300-620 — Frequently Asked Questions
Community-vetted answers to 59 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
ACI Multi-Site Architecture Descriptions
Option B describes ACI Multi-Pod, where one APIC cluster manages multiple sites. Multi-Site requires a separate APIC cluster for each site.
OSPF is commonly used for inter-site spine peering. While newer releases may support MP-BGP, OSPF is a valid and standard description for the underlay connection.
Cisco ACI L2Out Loop-Free Topology Actions
Default ACI fabric designs do not support direct leaf-to-leaf links. Such links can create loops if not carefully managed, so they must be removed to ensure a loop-free topology.
No. LACP bundles links for bandwidth and redundancy but does not prevent logical loops if the physical topology allows for them. MCP is needed for physical loop detection.
ACI Management and Data Plane Separation
Bridge Domains segment traffic at Layer 2 within a tenant but do not isolate management policies from the data plane globally.
A Tenant isolates configuration, policies, and data forwarding planes from other tenants in the ACI fabric.
ACI L3Out Contract Roles for External Initiation
Because the EPG is initiating the outbound connection to the external cloud, making it the consumer of that specific contract.
The EPG would offer services to the L3Out, but since the L3Out isn't requesting those services, the required access won't be granted.
ACI VMM Integration vSwitch Policy for Packet Loss
LACP requires strict support from both ends. In some ACI VMM integrations, MAC Pinning is preferred to avoid hashing inconsistencies that cause packet loss.
It binds a VM's traffic to a specific physical uplink, ensuring all packets follow the same path, which prevents reordering and loss during fabric processing.
ACI Out-of-Band APIC Access Configuration
Switching to in-band moves management traffic into the fabric, preventing direct out-of-band access to the 192.168.11.2 host.
Yes, but in this exam scenario, removing the in-band address is required to resolve the access issue for the specific OOB host.
APIC Fallback Authentication for Local Access
Referencing the local realm in the fallback domain configures the system's internal fallback behavior but may not provide a user-selectable login option in the GUI as reliably as a dedicated domain.
Cisco recommends creating an additional login domain specifically for local accounts to ensure clear separation and reliable access during primary server outages.
How to Add a Second L3Out Link to Core-2 for BL-1002 Connectivity?
The OSPF interface profile already exists on the logical interface profile; a new path automatically uses it, so adding another profile is unnecessary.
It creates the new link to Core-2 with its own IP and VLAN, inheriting the existing OSPF and routing settings for identical connectivity.
ACI VMM Domain Port Group Not Created: What Fix?
APIC allocates a VLAN from the VMM domain's VLAN pool for each automatic port group, so an empty VMware/west-VLP leaves no VLAN ID to assign and vCenter creation fails.
Credentials affect VMM domain inventory and connectivity, but the exhibit's EPG-to-VMM association is already in place; the direct blocker is that west-VLP has no usable VLANs for port group allocation.
How Can EPG-12 and EPG-10 Share VLAN-12 on the Same ACI Leaf?
Cisco requires EPGs that share one VLAN encapsulation on a leaf to be in different bridge domains, so reusing EPG-10's BD would violate the duplicate-encapsulation guidelines.
No. Native VLAN applies to untagged or trunk traffic, while the conflict here is about ACI EPG VLAN encapsulation uniqueness, which port-local VLAN scope resolves.
How to Prevent Unknown Unicast Flooding in a Cisco ACI Bridge Domain?
In optimized (hardware-proxy) mode, the leaf sends unknown unicast to the spine proxy instead of flooding the BD's multicast tree (GIPo), so frames are not flooded everywhere.
No. Flood in Encapsulation keeps the default flooding behavior and sends unknown unicast over the BD multicast tree; it does not prevent flooding.
How to Upgrade Cisco ACI Firmware with Minimal Disruption
Cisco wants the engineer to choose the validated target image, not whichever file was uploaded last. That control is what keeps the three-APIC cluster, spines and leaves on the intended release.
No. The APIC cluster is upgraded first, then leaf and spine switches are handled in their own maintenance groups so the 1-Gb server and 10-Gb storage links are not disrupted together.
Which Bridge Domain Setting Enables ACI Source IP Learning?
Unicast Routing is the ACI BD setting that allows the leaf to learn IP addresses from data-plane traffic on front-panel ports. Without it, the leaf does not perform that IP address learning.
No. ARP Flooding controls how ARP requests are flooded in the bridge domain, while source IP learning is controlled by the BD's Unicast Routing setting.
Migrating ESXi Gateway to Firewall in ACI
Disabling unicast routing turns the BD into a pure L2 domain. The ACI switch will not process IP headers for routing, so packets to the firewall will be dropped or flooded incorrectly.
Not necessarily. The firewall can be in the same EPG/BD or connected via an L3Out. However, the BD itself must have unicast routing enabled to pass IP traffic.
Replacing VMs in Cisco ACI VPC Interface Policy Group
No, VLAN pools are not assigned directly to interface policy groups. They must be associated with an AAEP, which is then attached to the interface.
The AAEP maps the interface to a specific VLAN pool and physical domain, enabling the correct network connectivity for endpoints.
