CCNA AI and Network Operations Practice Question
A network administrator is introducing a controller-based automation workflow that will push configuration changes to dozens of access switches. The administrator wants each change to be validated against the intended state before it reaches production devices. Which practice best supports this requirement?
⚠ Common exam trap
The trap here is equating post-change log review or broad access with validation, when validation must occur before the change reaches production devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Test the change on a lab device or simulation, then stage and verify it against a limited group before broad rollout.
Validation before production requires an environment and a process that catch mismatches early. Exercising the change in a lab or simulation, then applying it to a small staged group and verifying the resulting state, limits blast radius and confirms intent. Backups, access control, and post-hoc log review are supporting controls, but none of them validate a change before it reaches every device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable configuration backups so the controller always writes the newest configuration to devices.
Why it's wrong here
Backups are the safety net that enables rollback when a change fails validation or causes unexpected behavior. Disabling them removes the ability to restore a known-good state and does nothing to validate intent before deployment. This choice increases risk and directly undermines the goal of safe, verified changes.
- ✓
Test the change on a lab device or simulation, then stage and verify it against a limited group before broad rollout.
Why this is correct
Validating in a lab or simulation and then verifying on a small staged group confirms the change matches intended state before it spreads. Any mismatch is caught while blast radius is small, and the verified configuration can be promoted with confidence, which is exactly the pre-production validation the administrator seeks.
- ✗
Apply the change directly to all switches during a maintenance window and review logs afterward.
Why it's wrong here
Pushing changes directly and reviewing logs afterward is reactive. Any error reaches every switch simultaneously, and the review happens only after impact. This approach offers no validation against intended state before deployment, so it contradicts the requirement to verify changes prior to touching production devices.
- ✗
Grant every engineer write access to the controller so changes can be applied by whoever is available.
Why it's wrong here
Broad write access increases the chance of unverified or conflicting changes reaching production. It addresses staffing convenience, not validation of intended state. Without review gates, an unauthorized or mistaken edit can propagate widely, so this practice weakens rather than strengthens the pre-deployment validation the scenario requires.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.