Cisco CCNP Data Center DCCOR (350-601) · Difficulty

Medium 350-601 practice questions

Applied — put a concept to work in a realistic situation. 122 medium questions available — no sign-up, always free.

Question 1 of 25

An ACI administrator has an existing contract between the Web-EPG and App-EPG that permits all TCP traffic. A new security requirement mandates that TCP port 23 (Telnet) be explicitly denied between these two EPGs while all other permitted TCP traffic continues to flow. The administrator wants to apply this exception without rewriting the entire allow contract. Which ACI construct should be applied to enforce this specific deny?

Reviewed for accuracy · Report an issue
Question 2 of 25

A network engineer is deploying a new three-tier application in Cisco ACI. The Web, App, and DB endpoints are each placed in their own EPG within a single bridge domain and VRF. By default, no traffic flows between the EPGs. The engineer wants Web endpoints to reach App endpoints on TCP 8080, but must NOT permit any other inter-EPG traffic. Which configuration correctly achieves this requirement?

Reviewed for accuracy · Report an issue
Question 3 of 25

An engineer is configuring an ACI L3Out to connect the fabric to an external OSPF router. Internal EPGs must be able to reach any destination learned via the L3Out, and a contract has already been created between the internal EPG and the external EPG. When configuring the external EPG (L3 External Network), which subnet scope setting must be applied to the 0.0.0.0/0 subnet so that the external routes are properly classified into the external EPG for contract enforcement?

Reviewed for accuracy · Report an issue
Question 4 of 25

A data center administrator is securing an ACI fabric that hosts a multi-tenant virtualized environment. Several VMs belonging to the same application EPG must be dynamically isolated based on their VM attributes (for example, VM name containing 'DB') without moving them to a different base EPG or requiring VLAN reassignment. The administrator wants endpoints matching the criteria to be classified into a separate policy group so that contracts can control communication between them and the rest of the EPG. Which ACI feature should be implemented to meet this requirement?

Reviewed for accuracy · Report an issue
Question 5 of 25

A network engineer is designing an ACI application profile for a three-tier application (web, app, database). The security team requires that web servers can only reach app servers on TCP 8080, and app servers can only reach database servers on TCP 1521. All three tiers reside in the same bridge domain and VRF. Which approach correctly enforces this policy in ACI?

Reviewed for accuracy · Report an issue
Question 6 of 25

You are deploying a pair of Nexus 9300 leaf switches in a Cisco ACI fabric to provide a vPC to a dual-homed application server. After configuring the vPC interface policy group and applying it to both leaf ports, the server's port-channel remains down and the APIC reports the leaves are not forming a vPC domain. Which configuration step is required to establish the vPC domain between the two leaf switches in ACI?

Reviewed for accuracy · Report an issue
Question 7 of 25

A data center team is designing an AI training cluster with servers containing 8 GPUs each. Within a single server, GPUs must exchange gradients at maximum bandwidth with the lowest possible latency, bypassing CPU and PCIe bottlenecks. Across servers, GPUs connect through a lossless Ethernet fabric using RoCEv2. Which technology provides the intra-server (scale-up) high-speed GPU-to-GPU interconnect that the design should specify?

Reviewed for accuracy · Report an issue
Question 8 of 25

A data center automation engineer maintains Cisco Nexus 9000 switches using Ansible with the cisco.nxos collection. Before applying a large VLAN and interface configuration change to production leaf switches, the engineer wants to preview exactly which tasks would report a change WITHOUT altering any device state, and also wants confidence that re-running the playbook after a successful apply will report no further changes. Which combination of Ansible characteristics satisfies both requirements?

Reviewed for accuracy · Report an issue
Question 9 of 25

A network automation engineer is storing an Ansible playbook and its variable files in a shared Git repository used to configure Cisco Nexus 9000 switches. The variable files contain BGP neighbor authentication keys and device login credentials in plaintext. Security policy requires that these secrets not be readable in the repository while still allowing the playbook to run non-interactively in a CI/CD pipeline. Which approach meets the requirement?

Reviewed for accuracy · Report an issue
Question 10 of 25

A network engineer is deploying a VXLAN BGP EVPN fabric with 2 spine switches and 40 leaf switches. To avoid a full mesh of iBGP sessions in a single AS (65001), the engineer wants a scalable control-plane design for distributing EVPN routes between all VTEPs. What is the recommended approach?

Reviewed for accuracy · Report an issue
Question 11 of 25

A network engineer is troubleshooting BUM traffic replication in a VXLAN EVPN fabric that uses ingress replication (no multicast in the underlay). Two VTEPs, Leaf-1 and Leaf-2, both host VNI 10100. Leaf-1 is not flooding broadcast frames for VNI 10100 to Leaf-2, so hosts behind Leaf-2 never receive ARP requests originated on Leaf-1. Which EVPN route type must be exchanged between the two VTEPs to build the ingress replication flood list for VNI 10100?

Reviewed for accuracy · Report an issue
Question 12 of 25

A data center engineer is planning software maintenance on a Cisco Nexus switch. In addition to the NX-OS image upgrade, Cisco has released a new EPLD (Electronic Programmable Logic Device) image to address a hardware programming issue on the I/O modules. The engineer wants to understand the operational impact before scheduling the change window. Which statement correctly describes the EPLD upgrade behavior?

