Ultimate Guide to Prepare 300-620 Certification Exam for CCNP Data Center in 2026
Use Real 300-620 Dumps - Cisco Correct Answers updated on 2026
NEW QUESTION # 23
An ACI administrator notices a change in the behavior of the fabric. Which action must be taken to determine if a human intervention introduced the change?
- A. Inspect the output of show command history in the APIC CLI.
- B. Inspect audit logs in the APIC UI to see all user events.
- C. Inspect /var/log/audit_messages on the APIC to see a record of all user actions.
- D. Inspect event records in the APIC UI to see all actions performed by users.
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/all/faults/guide/b_APIC_F aults_Errors/b_IFC_Faults_Errors_chapter_010.html
NEW QUESTION # 24
An engineer wants to filter the System Faults page and view only the active faults that are present in the Cisco ACI fabric. Which two lifecycle stages must be selected for filtering? (Choose two.)
- A. Raised
- B. Retaining
- C. Raised, Clearing
- D. Soaking, Clearing
- E. Soaking
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/all/faults/guide/b_APIC_Faults_Errors/ b_IFC_Faults_Errors_chapter_01.html
NEW QUESTION # 25
An engineer is implementing a Cisco ACI environment that consists of more than 20 servers. Two of the servers support only Cisco Discovery Protocol with no order link discovery protocol. The engineer wants the servers to be discovered automatically by the Cisco ACI fabric when connected. Which action must be taken to meet this requirement?
- A. Configure a lower order policy group that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
- B. Create an interface profile for the interface that disables LLDP on the desired switch that is referenced by the interface policy group.
- C. Create an override policy that enables Cisco Discovery Protocol after LLDP is enabled in the default policy group.
- D. Configure a higher order interface policy that enables Cisco Discovery Protocol for the interface on the desired leaf switch.
Answer: C
NEW QUESTION # 26
Refer to the exhibit.
Which two objects are created as a result of the configuration? (Choose two.)
- A. application profile
- B. VRF
- C. endpoint group
- D. bridge domain
- E. attachable AEP
Answer: B,D
NEW QUESTION # 27
Which two actions extend a Layer 2 domain beyond the ACI fabric? (Choose two.)
- A. creating an external physical network
- B. creating a single homed Layer 3 Out
- C. extending the bridge domain out of the ACI fabric
- D. extending the EPG out of the ACI fabric
- E. extending the routed domain out of the ACI fabric
Answer: D,E
Explanation:
Section: External Network Connectivity
NEW QUESTION # 28
Refer to the exhibit.
Refer to the exhibit. A company merges three of its departments: CORP, HR, and SERVICES, Currently, the connectivity between departments is achieved by using VRF route leaking. The requirement is to redesign the Cisco ACI networking architecture to communicate between EPGs and BDs from any tenant without configuring contracts or VRF route leaking. Which configuration meets these criteria?
- A. Configure an enforced VRF in the user tenant and map all required EPGs to it.
- B. Implement an unenforced VRF in the common tenant and map all required BDs to it.
- C. Configure an unenforced VRF in the user tenant and map all required EPGs to it.
- D. Implement an enforced VRF in the common tenant and map all required BDs to it.
Answer: B
Explanation:
To enable communication between EPGs and BDs from any tenant without the need for contracts or VRF route leaking, the best approach is to implement an unenforced VRF within the common tenant. By doing so, all bridge domains that are associated with this VRF will be able to communicate with each other without additional configurations. This method simplifies the network architecture and reduces the complexity associated with contract management and VRF route leaking1.
Reference:
Cisco ACI Contract Guide White Paper1
NEW QUESTION # 29
Refer to the exhibit.
An application called App_1 is hosted on the server called S1. A silent host application. App_2. is hosted on S2. Both applications use the same VLAN encapsulation, which action forces Cisco ACI fabric to learn App_2 on ACI leaf 2?
- A. Set L3 Unknown Multicast to Optimized flood.
- B. Set Multi-Destination Flooding to Drop.
- C. Set Unicast Routing to Hardware Proxy.
- D. Set L2 Unknown Unicast to Flood.
Answer: D
Explanation:
The scenario involves an application (App_1) on server S1 and a silent host application (App_2) on S2, both using the same VLAN encapsulation. The task is to force the ACI fabric to learn App_2 on Leaf-2. A silent host does not generate traffic, so special handling is needed.
Requirement Analysis
A silent host requires flooding (e.g., ARP or unknown unicast) to be learned by the fabric when it moves or is detected.
The goal is to ensure Leaf-2 learns App_2's endpoint.
Option Evaluation
A . Set Multi-Destination Flooding to Drop:
Dropping multi-destination traffic prevents learning, which is counterproductive for a silent host.
Reference:
B . Set Unicast Routing to Hardware Proxy:
Hardware proxy optimizes unicast routing but does not force learning of a silent host via flooding.
C . Set L2 Unknown Unicast to Flood:
Enabling L2 unknown unicast flooding causes the fabric to flood traffic (e.g., ARP) across the bridge domain, allowing Leaf-2 to learn App_2's MAC address even if it is silent.
D . Set L3 Unknown Multicast to Optimized Flood:
This applies to multicast traffic and is irrelevant for learning a silent host's MAC address.
Final Answer Justification
C is correct because flooding L2 unknown unicast traffic ensures the ACI fabric learns App_2 on Leaf-2 by propagating ARP or other discovery traffic.
