600-660 Sample Questions & Answers
VRF route leaking and Layer 3 out transit routing carry the top weight, alongside VxLAN packet forwarding with server NIC teaming, IPN implementation for Multipod, Multi-Site Orchestrator deployment, and moving network-centric designs into ACI.
Launch the full 600-660 simulator →Showing 10 of 20 free samples.
- Question 1AdvancedSelect 2
Advanced ACI Policies and Integrations · Implement Layer 4 through Layer 7 PBR (including use cases)
A solutions architect is designing a service graph with Policy-Based Redirect (PBR) to send specific traffic to a firewall for inspection. The firewall is stateful and must see both the request and response packets of a flow. The client EPG and server EPG are in the same Bridge Domain.
CLIENT (EPG-A) [ ACI FABRIC ] SERVER (EPG-A) | PBR v FIREWALLWhich two settings are mandatory for this PBR deployment to function correctly? (Select TWO)
Show answer & explanation
Correct answers: C, E
Symmetric PBR ensures that return traffic from the server to the client is also redirected through the same firewall instance, which is essential for stateful inspection.
Since the client and server are in the same EPG (and therefore the same BD), this is an intra-EPG contract scenario. For PBR to work in this case, both the consumer and provider connectors of the service graph must be attached to the same EPG (EPG-A), effectively redirecting traffic that originates and terminates within that EPG.
- Question 2Intermediate
Multipod · Describe packet flow between pods
True or False: In a Cisco ACI Multi-Pod deployment, the Council of Oracle Protocol (COOP) is used for announcing endpoint information not only to the local pod's spines but also to the spines in remote pods via the IPN.
Show answer & explanation
Correct answer: B
This statement is false. COOP is responsible for distributing endpoint information (MAC and IP addresses) to the spine proxy database within its local pod only. For inter-pod communication, MP-BGP EVPN is used over the IPN to advertise endpoint reachability information between the pods.
- Question 3Beginner
ACI Packet Forwarding · Implement endpoint learning optimizations
In a Cisco ACI fabric, an administrator needs to ensure that an IP address is only learned as an endpoint if it belongs to a configured subnet on the Bridge Domain. Any IP learned from a source outside of the BD's defined subnets should be discarded. Which setting on the Bridge Domain achieves this?
Show answer & explanation
Correct answer: A
The 'Limit IP Learning to Subnet' option (also known as Enforce Subnet Check in some versions/contexts) on a Bridge Domain enforces that the fabric only learns endpoint IP addresses that fall within the subnets configured under that BD. This is a security and hygiene feature to prevent learning of unexpected or misplaced endpoints.
- Question 4Advanced
Multisite · Describe communication across sites
An organization has two ACI fabrics, SiteA and SiteB, managed by a Cisco Multi-Site Orchestrator (MSO). A web application in SiteA (VRF1, EPG-Web) needs to access a database in SiteB (VRF2, EPG-DB). The requirement is to allow this communication without merging the VRFs. Which MSO construct must be configured in the schema to enable this inter-site, inter-VRF communication?
Show answer & explanation
Correct answer: D
In MSO, communication between EPGs in different VRFs and different sites is achieved by configuring route leaking between the VRFs at the schema level. This is typically done in conjunction with an inter-site L3Out configuration within the template. MSO automates the underlying BGP EVPN route-target configurations on both fabrics to allow the selective exchange of routes between VRF1 in SiteA and VRF2 in SiteB, enabling the required communication.
- Question 5Intermediate
Advanced ACI Policies and Integrations · Implement VRF route leaking
An engineer is configuring VRF route leaking between VRF-A and VRF-B within a single ACI tenant. The goal is to allow a specific subnet (192.168.10.0/24) from an EPG in VRF-A to be accessible by an EPG in VRF-B. What is the key configuration object that controls which specific prefixes are leaked?
Show answer & explanation
Correct answer: B
When configuring inter-VRF route leaking, the subnet object under the EPG that is providing the contract must have its scope configured correctly. To leak the subnet to another VRF, the scope must be set to 'Shared between VRFs'. This tells the fabric that this specific prefix is eligible to be advertised to other VRFs that consume the contract.
- Question 6AdvancedSelect 2
Advanced ACI Policies and Integrations · Implement Layer 3 out transit routing
A consultant is tasked with designing a transit routing solution using Cisco ACI. Two external routers, R1 and R2, are connected to the ACI fabric via separate L3Outs. The goal is for R1 to learn routes from R2, and vice-versa, through the ACI fabric. The fabric itself should not originate any routes.
R1 [ ACI Fabric ] R2 (OSPF Area 1) (VRF-Transit) (OSPF Area 2)Which two configuration settings are essential for enabling this transit routing scenario? (Select TWO)
Show answer & explanation
Correct answers: A, E
The 'Export Route Control Subnet' option under the external EPG (InstP) is used to control which learned routes are re-advertised out of that L3Out. It is a fundamental component of transit routing.
The 'Import Route Control Subnet' option controls which external routes are imported into the ACI fabric's routing table for the VRF. For transit routing, routes learned from one L3Out (import) must be allowed to be advertised to the other (export).
- Question 7Beginner
ACI Packet Forwarding · Describe packet forwarding between leafs (VxLAN)
What is the primary function of the Forwarding Tag (FTAG) in a Cisco ACI fabric?
Show answer & explanation
Correct answer: B
In ACI, multi-destination traffic (like multicast or broadcast) needs to be forwarded efficiently. The fabric builds multicast trees, and the Forwarding Tag (FTAG) is used by the ingress leaf to select a specific tree (and therefore a specific spine switch) to forward the traffic. This acts as a load-balancing mechanism, ensuring that not all multi-destination traffic from a leaf goes to the same spine.
- Question 8Advanced
Multipod · Implement service graph with multipod
When implementing a service graph in a Multi-Pod ACI fabric, a firewall is deployed in Pod1. An application server in Pod2 needs to have its traffic inspected by this firewall. What is a critical design consideration for the firewall's Bridge Domain to ensure proper traffic return?
Show answer & explanation
Correct answer: B
When a service device like a firewall is in one pod, and the consumer/provider is in another, the return traffic from the firewall needs a way to get back to the correct pod. The subnet of the firewall's bridge domain must be advertised externally (e.g., via an L3Out) so that it is propagated over the IPN via MP-BGP EVPN. This ensures that when the server in Pod2 replies, the fabric knows to route the traffic to the firewall in Pod1 for inspection before forwarding it to the original client.
- Question 9Intermediate
Traditional network with ACI · Describe network-centric and application-centric designs
A network administrator is migrating a legacy data center to a network-centric ACI design. They have created one Bridge Domain and one EPG for each legacy VLAN. What is a primary drawback of this initial migration approach?
Show answer & explanation
Correct answer: B
The network-centric approach (1 VLAN = 1 BD = 1 EPG) is a common first step in migration because it mirrors the traditional network construct. However, its main drawback is that all devices within that legacy VLAN are now in the same EPG, and by default, all endpoints within an EPG can communicate freely. This fails to leverage the primary benefit of ACI: using contracts between more granular EPGs to achieve zero-trust micro-segmentation based on application function, not just network location.
- Question 10Beginner
Multisite · Implement Multi-Site Orchestrator
True or False: When using Cisco Multi-Site Orchestrator (MSO) to deploy a schema to multiple sites, all APICs in all sites must be running the exact same firmware version as the MSO.
Show answer & explanation
Correct answer: B
This statement is false. Cisco MSO maintains a compatibility matrix that allows it to manage ACI fabrics running different, but compatible, versions of APIC software. While it's a best practice to keep versions closely aligned, they are not required to be identical. The MSO version must be compatible with the APIC versions of the sites it manages, as documented by Cisco.
Ready for the real thing?
The full 600-660 simulator has every exam-style question, timed mode, and instant scoring.