In a controller-based design, which statement best describes a northbound API?
In a controller-based architecture, the northbound API (often RESTful) faces applications and orchestration systems, allowing them to request network services or retrieve telemetry without manual device-level configuration. It abstracts the underlying network complexity, so external software can communicate intent to the controller, which then translates that intent into device-specific actions. This direction is 'north' because it sits above the controller in the logical hierarchy.
Why this answer
A northbound API is the interface exposed by the controller to external applications, orchestration systems, dashboards, or automation tools. In plain language, it is the way software above the controller communicates with the controller so that it can request data, apply policy, or trigger changes. This is different from the southbound side, where the controller interacts with the underlying infrastructure devices.
This concept appears often in automation topics because it helps define where the controller sits in the larger architecture. A northbound API is not a physical cable, and it does not replace security controls. It is an application-facing software interface, which is exactly what the correct answer should capture.
Exam trap
A frequent exam trap is mistaking the northbound API for a physical cable or a routing protocol. Some candidates incorrectly associate 'northbound' with physical connections between controllers or with link-state protocols, which is incorrect. Northbound APIs are purely logical interfaces used by applications to communicate with the controller, not hardware or routing mechanisms.
Another trap is assuming northbound APIs bypass security controls; in reality, these APIs require proper authentication and authorization. Misunderstanding these points can lead to selecting incorrect answers that describe physical or protocol-related concepts rather than software interfaces.
Why the other options are wrong
This option incorrectly describes a northbound API as a cable type, which is a physical concept unrelated to the logical API direction in controller architectures.
This option confuses northbound APIs with routing protocols like link-state protocols, which are unrelated to the software interface role of northbound APIs.
This option falsely claims that northbound APIs remove the need for authentication, ignoring that security controls remain essential for API access.