Get all the Information About Cisco 300-620 Exam 2026 Practice Test Questions
Check Real Cisco 300-620 Exam Question for Free (2026)
Cisco 300-620 certification exam is designed to test your knowledge and skills related to implementing Cisco's Application Centric Infrastructure (ACI). Implementing Cisco Application Centric Infrastructure certification is intended for network engineers, network designers, and network administrators who work with ACI solutions. By passing the Cisco 300-620 exam, you can prove your expertise in implementing and managing Cisco ACI technologies.
NEW QUESTION # 125
An engineer must configure a Layer 3 connection to the WAN router. The hosts in production VRF must access WAN subnets. The engineer associates EPGs in the production VRF with the external routed domain. Which action completes the task?
- A. Configure the Export Route Control Subnet scope for the external EPG.
- B. Configure the External Subnets for the External EPG scope for the external EPG.
- C. Configure the Shared Route Control Subnet scope for the external EPG.
- D. Configure the Import Route Control Subnet scope for the external EPG.
Answer: A
Explanation:
To complete the task of configuring a Layer 3 connection to the WAN router and allowing hosts in the production VRF to access WAN subnets, the engineer should configure the Export Route Control Subnet scope for the external EPG. This setting allows the subnets associated with the external EPG to be advertised to external routers, enabling connectivity to the WAN.
NEW QUESTION # 126
Refer to the exhibit, An engineer is deploying a Cisco ACI environment but experiences a STP loop between switch1 and switch2. Which configuration step is needed to break the STP loop?
- A. Configure a Layer 2 external bridged network on the interfaces facing the MST switches.
- B. Enable the native VLAN on the interfaces facing the MST switches using static pons in a dedicated EPG.
- C. Enable BPDU filter under the STP interface policy on the Interfaces lacing the MST switches.
- D. Configure the STP instance to VLAN mapping under the switch STP policy.
Answer: B
NEW QUESTION # 127
Refer to the exhibit.
A customer is deploying a WAN with these requirements: *Routers 1 and 2 must receive only routes 192.168.11.0/24 and 192.168.21.0724 from the Cisco ACI fabric *Reachability to the WAN users must be permitted only for the servers that are located in vrf_prod.
Which settings must be configured to meet these objectives?
- A. Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF. Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet.
- B. Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG.
- C. Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally.
Configure the subnet 192.168.31.0/24 as Private to VRF.
Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet. - D. Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally.
Configure the subnet 192.168.31.0/24 as Private to VRF.
Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG.
Answer: D
Explanation:
The scenario involves deploying a WAN with Cisco ACI, where Routers 1 and 2 (connected via an L3Out with OSPF Area 0) must receive specific routes (192.168.11.0/24 and 192.168.21.0/24) from the ACI fabric, and reachability to WAN users must be permitted only for servers in vrf_prod. The diagram shows three bridge domains (bd_vlan11, bd_vlan21, bd_vlan31) with their respective subnets and EPGs, all under vrf_prod, along with an L3Out (epg_l3out) for WAN connectivity.
Requirement Analysis
Routers 1 and 2 must receive only routes 192.168.11.0/24 and 192.168.21.0/24:
These subnets belong to bd_vlan11 and bd_vlan21, respectively. To advertise these routes to Routers 1 and 2 via the L3Out, they must be marked with the appropriate scope in the bridge domain configuration.
In ACI, the "Advertised Externally" scope on a subnet ensures that it is advertised to external routers via the L3Out routing protocol (OSPF in this case).
Reachability to WAN users must be permitted only for servers in vrf_prod:
This implies that only the subnets in vrf_prod (192.168.11.0/24, 192.168.21.0/24, and 192.168.31.0/24) should be accessible, but WAN users should only reach specific subnets based on policy.
The external EPG (epg_l3out) represents the WAN users (10.171.0.0/16), and its subnet scope must control inbound reachability.
The subnet 192.168.31.0/24 (bd_vlan31) should not be advertised to the WAN, as it is not listed in the routes Routers 1 and 2 should receive.
Option Evaluation
A . Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF. Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG:
Setting 192.168.11.0/24 and 192.168.21.0/24 as "Private to VRF" means they are not advertised externally, which fails the requirement for Routers 1 and 2 to receive these routes.
Setting 192.168.31.0/24 as "Advertised Externally" incorrectly advertises this subnet to the WAN, which is not desired.
The "External Subnets for External EPG" scope on 0.0.0.0/0 allows WAN users to reach all subnets in vrf_prod, which is correct for reachability.