Primary Cisco Reference:
Cisco ACI Endpoint Learning Guide, "Flooding for Silent Hosts."
Cisco APIC Bridge Domain Configuration Guide.
NEW QUESTION # 30
How is an EPG extended outside of the ACI fabric?
- A. Create an external routed network that is assigned to an EPG.
- B. Statically assign a VLAN ID to a leaf port in an EPG.
- C. Create an external bridged network that is assigned to a leaf port.
- D. Enable unicast routing within an EPG.
Answer: B
Explanation:
Section: ACI Fabric Infrastructure
Explanation/Reference: https://www.dclessons.com/l2-external-network-with-aci
NEW QUESTION # 31
A customer must deploy three Cisco ACI based data centers. Each site must be separated from the others. Which characteristic of Cisco ACI Multi-Pod makes it unsuitable for this deployment?
- A. places leaf switches in the remote site that belong to the same fabric as at the headquarters site
- B. has distance and scale limitations
- C. creates a virtual pod in the remote location
- D. requires all pods to share the same Cisco APIC cluster
Answer: D
Explanation:
The characteristic of Cisco ACI Multi-Pod that makes it unsuitable for deploying three separate data centers is that it requires all pods to share the same Cisco APIC cluster. In a Multi-Pod deployment, all the pods are part of the same fabric and are managed by a single APIC cluster, which means that they are not completely isolated from each other.
NEW QUESTION # 32
Refer to the exhibit. An engineer must migrate workloads from the brownfield network to the Cisco ACI fabric. The VLAN 10 default gateway remains in the router located in the brownfield network. The bridge domain has already been associated with L2Out. Which two actions must be taken to migrate the workloads? (Choose two.)
- A. Map the MAC address of the default gateway to the bridge domain.
- B. Configure Multi-Destination Flooding Flood in Encapsulation.
- C. Enable ARP Flooding.
- D. Set L2 Unknown Unicast Flood.
- E. Select limit IP learning to Subnet.
Answer: C,D
Explanation:
Enable ARP flooding: ARP requests originated from devices connected to the Cisco ACI fabric should be able to reach the default gateway or other endpoints part of the same IP subnet and still connected to the brownfield network. Since those entities are unknown to the Cisco ACI fabric, it is required to flood ARP requests across the Cisco ACI fabric and toward the brownfield network.
Enable Unknown Unicast flooding: similar considerations valid for ARP traffic apply also to Layer
2 unknown traffic (unicast and multicast), so it is required to ensure flooding is enabled in this phase for those traffic types.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/migration_guides/migratin g_existing_networks_to_aci.html#_Toc133408118
NEW QUESTION # 33
An engineer is creating a configuration import policy that must terminate if the imported configuration is incompatible with the existing system. Which import mode achieves this result?
- A. merge
- B. atomic
- C. replace
- D. best effort
Answer: B
Explanation:
importMode
Best-effort mode: each MO is applied individually, and errors only cause the invalid MOs to be skipped.
Note
If the object is not present on the controller, none of the children of the object get configured.
Best-effort mode attempts to configure the children of the object.
Atomic mode: configuration is applied by whole shards. A single error causes whole shard to be rolled back to its original state.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/aci- fundamentals/Cisco-ACI-Fundamentals-401/Cisco-ACI-Fundamentals- 401_chapter_01011.html
NEW QUESTION # 34 
Refer to the exhibit. A client reports that the ACI domain connectivity to the fiber channel storage is experiencing a B2B credit oversubscription. The environment has a SYSLOG server for state collection messages. Which value should be chosen to clear the critical fault?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
Section: ACI Management
NEW QUESTION # 35
Which protocol does ACI use to securely sane the configuration in a remote location?
- A. TFTP
- B. HTTPS
- C. FTP
- D. SCP
Answer: D
NEW QUESTION # 36
Which two types of interfaces are supported on border leaf switches to connect to an external router? (Choose two.)
- A. FEX host interface
- B. out of band interface
- C. subinterface with VXLAN tagging
- D. subinterface with 802.1Q tagging
- E. Switch Virtual Interface
Answer: D,E
NEW QUESTION # 37
A network engineer must allow secure access to the Cisco ACl out-of-band (OOB) management only from external subnets 10 0 0024 and 192.168 20 G'25. Which configuration set accomplishes this goal?
- A. Option B
- B. Option A
- C. Option C
- D. Option D
Answer: C
NEW QUESTION # 38
An engineer configures an L30ut in VRF-1 that was configured for Import Route Control Enforcement. The L30ut uses OSPF to peer with a core switch. The L30ut has one external EPG, it has been configured with a subnet 10.1.0.0/24. Which scope must be set to force 10.1.0.0/24 to populate in the routing table for VRF-1?
- A. Import Route Control Subnet
- B. Export Route Control Subnet
- C. Shared Route for External EPG
- D. External Subnet for External EPG
Answer: A
Explanation:
The "Import Route Control Subnet" scope is used to control which external routes are imported into the ACI fabric's routing table
NEW QUESTION # 39
......
CCNP Data Center -300-620 Exam-Practice-Dumps: https://www.dumpsreview.com/300-620-exam-dumps-review.html
300-620 Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=1vibDNc8oHr4KqIVa8RkItIE8kDpeG66t

