Courseiva
Virtualization →mediumMultiple Choice

CCNP Virtualization Practice Question

A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?

⚠ Common exam trap

The trap here is assuming the central APIC controller enforces contracts in the data path rather than only distributing policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy enforcement point on the leaf where the EPGs reside

ACI applies contracts at the leaf switch, which acts as the policy enforcement point for the attached EPGs. The APIC distributes the compiled policy, but the leaf hardware renders and enforces the permit for TCP port 443 between the two EPGs in their respective bridge domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VXLAN tunnel interface on the spine

    Why it's wrong here

    Spine switches in an ACI fabric forward VXLAN-encapsulated traffic based on the fabric's forwarding tables but do not host EPG-level contract enforcement. Contract policy is enforced at the leaf where endpoints attach, so the spine tunnel interface is not the enforcement point described.

  • ✗

    The bridge domain subnet SVI on the border leaf

    Why it's wrong here

    A bridge domain SVI provides default gateway functionality for a subnet, not contract enforcement between EPGs. Contracts are applied at the leaf access policy layer using the EPG and contract relationship, so the SVI is not where the permitted TCP port 443 rule is enforced.

  • ✓

    The policy enforcement point on the leaf where the EPGs reside

    Why this is correct

    In ACI, the leaf switch acts as the policy enforcement point, translating contracts into hardware ACL and forwarding rules applied to the EPG interfaces. When a contract permitting TCP 443 is attached between EPGs, the leaf enforces that filter for traffic between them, which is exactly the construct required.

  • ✗

    The APIC controller cluster policy compiler

    Why it's wrong here

    The APIC cluster compiles and distributes policy to the leaves but does not sit in the data path, so it cannot enforce the TCP 443 permit rule on live traffic. Enforcement occurs on the leaf switch hardware, making APIC the policy source rather than the enforcement point.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.