Implementing Cisco Application Centric Infrastructure - Advanced (DCACIA) Free Sample Questions

20 free sample questions238 in the full practice test

Try simulator

600-660 Sample Questions

  1. Question 1

    A financial institution is deploying a Cisco ACI Multi-Pod fabric. To meet regulatory requirements, all inter-pod traffic traversing the IPN must be encrypted. The IPN is comprised of Nexus 7700 switches which do not natively support CloudSec. Which ACI feature must be configured on the spine switches to meet this requirement?

    Answer and explanation

    Correct answer: B

    When the IPN devices do not support CloudSec, the recommended and supported method for encrypting inter-pod traffic is to use MACsec (802.1AE) on the physical links between the ACI spine switches and the IPN. This provides hop-by-hop Layer 2 encryption. CloudSec is used for ACI Multi-Site encryption over the ISN. L3Out with IPsec is a valid encryption method but is more complex and typically used for connecting to external networks, not for the IPN itself. GDOI is not the standard mechanism for IPN encryption in ACI.

  2. Question 2

    An administrator is troubleshooting endpoint learning in a large ACI fabric. They notice that a specific leaf switch is frequently flagging endpoints as 'rogue' even though the endpoints are legitimate and have not physically moved. The affected endpoints are connected via a vPC to a pair of leaf switches. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: D

    When a server connected via vPC uses an active/active NIC teaming mode (like source MAC hashing) without a link aggregation protocol like LACP, it can send traffic from the same MAC address out of both physical NICs. The ACI leaf switches may see the same endpoint MAC address rapidly appearing on different ports in the vPC, leading the rogue endpoint detection feature to incorrectly flag it. The correct configuration is to use LACP for active/active teaming to present a single logical link to the fabric.

  3. Question 3

    A network architect is designing a Cisco ACI Multi-Site solution to connect two data centers. They need to stretch a Bridge Domain (BD) between the two sites but want to ensure that BUM (Broadcast, Unknown Unicast, Multicast) traffic from Site1 does not flood over the ISN to Site2. Which configuration on the stretched BD object within the MSO schema will achieve this goal?

    Answer and explanation

    Correct answer: C

    In a Multi-Site environment, the Bridge Domain can be configured with 'Optimized WAN' (OWAN) mode, also referred to as 'Inter-Site BUM Traffic Allow' set to disabled. This configuration ensures that BUM traffic is contained within the local site and not forwarded across the Inter-Site Network (ISN). This is the standard best practice to conserve expensive WAN bandwidth and prevent fault propagation between sites.

  4. Question 4

    An engineer needs to implement a policy where EPG-Web is allowed to communicate with EPG-App on TCP port 8080, but under no circumstances should EPG-Web be able to initiate any traffic to EPG-DB. Both EPG-Web and EPG-App are consumers of a contract provided by EPG-DB. How can this explicit denial be enforced with the highest precedence?

    Answer and explanation

    Correct answer: B

    A taboo contract is a special type of contract that explicitly denies communication between EPGs. It has a higher priority than standard allow contracts. By creating a taboo contract between EPG-Web and EPG-DB, all traffic will be dropped, regardless of any other contracts that might permit communication. A standard contract with a deny filter has lower precedence. vzAny doesn't provide the specific EPG-to-EPG denial required. Setting contract priorities can work but is more complex to manage; taboo is the most direct and highest-precedence method for this specific requirement.

  5. Question 5

    Multiple answers

    During a migration from a traditional network to Cisco ACI, an engineer connects a legacy switch trunk port to an ACI leaf switch. The legacy switch is the STP root for several VLANs. To prevent loops while allowing for a phased migration, how should Spanning Tree Protocol be handled on the ACI side? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    BPDU Filter prevents the ACI leaf from sending BPDUs out of the port, which is crucial to not interfere with the external STP domain where the legacy switch is root.

    BPDU Guard should be enabled on ACI ports facing traditional switches. This is a safety mechanism; if the ACI leaf unexpectedly receives a superior BPDU, it will err-disable the port, preventing a potential loop from forming. The combination of BPDU Filter (outbound) and BPDU Guard (inbound) is the Cisco best practice for this scenario.

  6. Question 6

    Multiple answers

    A solutions architect is designing a service graph with Policy-Based Redirect (PBR) to send specific traffic to a firewall for inspection. The firewall is stateful and must see both the request and response packets of a flow. The client EPG and server EPG are in the same Bridge Domain.

    CLIENT (EPG-A) [ ACI FABRIC ] SERVER (EPG-A)
    | PBR
    v
    FIREWALL
    

    Which two settings are mandatory for this PBR deployment to function correctly? (Select TWO)

    Answer and explanation

    Correct answers: C, E

    Symmetric PBR ensures that return traffic from the server to the client is also redirected through the same firewall instance, which is essential for stateful inspection.

    Since the client and server are in the same EPG (and therefore the same BD), this is an intra-EPG contract scenario. For PBR to work in this case, both the consumer and provider connectors of the service graph must be attached to the same EPG (EPG-A), effectively redirecting traffic that originates and terminates within that EPG.

  7. Question 7

    True or False: In a Cisco ACI Multi-Pod deployment, the Council of Oracle Protocol (COOP) is used for announcing endpoint information not only to the local pod's spines but also to the spines in remote pods via the IPN.

    Answer and explanation

    Correct answer: B

    This statement is false. COOP is responsible for distributing endpoint information (MAC and IP addresses) to the spine proxy database within its local pod only. For inter-pod communication, MP-BGP EVPN is used over the IPN to advertise endpoint reachability information between the pods.

  8. Question 8

    In a Cisco ACI fabric, an administrator needs to ensure that an IP address is only learned as an endpoint if it belongs to a configured subnet on the Bridge Domain. Any IP learned from a source outside of the BD's defined subnets should be discarded. Which setting on the Bridge Domain achieves this?

    Answer and explanation

    Correct answer: A

    The 'Limit IP Learning to Subnet' option (also known as Enforce Subnet Check in some versions/contexts) on a Bridge Domain enforces that the fabric only learns endpoint IP addresses that fall within the subnets configured under that BD. This is a security and hygiene feature to prevent learning of unexpected or misplaced endpoints.

  9. Question 9

    An organization has two ACI fabrics, SiteA and SiteB, managed by a Cisco Multi-Site Orchestrator (MSO). A web application in SiteA (VRF1, EPG-Web) needs to access a database in SiteB (VRF2, EPG-DB). The requirement is to allow this communication without merging the VRFs. Which MSO construct must be configured in the schema to enable this inter-site, inter-VRF communication?

    Answer and explanation

    Correct answer: D

    In MSO, communication between EPGs in different VRFs and different sites is achieved by configuring route leaking between the VRFs at the schema level. This is typically done in conjunction with an inter-site L3Out configuration within the template. MSO automates the underlying BGP EVPN route-target configurations on both fabrics to allow the selective exchange of routes between VRF1 in SiteA and VRF2 in SiteB, enabling the required communication.

  10. Question 10

    An engineer is configuring VRF route leaking between VRF-A and VRF-B within a single ACI tenant. The goal is to allow a specific subnet (192.168.10.0/24) from an EPG in VRF-A to be accessible by an EPG in VRF-B. What is the key configuration object that controls which specific prefixes are leaked?

    Answer and explanation

    Correct answer: B

    When configuring inter-VRF route leaking, the subnet object under the EPG that is providing the contract must have its scope configured correctly. To leak the subnet to another VRF, the scope must be set to 'Shared between VRFs'. This tells the fabric that this specific prefix is eligible to be advertised to other VRFs that consume the contract.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 238 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon