Cisco · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
An engineer needs to automate the deployment of a new VLAN across multiple switches. Which tool is best suited for this task?
NetFlow
Syslog
Ansible
Ansible's agentless architecture pushes declarative configuration over SSH, letting a single playbook apply identical VLAN definitions across many switches simultaneously. This directly satisfies the stem's requirement to automate deployment across multiple devices, unlike manual CLI entry or per-device scripting, and needs no software installed on the switches themselves.
SNMP
A DevOps team wants to version control their network configurations. Which tool should they use?
Puppet
Jenkins
Git
Git provides distributed version control with commit history, branching and merging, satisfying the team's need to track changes to network configuration files over time. Unlike CI/CD orchestrators or configuration management tools, Git directly addresses versioning itself, letting engineers diff revisions and roll back faulty changes precisely.
Docker
During an automation script run, a network device returns HTTP 429. What does this indicate?
Internal server error
Rate limiting
HTTP 429 is the standard 'Too Many Requests' status code, returned when a client exceeds the server's permitted request rate within a given window. It directly signals rate limiting, satisfying the stem's scenario of an automation script being throttled by the network device.
Authentication failure
Resource not found
A network automation engineer is writing a Python script to configure multiple devices. Which library is most appropriate for SSH-based interactions?
requests
socket
Netmiko
Netmiko abstracts SSH transport for multi-vendor network devices, handling prompt detection and enable-mode escalation that raw Paramiko requires manually. It satisfies the stem's SSH-based interaction constraint across multiple device types, unlike RESTCONF or SNMP libraries.
paramiko
In a CI/CD pipeline for network changes, which practice best ensures that a configuration push does not disrupt production traffic?
Disable rollback
Canary deployment
Canary deployment pushes the configuration to a small subset of devices first, allowing traffic impact to be observed before fleet-wide rollout. This limits blast radius, satisfying the requirement that a configuration push does not disrupt production traffic.
Push all changes at once
Skip validation
An engineer uses Ansible to push a configuration change to 100 switches. The playbook fails on 5 switches. What is the most efficient way to apply the change only to those 5?
Use Ansible's --limit with the retry file
Ansible writes failed hosts to a retry file, and --limit accepts that file to target only those hosts. This satisfies the requirement to reapply the change to the five failed switches without rerunning the playbook against all 100.
Use --skip-tags on successful hosts
Re-run the playbook on all switches
Manually configure the 5 switches
Want more Infrastructure and Automation practice?
Practice this domain15% of exam · 6 sample questions below
A developer creates a Dockerfile for a Python web application. Which instruction should be used to copy the application source code into the container image?
CMD
COPY
COPY transfers files from the build context into the image filesystem, so the Python source lands in the image. ADD also copies but additionally handles remote URLs and archive extraction, which the stem does not require.
RUN
EXPOSE
A Docker container needs to be started in detached mode with port mapping from host port 8080 to container port 80. Which command accomplishes this?
docker start -d -p 8080:80 myapp
docker run -d -p 8080:80 myapp
The `-d` flag detaches the container, running it in the background, while `-p 8080:80` maps host port 8080 to container port 80, satisfying both stem constraints. The syntax `host:container` is critical here; reversing it would publish the wrong port. This single command therefore meets the detached-mode and port-mapping requirements exactly.
docker run -it -p 8080:80 myapp
docker run -d -p 80:8080 myapp
In a docker-compose.yaml file, which key is used to define the container image to be built from a Dockerfile in the current directory?
dockerfile
image
context
build
The build key names the directory containing the Dockerfile, so Compose builds the image from that context rather than pulling a prebuilt one. Specifying image alone would only tag or fetch an existing image, failing the requirement to build from the current directory.
A company deploys a microservice using Kubernetes. The service must be accessible externally via a stable IP address and load-balanced across pods. Which Service type should be used?
NodePort
ClusterIP
LoadBalancer
LoadBalancer provisions an external cloud load balancer with a stable, routable IP that distributes traffic across the backing pods. ClusterIP is internal-only and NodePort exposes a high port on each node, neither meeting the stable external IP requirement.
