Cisco CCIE Data Center Preparation Q&A (2026)
The CCIE Data Center lab is an eight-hour practical exam across fabric networking, compute, storage, cloud integration, security, and automation. This guide rewrites the important questions in simple technical words so you can revise faster and avoid the “almost right” answers that cost marks.
In This Lesson
Organize CCIE Data Center preparation around architecture, configuration, automation, and troubleshooting evidence. The topic categories help expose gaps without treating memorization as lab readiness.
Quick Learning Map
Keep this three-step view in mind as you work through the detailed lesson.
Map the blueprint
Group study by ACI, NX-OS, VXLAN EVPN, compute, storage, security, and automation.
Practice integrated tasks
Build labs where technologies interact and failure symptoms cross domains.
Review like an operator
Verify state, explain outputs, document rollback, and repeat weak scenarios.
Cisco CCIE Data Center Preparation Q&A (2026) at a Glance
Use this summary before moving into the detailed explanations, examples, commands, and checks.
Core focus
Organize CCIE Data Center preparation around architecture, configuration, automation, and troubleshooting evidence.
Key connection
Map the blueprint → Practice integrated tasks → Review like an operator
Practical outcome
The topic categories help expose gaps without treating memorization as lab readiness.
Quick Exam Snapshot
| Area | Simple View |
|---|---|
| Qualifying exam | 350-601 DCCOR, about 120 minutes, focused on core data center technologies. |
| Lab exam | 8-hour hands-on practical lab covering real configuration and troubleshooting tasks. |
| Main domains | Network, compute, storage, automation, and security. |
| Typical preparation | 12 to 24 months, depending on existing ACI, UCS, storage, and automation experience. |
10 Topic Categories
| # | Category | What to Master |
|---|---|---|
| 1 | ACI Fabric | Tenants, VRFs, BDs, EPGs, contracts, L3Out, Multi-Site, Multi-Pod. |
| 2 | NX-OS | vPC, FabricPath basics, OTV, ISSU, Nexus troubleshooting. |
| 3 | VXLAN EVPN | Route types, symmetric IRB, anycast gateway, ARP suppression. |
| 4 | UCS Compute | Fabric Interconnects, IOM, service profiles, VIC, boot from SAN. |
| 5 | Storage | Fibre Channel, zoning, FCoE, NVMe-oF, MDS operations. |
| 6 | HyperFlex | HX Data Platform, replication factor, stretch cluster, witness. |
| 7 | Security | ACI microsegmentation, TrustSec, SGT, contracts, PBR. |
| 8 | Cloud | Nexus Dashboard, NDO, NDFC, Cloud ACI, multi-site policy. |
| 9 | Automation | ACI REST API, YANG, NETCONF, RESTCONF, Python, Ansible. |
| 10 | Lab Strategy | Speed, verification, time management, full-lab practice. |
Category 1: ACI Fabric Architecture
Q1. How do Tenant, VRF, Bridge Domain, EPG, and Contract relate?
A Tenant is the top-level container. A VRF is the routing table inside the tenant. A Bridge Domain is the Layer 2 network and belongs to one VRF. An EPG is a group of endpoints that need the same policy. A Contract is the rule that allows traffic between EPGs. By default, EPG-to-EPG traffic is blocked unless a contract permits it.
Lab tip: One Bridge Domain can contain multiple EPGs. Same subnet does not automatically mean free communication in ACI policy design.
Q2. What is flooding mode vs proxy mode in an ACI Bridge Domain?
Flooding mode sends ARP or unknown traffic through the fabric. Proxy mode uses the ACI endpoint database so the fabric can answer or forward without flooding. In most modern routed ACI designs, proxy behavior is preferred because it reduces unnecessary broadcast traffic.
moquery -c fvBD -f 'fvBD.name=="App-BD"' | grep -E "arpFlood|unkMacUcastAct|unicastRoute"
arpFlood : no
unkMacUcastAct : proxy
unicastRoute : yes
Q3. EPG-Web cannot reach EPG-App. Contract exists. What should you check first?
Check the contract direction first. One EPG should provide the contract and the other should consume it. Then confirm the filter protocol and port, endpoint learning, and zoning rules on the leaf switch.
show zoning-rule scope <vrf-vnid>
show endpoint vrf <tenant>:<vrf>
moquery -c vzFilter
moquery -c vzEntry
Q4. What is L3Out?
L3Out connects ACI to external routed networks such as WAN, internet edge, firewalls, or non-ACI data centers. It defines routing, interfaces, external EPGs, and contracts for traffic between the fabric and outside networks.
Q5. Multi-Pod vs Multi-Site?
Multi-Pod is one ACI fabric stretched across multiple pods using the same APIC cluster. Multi-Site is multiple independent ACI fabrics managed through Nexus Dashboard Orchestrator. In simple words: Multi-Pod extends one fabric; Multi-Site connects multiple fabrics.
Category 2: NX-OS and Nexus Switching
Q6. What is vPC?
vPC lets one downstream device build a port-channel to two Nexus switches at the same time. It gives active-active links, avoids STP blocking, and improves redundancy. If the peer link fails while keepalive is still up, the secondary switch usually suspends vPC ports to avoid split-brain.
show vpc
show vpc brief
show vpc consistency-parameters global
show vpc peer-keepalive
Q7. What is FabricPath?
FabricPath is Cisco Layer 2 multipath technology. It replaces STP in the core with a routed-style Layer 2 fabric using IS-IS. Modern designs usually prefer VXLAN EVPN, but FabricPath can still appear in comparison questions.
Q8. What is OTV?
OTV extends Layer 2 VLANs between data centers over an IP network. It avoids extending STP between sites and advertises MAC reachability through the overlay. It is mainly seen in older data center interconnect designs.
Q9. What is ISSU on Nexus?
ISSU means In-Service Software Upgrade. It upgrades a redundant Nexus system with minimal traffic disruption. It needs dual supervisors, SSO, compatible software path, and a healthy system state before upgrade.
show system issu state
show redundancy status
show module
show install all impact nxos bootflash:<image-name>
Category 3: VXLAN and BGP EVPN
Q10. Explain EVPN route types 2, 3, and 5.
- Type 2 carries MAC and optional IP information for endpoints.
- Type 3 tells other VTEPs which VNIs need BUM traffic delivery.
- Type 5 carries IP prefixes for routed reachability between VRFs or external networks.
Q11. Symmetric vs asymmetric IRB?
Asymmetric IRB routes at the ingress VTEP and bridges at the egress VTEP. It needs many VNIs everywhere and does not scale well. Symmetric IRB routes at both ingress and egress using an L3 VNI per VRF. This is the scalable data center design.
vlan 3967
vn-segment 50001
vrf context PROD
vni 50001
interface nve1
member vni 50001 associate-vrf
Q12. What is Anycast Gateway?
Every leaf has the same gateway IP and MAC for a subnet. A local server always uses its local leaf as the default gateway. This removes the need for HSRP or VRRP inside the VXLAN fabric.
Q13. How does ARP suppression work?
The leaf learns MAC/IP pairs from EVPN Type 2 routes. If a host asks for a known IP, the local leaf replies instead of flooding ARP across the fabric. This reduces broadcast traffic and improves scale.
Category 4: Cisco UCS and Compute
Q14. What are Fabric Interconnect, IOM, and Service Profile?
Fabric Interconnects are the control and traffic aggregation point for UCS. IOMs connect blade chassis to the Fabric Interconnects. A Service Profile defines server identity such as MACs, WWPNs, BIOS policy, boot policy, firmware, and adapter settings.
Q15. Service Profile vs Service Profile Template?
A Service Profile is the actual server identity. A template is the reusable design. Updating templates push changes to linked profiles. Initial templates only affect new profiles created later.
Q16. What is UCS VIC?
The VIC is the virtual interface card. It can present multiple vNICs and vHBAs to the server operating system from the same physical adapter. The configuration comes from the UCS service profile.
Q17. Explain boot from SAN.
Boot from SAN means the server boots from a storage LUN instead of local disk. You need a boot policy, vHBA WWPN, SAN zoning, storage masking, and the correct target LUN. If boot fails, check zoning and WWPN first.
show flogi database
show zoneset active
show interface fc brief
show npv flogi-table
Category 5: Storage Networking
Q18. What is Fibre Channel zoning?
Zoning controls which initiators and targets can talk in the SAN. WWN zoning follows the device identity. Port zoning follows the switch port. Hard zoning is enforced in hardware and is the safer model.
Q19. What is FCoE?
FCoE carries Fibre Channel frames over Ethernet. Because Fibre Channel expects lossless transport, FCoE needs Data Center Bridging features like PFC, ETS, and DCBX.
feature fcoe
feature npiv
show interface ethernet 1/1 priority-flow-control
show queuing interface ethernet 1/1
Q20. What is NVMe-oF?
NVMe over Fabrics extends NVMe storage over a network. It is faster and more parallel than older SCSI-based storage protocols. Common transports are NVMe/TCP, NVMe/RDMA, and NVMe/FC.
Category 6: HyperFlex and Hyperconverged Infrastructure
Q21. What is Cisco HyperFlex?