How Does ACI Multi-Pod Forward ARP When Flooding Is Disabled?
ARP optimization is a leaf function that answers ARP locally using COOP-learned remote IP-to-MAC bindings; it does not describe how a spine forwards an ARP request from POD1 to POD2.
It is the destination address the spine uses to forward ARP Glean messages to leaf switches in remote pods when ARP flooding is disabled in the bridge domain.
Which ACI Bridge Domain Setting Forces Remote Leaves to Delete EP1?
No. You must also enable Clear Remote MAC Entries on the bridge domain; only then does the local leaf signal remote leaves to delete EP1 immediately instead of waiting for the aging timer.
Hardware Proxy uses the spine proxy for unknown unicast and does not expose the Clear Remote MAC Entries option, so remote leaves keep EP1 until the endpoint aging timer expires.
Which ACI VPC Protection Type Pairs Odd and Even Leaf Switches?
Consecutive pairs adjacent leaves such as 101-102 and 103-104, so each VPC group would contain one odd and one even switch instead of two odd or two even leaves.
No. Explicit requires the administrator to name the two leaf nodes that form each VPC pair, so APIC does not select the groups automatically as the scenario demands.
Which Component Provides Layer 2 and Layer 3 Connectivity Across ACI Pods?
VXLAN is the encapsulation the ACI fabric uses end to end, but it still needs the Inter-Pod Network to carry its packets between pods, so the IPN is the connectivity component.
COOP is a spine control-plane protocol that shares endpoint reachability information between pods, while the IPN is the data-path network that actually transports the VXLAN traffic.
How to complete ACI SNMP trap destination configuration?
The SNMP Monitoring Destination Group defines trap receivers, and SNMP traps are sent to UDP 162. UDP 161 is for polling, which is handled by the SNMP Client Group Profile.
ACI does not have an 'SNMP management contract'; the mgmt tenant out-of-band contract on the OOB EPG is where you add the UDP 162 filter for SNMP traps.
Cisco ACI VMM Port Group Naming Convention
The VMM domain is used for association and mapping, but the port group name is automatically generated using only the Tenant, Application Profile, and EPG names.
No, the Bridge Domain is associated with the EPG for Layer 2 connectivity but is not included in the vCenter port group naming string.
ACI Endpoint Communication within Same EPG
Contracts only restrict traffic between different EPGs. Traffic within the same EPG is permitted by default.
It enables Layer 3 routing capabilities within the Bridge Domain, allowing the fabric to route packets between subnets or endpoints if L2 forwarding fails.
How Is a Server Learned on a vPC Peer Leaf in Cisco ACI?
Plain remote entries come from leaf switches that are not vPC peers; because Leaf1 is Leaf2's vPC peer, the synchronized entry is flagged on-peer, a special variant of remote.
A bounce entry is a temporary entry created after an endpoint move or MAC flap to avoid black-holing traffic until the endpoint is re-learned; S1 is stable here, so it is not bounce.
How Does Cisco ACI Detect a Moved Silent Host's IP Address?
A bounce entry is installed on the old leaf only after the move is detected via COOP, so it redirects traffic to the new location instead of discovering where a silent host went.
The leaf proxy-replies from its stale endpoint entry, the ARP request never reaches the moved host, and the new location stays undetected until the silent host sends traffic.
Which Action Completes L4-L7 Device Object for Single-NIC Routed Firewall?
GoTo is the default function type for routed mode in ACI, so changing it to GoTo is redundant; the missing configuration is the second cluster interface.
Yes, by defining both inside and outside cluster interfaces on the same adapter using VLANs or subinterfaces, which allows the firewall to route traffic.
Which Feature Programs Leaf Policy CAM Without VM Traffic?
Resolution immediacy only decides whether the policy is resolved/downloaded onto the leaf, while deployment immediacy decides when that policy is actually written into the leaf's hardware policy CAM.
The leaf holds the policy until the first packet arrives from an endpoint, so no CAM entry is programmed until VM traffic reaches the leaf switch.
Detecting Silent Endpoints in Cisco ACI L3BD
In a pure Layer 2 BD, endpoints are learned only when they send traffic. Silent devices never initiate traffic, so they remain invisible to the MAC address table.
Yes, it generates ARP requests to probe for endpoints. However, this is a controlled overhead necessary for accurate inventory and policy application in ACI.
Cisco ACI User Security Domain Configuration
The 'common' security domain is associated with all tenants by default. Assigning it grants access to every tenant, violating the requirement to access ONLY Common and PROD.
It creates a specific permission scope limited to the PROD tenant. Associating this domain with the user explicitly grants access to PROD without affecting other tenants.
ACI COOP Endpoint Type: Bounce Entry vs Remote
Remote is a general state; bounce entry is the specific ACI term for an endpoint learned via COOP from spines rather than direct data-plane learning.
Enabling MCP to Prevent Layer 2 Loops in ACI
No, local enablement only affects the specific interface. Global enablement is required for the fabric to coordinate loop detection and mitigation.
It is configured under Fabric > Access Policies > Policies > Global > MCP Instance Policy.