ExternalName
A developer is writing a Dockerfile for a Node.js application. They want to set a build-time variable for the application version that can be changed without modifying the Dockerfile. Which instruction should be used?
RUN
ARG
ARG declares build-time variables that persist only during image construction, so the version can be passed via --build-arg without editing the Dockerfile. ENV would bake the value permanently into the image, failing the requirement that it change without modifying the Dockerfile.
ENV
CMD
A Kubernetes pod needs to read configuration data such as database hostname, which is non-sensitive and may change across environments. Which resource should be used to store this data and inject it into the pod?
Deployment
Secret
Service
ConfigMap
ConfigMaps hold non-sensitive configuration as key-value pairs, decoupled from pod images, so database hostnames can vary per environment without rebuilding containers. Secrets are reserved for sensitive data, making ConfigMap the appropriate resource for injection via environment variables or volumes.
Want more Application Deployment and Security practice?
Practice this domain20% of exam · 6 sample questions below
What HTTP method should be used to update only the description field of a network device resource via a REST API?
DELETE
PUT
POST
PATCH
PATCH applies a partial modification, sending only the description field in the request body while leaving all other device attributes untouched. PUT would replace the entire resource representation, risking unintended overwrites of unmentioned fields. This satisfies the stem's constraint of updating solely the description.
A developer is building a script to retrieve a list of network devices from Cisco DNA Center. The API response includes a 'nextToken' field in the body to indicate more results. What pagination method is being used?
Cursor-based pagination
The nextToken field is an opaque cursor marking the next page position; the client returns it unchanged to fetch subsequent results. This is cursor-based pagination, distinct from offset or page-number schemes that use numeric limits and offsets.
Page-based pagination
Offset/Limit pagination
Link header pagination
Which HTTP header is used to specify the format of the request body (e.g., application/json) when sending a POST request to a REST API?
Accept
Content-Type
Content-Type specifies the media type of the request body, such as application/json, so the server knows how to parse the POST payload. Accept instead describes the desired response format, so Content-Type satisfies the requirement to declare the body's format.
Authorization
X-Requested-With
A developer is using the Meraki Dashboard API and receives a 429 Too Many Requests error. The API documentation states a rate limit of 5 calls per second. What is the best practice to handle this?
Ignore the error and retry immediately.
Use a different API key to bypass the limit.
Increase the number of concurrent requests to exhaust the rate limit quickly.
Implement exponential backoff and honor the Retry-After header.
Exponential backoff spaces retries progressively, preventing repeated collisions with the 5 calls per second limit, while honouring Retry-After respects the server's stated wait. Together they satisfy the rate-limit constraint without hammering the Meraki Dashboard API.
Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required, such as a backend service calling Cisco API?
Authorization code grant
Password grant
Device code grant
Client credentials grant
The client credentials grant exchanges the application's own client ID and secret directly for an access token, with no resource owner or browser redirect involved. This matches server-to-server backend calls where no user context exists, unlike authorisation code or implicit grants.
A developer wants to use Postman to test a REST API that requires a Bearer token. Where should the token be placed in the request?
In the Authorization header
Bearer tokens are transmitted as credentials in the Authorization header using the scheme "Bearer <token>". Placing it there satisfies the API's authentication requirement, so Postman sends it with every request and the server validates the caller's identity before processing.
As a query parameter
In a custom header like X-Auth-Token
In the request body
Want more Understanding and Using APIs practice?
Practice this domain15% of exam · 6 sample questions below
A developer writes a Python script to read a configuration file. Which code snippet correctly opens the file 'config.json' for reading and ensures the file is closed after use?
with open('config.json', 'r') as f:\n data = f.read()
The with statement opens config.json in read mode and guarantees closure via context-manager protocol, even if an exception occurs. This satisfies the stem's requirement that the file is closed after use, unlike manual open calls lacking explicit close.
open('config.json', 'r') as f:\n data = f.read()
with open('config.json', 'r') as f, data = f.read()
file = open('config.json', 'r')\ndata = file.read()\nfile.close()
A network automation script uses the requests library to retrieve device information from a REST API. The API requires authentication via a bearer token. Which code example correctly sets the Authorization header?
