nerdexam
Cisco

300-320 · Question #508

What is the built in native security to ACI?

The correct answer is B. Native Deny. In Cisco ACI, the default security posture is 'Native Deny' (also called 'deny by default'). All traffic between EPGs (Endpoint Groups) is denied by default unless a Contract explicitly permits it. This is the foundational security model of ACI - no communication is allowed…

Advanced Data Center Networks

Question

What is the built in native security to ACI?

Options

  • AIPS
  • BNative Deny
  • CEPG to EPG ...
  • DACL

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    91% (41)
  • C
    4% (2)
  • D
    2% (1)

Explanation

In Cisco ACI, the default security posture is 'Native Deny' (also called 'deny by default'). All traffic between EPGs (Endpoint Groups) is denied by default unless a Contract explicitly permits it. This is the foundational security model of ACI - no communication is allowed between EPGs without an administrator-defined Contract, making it a whitelist-based security architecture. IPS, ACLs, and EPG-to-EPG constructs are either external add-ons or configuration mechanisms, not the underlying native security behavior.

Topics

#ACI#native deny#EPG security#default policy

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice