Authentic Best resources for 300-620 Test Engine Practice Exam [Q15-Q34]

Share

Authentic Best resources for 300-620 Test Engine Practice Exam

[2026] 300-620 PDF Questions - Perfect Prospect To Go With Actual4Labs Practice Exam


Cisco 300-620 exam is an essential certification for IT professionals who are responsible for managing and implementing Cisco ACI solutions. 300-620 exam validates the candidate's knowledge and skills related to Cisco ACI implementation, configuration, and management. By passing 300-620 exam, candidates can demonstrate their expertise in Cisco ACI and enhance their career prospects in the IT industry.


Cisco 300-620 Exam Topics:

SectionWeightObjectives
Integrations15%1. Implement VMware vCenter DVS integration
2. Describe resolution immediacy in VMM
3. Implement service graph (managed and unmanaged)
ACI Packet Forwarding15%1. Describe endpoint learning
2. Implement bridge domain configuration **** (unicast routing, Layer 2 unknown hardware proxy, ARP flooding)
ACI Management20%1. Implement out-of-band and in-band
2. Utilize syslog and snmp services
3. Implement configuration backup (snapshot/config import export)
4. Implement AAA and RBAC
5. Configure an upgrade
ACI Fabric Infrastructure20%1. Describe ACI topology and hardware
2. Describe ACI Object Model
3. Utilize faults, event record, and audit log
4. Describe ACI fabric discovery
5. Implement ACI policies
  • access
  • fabric

6. Implement ACI logical constructs

  • tenant
  • application profile
  • VRF
  • bridge domain (unicast routing, Layer 2 unknown hardware proxy, ARP flooding)
  • endpoint groups (EPG)
  • contracts (filter, provider, consumer, reverse port filter, VRF enforced)

 

NEW QUESTION # 15
Refer to the exhibit. The default route is not present in the routing tables of the Cisco ACI leaf switches. All static and direct routes are currently being redistributed and advertised.

Which action must be taken to advertise a default route on the eBGP L3Out?

  • A. Configure a static default route on the ACI node profiles with next-hop null.
  • B. Create a Default Route Leak Policy on the L3Out.
  • C. Enable a BGP peer prefix policy set to Always.
  • D. Implement an export route map matching 0.0.0.0/0.

Answer: B


NEW QUESTION # 16
A Solutions Architect is asked to design two data centers based on Cisco ACI technology that can extend L2/L3, VXLAN, and network policy across locations. ACI Multi-Pod has been selected.
Which two requirements must be considered in this design? (Choose two.)

  • A. A single APIC Cluster is required in a Multi-Pod design. It is important to place the APIC Controllers in different locations in order to maximize redundancy and reliability.
  • B. ACI Multi-Pod does not support Firewall Clusters across Pods. Firewall Clusters should always be local.
  • C. ACI Multi-Pod requires an IP Network supporting PIM-Bidir.
  • D. ACI underlay protocols, i.e. COOP, IS-IS and MP-BGP, spans across pods. Create QoS policies to make sure those protocols have higher priority.
  • E. Multi-Pod requires multiple APIC Controller Clusters, one per pod. Make sure those clusters can communicate to each other through a highly available connection.

Answer: A,C

Explanation:
Multipod is with only a single APIC cluster - multisite requires multiple clusters.
"The entire network hence runs as a single large fabric from an operational perspective; however, ACI Multi-Pod introduces specific enhancements to isolate as much as possible the failure domains between Pods, contributing to increase the overall design resiliency. This is achieved by running separate instances of fabric control planes (IS-IS, COOP, MP-BGP) across Pods."
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric- infrastructure/white-paper-c11-737855.html


NEW QUESTION # 17
Which role do interfaces Ethernet 1/49-50 have in this output?

