350-401 Infrastructure Practice Question
A network engineer is designing a new data center network using Cisco ACI. The engineer needs to ensure that traffic between two endpoints in different EPGs is allowed only if a contract permits it. Which ACI construct is used to define the rules that permit or deny traffic between EPGs?
⚠ Common exam trap
Candidates often confuse the logical grouping constructs like tenants, application profiles, and bridge domains with the policy enforcement construct, which is the contract.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contract
In Cisco ACI, contracts are the constructs that define the rules for permitting or denying traffic between EPGs. A contract contains subjects and filters that specify the allowed protocols and ports. EPGs can be providers or consumers of contracts, and traffic is only allowed if a contract is in place. This policy-based approach ensures that communication between endpoints is explicitly permitted, aligning with a zero-trust security model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tenant
Why it's wrong here
A tenant is a logical container for ACI policies and objects, such as EPGs, contracts, and filters. It does not define the rules for traffic between EPGs; rather, it houses them. The tenant provides isolation and is the top-level policy element. While contracts are defined within a tenant, the tenant itself does not permit or deny traffic. Therefore, this option is not the correct construct for defining traffic rules.
- ✓
Contract
Why this is correct
In Cisco ACI, a contract defines the rules that permit or deny traffic between EPGs. It consists of subjects and filters that specify the protocols and ports allowed. Contracts are applied to EPGs as providers or consumers. When an EPG provides a contract and another consumes it, traffic is allowed according to the contract's filters. This is the fundamental mechanism for enforcing policy in ACI, making it the correct answer.
- ✗
Application Profile
Why it's wrong here
An application profile (AP) is a collection of EPGs that represent an application. It is used to group EPGs logically but does not define the rules for traffic between them. Contracts are used to define those rules. The AP provides a way to apply policies to a set of EPGs, but it does not itself permit or deny traffic. This option is incorrect because it does not specify the traffic rules.
- ✗
Bridge Domain
Why it's wrong here
A bridge domain (BD) in ACI is a layer 2 broadcast domain that contains subnets and provides default gateway functionality. It is associated with EPGs but does not define traffic rules between them. Contracts are used for that purpose. The BD is responsible for forwarding within a subnet, but inter-EPG traffic is controlled by contracts. Thus, this option is not correct.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.