Network
Drill 20 practice questions focused entirely on Network for the Cisco 350-601 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
In a Cisco ACI fabric, an application team reports that a legacy clustering application relying on gratuitous ARP and silent hosts is failing intermittently after workloads were migrated into a new bridge domain (BD). The BD was created with the default optimized settings. Which BD configuration change should the network engineer make to best support the silent hosts and the application's ARP-based behavior?
A network engineer is deploying a new three-tier application in Cisco ACI. The Web, App, and DB endpoints are each placed in their own EPG within a single bridge domain and VRF. By default, no traffic flows between the EPGs. The engineer wants Web endpoints to reach App endpoints on TCP 8080, but must NOT permit any other inter-EPG traffic. Which configuration correctly achieves this requirement?
An engineer is configuring an ACI L3Out to connect the fabric to an external OSPF router. Internal EPGs must be able to reach any destination learned via the L3Out, and a contract has already been created between the internal EPG and the external EPG. When configuring the external EPG (L3 External Network), which subnet scope setting must be applied to the 0.0.0.0/0 subnet so that the external routes are properly classified into the external EPG for contract enforcement?
A network engineer is designing an ACI application profile for a three-tier application (web, app, database). The security team requires that web servers can only reach app servers on TCP 8080, and app servers can only reach database servers on TCP 1521. All three tiers reside in the same bridge domain and VRF. Which approach correctly enforces this policy in ACI?
An ACI administrator is deploying two new EPGs, each mapped to a different physical domain. EPG-Web uses a physical domain tied to VLAN Pool-A (dynamic allocation, blocks 100-200), and EPG-App uses a physical domain tied to VLAN Pool-B (static allocation, blocks 150-250). After the administrator statically binds EPG-App to a leaf port using VLAN 175, EPG-Web endpoints intermittently lose connectivity. What is the most likely root cause?
You are deploying a pair of Nexus 9300 leaf switches in a Cisco ACI fabric to provide a vPC to a dual-homed application server. After configuring the vPC interface policy group and applying it to both leaf ports, the server's port-channel remains down and the APIC reports the leaves are not forming a vPC domain. Which configuration step is required to establish the vPC domain between the two leaf switches in ACI?
A data center runs VXLAN BGP EVPN across two leaf switches (Leaf1 and Leaf2) with ARP suppression enabled on the bridge domain's associated VLAN. Host A on Leaf1 attempts to reach Host B, a silent host connected to Leaf2 that has not yet sent any traffic. Host A sends an ARP request for Host B. Which behavior occurs?
A network engineer is deploying a VXLAN BGP EVPN fabric with 2 spine switches and 40 leaf switches. To avoid a full mesh of iBGP sessions in a single AS (65001), the engineer wants a scalable control-plane design for distributing EVPN routes between all VTEPs. What is the recommended approach?
A network engineer is troubleshooting BUM traffic replication in a VXLAN EVPN fabric that uses ingress replication (no multicast in the underlay). Two VTEPs, Leaf-1 and Leaf-2, both host VNI 10100. Leaf-1 is not flooding broadcast frames for VNI 10100 to Leaf-2, so hosts behind Leaf-2 never receive ARP requests originated on Leaf-1. Which EVPN route type must be exchanged between the two VTEPs to build the ingress replication flood list for VNI 10100?
A data center engineer is troubleshooting an ACI fabric where an endpoint in EPG-Web on Leaf-101 sends an ARP request for an endpoint in the same bridge domain that is currently unlearned by the fabric. The bridge domain is configured with ARP Flooding disabled and L2 Unknown Unicast set to Hardware Proxy. How does the ACI fabric handle this ARP request?
A data center engineer bundles four interfaces into a port-channel between a Nexus 9000 and a downstream server using LACP. The requirement is that if fewer than three member links are operational, the entire port-channel must go down rather than forward traffic on the remaining links. Additionally, if the server sends no LACP PDUs on a member interface, that interface must NOT independently forward traffic as a standalone access port. Which combination of configuration achieves both requirements?
A network engineer configures NetFlow on a Cisco Nexus 9000 switch to analyze traffic patterns for capacity planning. After applying a custom flow record, the collector receives flow entries, but flows that share the same source IP, destination IP, and protocol but differ only by TCP port are being aggregated into a single flow entry instead of being tracked separately. Which change to the flow record configuration resolves this issue?
A network engineer on a Cisco Nexus 9000 switch made several configuration changes to routing and interface parameters during a maintenance window. After the changes, an application team reports connectivity failures. The engineer had created a checkpoint named 'pre-change' before starting. Which action restores the exact running configuration to the state captured in that checkpoint with the least disruption, applying only the differences?
A data center operations team wants proactive detection of configuration drift, forwarding inconsistencies, and pre-change impact validation across their ACI and NX-OS fabrics. They deploy Cisco Nexus Dashboard with an AI/ML-powered assurance service that continuously ingests telemetry and models the network's intended state versus actual state. Which capability of this service specifically allows the team to simulate a proposed policy change and predict whether it will introduce connectivity or contract violations BEFORE the change is committed to the fabric?
A data center engineer must upgrade the NX-OS software on a pair of Nexus 9000 switches that forward critical production traffic. Management requires that data-plane forwarding continues uninterrupted during the upgrade of a single switch. Which upgrade method and condition must be satisfied to meet this requirement?
A network engineer must capture traffic from server-facing interfaces on a Nexus 9000 leaf switch and deliver it to a packet analyzer located in a different data center pod across a routed Layer 3 boundary. The analyzer cannot be relocated, and no Layer 2 adjacency exists between the leaf and the analyzer subnet. Which monitoring method should the engineer implement to meet this requirement?
A data center operations team is monitoring a fleet of Nexus 9000 switches. They complain that their SNMP-based polling of interface counters every 60 seconds misses short-lived microbursts and adds CPU load during collection cycles. They want near-real-time visibility into interface statistics with minimal device overhead and the ability to push data directly to a collector. Which approach best addresses these requirements?
A data center engineer notices that after a vPC domain reload on the secondary Nexus 9000 switch, all vPC member ports briefly went down and traffic was disrupted even though the type-1 consistency parameters matched on both peers. The engineer wants to prevent vPC member ports from being suspended on the recovering peer before it has fully synchronized state with the primary peer following a reload. Which vPC feature should be enabled to address this?
A consortium of regional hospitals wants to share a common cloud infrastructure that supports their shared compliance requirements (HIPAA), security policies, and mission. The infrastructure will be jointly owned and managed by several of the participating organizations and a third-party provider, and access is restricted exclusively to the member hospitals. According to NIST SP 800-145, which cloud deployment model best describes this arrangement?
A cloud architect is documenting a public cloud offering to justify it aligns with NIST SP 800-145. The finance team notices that during month-end processing, compute capacity automatically scales out within minutes to handle the load and then scales back in afterward, appearing to consumers as effectively unlimited and available at any time. Which of the five essential characteristics defined in NIST SP 800-145 does this behavior specifically describe?
More 350-601 practice
Keep going with the other Cisco CCNP Data Center DCCOR (350-601) domains, or take a full timed mock exam.
← Back to 350-601 overview