300-610 · Question #333
Refer to the exhibit. A company must implement segmentation in Cisco ACI to create multiple security groups to allow endpoints within the same IP subnet to belong to different groups. Which two soluti
The correct answer is B. Configure multiple EPGs, each associated with its own BD configured with subnet, and add them D. Configure multiple EPGs that span across the same BD, each configured with multiple subnets.. Endpoint Security Groups (ESGs) let you build security groups independent of IP subnet boundaries; you can group endpoints based on policy needs (for example by associating EPGs into ESGs) to achieve segmentation even when addressing is the same. Using multiple EPGs that share th
Question
Refer to the exhibit. A company must implement segmentation in Cisco ACI to create multiple security groups to allow endpoints within the same IP subnet to belong to different groups. Which two solutions meet these requirements? (Choose two.)
Exhibit
Options
- AConfigure multiple EPGs, each associated with its own BD, with each BD configured with a single
- BConfigure multiple EPGs, each associated with its own BD configured with subnet, and add them
- CConfigure multiple BDs with a single subnet and assign endpoints with IPs from different subnets
- DConfigure multiple EPGs that span across the same BD, each configured with multiple subnets.
- EConfigure multiple SGTs that span across the same BD configured with multiple subnets and
How the community answered
(53 responses)- A9% (5)
- B74% (39)
- C4% (2)
- E13% (7)
Explanation
Endpoint Security Groups (ESGs) let you build security groups independent of IP subnet boundaries; you can group endpoints based on policy needs (for example by associating EPGs into ESGs) to achieve segmentation even when addressing is the same. Using multiple EPGs that share the same Bridge Domain allows endpoints in the same IP subnet to be placed into different policy groups, which is the core requirement for intra-subnet segmentation in ACI.
Topics
Community Discussion
No community discussion yet for this question.