  • A. server uplink ports
  • B. server fabric ports
  • C. leaf fabric ports
  • D. leaf access ports

Answer: C


NEW QUESTION # 18
An engineer configured a bridge domain with the hardware-proxy option for Layer 2 unknown unicast traffic. Which statement is true about this configuration?

  • A. The Layer 2 unknown hardware proxy lacks support of the topology change notification.
  • B. The leaf switch drops the Layer 2 unknown unicast packet if it is unable to find the MAC address in the local forwarding tables.
  • C. The spine switch drops the Layer 2 unknown unicast packet if it is unable to find the MAC address in the proxy database.
  • D. The leaf switch forwards the Layers 2 unknown unicast packets to all other leaf switches if it is unable to find the MAC address in its local forwarding tables.

Answer: C

Explanation:
When using hardware-proxy, you should consider enabling unicast routing and defining a subnet on the bridge domain. This is because with hardware-proxy on, if a MAC address has been aged out in the spine switch-proxy, traffic destined to this MAC address is dropped.
Reference: https://www.cisco.com/c/en/us/td/docs/dcn/whitepapers/cisco-application-centric- infrastructure-design-guide.html#Usinghardwareproxytoreduceflooding


NEW QUESTION # 19
What does a bridge domain represent?

  • A. Layer 3 cloud
  • B. tenant
  • C. physical domain
  • D. Layer 2 forwarding construct

Answer: D

Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2- x/L2_config/b_Cisco_APIC_Layer_2_Configuration_Guide/ b_Cisco_APIC_Layer_2_Configuration_Guide_chapter_010.html


NEW QUESTION # 20
A network engineer must integrate VMware vCenter cluster with Cisco ACI. The requirement is for the management traffic of the hypervisors and VM controllers to use the virtual switch associated with the Cisco Application Policy. The EPG called "Vmware-MGMT" with VLAN 300 has been created for this purpose. Which set of steps must be taken to complete the configuration?

  • A. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
    Associate the target EPG with the VMM domain with default settings.
  • B. Associate the target EPG with the VMM domain with default settings.
    Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
  • C. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
    Create a static binding in the target EPG toward VMware hypervisors with VLAN 300, untagged access VLAN, and Untagged 802.1P mode.
  • D. Add VLAN 300 with static allocation to the VLAN POOL that is used for VMM integration.
    Attach the VMM domain to the target EPG with resolution preprovision, mode static, untagged access VLAN, and Port-Encap 300.

Answer: C

Explanation:
To integrate the VMware vCenter cluster with Cisco ACI and ensure that the management traffic of the hypervisors and VM controllers uses the virtual switch associated with the Cisco Application Policy, the following steps must be taken:
Enable Infrastructure VLAN on AAEP used toward VMware hypervisors: This step involves enabling the infrastructure VLAN on the Attachable Access Entity Profile (AAEP) that is used for the VMware hypervisors. This VLAN is used for carrying infrastructure traffic such as management, vMotion, and fault tolerance.
Create a static binding in the target EPG toward VMware hypervisors with VLAN 300: This step involves creating a static binding in the "Vmware-MGMT" EPG for the VMware hypervisors with VLAN 300, setting it as an untagged access VLAN, and using Untagged 802.1P mode. This ensures that the management traffic is correctly tagged and associated with the appropriate EPG.
Reference:
Cisco ACI Fabric Hardware Installation Guide
Cisco ACI Troubleshooting Guide
Cisco ACI Multi-Site Architecture White Paper
Cisco ACI Virtual Machine Manager (VMM) Integration White Paper


NEW QUESTION # 21
An engineer configures a one-armed policy-based redirect service Insertion for an unmanaged firewall. The engineer configures these Cisco ACI objects:
a contract named All_Traffic_Allowed
a Layer 4 to Layer 7 device named FW-Device
a policy-based redirect policy named FW-1Arm-Policy-Based RedirectPolicy Which configuration set redirects the traffic to the firewall?

