300-630 Sample Questions

300-630 Sample Questions & Answers

VRF route leaking alongside Layer 3 transit-routing configuration carries the top weight, together with packet forwarding between leafs, IPN design for Multi-Pod, the Nexus Dashboard Orchestrator for Multi-Site, and migrating network-centric designs into ACI.

Launch the full 300-630 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Multi-Site · Implement Nexus Dashboard Orchestrator

    True or False: In a Cisco ACI Multi-Site deployment, a contract with 'Global' scope configured in a schema on the Nexus Dashboard Orchestrator (NDO) can only be consumed by EPGs within the same tenant.

    Show answer & explanation

    Correct answer: B

    False. A contract with 'Global' scope, when configured in a schema on the NDO, allows it to be exported to other tenants. This enables inter-tenant communication across the Multi-Site fabric, a key feature for shared service designs in a multi-site environment.

  2. Question 2Intermediate

    Advanced ACI Policies and Integrations · Implement Layer 4 through Layer 7 PBR (including use cases)

    A network engineer is implementing Layer 4-7 Policy-Based Redirect (PBR) in an ACI fabric to steer traffic through a firewall. The service graph is deployed, but traffic is not being correctly redirected. The firewall is a single-node device (not a cluster) and is connected to two separate leaf switches for redundancy. The PBR destination (the firewall's EPG) has health monitoring enabled. Which configuration is essential for the PBR policy to function correctly in this redundant, non-clustered setup?

    Show answer & explanation

    Correct answer: D

    When using PBR with a redundant, non-clustered service device, ACI needs a mechanism to track the health of the destination and redirect traffic if a path fails. The 'PBR Tracking' for a service device feature allows the fabric to monitor the health of multiple PBR destinations (the firewall interfaces on each leaf). If one path fails its health check, ACI automatically redirects traffic to the other healthy destination, ensuring service availability. This is the correct mechanism for this specific high-availability scenario.

  3. Question 3Intermediate

    Advanced ACI Policies and Integrations · Implement contracts (pcTag, global pcTab, contract priorities, taboo, and deny filter)

    An e-commerce company is migrating its three-tier application to a Cisco ACI fabric. The architecture requires that the Web EPG can initiate connections to the App EPG, and the App EPG can initiate connections to the DB EPG. However, the Web EPG must be strictly prohibited from communicating directly with the DB EPG. The VRF is operating in 'Enforced' mode. Which contract and filter configuration will achieve this policy?

    graph TD subgraph Tenant subgraph VRF [VRF: Enforced] EPG_Web[Web EPG] EPG_App[App EPG] EPG_DB[DB EPG] end end EPG_Web -- "Provide: http/s" --> EPG_App EPG_App -- "Consume: http/s" --> EPG_Web EPG_App -- "Provide: sql" --> EPG_DB EPG_DB -- "Consume: sql" --> EPG_App EPG_Web -.->|X DENIED X| EPG_DB
    Show answer & explanation

    Correct answer: B

    This is the most direct and correct way to implement the policy. A contract from App to Web allows the required communication. A second contract from DB to App allows that required communication. Because the VRF is in 'Enforced' mode, any communication not explicitly permitted by a contract is denied by default. Therefore, no communication is possible between Web and DB, and no additional 'deny' or 'taboo' contract is necessary.

  4. Question 4Intermediate

    Multi-Pod · Implement IPN

    A Cisco ACI fabric is being extended to a new data hall, creating a Multi-Pod topology. The IPN is built using non-ACI Nexus switches. An architect needs to ensure that if a spine switch's link to the IPN fails, traffic is rerouted in under one second. Which technology should be implemented on the spine switches and the IPN devices to meet this fast convergence requirement?

    Show answer & explanation

    Correct answer: A

    Bidirectional Forwarding Detection (BFD) is the recommended mechanism for achieving fast failure detection and convergence in an IPN. BFD provides low-overhead, sub-second failure detection for the OSPF adjacencies between the ACI spine switches and the IPN devices. When a failure is detected by BFD, it immediately informs OSPF, which can then reconverge much faster than it would by waiting for its own hello/dead timers to expire.

  5. Question 5IntermediateSelect 2

    Traditional network with ACI · Describe STP BPDU handling in ACI (FD-VNID and VLAN pool consideration)

    When integrating a traditional Layer 2 network with a Cisco ACI fabric, a network administrator must prevent STP BPDUs from the legacy network from entering the ACI fabric and causing potential instability. Which two ACI policies are commonly used on the interface policy group for the ports connecting to the legacy switches to achieve this? (Select TWO).

    Show answer & explanation

    Correct answers: A, D

    BPDU Guard, when enabled on an ACI leaf port, will err-disable the port if it receives a BPDU. This is a strong protective measure to ensure that no external STP instance can influence the ACI fabric.

