CCNP Automation Practice Question
A network administrator is comparing configuration management tools and wants to use one that is agentless, uses YAML for playbooks, and communicates with Cisco IOS XE devices over SSH. Which tool best meets these requirements?
⚠ Common exam trap
The trap here is assuming that any tool using YAML or supporting SSH is equivalent, when in fact Ansible is uniquely agentless with YAML playbooks as its core design.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ansible
Ansible is designed as an agentless automation tool that communicates over SSH and uses YAML playbooks. It provides network-specific modules for Cisco IOS XE, allowing configuration and command execution without installing software on the managed devices. This combination of agentless architecture, YAML syntax, and SSH transport exactly matches the administrator's requirements, distinguishing it from agent-based tools like Puppet, Chef, and SaltStack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Puppet
Why it's wrong here
Puppet typically requires an agent installed on managed nodes, although it can operate in agentless mode with SSH for some modules. However, its manifests are written in a Ruby-based DSL, not YAML, and its primary model is agent-based. For Cisco network devices, Puppet support often relies on dedicated modules and may not be as straightforward for pure SSH-based configuration as the tool described.
- ✗
Chef
Why it's wrong here
Chef uses Ruby-based recipes and cookbooks, not YAML, and traditionally requires a Chef client agent on managed nodes. While Chef can manage network devices through specific resources, it does not natively use YAML for its configuration definitions. The requirement for agentless operation over SSH with YAML playbooks does not align with Chef's standard architecture.
- ✗
SaltStack
Why it's wrong here
SaltStack can operate in an agentless mode using SSH, but its default communication model uses a master-minion architecture with agents. Its configuration files are written in YAML, but the typical deployment for network devices often relies on proxy minions rather than direct SSH. The scenario emphasizes agentless SSH and YAML playbooks, which is more characteristic of Ansible's standard workflow.
- ✓
Ansible
Why this is correct
Ansible is agentless, connecting to devices over SSH, and uses YAML-formatted playbooks to define automation tasks. It includes modules such as ios_config and ios_command that specifically target Cisco IOS XE devices. This matches all stated requirements: no agent, YAML syntax, and SSH communication, making it the correct choice for this scenario.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.