Courseiva
SecurityhardMultiple ChoiceObjective-mapped

350-601 Security Practice Question

A data center architect is designing security for a Cisco ACI fabric that must comply with PCI DSS. The requirement is to encrypt all traffic between EPGs within the same tenant. Which solution should be used?

⚠ Common exam trap

Many exam-takers assume encryption requires an external firewall or VPN, but Cisco ACI natively supports contract-based encryption using MACsec, which is the correct and simplest solution for intra-tenant EPG traffic encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a contract with the 'encrypt' flag enabled between the EPGs.

Cisco ACI supports encryption of traffic between EPGs within the same tenant using a contract with the 'encrypt' flag enabled. This leverages the ACI fabric's built-in capability to apply AES-based encryption (e.g., AES-256-GCM) at the leaf switch level, ensuring data confidentiality for PCI DSS compliance without requiring external devices or complex routing changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable port security on the leaf switch interfaces.

    Why it's wrong here

    Port security does not encrypt traffic.

  • Use a contract with the 'encrypt' flag enabled between the EPGs.

    Why this is correct

    ACI contracts support encryption enforcement using MACsec or IPsec.

  • Create separate VRFs for each EPG and route traffic through a firewall.

    Why it's wrong here

    Adds complexity but not native encryption.

  • Configure a site-to-site VPN between the leaf switches.

    Why it's wrong here

    VPN is for external connectivity, not internal.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 350-601 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.