Questions for the 300-620 were updated on : Dec 12 ,2025
What is the maximum number of sites connected using spine back-to-back with a direct link in a
Cisco ACI Multi-Site fabric?
A
Explanation:
In a Cisco ACI Multi-Site setup, back-to-back spine connectivity is limited to a direct connection
between two sites. This design simplifies inter-site communication by avoiding the need for an
intermediate Inter-Pod Network (IPN) or Multi-Site Orchestrator.
Refer to the exhibit.
Refer to the exhibit. An engineer connects a Cisco ACI fabric to two different Cisco Nexus 9000 Series
Switches. The fabric must be configured to ensure a loop-free topology and N9K1 be configured as
the root bridge for VLAN 10. Which action meets these requirements?
B
A Cisco ACI fabric is integrated with a Cisco ASA firewall using a service graph under the tenant called
Operations. The fabric must permit the firewall used on tenant Operations to be referenced by the
tenant called Management. Which export action must be used to accomplish this goal?
A
Explanation:
In Cisco ACI, when a service graph is deployed under one tenant (e.g., Operations) and needs to be
referenced by another tenant (e.g., Management), the Layer 4-Layer 7 (L4-L7) device export action is
used. This allows the firewall or other L4-L7 devices defined in the service graph to be shared across
tenants. By exporting the L4-L7 device, the configuration enables the Management tenant to
reference and use the firewall deployed in the Operations tenant.
An engineer needs to avoid loops in the ACI network and needs an ACI leaf switch to error-disable an
interface if the interface receives an ACI-generated packet. Which action meets these requirements?
D
Explanation:
MisCabling Protocol (MCP) detects loops from external sources (i.e., misbehaving servers, external
networking equipment running STP, etc.) and will err-disable the interface on which ACI receives its
own packet. Enabling this feature is a best practice, and it should be enabled globally and on all
interfaces, regardless of the end device. For MCP to be enabled, you need to have it enabled globally
and on a per-interface basis. While MCP is enabled on all interfaces by default, it is not turned “on”
until you also enable it globally. The global configuration knob for MCP can be enabled by configuring
the global settings here: Fabric > Access Policies > Global Policies > MCP Instance Policy default.
https://www.cisco.com/c/dam/en/us/solutions/collateral/data-center-virtualization/application-
centric-infrastructure/aci-guide-using-mcp-mis-cabling-protocol.pdf
Refer to the exhibit.
A network engineer must improve the configuration backup process and the configuration restore
process. The current ACI solution is integrated with VMMs and third-y.. L4-L7 devices. The process
requires that no additional information be re-entered when importing the configuration for a fully-
functional state. Which configuration configures the port policy?
A
Explanation:
Enabling AES encryption ensures that sensitive data, such as credentials for VMMs and third-party
integrations, is securely encrypted in the backup file. This is essential for a fully functional restore
without requiring re-entry of sensitive details.
An engineer implements a configuration backup on the Cisco APIC. The backup job must meet these
requirements:
• The backup must transfer the encrypted data to the remote server.
• The transfer must be resumed if the connection is interrupted.
Which configuration set meets these requirements?
D
Network engineer configured a Cisco ACI fabric as follows:
• An EPG called EPG-A is created and associated with a VMM domain called North. •The EPG-A is
associated with BD-A and is in an application profile called Apps-A.
• The BD-A is associated with VRF-1 in the Prod tenant.
Which port group must be selected to place VMs in EPG-A?
D
Cisco ACI fabric must detect all silent endpoints for the Layer 3 bridge domain. Which actions
accomplish this goal?
C
How many ARP requests are sent from leaf switches to perform host tracking for local endpoints?
A
An engineer plans a Cisco ACI firmware upgrade. The ACI fabric consists of three Cisco APIC
controllers, two spine switches, and four leaf switches. Two leaf switches have 1-Gb copper s for bare
metal servers, and the other two leaf switches have 10-Gb SFP ports to connect storage. Which set of
actions accomplishes an upgrade with minimal disruptions?
C
Engineer resolves an underlying condition of a fault but notices that the fault was not deleted from
the Faults view. Which two actions must be taken to remove the fault? (Choose two.)
AB
Refer to the exhibit.
The Cisco ACI fabric is built with L20ut to the N9K1 and N9K2 switches. The switches run the RSTP
protocol. The requirement is for the Cisco ACI fabric to detect 5 from the N9K and for the fabric to be
protected against loops. Which set of actions must be taken to meet the requirements?
D
What is the result of selecting the On Demand attribute in the Deploy Immediacy feature during
VMM domain association to an EPG?
B
Refer to the exhibit.
Refer to the exhibit. A client is configuring a new Cisco ACI fabric. All VLANs will be extended during
the migration phase using the VPC connections on leaf switches 3. 4 and leaf switches toward the
legacy network. The migration phase has these requirements;
* If The legacy switches must be able to transfer BPDUs through the ACI fabric.
* If the legacy switches fail to break a loop. Cisco ACI must break the loop.
Which group settings must be configured on VPC interface policy groups ipg_vpc-legacy_1 and
ipg_vpc-legacy_2 to meet these requirements?
B
Cisco ACI fabric contains a tenant called Prod. User_1 must have write access to tenant Prod and full
access to the fabric access policy. Which set of actions must be taken to meet these requirements?
D