator must migrate the vSphere Management VMkernel of all ESXi hosts in the production cluster from the standard default virtual switch to a VDS that is integrated with APIC in a VMM domain. Which action must be completed in this scenario?

  • A. The Management VMkernel EPG resolution must be set to Pre-Provosion.
  • B. The administrator must set the Management VMkernel BD resolution immediacy to On-Demand.
  • C. The VMkernel Management BD must be located under the Management Tenant.
  • D. The administrator must create an in-band VMM Management EPG before performing the migration.

Answer: A

Explanation:
When migrating the vSphere Management VMkernel of all ESXi hosts from the standard default virtual switch to a Virtual Distributed Switch (VDS) that is integrated with APIC in a VMM domain, it is essential to set the Management VMkernel EPG resolution to Pre-Provision. This action ensures that the necessary policies are in place on the ACI fabric before the migration occurs, allowing for a seamless transition and continuous management connectivity.


NEW QUESTION # 42
Cisco ACI fabric has three different endpoints S1, S2. and S3. These endpoints must communicate with each other without contracts. These objects have been created in APIC:
* Two EPGs named DNS_EPG and Database_EPG
* Two application profiles. PROD_App and Data_App
* Two bridge domains DNS_BD and Database_BD
* PROD_APP and Database_BD mapped to Tenant PROD
* Data_App and DNS_BD mapped to Tenant Data
Which set of actions completes the fabric configuration?

  • A. Add S1, S2, S3 under Database_EPG.
    MAP Database_EPG under Data_App.
    Associate Datbase_EPG with Database_BD.
  • B. Add S1, S2, S3 under Database_EPG.
    MAP Database_EPG under PROD_ App.
    Associate Datbase_EPG with DNS_BD.
  • C. Add S1, S2, S3, under DNS_EPG.
    MAP DNS_EPG to Data_App.
    Associate DNS_EPG with Dns_BD.
  • D. Add S1, S2, S3 under DNS_EPG.
    MAP DNS_EPG to Data_App.
    Associate DNS_EPG with Database_BD.

Answer: C


NEW QUESTION # 43
What are two descriptions of ACI multi-site? (Choose two.)

  • A. ACI Multi-Site is a solution that supports a dedicated APIC cluster per site
  • B. The Multi-Site orchestrator must be directly attached to one ACI leaf.
  • C. The Inter-Site network routers should run OSPF to establish peering with the spines.
  • D. Routers in the inter-Site network must run OSPF. DHCP relay, and MP-BGP
  • E. ACI Multi-Site is a solution that allows one APIC cluster to manage multiple ACI sites

Answer: A,E

Explanation:
ACI Multi-Site architecture is designed to interconnect geographically dispersed data centers and extend Layer 2 and Layer 3 connectivity between those locations with consistent policy enforcement. It allows for either a single APIC cluster to manage multiple ACI sites or supports a dedicated APIC cluster per site. This architecture ensures a scalable and flexible approach to managing multiple data center sites, providing a unified policy framework and operational model across the sites34.
Reference:
Cisco Multi-Site Deployment Guide for ACI Fabrics3
Cisco ACI Multi-Site Architecture White Paper4


NEW QUESTION # 44
A network engineer configured a Cisco ACI fabric as follows:
- An EPG called EPG-A is created and associated with a VMM domain
called North.
- The EPG-A is associated with BD-A and is in an application profile
called Apps-A.
- The BD-A is associated with VRF-1 in the Prod tenant.
Which port group must be selected to place VMs in EPG-A?

  • A. Prod|Business_Apps|BD-A|EPG-A
  • B. Prod|Apps-A|North|EPG-A
  • C. Prod|VRF-1|Apps-A|EPG-A
  • D. Prod|Apps-A|EPG-A

Answer: D

Explanation:
The port group name is a concatenation of the tenant name, the application profile name, and the EPG name.
https://www.cisco.com/c/dam/m/en_us/solutions/data-center-virtualization/application-centric- infrastructure/aci-virtualization-guide-chapter.pdf


NEW QUESTION # 45
......

Reliable Study Materials for 300-620 Exam Success For Sure: https://www.torrentexam.com/300-620-exam-latest-torrent.html

Get Unlimited Access to 300-620 Certification Exam Cert Guide: https://drive.google.com/open?id=147-R_QCjKEKTlucN9PM80t9j-QOi-8JG