Conclusion: Fails the first requirement (route advertisement).
Reference:
B . Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Private to VRF. Configure the subnet 192.168.31.0/24 as Advertised Externally. Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet:
Similar to Option A, setting 192.168.11.0/24 and 192.168.21.0/24 as "Private to VRF" prevents their advertisement to the WAN, failing the first requirement.
Setting 192.168.31.0/24 as "Advertised Externally" incorrectly advertises this subnet.
The "Shared Route Control Subnet" scope allows route leaking between VRFs, which is irrelevant here since there is only one VRF (vrf_prod) and no route leaking is required.
Conclusion: Fails both requirements (route advertisement and reachability control).
C . Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally. Configure the subnet 192.168.31.0/24 as Private to VRF. Configure an EPG subnet 0.0.0.0/0 as Shared Route Control Subnet:
Setting 192.168.11.0/24 and 192.168.21.0/24 as "Advertised Externally" ensures these subnets are advertised to Routers 1 and 2 via OSPF, meeting the first requirement.
Setting 192.168.31.0/24 as "Private to VRF" prevents its advertisement to the WAN, which aligns with the requirement since only 192.168.11.0/24 and 192.168.21.0/24 should be advertised.
The "Shared Route Control Subnet" scope on 0.0.0.0/0 in the external EPG is incorrect for controlling reachability. This scope is used for route leaking, not for defining which subnets are accessible from the external EPG.
Conclusion: Meets the first requirement but fails the second (reachability control).
D . Configure the subnets 192.168.11.0/24 and 192.168.21.0/24 as Advertised Externally. Configure the subnet 192.168.31.0/24 as Private to VRF. Configure an EPG subnet 0.0.0.0/0 as External Subnets for External EPG:
Setting 192.168.11.0/24 and 192.168.21.0/24 as "Advertised Externally" ensures these subnets are advertised to Routers 1 and 2 via OSPF, meeting the first requirement.
Setting 192.168.31.0/24 as "Private to VRF" prevents its advertisement to the WAN, which is correct since only the specified subnets should be advertised.
The "External Subnets for External EPG" scope on 0.0.0.0/0 in the external EPG (epg_l3out) allows WAN users (10.171.0.0/16) to reach all subnets in vrf_prod, which includes 192.168.11.0/24, 192.168.21.0/24, and 192.168.31.0/24. This satisfies the second requirement, as servers in vrf_prod are accessible, and contracts can further restrict access if needed (though not specified in the question).
Conclusion: Meets both requirements (route advertisement and reachability).
Final Answer Justification
D is correct because:
It ensures that only 192.168.11.0/24 and 192.168.21.0/24 are advertised to Routers 1 and 2 by setting their scope to "Advertised Externally." It keeps 192.168.31.0/24 private to vrf_prod by setting its scope to "Private to VRF." It allows WAN users to reach all vrf_prod subnets (including servers) by setting 0.0.0.0/0 as "External Subnets for External EPG," fulfilling the reachability requirement.
Primary Cisco Reference:
Cisco APIC Layer 3 Configuration Guide, "Configuring Subnets for L3Out." Cisco ACI Routing and Forwarding Guide, "External EPG and Subnet Scopes." Cisco ACI Best Practices, "Controlling Route Advertisement and Reachability."
NEW QUESTION # 128
Which tenant is used when configuring in-band management IP addresses for Cisco APICs, leaf nodes, and spine nodes?
- A. default
- B. common
- C. mgmt
- D. infra
Answer: D
NEW QUESTION # 129
An engineer must limit management access to me Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?
- A. policy on the management VLAN
- B. policy In the management tenant
- C. ACL on the console interface
- D. ACL on the management interface of the APIC
Answer: B
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Oper
NEW QUESTION # 130
Cisco ACI fabric is integrated with VMware VDS. The fabric must apply a security policy to check the integrity of traffic out of the network adapter. Which action must be taken to drop the .. when the ESXi host discovers a mismatch between the actual source MAC address transmitted by the guest operating system and the effective MAC address of the virtual machine ....?
- A. Accept MAC changes.
- B. Reject forged transmits.
- C. Accept forged transmits.
- D. Reject MAC changes.
Answer: C
Explanation:
https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-7DC6486F-5400-44DF-8A62-6273798A2F80.html
NEW QUESTION # 131
In Cisco ACI, general steps are required to create an Application Network Profile. In Cisco ACI, general steps are required to create an Application Network Profile.
