Data Center, Professional Practice Questions
Prepare for JN0-683 with more than an answer.
- Exam fee
- $400 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Data Center Deployment and Management
- Layer 3 Fabrics (IP Fabrics)
- VXLAN
- EVPN-VXLAN Signaling
- Data Center Interconnect (DCI)
- Data Center Multitenancy and Security
- 1
A data center fabric is designed with an oversubscription ratio of 3:1 at the leaf layer. Each leaf has 48 x 10 Gbps server-facing ports and 6 x 40 Gbps uplink ports to the spine layer. What does this 3:1 ratio signify?
Show answer details
Correct answer: B
Oversubscription ratio is the ratio of downstream bandwidth (server-facing) to upstream bandwidth (uplinks). In this case, the total downstream bandwidth is 48 * 10 Gbps = 480 Gbps. The total upstream bandwidth is 6 * 40 Gbps = 240 Gbps. However, the question states a 3:1 ratio. This implies that the total potential ingress traffic from servers (downstream) is three times the available egress capacity to the fabric core (upstream). The numbers given in the example (480:240) represent a 2:1 ratio. The question asks what a 3:1 ratio signifies in principle.
- 2
What is the primary difference between a Centrally-Routed Bridging (CRB) and an Edge-Routed Bridging (ERB) architecture in an EVPN-VXLAN fabric?
Show answer details
Correct answer: B
The fundamental difference lies in the placement of the Layer 3 gateway (IRB interface). In a CRB architecture, the IRB interfaces and all inter-subnet (inter-VNI) routing logic reside on the spine switches or dedicated gateway routers. In an ERB architecture, each leaf switch acts as a Layer 3 gateway for its locally attached hosts, distributing the routing function across the fabric edge.
- 3
When extending Layer 2 domains between two data centers using EVPN-VXLAN, which EVPN route type is primarily responsible for advertising the MAC addresses of hosts from one data center to the other?
Show answer details
Correct answer: B
The EVPN Type 2 route is the workhorse for host reachability information. It carries the host's MAC address (and optionally its IP address), allowing VTEPs in the remote data center to learn the location of hosts in the source data center. This is fundamental for forwarding Layer 2 traffic across the DCI.
- 4
You are examining the BGP EVPN table on a leaf switch and see a Type 2 route. Which two pieces of information are contained within this route type? (Select TWO)
Show answer details
Correct answer: A, C
The primary purpose of a Type 2 route is to advertise the MAC address of a connected host.
The Type 2 route includes the Layer 2 VNI (or MPLS label) to associate the host MAC with its correct broadcast domain.
- 5
Case Study
A company has two data centers, DC1 and DC2, interconnected with a Layer 3 DCI using EVPN Type 5 routes. Each data center has its own EVPN-VXLAN fabric. A specific tenant, 'Tenant-Blue', exists in both data centers. VMs within Tenant-Blue in DC1 can communicate with each other, and VMs within Tenant-Blue in DC2 can also communicate. However, communication fails for any VM trying to cross from DC1 to DC2.
An administrator on the DC1 gateway verifies that it has an EBGP session with the DC2 gateway and is receiving Type 5 routes from DC2. However, these routes are not being installed into the Tenant-Blue VRF routing table. The configuration on the DC1 gateway for the Tenant-Blue VRF is as follows:
routing-instances { Tenant-Blue { instance-type vrf; route-distinguisher 1.1.1.1:100; vrf-target export target:65001:100; ... } }What is the most likely configuration error preventing inter-DC communication for Tenant-Blue?