HyperFlex is Cisco hyperconverged infrastructure built on UCS. It pools local disks from multiple nodes into one distributed storage system. Data is protected using replication factors such as RF2 or RF3.
Q22. What is a HyperFlex Stretch Cluster?
A stretch cluster runs across two sites with a witness at a third location. It gives zero-RPO style protection because writes are synchronously copied across sites. Use it only when latency and bandwidth requirements are met.
Category 7: Data Center Security
Q23. What is ACI microsegmentation?
Microsegmentation lets you apply policy between workloads even if they are in the same VLAN or subnet. In ACI, endpoints can be placed into different EPGs and controlled by contracts.
Q24. How does TrustSec integrate with ACI?
TrustSec uses Security Group Tags to identify users or devices. ACI can use this identity to apply policy. This reduces dependence on static IP ACLs and helps create identity-based data center access rules.
Category 8: Cloud and Multi-Site Architecture
Q25. What is Cisco Nexus Dashboard?
Nexus Dashboard is Cisco's common platform for data center management applications. NDO manages multi-site policy, NDI provides insights and analytics, and NDFC automates NX-OS and SAN fabrics.
Q26. What is Cloud ACI?
Cloud ACI extends ACI policy concepts to public cloud. Tenants, VRFs, EPGs, and contracts map to cloud constructs like VPCs, VNets, security groups, and application security groups.
Category 9: Automation and Programmability
Q27. How do you create an ACI tenant using REST API?
First authenticate to APIC and receive a token. Then send a JSON payload to create the tenant object in the ACI management tree.
import requests
APIC = "https://10.0.0.1"
login = {"aaaUser": {"attributes": {"name": "admin", "pwd": "password"}}}
r = requests.post(f"{APIC}/api/aaaLogin.json", json=login, verify=False)
token = r.json()["imdata"][0]["aaaLogin"]["attributes"]["token"]
cookies = {"APIC-cookie": token}
tenant = {"fvTenant": {"attributes": {"name": "Production"}}}
requests.post(f"{APIC}/api/node/mo/uni.json", json=tenant, cookies=cookies, verify=False)
Q28. What are YANG, NETCONF, and RESTCONF?
YANG defines the data model. NETCONF sends YANG-modeled data over SSH, usually using XML. RESTCONF exposes similar data through HTTPS with REST-style methods and JSON or XML.
Q29. How does NX-OS support Python?
NX-OS supports Python for on-box automation and health checks. It is useful for local tasks, but heavy automation should usually run off-box through Ansible, Nornir, NETCONF, RESTCONF, or APIs.
Category 10: Lab Strategy and Study Plan
Q30. How should you manage time in the CCIE DC lab?
Read the full exam first, identify task dependencies, solve the tasks you know well, and leave time for verification. Do not spend 90 minutes on one small task. Mark it, move forward, and return later.
# Simple lab-time habit
1. Read all tasks first
2. Mark dependencies
3. Solve known tasks first
4. Verify before moving on
5. Save final time for end-to-end checks
Q31. What is NDFC?
Nexus Dashboard Fabric Controller automates VXLAN EVPN and SAN fabric provisioning. You define the intent, and NDFC generates and deploys NX-OS configuration for fabric, VRFs, networks, and policies.
Q32. What resources help most?
| Resource | Best Use |
|---|---|
| Cisco dCloud | Hands-on practice for ACI, UCS, MDS, and Nexus labs. |
| ACI Simulator | Practice tenants, VRFs, BDs, EPGs, contracts, and L3Out workflows. |
| Nexus 9000v | Build NX-OS, vPC, VXLAN EVPN, and BGP labs. |
| Cisco Learning Network | Track official exam discussions and blueprint updates. |
| Third-party workbooks | Use timed labs and scenario practice for speed. |
12-Month Study Roadmap
| Phase | Duration | Focus |
|---|---|---|
| Phase 1 | Months 1-3 | Blueprint study and pass 350-601 DCCOR. |
| Phase 2 | Months 4-7 | Deep labs for ACI, UCS, VXLAN EVPN, MDS, and automation. |
| Phase 3 | Months 8-10 | Timed scenario labs and weak-area correction. |
| Phase 4 | Months 11-12 | Speed drills, verification commands, and full lab readiness. |
What Separates Passers from Repeat Candidates
- Lab speed: You must configure quickly and accurately.
- Verification habit: Every task needs a command or GUI check before you move on.
- Cross-domain strength: Networking alone is not enough; storage, compute, and automation matter.
- Calm execution: Skip stuck tasks, keep notes, and return with fresh eyes.