Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-620 Exam - Topic 12 Question 51 Discussion

An engineer must limit management access to me Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?
C) ACL on the management interface of the APIC
A) policy In the management tenant
B) policy on the management VLAN
D) ACL on the console interface

Cisco 300-620 Exam - Topic 12 Question 51 Discussion

Actual exam question for Cisco's 300-620 exam
Question #: 51
Topic #: 12
[All 300-620 Questions]

An engineer must limit management access to me Cisco ACI fabric that originates from a single subnet where the NOC operates. Access should be limited to SSH and HTTPS only. Where should the policy be configured on the Cisco APIC to meet the requirements?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Shenika
10 months ago
ACL on the management interface seems like a solid option too.
upvoted 0 times
...
Lenna
10 months ago
Wait, can you really limit access like that? Sounds tricky!
upvoted 0 times
...
Truman
10 months ago
Not so sure about that, what about the management VLAN?
upvoted 0 times
...
Vincenza
11 months ago
Definitely agree, management tenant is the way to go!
upvoted 0 times
...
Gladys
11 months ago
I think the policy should be in the management tenant.
upvoted 0 times
...
Novella
11 months ago
I’m leaning towards the ACL on the management interface of the APIC, but I need to double-check if that aligns with the access requirements.
upvoted 0 times
...
Rodolfo
11 months ago
I feel like the management VLAN might be relevant here, but I can't remember if it specifically restricts access to just SSH and HTTPS.
upvoted 0 times
...
James
11 months ago
I remember a practice question that involved ACLs on the management interface, but I can't recall if that was the right approach for this scenario.
upvoted 0 times
...
Dante
11 months ago
I think the policy should be configured in the management tenant, but I'm not entirely sure if that's the best option.
upvoted 0 times
...
Casie
11 months ago
I'm a bit confused on this one. I know the Service Desk is involved in both Incident and Change Management, but I'm not sure which one is the right answer here. I'll need to review my notes.
upvoted 0 times
...
Barney
11 months ago
I think the key here is understanding the client's specific needs and how the "Consolidate with import" feature in Finance and Operations can address them. I'll need to review the documentation and consider any potential limitations or alternative approaches.
upvoted 0 times
...
Stanford
11 months ago
The Intermediate Routing pattern seems familiar, but I'm not sure how the Service Agent fits into this. I think we went over something similar in practice questions.
upvoted 0 times
...
Margarett
11 months ago
Disabling server affinity could also help with load balancing, but I'm not sure if that's the complete solution. I'll need to consider all the options.
upvoted 0 times
...
Shala
11 months ago
I remember studying a configuration tool for quick deployment; maybe that's related but I don't think it's the Switch Selector itself.
upvoted 0 times
...
Quiana
11 months ago
Okay, I've got this. The key is to use the mean of the sample means and the mean of the ranges to calculate the control limits. I remember the formulas from class, so I'm confident I can get the right answer.
upvoted 0 times
...
Aleisha
11 months ago
I'm confused about the numbering types. Isn't “subscriber” used for direct dial numbers? Wouldn't that mean A or B have to be right?
upvoted 0 times
...
Chandra
1 year ago
I'm leaning towards option C as well. It makes the most sense to control the management access at the interface lChandral, where we can specifically limit the allowed protocols.
upvoted 0 times
Alex
1 year ago
Yes, that way we can restrict management access to just SSH and HTTPS from the NOC subnet.
upvoted 0 times
...
Genevive
1 year ago
I agree, configuring the ACL on the management interface of the APIC is the most logical solution.
upvoted 0 times
...
Catarina
1 year ago
I think option C is the best choice. It allows us to control access at the interface level.
upvoted 0 times
...
...
Lenita
1 year ago
Haha, I bet the engineer who wrote this question has a really good sense of humor. Configuring an ACL on the console interface? That's like trying to lock the front door while leaving the back door wide open!
upvoted 0 times
Joanne
1 year ago
D) ACL on the console interface
upvoted 0 times
...
Malissa
1 year ago
C) ACL on the management interface of the APIC
upvoted 0 times
...
Devorah
1 year ago
B) policy on the management VLAN
upvoted 0 times
...
Sarah
1 year ago
A) policy In the management tenant
upvoted 0 times
...
Nancey
1 year ago
B) policy on the management VLAN
upvoted 0 times
...
Francine
1 year ago
That's a good point, it would be pretty funny to configure the ACL on the console interface!
upvoted 0 times
...
Carlota
1 year ago
C) ACL on the management interface of the APIC
upvoted 0 times
...
Candida
1 year ago
A) policy In the management tenant
upvoted 0 times
...
...
Alica
1 year ago
Option D is a bit of a stretch, don't you think? Why would we need to configure an ACL on the console interface? That's just silly.
upvoted 0 times
...
Felix
1 year ago
I'm not sure about this one. Wouldn't it make more sense to configure the policy in the management tenant? That seems like the logical place to handle management access.
upvoted 0 times
...
Kerry
1 year ago
I think the correct answer is option C. The policy should be configured as an ACL on the management interface of the APIC to limit access to SSH and HTTPS only.
upvoted 0 times
Giuseppe
1 year ago
That makes sense, limiting access to SSH and HTTPS only from a single subnet where the NOC operates.
upvoted 0 times
...
Latrice
1 year ago
I agree, option C is the correct answer. It should be configured as an ACL on the management interface of the APIC.
upvoted 0 times
...
...
Shantell
1 year ago
I believe the ACL should be configured on the management interface of the APIC for better control.
upvoted 0 times
...
Mindy
1 year ago
I agree with Whitney, it makes sense to limit access in the management tenant.
upvoted 0 times
...
Whitney
1 year ago
I think the policy should be configured in the management tenant.
upvoted 0 times
...

Save Cancel