600-660 Practice Questions
Prepare for 600-660 with more than an answer.
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 5
- ACI Packet Forwarding20%
- Advanced ACI Policies and Integrations25%
- Multipod20%
- Multisite20%
- Traditional network with ACI15%
- 1
What specific type of information is stored in the spine switch proxy database, which is populated by the Council of Oracle Protocol (COOP)?
Show answer details
Correct answer: C
COOP is the control plane protocol used within an ACI pod to communicate endpoint information. When a leaf switch learns a new endpoint (MAC/IP), it reports this to the spine switches via COOP. The spines maintain this information in a proxy database, which maps the endpoint identity to its location, identified by the VTEP (VXLAN Tunnel End Point) IP address of the leaf switch where the endpoint resides. This allows for the 'hardware proxy' functionality for unknown unicast lookups.
- 2
When using the 'common' tenant in Cisco ACI to provide shared services like DNS or Active Directory, which statement accurately describes how contracts must be configured?
Show answer details
Correct answer: A
For a shared service to be accessible from other tenants, the contract that permits access to the service must be defined within the 'common' tenant. Then, this contract must be explicitly 'exported' to the user tenants that need to consume the service. The user tenants will then consume the exported contract, allowing their EPGs to communicate with the shared service EPG in the common tenant.
- 3
An administrator is setting up a Multi-Pod ACI fabric and is configuring the IPN. Which routing protocol is required to run between the ACI spine switches and the IPN devices to exchange reachability information for the pod TEP pools?
Show answer details
Correct answer: D
To establish connectivity across the Inter-Pod Network (IPN), an interior gateway protocol (IGP) is needed. Cisco ACI requires OSPF to be configured between the spine switches and the IPN devices. This OSPF instance is used to advertise the TEP pools of each pod, enabling the spines in one pod to establish VXLAN tunnels with the spines in other pods. BGP is used on top of this connectivity for EVPN address family updates, but OSPF provides the essential underlay routing.
- 4
In a Cisco ACI Multi-Site environment, what is the function of the Inter-Site Network (ISN)?
Show answer details
Correct answer: C
The Inter-Site Network (ISN) is the IP network that provides transport connectivity between the different ACI sites (fabrics). The spine switches of each site connect to the ISN. Control plane (MP-BGP EVPN) and data plane (VXLAN) traffic between sites is tunneled over this Layer 3 network. The ISN is the equivalent of the IPN in a Multi-Pod architecture but for Multi-Site.
- 5
An endpoint on Leaf-1 needs to send a unicast packet to an endpoint on Leaf-3. The ACI fabric has already learned the location of both endpoints. How is the packet forwarded from Leaf-1 to Leaf-3?
flowchart TD subgraph ACI Fabric Spine1 --- Leaf1 Spine1 --- Leaf2 Spine1 --- Leaf3 Spine2 --- Leaf1 Spine2 --- Leaf2 Spine2 --- Leaf3 end EP1([EP 1 on Leaf-1]) --> Leaf1 Leaf3 --> EP2([EP 2 on Leaf-3])Show answer details
Correct answer: C
ACI uses a VXLAN overlay for data plane forwarding. When Leaf-1 receives a packet for a known remote endpoint on Leaf-3, it encapsulates the original packet in a VXLAN header. The outer IP header of this new packet will have Leaf-1's VTEP IP as the source and Leaf-3's VTEP IP as the destination. The spine switches act as a simple IP transport network, forwarding this encapsulated packet based on the outer destination IP address (Leaf-3's VTEP IP) without inspecting the inner packet.
- 6
A financial institution is deploying a Cisco ACI Multi-Pod fabric. To meet regulatory requirements, all inter-pod traffic traversing the IPN must be encrypted. The IPN is comprised of Nexus 7700 switches which do not natively support CloudSec. Which ACI feature must be configured on the spine switches to meet this requirement?
Show answer details
Correct answer: B
When the IPN devices do not support CloudSec, the recommended and supported method for encrypting inter-pod traffic is to use MACsec (802.1AE) on the physical links between the ACI spine switches and the IPN. This provides hop-by-hop Layer 2 encryption. CloudSec is used for ACI Multi-Site encryption over the ISN. L3Out with IPsec is a valid encryption method but is more complex and typically used for connecting to external networks, not for the IPN itself. GDOI is not the standard mechanism for IPN encryption in ACI.
- 7
An administrator is troubleshooting endpoint learning in a large ACI fabric. They notice that a specific leaf switch is frequently flagging endpoints as 'rogue' even though the endpoints are legitimate and have not physically moved. The affected endpoints are connected via a vPC to a pair of leaf switches. What is the most likely cause of this issue?
Show answer details
Correct answer: D
When a server connected via vPC uses an active/active NIC teaming mode (like source MAC hashing) without a link aggregation protocol like LACP, it can send traffic from the same MAC address out of both physical NICs. The ACI leaf switches may see the same endpoint MAC address rapidly appearing on different ports in the vPC, leading the rogue endpoint detection feature to incorrectly flag it. The correct configuration is to use LACP for active/active teaming to present a single logical link to the fabric.
- 8
A network architect is designing a Cisco ACI Multi-Site solution to connect two data centers. They need to stretch a Bridge Domain (BD) between the two sites but want to ensure that BUM (Broadcast, Unknown Unicast, Multicast) traffic from Site1 does not flood over the ISN to Site2. Which configuration on the stretched BD object within the MSO schema will achieve this goal?
Show answer details
Correct answer: C
In a Multi-Site environment, the Bridge Domain can be configured with 'Optimized WAN' (OWAN) mode, also referred to as 'Inter-Site BUM Traffic Allow' set to disabled. This configuration ensures that BUM traffic is contained within the local site and not forwarded across the Inter-Site Network (ISN). This is the standard best practice to conserve expensive WAN bandwidth and prevent fault propagation between sites.
- 9
An engineer needs to implement a policy where EPG-Web is allowed to communicate with EPG-App on TCP port 8080, but under no circumstances should EPG-Web be able to initiate any traffic to EPG-DB. Both EPG-Web and EPG-App are consumers of a contract provided by EPG-DB. How can this explicit denial be enforced with the highest precedence?
Show answer details
Correct answer: B
A taboo contract is a special type of contract that explicitly denies communication between EPGs. It has a higher priority than standard allow contracts. By creating a taboo contract between EPG-Web and EPG-DB, all traffic will be dropped, regardless of any other contracts that might permit communication. A standard contract with a deny filter has lower precedence. vzAny doesn't provide the specific EPG-to-EPG denial required. Setting contract priorities can work but is more complex to manage; taboo is the most direct and highest-precedence method for this specific requirement.
- 10
During a migration from a traditional network to Cisco ACI, an engineer connects a legacy switch trunk port to an ACI leaf switch. The legacy switch is the STP root for several VLANs. To prevent loops while allowing for a phased migration, how should Spanning Tree Protocol be handled on the ACI side? (Select TWO)
Show answer details
Correct answer: B, D
BPDU Filter prevents the ACI leaf from sending BPDUs out of the port, which is crucial to not interfere with the external STP domain where the legacy switch is root.
BPDU Guard should be enabled on ACI ports facing traditional switches. This is a safety mechanism; if the ACI leaf unexpectedly receives a superior BPDU, it will err-disable the port, preventing a potential loop from forming. The combination of BPDU Filter (outbound) and BPDU Guard (inbound) is the Cisco best practice for this scenario.
