Terraform ACI Provider Authentication and APIC DOS Threshold Counting

Evaluate automation and orchestration technologies
Answer Correct answer: C — A Terraform provider block using user ID and password makes APIC count each authentication request against the DOS-prevention threshold.

An engineer must automate the provisioning of Cisco ACI objects using the Terraform tool. The engineer must ensure that APIC counts the authentication login requests against the threshold to avoid a DOS attack. Which configuration must be used in Terraform to accomplish these goals?

  1. resources with user ID and password
  2. resources with signature-based authentication
  3. provider with user ID and password Correct Answer
  4. provider with signature-based authentication

Community Votes

C
54%
D
46%

54% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

User ID/password authentication obtains a token per session and APIC counts those login requests; signature-based auth is designed to avoid the DOS-prevention threshold. Auth is a provider-level setting.

For ACI Terraform automation where APIC must count auth requests against the DOS threshold, configure the provider with user ID and password rather than signature-based auth.

Placing credentials under a resource instead of the provider, or picking signature-based auth because it sounds more secure while the question explicitly wants request counting.

Community Discussion (6 comments)

gaz1978 👍 5 Selected: C
The question states 'engineer must ensure APIC count the requests' https://registry.terraform.io/providers/CiscoDevNet/aci/latest/docs Authentication with user-id and password. In this method, it will obtain an authentication token from Cisco APIC and will use that token to authenticate. A limitation with this approach is APIC counts the request This is what the question asked for so I think it is C
VTi 👍 5 Selected: D
Answer is D. APIC counts the request to authenticate and threshold it to avoid DOS attack. After too many attempts this authentication method may fail as the threshold will be exceeded. To avoid the above-mentioned problem Cisco APIC supports signature-based authentication. https://registry.terraform.io/providers/CiscoDevNet/aci/latest/docs
bizzar7774 👍 1 Selected: D
I choose D because C could trigger DOS prevention mechanisms
ed27 👍 1 Selected: C
Agree with Arch_Angel and gaz1978, that is what the question calls for the count, not to avoid it
elper 👍 1 Selected: C
C looks correct.
Arch_Angel 👍 2
C is the answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that APIC must count the authentication login requests against the threshold so the DOS-prevention mechanism engages. The Cisco ACI Terraform provider supports user ID/password and signature-based auth. With user ID/password, the provider obtains a token per session and APIC counts those login requests, which is the behavior the question asks for. The configuration belongs under the provider block, not a resource block, because authentication is provider-level.

Why the Other Options Are Wrong

D. Signature-based authentication is designed to avoid hitting the DOS-prevention threshold, so it does not satisfy "APIC counts the request." A and B place the credential under a resource, but authentication is configured at the provider level, not per resource.

Community Comment Notes

Votes are close (C 54 / D 46). Commenter gaz1978 (5 likes) quotes the provider docs: user-id/password authentication "obtain an authentication token... APIC counts the request," matching the question wording. VTi argues D but misreads the goal as avoiding the threshold rather than ensuring counting.

Official Reference

Related Analysis

← Back to 350-601 Study Guide