Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.
Start Scenario PracticeA network automation engineer is evaluating options for model-driven programmability on Cisco devices. Which THREE are valid YANG model sources or tools? (Choose three.)
Explanation: pyang is a YANG tool, yangcatalog.org is a repository, and Cisco native models are valid sources. OpenConfig is a standard, but oc-interfaces is a model, not a source/tool.
A developer is troubleshooting a Cisco RESTCONF API call that returns a 409 Conflict error. Which two scenarios could cause this? (Choose two.)
Explanation: Option B is correct because RESTCONF returns HTTP 409 Conflict when the server cannot complete the request due to a conflict with the resource's current state, such as attempting to delete a resource that is still referenced or in use by another object. Option C is correct because a 409 Conflict is also returned when a client attempts to create a resource that already exists, violating the uniqueness constraint of the target data node. Option A is incorrect because a missing authentication token produces HTTP 401 Unauthorized (or 403 Forbidden), not 409. Option D is incorrect because a nonexistent resource yields HTTP 404 Not Found. Option E is incorrect because invalid data types trigger HTTP 400 Bad Request due to schema or validation failure.
Which TWO are valid methods to secure a Docker container?
Explanation: Option A (Use read-only filesystem) is correct because mounting a container's root filesystem with the --read-only flag prevents processes from writing to the filesystem, which blocks malware persistence, unauthorized file modification, and many privilege-escalation or tampering attacks. Option C (Set resource limits) is correct because constraining CPU, memory, and other resources via flags such as --memory, --cpus, or --pids-limit mitigates denial-of-service and resource-exhaustion attacks, and limits the blast radius if a container is compromised. The remaining options weaken security: exposing all ports (B) unnecessarily enlarges the attack surface, running containers as root (D) violates least privilege and increases the impact of a container breakout, and disabling network isolation (E) removes segmentation that normally restricts lateral movement between containers and hosts.
Which TWO Ansible modules are commonly used for automating Cisco IOS devices?
Explanation: The `ios_config` module is correct because it is specifically designed to manage Cisco IOS device configurations by sending configuration commands via SSH or Telnet, using the CLI to apply changes to the running or startup configuration. This module is part of Ansible's `cisco.ios` collection and directly supports the IOS operating system, making it the standard choice for automating configuration tasks on Cisco IOS devices.
Which TWO actions are best practices for managing secrets in a CI/CD pipeline?
Explanation: Option B is correct because loading secrets as environment variables from a .env file that is excluded from version control (e.g., via .gitignore) keeps credentials out of the repository history and injects them only at runtime, reducing exposure. Option E is correct because a dedicated secrets manager like HashiCorp Vault centralizes storage, enforces access policies, supports dynamic/short-lived credentials, and provides auditing and encryption, which are core best practices for CI/CD secret handling. Option A is wrong because long-lived static passwords increase the blast radius if leaked and violate rotation and least-privilege principles. Option C is wrong because hardcoding secrets in source code exposes them to anyone with repository access and persists them in build artifacts and history. Option D is wrong because committing secrets to a configuration file in git stores them in plaintext within version control, where they can be cloned, forked, or leaked.
+15 more scenario questions available
Practice all Select Two (Multi-Select) QuestionsMulti-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination. These appear throughout the 200-901 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 200-901. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 200-901 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Select Two (Multi-Select) Questions session with instant scoring and detailed explanations.
Start Scenario Practice →