headers = {'Authorization': 'Token ' + token}\nresponse = requests.get(url, headers=headers)
response = requests.get(url, headers={'Authorization': token})
headers = {'Authorization': 'Bearer ' + token}\nresponse = requests.get(url, headers=headers)
The Authorization header must carry the literal scheme 'Bearer' followed by a space and the token value. Concatenating 'Bearer ' with the token and passing the dictionary via the headers parameter sets this correctly for the authenticated GET request.
response = requests.get(url, auth=('Bearer', token))
Which HTTP status code indicates that a POST request successfully created a new resource?
204 No Content
301 Moved Permanently
201 Created
HTTP 201 Created is returned when a POST request results in a new resource being created on the server, typically accompanied by a Location header identifying the new resource's URI. It precisely signals successful creation, unlike 200 OK, which merely indicates general success.
200 OK
In Python, which data type is used to represent an unordered collection of unique elements?
set
A `set` stores an unordered collection of unique elements, automatically discarding duplicates on insertion. This directly satisfies the stem's two constraints: no defined ordering, and uniqueness of members. Hash-based storage gives average O(1) membership testing, unlike lists or tuples, which permit duplicates and preserve insertion order.
tuple
list
dict
A Python function needs to accept a variable number of keyword arguments. Which parameter syntax should be used?
*kwargs
**kwargs
The double-asterisk prefix collects arbitrary keyword arguments into a dictionary, letting the function accept any number of named parameters. A single asterisk would instead gather positional arguments into a tuple, so **kwargs is the syntax that satisfies the variable keyword argument requirement.
*args
&kwargs
In a microservices architecture, which of the following is a key characteristic compared to a monolithic architecture?
Changes require rebuilding the entire application.
Services communicate via lightweight protocols such as HTTP/REST.
Microservices decompose functionality into independently deployable units that interact over network calls rather than in-process method invocation. Using lightweight protocols such as HTTP/REST lets each service expose a language-agnostic interface, satisfying the loose-coupling and independent-scalability constraint that monolithic architectures cannot meet.
The entire application is deployed as a single unit.
All services share the same database.
Want more Software Development and Design practice?
Practice this domain15% of exam · 6 sample questions below
A developer needs to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint and HTTP method should be used?
POST /dna/intent/api/v1/issues
POST /dna/system/api/v1/auth/token
GET /dna/intent/api/v1/network-device
The `GET /dna/intent/api/v1/network-device` endpoint retrieves all network devices from Cisco DNA Center, satisfying the stem’s requirement to “retrieve a list” by using the HTTP GET method, which is idempotent and safe for read-only operations. This contrasts with POST, which would create a new resource, and DELETE, which would remove devices. The path’s `/network-device` resource collection directly maps to the requested data set.
GET /dna/intent/api/v1/topology/l2/{vlanID}
A developer wants to send a message to a specific room in Webex using the API. The developer already has the room ID. Which API call is correct?
POST /v1/messages with body { 'roomId': 'Y2lzY29zcGFyazovL3VzL1JPT00v...', 'text': 'Hello' }
The Webex messaging endpoint accepts POST /v1/messages, and targeting an existing space requires the roomId field in the JSON body alongside text. This call satisfies the constraint of using the already-obtained room ID to post into that specific room.
PUT /v1/messages with body { 'roomId': '...', 'text': 'Hello' }
POST /v1/rooms with body { 'title': 'New Room' }
GET /v1/messages with query parameter roomId='...'
When using the Meraki Dashboard API, what HTTP header is used to pass the API key?
API-Key: <key>
X-Cisco-Meraki-API-Key: <key>
The Meraki Dashboard API authenticates each request by placing the API key in the X-Cisco-Meraki-API-Key request header. This satisfies the stem's requirement, since the key is passed as a custom HTTP header rather than a query string or bearer token.
Authorization: Bearer <key>
Meraki-API-Key: <key>
A developer is automating network configuration using Cisco DNA Center. They want to deploy a configuration template to multiple devices. Which API category should they use?
