300-620 Sample Questions

300-620 Sample Questions & Answers

Fabric architecture, external Layer 2/3 connectivity and day-to-day ACI management are weighted equally highest, alongside endpoint-learning behavior, VMM integration, and awareness of Multi-Pod, Multi-Site and Remote Leaf designs.

Launch the full 300-620 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    External Network Connectivity · L3Out OSPF Configuration

    A network administrator is configuring an L3Out on a border leaf to establish an OSPF adjacency with a core router. The administrator has configured the L3Out, a node profile, an interface profile, and the OSPF interface policy. However, the OSPF adjacency is not forming. What is a common configuration step that is missing?

    Show answer & explanation

    Correct answer: C

    For an L3Out to be fully functional and for routes to be exchanged, an External EPG (also known as an External Network Instance Profile) must be configured. This object is used to classify external networks and apply contracts. Without it, the L3Out is not complete, and routing protocol adjacencies may not form correctly or routes will not be exchanged.

  2. Question 2Intermediate

    Integrations · VMM Domain Microsegmentation

    An organization is using Cisco ACI with VMware vCenter integration. They want to automatically assign newly provisioned VMs to specific EPGs based on the VM name. For example, any VM with a name starting with 'WEB' should be placed in the 'Web_EPG'. Which ACI feature should be used to achieve this?

    Show answer & explanation

    Correct answer: A

    Microsegmentation (uSeg) EPGs allow for the dynamic classification of endpoints based on their attributes. When integrated with a VMM domain like VMware vCenter, you can create rules based on various VM attributes, including 'VM Name', 'IP Address', 'OS', or custom attributes. This allows for automated policy assignment without manual intervention.

  3. Question 3Beginner

    ACI Fabric Infrastructure · ACI Logical Constructs

    A new tenant has been created in Cisco ACI. An engineer creates a VRF, a bridge domain, and an application profile with an EPG. The engineer then discovers that endpoints within the EPG cannot communicate with each other, even though they are in the same subnet. Which object is most likely missing or misconfigured in this basic setup?

    Show answer & explanation

    Correct answer: B

    In the ACI object model, the Layer 2 forwarding construct (Bridge Domain) must be linked to the Layer 3 routing context (VRF). If the BD is not associated with a VRF, the fabric does not have a complete L2/L3 forwarding context, and endpoints will not be able to communicate, even within the same subnet, because essential functions like ARP are tied to this relationship.

  4. Question 4Beginner

    ACI Management · Firmware Management

    To upgrade the firmware on all leaf and spine switches in an ACI fabric, an administrator must create a ______, which contains the target firmware version, and a ______, which defines the nodes to be upgraded and the upgrade schedule.

    Show answer & explanation

    Correct answer: A

    The ACI firmware upgrade process involves two main components: a Firmware Group, which specifies the target firmware image, and a Maintenance Group, which contains the nodes to be upgraded and the schedule (or trigger) for the upgrade.

  5. Question 5Intermediate

    ACI Packet Forwarding · COOP Protocol

    What is the primary function of the Council of Oracle Protocol (COOP) in the Cisco ACI fabric?

    Show answer & explanation

    Correct answer: B

    COOP is a zero-conf protocol used to communicate endpoint mapping information (IP/MAC/VRF to VTEP) to the spine switches. It ensures that all spines maintain a consistent copy of the mapping database, which is used for forwarding decisions. This allows any leaf to send traffic to a spine, which can then correctly forward it to the destination leaf.

  6. Question 6Advanced

    ACI Anywhere · ACI Multi-Site Orchestrator (NDO) Configuration

    A financial institution is implementing a Cisco ACI Multi-Site architecture to connect two data centers for disaster recovery. They need to stretch a VRF and several bridge domains between the two sites to allow for seamless VM mobility. Security policy for the application must be consistent across both sites.

    The network team has deployed a Multi-Site Orchestrator (NDO) and onboarded both ACI sites. They need to design the objects in NDO that will be pushed to each site's APIC. The goal is to manage the stretched objects from a single pane of glass while allowing site-local objects to be managed independently by each site's APIC.

    Which NDO objects should the team create and configure to achieve this goal for the stretched application components?

    Show answer & explanation

    Correct answer: B

    In NDO (formerly MSO), the correct method to create stretched objects is to use a single schema that is associated with all relevant sites. Within this schema, you create a template that holds the configuration for the stretched tenant. By defining the VRF, BDs, and EPGs within this single template and marking the tenant as stretched, NDO ensures that the same configuration and policies are deployed consistently across both APIC sites, fulfilling the requirement for seamless mobility and consistent security.

  7. Question 7Intermediate

    ACI Packet Forwarding · Endpoint Learning Troubleshooting

    An administrator is troubleshooting endpoint learning issues. An endpoint connected to leaf-101 is unable to communicate with an endpoint connected to leaf-102. The administrator confirms both endpoints are in the same bridge domain and EPG. Using the leaf CLI, which command helps verify if leaf-101 has learned the remote endpoint attached to leaf-102?

    Show answer & explanation

    Correct answer: A

    The command show system internal epm endpoint ip on a leaf switch displays the endpoint manager (EPM) table entry for a specific IP address. This command will show if the endpoint is known, whether it is local or remote, the VTEP of the remote leaf it's attached to, and the encapsulation details. It is the most direct way to verify remote endpoint learning on a leaf.

  8. Question 8Advanced

    External Network Connectivity · L3Out Preferred Group

    What is the purpose of the 'preferred group' option for an External EPG (L3Out EPG)?

    Show answer & explanation

    Correct answer: C

    The 'preferred group' is a mechanism to relax the contract requirement for certain EPGs. When an EPG (including an External EPG) is a member of the preferred group, it can communicate freely with any other EPG in the same VRF that is also a member of the preferred group, without an explicit contract. This is essentially a shortcut to an 'any-to-any' policy within the group.

  9. Question 9Intermediate

    ACI Management · RBAC and Security Domains

    A consultant needs to provide read-only access to a specific tenant for an audit team. The auditors must not be able to see any other tenants or fabric-wide configurations. Which combination of RBAC components should be created and assigned to the auditors' user accounts?

    Show answer & explanation

    Correct answer: C

    In ACI's Role-Based Access Control (RBAC) model, a 'Role' defines the permissions (what a user can do, e.g., read or write), and a 'Security Domain' defines the scope (which objects a user can see, e.g., a specific tenant). To meet the requirement, you must create a new security domain that is explicitly tied to the target tenant and a role with read-only permissions. Assigning the user this role within this security domain grants them the exact access required.

  10. Question 10BeginnerSelect 3

    ACI Fabric Infrastructure · ACI Policies

    Which three policies are configured under the 'Fabric' tab in the APIC GUI? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, E

    VLAN Pools are configured under Fabric -> Access Policies. They define the ranges of VLAN IDs that can be used for port attachments.

    The BGP Route Reflector policy, which defines the spine nodes that act as MP-BGP route reflectors for the fabric, is a fabric-wide setting configured under Fabric -> Fabric Policies.

    AAEPs are a critical part of the access policy chain, linking domains (physical, VMM) to interface policies. They are configured under Fabric -> Access Policies.

Ready for the real thing?

The full 300-620 simulator has every exam-style question, timed mode, and instant scoring.