Reviewed for accuracy · Report an issue
Question 13 of 25

A storage administrator is editing the zoning configuration on a Cisco MDS 9000 fabric that uses enhanced zoning across VSAN 20. A colleague on another switch in the same fabric attempts to make zoning changes at the same time and reports an error that the operation cannot proceed. When the first administrator finishes, they modify a zone and then run 'zoneset activate name PROD-ZS vsan 20'. What behavior of enhanced zoning explains the colleague's error and ensures configuration consistency?

Reviewed for accuracy · Report an issue
Question 14 of 25

A storage administrator is hardening a MDS/Nexus Fibre Channel fabric that spans two data centers. Management requires that only explicitly approved switches be allowed to join VSAN 20, and any unauthorized switch attempting to merge into the fabric must be prevented from doing so and have its E_Port isolated. Which security feature meets this requirement?

Reviewed for accuracy · Report an issue
Question 15 of 25

A storage administrator connects a new server HBA to a Cisco MDS switch port configured in F mode. The port comes up, but the server cannot access its LUNs on the target array. On the MDS, the 'show flogi database' output lists the HBA's pWWN with an assigned FCID, but 'show fcns database' does not display the target array's pWWN as accessible to the initiator. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 16 of 25

A storage administrator is extending a Fibre Channel SAN between two data centers over a shared IP WAN link with 200 ms round-trip latency and limited bandwidth. The primary requirement is to reduce the amount of replication data traversing the WAN to fit within the available bandwidth. Which FCIP feature should be enabled on the MDS switches to meet this goal?

Reviewed for accuracy · Report an issue
Question 17 of 25

A storage administrator is configuring an iSCSI deployment on a Cisco Nexus/MDS environment and wants to reduce the frequency of full LUN rescans on hosts. A new storage array with additional targets has just been added to the same portal IP. Which iSCSI mechanism allows an already-logged-in initiator to learn about the newly added targets without manually reconfiguring each host?

Reviewed for accuracy · Report an issue
Question 18 of 25

A storage administrator is troubleshooting an ESXi host connected to a Cisco MDS fabric. The host's initiator successfully completes FLOGI and its zone with the target array is active, but the host cannot discover any LUNs presented by the target. On the MDS switch, the 'show fcns database' output lists both the initiator and target FC4 features, and 'show zone status' confirms the zone is fully activated in the correct VSAN. Which action should the administrator take NEXT to resolve the missing LUN visibility?

Reviewed for accuracy · Report an issue
Question 19 of 25

A storage administrator is hardening an MDS Fibre Channel fabric. A junior engineer accidentally cabled an unauthorized HBA into interface fc1/12, and it successfully performed FLOGI and began accessing the fabric. The administrator wants to ensure that only pre-approved pWWNs can log in on specific physical ports, and that any unauthorized device attempting FLOGI is automatically rejected without requiring manual zoning changes. Which feature should be implemented to enforce this?

Reviewed for accuracy · Report an issue
Question 20 of 25

A storage administrator has correctly configured single-initiator zoning on a Cisco MDS 9000 fabric so that a specific server HBA can reach a storage array's target port. However, the security team is concerned that the server can still see and potentially access LUNs belonging to other servers presented by that same array target port. Which additional control most directly restricts which specific LUNs behind the target port that particular server is permitted to access?

Reviewed for accuracy · Report an issue
Question 21 of 25

A data center engineer is deploying a new Cisco MDS 9148 fabric switch at the edge of an existing storage fabric. The core directors are already at their maximum supported domain ID count, and adding another domain ID would exceed the fabric's scalability limits. The engineer needs the edge switch to connect servers to the fabric without consuming an additional domain ID, while the core switches must be able to allow multiple logins over a single uplink. Which combination of features must be enabled to meet these requirements?

Reviewed for accuracy · Report an issue
Question 22 of 25

A storage engineer is connecting two Cisco MDS/Nexus FC switches with two 32G Fibre Channel links bundled into a port channel. The port channel must carry traffic for VSAN 10 and VSAN 20 across the ISL. After configuration, VSAN 20 traffic is not passing, though VSAN 10 works. The engineer confirms both member ports are up and the port channel is operational. What is the MOST likely cause?

Reviewed for accuracy · Report an issue
Question 23 of 25

A storage administrator is enabling Fibre Channel port security on VSAN 20 of a Cisco MDS switch to prevent unauthorized devices from logging into fabric ports. To speed initial configuration, they enable auto-learning, let all current devices perform FLOGI, and then plan to make the learned bindings permanent. Which action must they take so that the learned entries are retained and no NEW devices can be learned automatically afterward?

Reviewed for accuracy · Report an issue
Question 24 of 25

A storage administrator wants to ensure that only authenticated switches and end devices can join a Cisco MDS Fibre Channel fabric. The requirement is a challenge-response protocol that mutually authenticates devices using a shared secret before allowing fabric access, without relying solely on WWN-based lists. Which security mechanism should be configured?

Reviewed for accuracy · Report an issue
Question 25 of 25

A storage administrator is configuring zoning on a Cisco MDS fabric that connects 40 servers to a dual-controller storage array. To follow Cisco and industry best practices while minimizing RSCN disruption and simplifying troubleshooting, how should the administrator structure the zones?

Reviewed for accuracy · Report an issue