exam questions

Exam 300-630 All Questions

View all questions & answers for the 300-630 exam

Exam 300-630 topic 1 question 20 discussion

Actual exam question from Cisco's 300-630
Question #: 20
Topic #: 1
[All 300-630 Questions]



Refer to the exhibits. Which subject must be configured for the All_noSSH contract to allow all IP traffic except SSH between the two EPGs?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: D
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/ACI_Best_Practices/b_ACI_Best_Practices/ b_ACI_Best_Practices_chapter_010.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Netdude
8 months, 2 weeks ago
D is the correct answer! Though the SSH filter entry has a lower priority, it will still be executed first.. Deny actions and protocol ( SSH ) wins over filter priority. Also 'apply both directions' and reverse filter port should be checked.. https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-743951.html
upvoted 4 times
...
H_nna
1 year, 4 months ago
I go for D https://community.cisco.com/t5/application-centric-infrastructure/aci-contract/td-p/3855931
upvoted 3 times
[Removed]
10 months ago
D makes your SSH deny less eficient than your allow line, so it would be allowed either way. If you go with C, your traffic may go one way, but you wont get reply, so in the end it won´t work either
upvoted 2 times
...
...
NSF2
1 year, 6 months ago
All_noSSH contract to allow all IP traffic except SSH except SSH = deny allow all IP traffic = allow I too go with C
upvoted 1 times
...
DSAM9
2 years, 7 months ago
I think C is correct too, Priority become greyed if selected, so option A and B could not be, destination ports should not be swapped at source ports on provider EPG, (no need for provider EPG to answer) hence... Reverse Filter Ports should be disabled. denying SSH is a priority.
upvoted 3 times
...
apot
3 years, 1 month ago
I think C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago