CCIE Data Center (v2.0)

Question No: 141 – (Topic 2)

Refer to the exhibit.

Corporate ABC wants to implement control by allowing authorized virtual machine MAC addresses to send traffic to the Internet. The administrator wants to add this MAC ACL on Nexus7k-1 to achieve the task

[Configuration Output] Nexus7k-1:

mac access-list mac-acl

permit 0050.561f.73d3 0000.00ff.ffff any


interface e1/1

mac access-group mac-acl

However, this action does not work. Which two statements describe the issue? (Choose two.)

  1. The MAC address and mask do not match.

  2. The MAC ACL cannot be applied to egress traffic.

  3. This command is wrong to apply this ACL under interface.

  4. The sequence number is missing from the ACL.

  5. The MAC ACL is not supported on Cisco nexus 7000 Series.

Answer: B,C Explanation:

Ref:http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx- os/security/configuration/guide/sec_nx-os-cfg/sec_macacls.html

B is definitely correct as you can only apply a MAC ACLs to ingress traffic only

You can apply a MAC ACL as a port ACL to Layer 2, Layer 3, and Port-Channels but the command is as follows:

mac access-list acl-mac-01

permit 00c0.4f00.0000 0000.00ff.ffff any interface ethernet 2/1

mac port access-group acl-mac-01

Question No: 142 – (Topic 2)

Which two port profiles are used in VSM? (Choose two.)

  1. VEM

  2. VMkernels

  3. Ethernet

  4. vEthernet

  5. vNIC

Answer: C,D

Explanation: Ref: http://www.cisco.com/c/en/us/products/collateral/switches/nexus-1000v- switch-vmware-vsphere/guide_c07-704280.html

Question No: 143 – (Topic 2)

Which option lists valid network interfaces for VSM?

  1. Layer 2, Layer 3, and keepalive

  2. control, management, and packet

  3. management, Layer 2, and Layer 3

  4. management, packet, and VSM

Answer: B Explanation:

Ref: http://www.cisco.com/c/en/us/products/collateral/switches/nexus-1000v-switch- vmware-vsphere/guide_c07-556626.html#_Toc339600382

Question No: 144 – (Topic 2)

Refer to the exhibit.

On which VLAN does VLAN Discovery occur?

  1. VLAN 105

  2. VLAN 200

  3. VLAN 1105

  4. VLAN 1

Answer: D

Question No: 145 – (Topic 2)

By default, what type of SSH server key is generated by Cisco NX-OS Software?

  1. DSA key generated with 512 bits

  2. RSA key generated with 768 bits

  3. RSA key generated with 1024 bits

  4. DSA key generated with 1024 bits

  5. RSA key generated with 2048 bits

Answer: C

Question No: 146 – (Topic 2)

Refer to Exhibit:

Which option is the minimum number of vNICS required by the service profile to connect to all available


  1. 6

  2. 7

  3. 3

  4. 1

Answer: C

Question No: 147 – (Topic 2)

Each port that is configured to use LACP has an LACP port priority. Which statements are true about LACP port priority? (Choose three.)

  1. Port priority value can be configured between 1 and 65535.

  2. A higher port priority value means a higher priority of LACP.

  3. Port priority can be configured so that specific links can be chosen as active links rather than the hot standby links within the port channel.

  4. LACP uses the port priority with the port number to form the port identifier.

  5. LACP Port priority default value should always be changed

Answer: A,C,D

Question No: 148 – (Topic 2)

Which three port types support port security in Nexus 7000? (Choose 3)

  1. access ports.

  2. vPC ports

  3. SPAN source ports.

  4. Layer 2 and Layer 3 ports.

  5. SPAN destination ports.

  6. trunk ports.

Answer: A,C,F

Question No: 149 – (Topic 2)

Refer to the exhibit.

Which two statements are true? (Choose two.)

  1. Three pin groups are configured: one for the port-channel 10 in fabric interconnect B, one for int el/32 in fabric interconnect B, and one for int e1/31 in fabric interconnect B.

  2. Changing the target interface for an existing SAN pin group disrupts traffic for all vHBAs that use that pin group. The fabric interconnect performs a log in and log out for the Fibre Channel protocols to repin the traffic.

  3. To configure pinning for a server, you must include the SAN pin group in a vNIC policy. The vNIC policy is then included in the service profile assigned to that server. All traffic from the vNIC travels through the I/O module to the specified uplink Fibre channel port.

  4. In Fibre Channel switch mode, SAN pin groups are irrelevant. Any existing SAN pin groups are ignored.

  5. Edit this to show switch mode

Answer: B,D Explanation:

Ref:http://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/sw/gui/config/guide/1-0- 2/b_GUI_Config_Guide/GUI_Config_Guide_chapter19.html

Also see PDF: Configuring SAN Pin Groups

Question No: 150 – (Topic 2)

Which four tables are maintained by vPath? (Choose 4)

  1. service table

  2. path table

  3. IP/MAC table

  4. service node table

  5. flow table

  6. Neighbor table

  7. session table

Answer: A,B,D,E

