Courseiva
SecuritymediumMultiple SelectObjective-mapped

350-601 Security Practice Question

Which TWO of these are best practices for securing the Cisco ACI fabric?

⚠ Common exam trap

Cisco often tests the misconception that in-band management is acceptable for APIC connectivity, but the correct practice is to use out-of-band management to keep APIC traffic separate from the data plane and reduce attack surface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use security domains to control RBAC.

Security domains in Cisco ACI provide role-based access control (RBAC) by partitioning the fabric into logical groups, allowing administrators to restrict user permissions to specific tenants, EPGs, or policies. This is a core best practice to enforce least-privilege access and prevent unauthorized configuration changes across the fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use security domains to control RBAC.

    Why this is correct

    Security domains isolate tenant administration.

  • Use in-band management for APIC connectivity.

    Why it's wrong here

    Out-of-band is recommended for management traffic.

  • Enable certificate-based authentication for APIC access.

    Why this is correct

    Certificate-based auth provides stronger security.

  • Leave default passwords for fabric discovery.

    Why it's wrong here

    Default passwords must be changed.

  • Place APIC controllers in a DMZ.

    Why it's wrong here

    APICs should be in a secure management network.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-601 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.