350-601 · Question #320
The VMM domain is integrated between Cisco APICs and vCenter using a distributed vSwitch. The traffic must be blocked between a subset of endpoints in an EPG based on specific VM attributes and the…
The correct answer is A. 1. Set Allow Microsegmentation under the EPG VMM Domain Association to "True". Microsegmentation in Cisco ACI with a VMM domain (vCenter + DVS) allows policies to be applied to subsets of VMs within the same EPG based on VM attributes (such as VM name, tag, OS type, etc.). To enable this, 'Allow Microsegmentation' must be set to 'True' under the EPG VMM…
Question
The VMM domain is integrated between Cisco APICs and vCenter using a distributed vSwitch. The traffic must be blocked between a subset of endpoints in an EPG based on specific VM attributes and the rest of the VMs in that EPG. Which set of actions blocks this traffic?
Options
- A
- Set Allow Microsegmentation under the EPG VMM Domain Association to "True"
- B
- Set Allow Microsegmentation under the EPG VMM Domain Association to "False"
- C
- Set Allow Microsegmentation under the EPG VMM Domain Association to "True"
- D
- Set Allow Microsegmentation under the EPG VMM Domain Association to "True"
How the community answered
(19 responses)- A79% (15)
- B5% (1)
- C11% (2)
- D5% (1)
Explanation
Microsegmentation in Cisco ACI with a VMM domain (vCenter + DVS) allows policies to be applied to subsets of VMs within the same EPG based on VM attributes (such as VM name, tag, OS type, etc.). To enable this, 'Allow Microsegmentation' must be set to 'True' under the EPG VMM Domain Association. With microsegmentation enabled, the ACI system can create attribute-based EPGs (uSeg EPGs) that override the base EPG membership and enforce isolation or specific contracts. Setting it to 'False' (option B) disables this capability entirely, preventing VM-attribute-based policy enforcement within an EPG.
Topics
Community Discussion
No community discussion yet for this question.