Skip to content

300-630 Implementing Cisco Application Centric Infrastructure - Advanced (DCACIA) Practice Questions

Prepare for 300-630 with more than an answer.

201 questions in the full set20 sample questionsUpdated Aug 20, 2026

Unlock the full exam and previous versions

  • v1Version 1 162 questions Locked
  • 300-630Legacy Implementing Cisco Application Centric Infrastructure - Advanced (DCACIA) 201 questions Current
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 5
  1. ACI Packet Forwarding20%
  2. Advanced ACI Policies and Integrations25%
  3. Multi-Pod20%
  4. Multi-Site20%
  5. Traditional network with ACI15%
  1. 1

    What is the function of the pcTag (Policy Control Tag) within the Cisco ACI fabric?

    Show answer details

    Correct answer: C

    The pcTag, also known as the Class ID or Source Group, is a unique 16-bit (or larger) numerical identifier that the ACI fabric assigns to each EPG. When an endpoint is learned, it is associated with the pcTag of its EPG. This tag is then carried in the VXLAN header of packets sourced from that endpoint. Policy enforcement on the leaf switches is performed by matching the source pcTag and destination pcTag against the contract rules programmed in the TCAM, making enforcement highly efficient and scalable.

  2. 2

    A company is migrating its data center to Cisco ACI. A critical legacy application requires servers to be in the same Layer 2 broadcast domain, but for resilience, these servers are attached to leaf switches that are not vPC peers. Which ACI configuration on the Bridge Domain will allow Layer 2 traffic, such as broadcasts from the servers, to be forwarded efficiently across the fabric to all other servers in the same broadcast domain?

    Show answer details

    Correct answer: A

    When L2 Unknown Unicast is set to 'Flood' on a Bridge Domain, the fabric uses multicast in the underlay to forward any unknown unicast, broadcast, and multicast traffic to all leaf switches that have endpoints in that BD. This ensures that all servers in the broadcast domain receive the traffic, which is essential for legacy applications that rely on broadcast-based discovery or clustering mechanisms. Hardware Proxy is the default and more scalable option but relies on the spine proxy, which may not be suitable for applications requiring true L2 flooding.

  3. 3

    When configuring a BGP L3Out in a Cisco ACI fabric to connect to an external network, an engineer needs to ensure that only specific subnets from a tenant VRF are announced to the external BGP peer. Which two components must be configured and associated with the L3Out to achieve this route filtering? (Select TWO).

    Show answer details

    Correct answer: C, D

    This policy explicitly controls which subnets are advertised out of the fabric. By defining the specific subnets here, you are selecting them for potential advertisement.

    For a subnet defined within an ACI Bridge Domain to be eligible for advertisement to an external network via an L3Out, its scope must be set to 'Advertised Externally'. This flags the subnet for the fabric's routing process.

  4. 4

    A university is deploying a Cisco ACI Multi-Site fabric to connect its main campus and a remote research campus. The research campus needs access to high-performance computing (HPC) resources at the main campus. The Inter-Site Network (ISN) is a high-speed, low-latency dark fiber link. Which routing protocol is used over the ISN to exchange endpoint reachability and policy information between the ACI sites?

    Show answer details

    Correct answer: B

    Cisco ACI Multi-Site uses Multiprotocol BGP (MP-BGP) with the Ethernet VPN (EVPN) address family as its control plane protocol over the ISN. The spine switches in each site peer with each other over the ISN and use BGP EVPN to advertise MAC and IP address reachability information (endpoints) and policy information (VRF and BD VNIDs) between the sites.

  5. 5

    Which object in the Nexus Dashboard Orchestrator (NDO) is used to define a logical grouping of policies, tenants, and VRFs that can be consistently deployed and managed across multiple ACI sites?

    Show answer details

    Correct answer: B

    A Schema in NDO is a container for one or more templates. It defines the complete set of policies (including tenants, VRFs, BDs, EPGs, and contracts) that you want to manage as a single unit across multiple sites. By defining objects in a schema and applying it to sites, you ensure consistent configuration and policy enforcement across your entire Multi-Site domain.