Which order should the configuration be done?
1) Create connection points between EPGs by using policy constructs.
2) Create policies to define connectivity with permit, deny, log, and
so on.
3) Create EPGs.
- A. 2, 3, 1
- B. 1, 3, 2
- C. 3, 2, 1
- D. 1, 2, 3
Answer: C
NEW QUESTION # 132
Refer to the exhibit. A Cisco ACI fabric is created with L2Out to N7K1 and N7K2 switches. The switches are running MSTP with native VLAN 10. The N7K1 and N7K2 act as the root bridge for VLAN 20. An EPG named Data has been created. The ACI fabric must be configured with these requirements:
- The ACI fabric must receive MSTP BPDU.
- The N7K1 switch must act as the root bridge for VLAN 20.
Which set of actions accomplishes these goals?
- A. Encapsulate EPG Data with VLAN 20.
Set the VLAN mode to Trunk. - B. Encapsulate EPG Data with VLAN 10.
Set the VLAN mode to 802.1P. - C. Encapsulate EPG Data with VLAN 10.
Set the VLAN mode to Trunk. - D. Encapsulate EPG Data with VLAN 20.
Set the VLAN mode to 802.1P.
Answer: B
NEW QUESTION # 133
Which two protocols support accessing backup files on a remote location from the APIC? (Choose two.)
- A. SFTP
- B. SMB
- C. FTP
- D. HTTPS
- E. TFTP
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/troubleshooting/ b_APIC_Troubleshooting/b_APIC_Troubleshooting_appendix_010011.html
NEW QUESTION # 134
Which device is the pervasive gateway shown installed on?
- A. spine switch
- B. leaf switch
- C. proxy spine switch
- D. VMM switch
Answer: B
Explanation:
In Cisco ACI, the pervasive gateway is a distributed gateway architecture that enables all leaf switches to act as Layer 3 gateways for endpoints. This means that the default gateway IP address for a bridge domain (BD) is available on all leaf switches where the BD is deployed. The configuration in the exhibit, showing VLAN information with associated interfaces, indicates that the pervasive gateway is installed on the leaf switch as part of this distributed gateway architecture. This allows endpoints connected to the leaf to communicate with the gateway locally, reducing latency and improving scalability.
NEW QUESTION # 135
An engineer is configuring a VRF for a tenant named Cisco. Drag and drop the child objects on the left onto the correct containers on the right for this configuration.
Answer:
Explanation:
Explanation
Application profile---> VRF--> Bridge Domain---> EPG
NEW QUESTION # 136
An engineer must connect Cisco ACI fabric using Layer 2 with external third-party switches. The third-party switches are configured using 802.1s protocol. Which two constructs are required to complete the task?
(Choose two.)
- A. MCP policy with PDU per VLAN enabled
- B. static binding of native VLAN in all existing EPGs
- C. spanning tree policy for mapping MST Instances to VLANs
- D. MCP instance policy with administrative slate disabled
- E. dedicated EPG for native VLAN
Answer: C,E
Explanation:
https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/BRKACI-3101.pdf
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c07-732033.html


NEW QUESTION # 137
Refer to the exhibit. A network engineer must configure a user tenant to raise the error shown when configuring a new EPG. Which action accomplishes this goal?
- A. From Access Policies, set Exceed Action to Fail Transaction Action.
- B. From Access Policies, set Exceed Action to Raise Fault Action.
- C. From Fabric Policies, set Exceed Action to Fail Transaction Action.
- D. From Fabric Policies, set Exceed Action to Raise Fault Action.
Answer: A
Explanation:
The "quota exceeded" error shown is the API/UI blocking the transaction when you go over the configured quota. To force that behavior, you configure the tenant's Resource Quota policy (under Access Policies) and set its Exceed Action to Fail Transaction, which makes any over- quota create operation immediately error out as you see above.
NEW QUESTION # 138
An engineer plans a Cisco ACI firmware upgrade. The ACI fabric consists of three Cisco APIC controllers, two spine switches, and four leaf switches. Two leaf switches have 1-Gb copper s for bare metal servers, and the other two leaf switches have 10-Gb SFP ports to connect storage. Which set of actions accomplishes an upgrade with minimal disruptions?
- A. Upgrade the APIC controllers by selecting the desired firmware and choosing Upgrade Now.
Divide the switches into two upgrade groups: spines and leaves.
