Ansible ACI Automation Best Practices
Which TWO are best practices when automating ACI fabric configuration using Ansible?
Quick Answer
The answer is to use the cisco.aci collection and the state: query parameter for idempotent checks. This is correct because the cisco.aci collection is the official, Cisco-maintained Ansible collection that abstracts the ACI REST API, ensuring that your automation tasks are idempotent—meaning they can be run multiple times without causing unintended changes. The state: query parameter is specifically designed to retrieve the current state of an object without making modifications, which is a core best practice for verifying configuration before applying changes. On the Cisco DCCOR 350-601 exam, this concept tests your understanding of reliable automation in a data center environment; a common trap is confusing state: query with state: present or absent, which actually modify the fabric. Remember the memory tip: "Query to verify, present to apply"—always use query first for safe, idempotent checks.
⚠ Common exam trap
Cisco often tests the misconception that disabling certificate validation (validate_certs: no) is acceptable for lab environments, but the exam expects adherence to security best practices regardless of environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the cisco.aci collection
The cisco.aci collection is the official Ansible collection for automating Cisco ACI fabric configuration. It provides modules that abstract the ACI REST API, ensuring idempotent and reliable configuration management. Using this collection is a best practice because it is maintained by Cisco and follows Ansible's recommended approach for interacting with ACI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set validate_certs: no to avoid certificate errors
Why it's wrong here
Disabling certificate verification is a security risk.
- ✓
Use the cisco.aci collection
Why this is correct
The official collection provides idempotent modules for ACI.
- ✗
Store credentials in plain text in playbooks
Why it's wrong here
Credentials should be stored encrypted (e.g., Ansible Vault).
- ✓
Use state: query for idempotent checks
Why this is correct
state: query checks existing objects without changes.
- ✗
Use delegate_to: localhost for all tasks
Why it's wrong here
APIC tasks run on the controller; delegate_to is not required.
Go deeper
Related to this question
About these practice questions
One of 984 original 350-601 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-601
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. In an ACI fabric, an automation engineer needs to deploy tenant policies in an idempotent manner. Which approach is most aligned with best practices?
hard- A.Use the REST API with POST method for each creation
- ✓ B.Use Ansible with state: present in the cisco.aci collections
- C.Write CLI scripts using expect or pexpect
- D.Use Python SDK with a check-and-create loop
Why B: Ansible's `state: present` in the `cisco.aci` collection inherently provides idempotency: it checks the current state of the ACI object and only applies changes if the desired state differs, ensuring no duplicate or conflicting configurations. This aligns with best practices for automation, as it avoids manual error handling and guarantees consistent policy deployment without side effects.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.