  • A. Configure a policy-based redirect subject.
    Associate the policy-based redirect subject with All_Traffic_Allowed.
  • B. Configure a service graph.
    Associate the service graph with All_Traffic_Allowed.
  • C. Configure a firewall bridge domain.
    Associate the bridge domain with FW-Device.
  • D. Configure a device interface policy.
    Associate the device interface policy with FW-Device.

Answer: B


NEW QUESTION # 22
What must be configured to allow SNMP traffic on the APIC controller?

  • A. SNMP relay policy
  • B. out-of-band bridge domain
  • C. out-of-band management interface
  • D. contract under tenant mgmt

Answer: D


NEW QUESTION # 23
An engineer is configuring a VRF for a tenant named Cisco. Drag and drop the child objects on the left onto the correct containers on the right for this configuration.

Answer:

Explanation:

Explanation
Application profile---> VRF--> Bridge Domain---> EPG


NEW QUESTION # 24
What represents the unique identifier of an ACI object?

  • A. application programming interface
  • B. universal resource identifier (URI)
  • C. management information tree
  • D. distinguished name

Answer: D

Explanation:
Reference:
https://www.slideshare.net/CiscoDevNet/introduction-to-aci-apis


NEW QUESTION # 25
Which description regarding the initial APIC cluster discovery process is true?

  • A. The ACI fabric is discovered starting with the spine switches.
  • B. Every switch is assigned a unique AV by the APIC.
  • C. The APIC uses an internal IP address from a pool to communicate with the nodes.
  • D. The APIC discovers the IP address of the other APIC controllers by using Cisco Discovery Protocol.

Answer: C

Explanation:
The initial APIC cluster discovery process involves each APIC using an internal private IP address from a pool to communicate with the nodes and other APICs in the cluster. The APICs discover the IP addresses of other APIC controllers through an LLDP-based discovery process


NEW QUESTION # 26
An engineer is in the process of discovering a new Cisco ACI fabric consisting of two spines and four leaf switches. The discovery of leaf 1 has just been completed. Which two nodes are expected to be discovered next? (Choose two.)

  • A. spine 2
  • B. leaf 3
  • C. leaf 2
  • D. leaf 4
  • E. spine 1

Answer: A,E


NEW QUESTION # 27
An engineer needs to avoid loops in the ACI network and needs an ACI leaf switch to error-disable an interface if the interface receives an ACI-generated packet. Which action meets these requirements?

  • A. Enable the Loop Indication by MCP event in the Error Disabled Recovery Policy.
  • B. Set Rogue EP Control in the Endpoint Controls Policy.
  • C. Change the default administrative state of the global MCP Instance Policy.
  • D. Uncheck the Loop Protection Action check box in MCP Instance Policy.

Answer: C

Explanation:
MisCabling Protocol (MCP) detects loops from external sources (i.e., misbehaving servers, external networking equipment running STP, etc.) and will err-disable the interface on which ACI receives its own packet. Enabling this feature is a best practice, and it should be enabled globally and on all interfaces, regardless of the end device. For MCP to be enabled, you need to have it enabled globally and on a per-interface basis. While MCP is enabled on all interfaces by default, it is not turned "on" until you also enable it globally. The global configuration knob for MCP can be enabled by configuring the global settings here: Fabric > Access Policies > Global Policies > MCP Instance Policy default. https://www.cisco.com/c/dam/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/aci-guide-using-mcp-mis-cabling-protocol.pdf


NEW QUESTION # 28
Refer to the exhibit. The VMs called VM1 and VM2 are deployed on the ESXi Server in a Cisco ACI environment.
VM1 has MAC address A and an IP address 192.168.1.1/24, and VM2 has MAC address B.
VM1 has been shut down. Which set of actions must be taken to detect the movement of IP address 192.168.1.1/24 to MAC address B?