Start the firmware upgrade on the spine upgrade group and then proceed with the leaf upgrade group. - B. Upgrade the APIC controllers by selecting the desired firmware and choosing Upgrade Now.
Divide the switches into two upgrade groups with one spine, one 1-Gb switch, and one 10-Gb switch per group.
Start the firmware upgrade on the first upgrade group and when it finishes, start the second upgrade group. - C. Upgrade the APIC controllers as a single group by selecting the firmware and choosing Upgrade Now.
Divide the switches into four upgrade groups with one switch per group.
Start the firmware upgrade on each upgrade group in succession until all four are complete. - D. Upgrade the APIC controllers by initiating the upgrade process that uses the most recent uploaded firmware.
Divide the switches into three upgrade groups: spines, 1-Gb switches, and 10-Gb switches.
Start the firmware upgrade on the spine upgrade group and then proceed with the other two groups.
Answer: B
NEW QUESTION # 139
An application team tells the Cisco ACI network administrator that it wants to monitor the statistics of the unicast and BUM traffic that are seen in a certain EPG. Which statement describes the collection statistics?
- A. All EPGs in the Cisco ACI tenant object must be enabled for statistics to be collected.
- B. Cisco ACI does not capture statistics at the EPG level. Only statistics that pass through ACI contracts can be monitored.
- C. EPG statistics can be collected only for VMM domains. If a physical domain exists, statistics are not collected.
- D. The collection of statistics is enabled on the EPG level by enabling the statistics for unicast and BUM traffic.
Answer: D
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/Operating_ACI/guide/b_Cisco_Operating_ACI/b_Cisco_Operating_ACI_chapter_01011.html
NEW QUESTION # 140
An engineer must deploy Cisco ACI across 10 geographically separated data centers. Which ACI site deployment feature enables the engineer to control which bridge domains contain Layer 2 flooding?
- A. Multi-Pod
- B. Stretched Fabric
- C. GOLF
- D. Multi-Site
Answer: D
Explanation:
The Cisco ACI site deployment feature that enables an engineer to control which bridge domains contain Layer 2 flooding across geographically separated data centers is Multi-Site. This feature allows for the extension of Layer 2 and Layer 3 connectivity between different locations with consistent policy enforcement5.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/aci_multi-site/sw/2x/fundamentals/Cisco-ACI-Multi-Site-Fundamentals-Guide-211/Cisco-ACI-Multi-Site-Fundamentals-Guide-211_chapter_011.html#id_51188
NEW QUESTION # 141
An engineer is implementing a connection that represents an external bridged network. Which two configurations are used? (Choose two.)
- A. Layer 2 outside
- B. Layers 2 internal
- C. VXLAN outside
- D. Layer 2 remote fabric
- E. Static path binding
Answer: A,E
NEW QUESTION # 142
Refer to the exhibit. An engineer is integrating a VMware vCenter with Cisco ACI VMM domain configuration. ACI creates port-group names with the format of "Tenant | Application | EPG".
Which configuration option is used to generate port groups with names formatted as
"Tenant=Application=EPG"?
- A. virtual switch name
- B. security domains
- C. delimiter
- D. enable tag collection
Answer: C
Explanation:
Step 8 Configuring the delimiter during VMM domain creation, perform the following actions:
On the menu bar, choose VM NETWORKING > Inventory
In the Navigation pane, right-click VMware and click Create vCenter Domain.
In the Create vCenter Domain dialog box, enter a Name.
Optional: In the Delimiter field, enter one of the following: |, ~, !, @, ^, +, or =.
If you do not enter a symbol, the system default | delimiter will appear in the VMware PortGroup name.
NEW QUESTION # 143
What two actions should be taken to deploy a new Cisco ACI Multi-Pod setup? (Choose two.)
- A. Connect all spines to the IPN.
- B. Configure MP-BGP on IPN routers that face the Cisco ACI spines.
- C. Configure anycast RP for the underlying multicast protocol
- D. Increase interface MTU for all IPN routers to support VXLAN traffic.
- E. Configure the TEP pool of the new pod to be routable across the IPN.
Answer: D,E
NEW QUESTION # 144
......
Use Free 300-620 Exam Questions that Stimulates Actual EXAM : https://www.fast2test.com/300-620-premium-file.html
Get Ready to Boost your Prepare for your 300-620 Exam with 391 Questions: https://drive.google.com/open?id=1W9j4goIawhpx1Js7eVvUzogmBU70sMlT