  6. 6

    A financial institution is deploying a Cisco ACI Multi-Pod fabric to connect two data centers for disaster recovery. The Inter-Pod Network (IPN) is configured with OSPF area 0. During testing, engineers observe that endpoint information is not being exchanged between pods, although the spine switches in each pod have established OSPF adjacencies with the IPN devices. All physical links are confirmed to be up. Which configuration element is the most likely cause for the failure of inter-pod control plane communication?

    Show answer details

    Correct answer: B

    In a Multi-Pod fabric, the COOP protocol uses multicast to announce the spine proxy TEP addresses between pods. This requires multicast routing to be correctly configured and enabled on the IPN. Specifically, PIM Bi-directional (bidir) mode is a requirement for the IPN to properly forward the COOP multicast traffic. While OSPF establishes unicast reachability, the absence of PIM prevents the control plane announcements necessary for endpoint learning across pods.

  7. 7

    An ACI administrator needs to implement a shared service design. A DNS service is hosted in an EPG within the 'shared-services' VRF, and it must be accessible by EPGs in three separate tenant VRFs: 'prod', 'dev', and 'test'. To achieve this, the administrator has configured a contract between the DNS EPG and the consuming EPGs, and has configured the subnets under the Bridge Domains of the consuming EPGs with the 'Shared between VRFs' scope. What is the final critical step required to enable communication between the tenant VRFs and the shared-services VRF?

    Show answer details

    Correct answer: D

    For VRF route leaking to function for shared services, the subnet of the provider (the DNS service) must be leaked into the consumer VRFs, and the subnets of the consumers must be leaked into the provider VRF. While setting the consumer subnet scope to 'Shared between VRFs' is a necessary step, the provider's BD must also be explicitly associated with the consumer tenant VRFs. This action, combined with the contract, allows the fabric to program the necessary routes and policy for inter-VRF communication.

  8. 8

    A network architect is designing a security policy in Cisco ACI where all traffic within a VRF is denied by default, except for specific flows allowed by contracts. However, traffic between two specific EPGs, 'EPG-Legacy-App' and 'EPG-Legacy-DB', must be explicitly blocked under all circumstances, even if another contract might permit it. Which ACI objects should be used to meet these requirements? (Select TWO).

    Show answer details

    Correct answer: A, D

    A taboo contract is used to explicitly deny traffic between EPGs, and it takes precedence over any standard contracts that might permit the traffic. This directly fulfills the requirement to block communication between the two legacy EPGs regardless of other policies.

    Setting the VRF to 'Enforced' mode establishes a default-deny policy where no traffic is allowed unless explicitly permitted by a contract. This meets the primary requirement of denying all traffic by default.

  9. 9

    During the implementation of a Cisco ACI Multi-Pod environment, an engineer notices that while unicast traffic between endpoints in different pods is working correctly, multicast traffic from a source in Pod1 is not reaching receivers in Pod2. Both pods are part of the same bridge domain and VRF. The IPN is confirmed to have PIM enabled and functioning. What is the most likely reason for this multicast forwarding failure across pods?

    Show answer details

    Correct answer: C

    In ACI Multi-Pod, inter-pod multicast traffic is encapsulated using a VRF-specific multicast address known as the GIPo. Each VRF that needs to pass multicast traffic between pods must have a unique GIPo from the reserved multicast address pool configured under the tenant. If this is not configured, the fabric does not have a destination multicast address to use for the outer VXLAN header when forwarding multicast packets across the IPN.

  10. 10

    A consultant is tasked with optimizing endpoint learning in a large-scale ACI fabric that hosts a VDI environment. Due to the high rate of VM creation and destruction, the spine proxy's COOP database experiences significant churn. The goal is to prevent remote endpoints (endpoints in other pods) from being learned in a specific pod's leaf switches unless absolutely necessary, thereby reducing control plane overhead. Which setting should be configured on the bridge domains in the target pod?

    Show answer details

    Correct answer: C

    The 'Remote EP Learn' setting, available on a Bridge Domain, controls whether remote endpoints (those learned in other pods and advertised via COOP) are programmed into the local leaf switch tables. By disabling this feature, the leaf switches in that pod will not learn remote endpoint information. Instead, traffic destined for a remote endpoint will be forwarded to the spine proxy, which performs the lookup and forwards accordingly. This conserves leaf switch table space and reduces control plane churn at the cost of a slightly less optimal data path.

Create an account to continue.