    BPDU Filter, when enabled, prevents the ACI leaf port from both sending and receiving BPDUs. This effectively isolates the ACI fabric from the external STP domain without shutting down the port, making it a less disruptive option than BPDU Guard.

  6. Question 6Intermediate

    ACI Packet Forwarding · Implement endpoint learning optimizations (local/remote endpoint, limit IP subnet, enforce subnet check, IP dataplane leaning option in VRF, loop detection, and rogue EP)

    A systems administrator reports that a newly deployed virtual machine, VM-A, cannot communicate with any other endpoint. A network engineer investigates and finds that VM-A has moved from one ESXi host to another, and its IP address (10.10.10.5) is now rapidly flapping between two different leaf ports in the APIC endpoint table. This behavior is causing network instability. Which ACI feature is designed to detect and mitigate this specific issue?

    Show answer & explanation

    Correct answer: A

    Rogue Endpoint Control is the ACI feature specifically designed to handle situations where an endpoint's IP address is learned from an unauthorized or unexpected location, such as a different bridge domain or EPG. When an endpoint's IP flaps rapidly between ports, Rogue EP Control can detect this behavior, flag the endpoint as rogue, and quarantine it to prevent it from causing further instability in the fabric.

  7. Question 7Advanced

    Advanced ACI Policies and Integrations · Implement Layer 3 out VRF route leaking

    An organization has two tenants, Tenant-A and Tenant-B, each with its own VRF. A new requirement mandates that specific EPGs in Tenant-A must access a database in Tenant-B. This communication needs to traverse a firewall that is managed as a shared resource in the 'common' tenant. What is the most complex and critical type of route leaking that must be configured to facilitate this traffic flow?

    Show answer & explanation

    Correct answer: B

    This scenario requires a sophisticated form of route leaking often called 'transit routing with shared services.' It involves leaking routes from Tenant-A's VRF into the 'common' tenant's VRF, and from Tenant-B's VRF into the 'common' tenant's VRF. The firewall, connected via an L3Out (or service graph) in the 'common' tenant, then routes traffic between these leaked prefixes. This is effectively using the 'common' tenant as a transit VRF, which falls under the advanced topic of L3Out VRF route leaking.

  8. Question 8Beginner

    ACI Packet Forwarding · Implement end host attachment with ACI

    A service provider is using Cisco ACI to host multiple customers. To conserve IP addresses, the provider wants to use the same private subnet (e.g., 192.168.1.0/24) for multiple EPGs belonging to different tenants. Which ACI object property allows for this overlapping IP space while maintaining traffic isolation?

    Show answer & explanation

    Correct answer: B

    A VRF (Virtual Routing and Forwarding) instance creates a unique Layer 3 forwarding domain. By placing each tenant's EPGs and bridge domains into a separate VRF, the IP subnets are isolated from each other. The 'Private to VRF' scope on the bridge domain subnet ensures that the subnet is only significant within its own VRF, allowing the same IP address range to be reused in other VRFs without conflict.

  9. Question 9Intermediate

    Multi-Site · Describe stretched component options

    A Cisco ACI Multi-Site environment is being deployed. An architect decides to stretch a Bridge Domain (BD) and its associated EPGs between two sites using Nexus Dashboard Orchestrator (NDO). What is the primary implication of stretching the BD regarding the default gateway for endpoints in that subnet?

    Show answer & explanation

    Correct answer: C

    When a BD is stretched across sites using NDO, ACI automatically configures the subnet's gateway as an anycast gateway. This means the identical IP address and MAC address for the gateway are active on the border leaf switches in both sites simultaneously. This allows endpoints to use their local gateway for routing, optimizing north-south traffic and enabling seamless VM mobility without changing gateway configuration.

  10. Question 10Advanced

    Multi-Pod · Implement service graph with Multi-Pod

    A solutions architect is designing a service graph in a Multi-Pod ACI fabric to insert a pair of active/standby firewalls. The firewalls are physically located in Pod1 but must process traffic for endpoints in both Pod1 and Pod2. To ensure traffic symmetry (i.e., forward and reverse traffic for a flow must traverse the same firewall), which ACI feature is most critical to use in the service graph design?

    Show answer & explanation

    Correct answer: A

    When service devices are centralized in one pod but serve traffic from multiple pods, maintaining traffic symmetry is crucial for stateful devices like firewalls. ACI's PBR feature can be used to redirect traffic to the service node. By enabling the 'Symmetric PBR' option within the service graph's PBR policy, ACI ensures that the return traffic is redirected back to the same service node that processed the initial flow, thus preserving symmetry even across pods.

Ready for the real thing?

The full 300-630 simulator has every exam-style question, timed mode, and instant scoring.