Change your network
Correct. Template deployment, plug and play are part of 'change your network'.
Platform
Run your network
Know your network
An application sends many requests to the Meraki API and receives HTTP 429 errors. The response includes a 'Retry-After' header. What does this status code indicate?
The requested resource was not found
The server encountered an internal error
The API key is invalid
The client has exceeded the rate limit
HTTP 429 is 'Too Many Requests', returned when the client exceeds the Meraki API's rate limit. The Retry-After header tells the client how long to wait before retrying, confirming the request was throttled rather than rejected for authentication or syntax.
A developer is using NX-API on a Cisco Nexus switch to execute CLI commands via JSON. Which endpoint and method should be used?
GET /restconf/data/Cisco-NX-OS-device:cli
POST /api/cli with XML body
GET /ins?cmd=show version
POST /ins with JSON body
NX-API's JSON-RPC interface accepts commands at the /ins endpoint via HTTP POST, with the CLI commands supplied in the JSON body. GET is unsuitable because it cannot carry the command payload, and /cli returns plain text rather than JSON.
Want more Cisco Platforms and Development practice?
Practice this domain15% of exam · 6 sample questions below
In the OSI model, which layer is responsible for logical addressing and routing of packets between networks?
Layer 1 (Physical)
Layer 3 (Network)
Layer 3 provides logical addressing through IP addresses and determines packet forwarding between networks via routing protocols and routing tables. This satisfies the question's requirement, distinguishing it from Layer 2, which handles physical MAC addressing and local frame delivery.
Layer 4 (Transport)
Layer 2 (Data Link)
Which transport protocol is connection-oriented and ensures reliable delivery through acknowledgments and retransmissions?
IP
HTTP
TCP
TCP establishes a session via a three-way handshake before data transfer, then uses sequence numbers, acknowledgments and retransmission of lost segments to guarantee ordered, reliable delivery. This connection-oriented design directly satisfies the stem's requirement for acknowledged, retransmitted transport, unlike connectionless UDP.
UDP
A DNS AAAA record is used to resolve a hostname to what type of address?
Mail exchange server
IPv4 address
Canonical name alias
IPv6 address
An AAAA record maps a hostname to a 128-bit IPv6 address, satisfying the stem's requirement for the address family returned by this record type. It mirrors the A record's role for IPv4 but uses four times the bits, which is why the mnemonic quadruples the letter.
A network engineer is designing a subnet that needs to support 30 usable hosts. Which subnet mask should be used?
255.255.255.240 (/28)
255.255.255.0 (/24)
255.255.255.224 (/27)
A /27 mask leaves five host bits, yielding 32 addresses minus network and broadcast, so exactly 30 usable hosts. It is the smallest subnet satisfying the stated requirement without waste, whereas /28 would provide only 14 usable addresses.
255.255.255.192 (/26)
Which HTTP method is idempotent and used to update a resource by sending the full representation?
PUT
PUT is idempotent: repeating the same request yields the same resource state. It replaces the target resource entirely with the enclosed representation, unlike PATCH, which applies partial modifications, or POST, which is neither idempotent nor a full replacement.
DELETE
POST
GET
In the context of SDN, which API is used between the SDN controller and the network devices to configure forwarding behavior?
Northbound API
Eastbound API
Southbound API
The southbound API sits below the controller, translating its forwarding decisions into device-level configuration. OpenFlow is the canonical example, programming match-action flow tables on switches. This satisfies the stem's requirement for the interface used to configure forwarding behaviour on network devices.
REST API
Want more Network Fundamentals practice?
Practice this domainThe 200-901 exam has 95 questions and must be completed in 120 minutes. Cisco passing scores vary by exam version and are not always publicly listed. Check the official Cisco exam page before booking.
CLI output interpretation, network topology analysis, routing behaviour, switching concepts, troubleshooting, and configuration questions.
The exam covers 6 domains: Infrastructure and Automation, Application Deployment and Security, Understanding and Using APIs, Software Development and Design, Cisco Platforms and Development, Network Fundamentals. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Cisco 200-901 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.