300-320 · Question #508
What is the built in native security to ACI?
The correct answer is B. Native Deny. In Cisco ACI, the default security posture is 'Native Deny' (also called 'deny by default'). All traffic between EPGs (Endpoint Groups) is denied by default unless a Contract explicitly permits it. This is the foundational security model of ACI - no communication is allowed…
Question
What is the built in native security to ACI?
Options
- AIPS
- BNative Deny
- CEPG to EPG ...
- DACL
How the community answered
(45 responses)- A2% (1)
- B91% (41)
- C4% (2)
- D2% (1)
Explanation
In Cisco ACI, the default security posture is 'Native Deny' (also called 'deny by default'). All traffic between EPGs (Endpoint Groups) is denied by default unless a Contract explicitly permits it. This is the foundational security model of ACI - no communication is allowed between EPGs without an administrator-defined Contract, making it a whitelist-based security architecture. IPS, ACLs, and EPG-to-EPG constructs are either external add-ons or configuration mechanisms, not the underlying native security behavior.
Topics
Community Discussion
No community discussion yet for this question.