graph LR subgraph DC1 VM1(VM1 in Tenant-Blue) -- DCI_GW1(DCI GW1) end subgraph DC2 VM2(VM2 in Tenant-Blue) -- DCI_GW2(DCI GW2) end DCI_GW1 -- "EBGP Peering (Type 5 Routes)" -- DCI_GW2 DCI_GW2 --x "Routes NOT imported to VRF" DCI_GW1Show answer details
Correct answer: B
BGP uses Route Target (RT) communities to control which VRFs import which routes. The DC1 gateway is configured to export routes with
target:65001:100, but there is no correspondingvrf-importorvrf-target importstatement. This means it will not import any routes into the Tenant-Blue VRF. To fix this, the DC1 gateway needs avrf-target importstatement that matches the RT being exported by the DC2 gateway, and vice versa. - 6
A financial services firm is deploying a new IP fabric for high-frequency trading applications that rely on RoCEv2. The lead architect has mandated the use of Explicit Congestion Notification (ECN) to manage incipient congestion. During testing, engineers notice that while ECN is marking packets correctly on the leaf switches, the upstream spine switches are not reacting to these markings, leading to congestion drops. Which configuration stanza is missing on the spine switches to enable them to participate in the ECN congestion management process?
Show answer details
Correct answer: C
To enable a spine switch to react to ECN-marked packets received from leaf switches, ECN must be enabled on the egress queue schedulers. This allows the spine to mark packets with Congestion Experienced (CE) bits in the direction of the traffic source, signaling the sender to reduce its transmission rate. Simply having ECN enabled on the leaf is insufficient for end-to-end congestion management; all devices in the path must participate.
- 7
You are designing a data center interconnect (DCI) solution using EVPN Type 5 routes between two geographically separate sites. The goal is to provide Layer 3 connectivity for multiple tenants, each within their own VRF. For tenancy and routing policy control, which two components are essential for uniquely identifying and controlling the advertisement of IP prefixes across the DCI link? (Select TWO)
Show answer details
Correct answer: A, C
The Route Distinguisher (RD) is crucial as it prepends a unique 64-bit value to each tenant's IP prefix, making it globally unique within the BGP table. This allows for overlapping IP address spaces between different tenants.
The VRF Route Target (RT) is an extended BGP community that controls the import and export of routes into and out of a VRF. It acts as the policy mechanism to determine which prefixes from one data center are installed into the corresponding VRF in the remote data center.
- 8
A university is deploying a multi-tenant data center to serve different academic departments. The 'Engineering' VRF and the 'Research' VRF must be completely isolated. However, both departments need access to a shared 'HPC-Cluster' service located in a separate VRF. Which technique should be used on the border leaf switches to allow this specific, controlled communication while maintaining default isolation?
Show answer details
Correct answer: C
This is the standard and most scalable method for controlled route leaking. The 'HPC-Cluster' VRF would export its routes with a specific route target (e.g., target:65000:100). The 'Engineering' and 'Research' VRFs would then be configured to import routes tagged with target:65000:100. This allows them to learn the routes to the shared service without learning each other's routes, thus maintaining isolation.
- 9
True or False: When using Zero-Touch Provisioning (ZTP) for a Juniper QFX switch, the DHCP server can provide the switch with both a configuration file and a software image location in a single DHCP offer message.
Show answer details
Correct answer: A
This is true. The DHCP server uses specific options to direct the ZTP process. Typically, DHCP Option 66 (TFTP Server Name) or a similar option points to the file server, while Option 67 (Bootfile Name) can specify a configuration file. Juniper's ZTP process is flexible and can also use vendor-specific options (like Option 43) to provide URLs for both the software image and the configuration file.
- 10
An administrator is troubleshooting an EVPN-VXLAN fabric where hosts in VNI 10100 can communicate with each other, but they cannot reach hosts in VNI 10200 within the same tenant VRF. The fabric uses a symmetric IRB model. The administrator confirms that the IRB interfaces are correctly configured on the leaf switches. What is a likely missing piece of configuration causing this inter-VNI routing failure?
Show answer details
Correct answer: B
Symmetric IRB is a two-stage routing model. For traffic to be routed between different subnets (VNIs) across VTEPs, it must be encapsulated in a VXLAN tunnel associated with the Layer 3 context. This requires a dedicated L3 VNI to be configured under the
[edit routing-instances vxlan]hierarchy. Without the L3 VNI, the fabric can only bridge within an L2 VNI and cannot forward routed traffic between VTEPs.
