TechNuggets Academy

5.0 Security

Free Implementing Cisco Data Center Core Technologies practice — 6 questions on 5.0 Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · 5.0 Security
An ACI contract subject contains a single filter entry matching TCP destination port 80. 'Apply Both Directions' is enabled on the subject, but 'Reverse Filter Ports' is disabled. The provider EPG hosts a web server on port 80, and the consumer EPG initiates HTTP sessions to it. What is the result?
'Apply Both Directions' creates a second zoning-rule entry for provider-to-consumer traffic, but that entry still matches destination port 80 unless 'Reverse Filter Ports' is also enabled to swap source and destination ports in the reverse rule. Since the server's return traffic uses source port 80 and a high-numbered destination port, it does not match either rule, so the return traffic is dropped and the session breaks.
Question 2 of 6 · 5.0 Security
During a network convergence event on a Nexus 9000, OSPF adjacencies begin flapping. The engineer suspects CoPP is dropping legitimate OSPF hello packets under load. Which command should be used first to confirm whether CoPP is discarding this control-plane traffic?
'show policy-map interface control-plane' displays per-class conformed, exceeded, and violated packet/byte counters for the CoPP policy applied to the control-plane interface, directly showing whether the OSPF class-map is dropping (violating) packets.
Question 3 of 6 · 5.0 Security
A UCS Manager administrator creates a local user account and assigns it the 'operations' role along with a locale restricted to the 'Finance' sub-organization. The user reports being able to view and modify global server pools and policies defined in the root organization, which should be out of scope. What is the most likely cause?
In UCS Manager, a user account can be assigned multiple role-and-locale pairs. Effective access is the union of all assigned locales — if any one of those assignments has no locale restriction (full access), the user effectively has unrestricted organizational access regardless of the more restrictive Finance-only assignment. This is a well-known RBAC gotcha in UCS Manager.
Question 4 of 6 · 5.0 Security
On a Nexus switch, DHCP snooping and Dynamic ARP Inspection (DAI) must be enabled on VLAN 10, with the uplink port Ethernet1/1 (connected to the distribution switch) excluded from ARP inspection because it does not have a DHCP snooping binding for downstream traffic. Which configuration sequence achieves this?
DHCP snooping must be enabled globally and per-VLAN with 'ip dhcp snooping vlan 10', and the uplink must be trusted for snooping with 'ip dhcp snooping trust' so it isn't rate-limited or blocked. DAI is then enabled per-VLAN with 'ip arp inspection vlan 10', and the same uplink must separately be marked 'ip arp inspection trust' so ARP packets arriving on it skip binding-table validation (since no DHCP snooping bindings exist for upstream traffic).
Question 5 of 6 · 5.0 Security
An ACI architect needs a subset of EPGs within a single VRF to communicate freely with each other without configuring pairwise contracts, while EPGs outside this subset must still require explicit contracts to communicate with them. Which construct meets this requirement?
Preferred Group membership allows administrators to designate specific EPGs within a VRF as members of the 'preferred group,' which communicate with each other without contracts, while EPGs outside the group still require explicit contracts — satisfying the selective free-communication requirement.
Question 6 of 6 · 5.0 Security
A Nexus switch is configured with 'aaa authentication login default group tacacs+' and the TACACS+ server is configured to authorize commands per user role. After deployment, users authenticate successfully but are still able to execute configuration commands outside their assigned privilege, indicating command authorization is not being enforced by the switch. Which missing command explains this behavior?
Authentication only verifies identity; it does not enforce per-command authorization. NX-OS requires the explicit command 'aaa authorization commands default group tacacs+' to instruct the switch to send each entered command to the TACACS+ server for an authorization decision before execution.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →