Courseiva
AutomationhardMultiple SelectObjective-mapped

Ansible ACI Automation Best Practices

Which TWO are best practices when automating ACI fabric configuration using Ansible?

Quick Answer

The answer is to use the cisco.aci collection and the state: query parameter for idempotent checks. This is correct because the cisco.aci collection is the official, Cisco-maintained Ansible collection that abstracts the ACI REST API, ensuring that your automation tasks are idempotent—meaning they can be run multiple times without causing unintended changes. The state: query parameter is specifically designed to retrieve the current state of an object without making modifications, which is a core best practice for verifying configuration before applying changes. On the Cisco DCCOR 350-601 exam, this concept tests your understanding of reliable automation in a data center environment; a common trap is confusing state: query with state: present or absent, which actually modify the fabric. Remember the memory tip: "Query to verify, present to apply"—always use query first for safe, idempotent checks.

⚠ Common exam trap

Cisco often tests the misconception that disabling certificate validation (validate_certs: no) is acceptable for lab environments, but the exam expects adherence to security best practices regardless of environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use the cisco.aci collection

The cisco.aci collection is the official Ansible collection for automating Cisco ACI fabric configuration. It provides modules that abstract the ACI REST API, ensuring idempotent and reliable configuration management. Using this collection is a best practice because it is maintained by Cisco and follows Ansible's recommended approach for interacting with ACI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set validate_certs: no to avoid certificate errors

    Why it's wrong here

    Disabling certificate verification is a security risk.

  • Use the cisco.aci collection

    Why this is correct

    The official collection provides idempotent modules for ACI.

  • Store credentials in plain text in playbooks

    Why it's wrong here

    Credentials should be stored encrypted (e.g., Ansible Vault).

  • Use state: query for idempotent checks

    Why this is correct

    state: query checks existing objects without changes.

  • Use delegate_to: localhost for all tasks

    Why it's wrong here

    APIC tasks run on the controller; delegate_to is not required.

About these practice questions

One of 984 original 350-601 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-601

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. In an ACI fabric, an automation engineer needs to deploy tenant policies in an idempotent manner. Which approach is most aligned with best practices?

hard
  • A.Use the REST API with POST method for each creation
  • B.Use Ansible with state: present in the cisco.aci collections
  • C.Write CLI scripts using expect or pexpect
  • D.Use Python SDK with a check-and-create loop

Why B: Ansible's `state: present` in the `cisco.aci` collection inherently provides idempotency: it checks the current state of the ACI object and only applies changes if the desired state differs, ensuring no duplicate or conflicting configurations. This aligns with best practices for automation, as it avoids manual error handling and guarantees consistent policy deployment without side effects.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.