  • A. Disable ARP flooding.
    Enable unicast routing.
    Disable GARP-based detection.
  • B. Enable ARP flooding.
    Enable unicast routing.
    Enable GARP-based detection.
  • C. Disable ARP flooding.
    Disable unicast routing.
    Disable GARP-based detection.
  • D. Enable ARP flooding.
    Disable unicast routing.
    Enable GARP-based detection.

Answer: B

Explanation:
GARP is used to update IP to MAC relation on upstream network devices. It is most relevant in case of vmotions or VMs/servers moving from one host to another, and the MAC address changes, but the IP remains the same.
In the context of ACI, the leaf switches can detect MAC and IP address movement between leaf switch ports, leaf switches, bridge domains, and EPGs, but it does not detect the movement of an IP address to a new MAC address if the new MAC address is from the same interface and same EPG as the old MAC address.
When the GARP based detection option is enabled (configuration available under the BD), Cisco ACI will trigger an endpoint move based on GARP packets if the move occurs on the same interface and same EPG. If a GARP packet comes from the same interface and same EPG, then endpoint learning is triggered only when Unicast Routing, ARP Flooding, and "GARP based detection" are all enabled for the bridge domain.


NEW QUESTION # 29
A data center administrator is upgrading an ACI fabric. There are 3 APIC controllers in the fabric and all the servers are dual-homed to pairs of leaf switches configured in VPC mode. How should the fabric be upgraded to minimize possible traffic impact during the upgrade?

  • A. Option A
  • B. Option B
  • C. Option D
  • D. Option C

Answer: A


NEW QUESTION # 30
Refer to the exhibit. A company deployed Cisco ACI and plans to migrate the first servers to the Cisco ACI fabric. The current network setup experiences a small number of silent hosts. What is the Cisco recommended bridge domain configuration to support the network topology presented?

  • A. ARP Flooding: Disabled
    L3 Unknown Multicast Flooding: Flood
  • B. ARP Flooding: Enabled
    Multi Destination Flooding: Flood in BD
  • C. Unicast Routing: Disabled
    L2 Unknown Unicast: Flood
  • D. Unicast Routing: Enabled
    L2 Unknown Unicast: Hw Proxy

Answer: D

Explanation:
When you extend an existing L3-switched network into ACI and keep the original SVI as the gateway, enabling Unicast Routing on the bridge domain lets the fabric advertise its host routes back to that SVI. Setting L2 Unknown Unicast to HW Proxy ensures the spine/leaf fabric will proxy ARP and unknown-unicast MAC requests for those migrated servers so that "silent" hosts are reachable without flooding.


NEW QUESTION # 31
An engineer is configuring a VRF for a tenant named Cisco. Drag and drop the child objects on the left onto the correct containers on the right for this configuration.

Answer:

Explanation:


NEW QUESTION # 32
Refer to the exhibit.

When the subnet is configured on a bridge domain, on which physical devices is the gateway IP address configured?

  • A. all leaf switches and all spine nodes
  • B. all border leaf nodes where the bridge domain of the tenant is present
  • C. only spine switches where the bridge domain of the tenant is present
  • D. only leaf switches where the bridge domain of the tenant is present

Answer: D

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_0111.html


NEW QUESTION # 33
A Cisco ACI fabric is built to monitor and manage APIC devices using SNMP. Which action allows SNMP to receive traps from APIC controllers?

  • A. Permit UDP port 162 on the filter entry of the default subject.
  • B. Provide a standard contract under the management tenant.
  • C. Add a deny any rule under out-of-band contract.
  • D. Consume out-of-band contract from the common tenant.

Answer: A

Explanation:
SNMP traps are sent from the APIC to the trap receiver using UDP port 162. To allow these traps to leave the APIC through the management EPG, the filter entry in the default subject must explicitly permit UDP/162, enabling the APIC to send SNMP traps successfully.


NEW QUESTION # 34
......

Best updated resource for 300-620 Online Practice Exam: https://gocertify.actual4labs.com/Cisco/300-620-actual-exam-dumps.html

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now