Courseiva
Automation →easyMultiple Choice

CCNP Automation Practice Question

A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS devices. The administrator prefers a tool that uses YAML for playbooks and does not require installing software on the managed devices. Which tool should the administrator use?

⚠ Common exam trap

It's easy for candidates to confuse Ansible with other configuration management tools that also support agentless operation but use different languages or require more setup; Ansible uniquely uses YAML playbooks and is agentless.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ansible

Ansible is the correct choice because it is agentless, uses YAML for playbooks, and connects to Cisco IOS devices over SSH without requiring any software installation on the devices. It has a rich set of network modules, such as 'ios_config', that simplify configuration management. Other tools like Puppet and Chef use different languages and often require agents, making them less suitable for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Puppet

    Why it's wrong here

    Puppet typically requires an agent (Puppet agent) to be installed on managed nodes, although it can operate in agentless mode via SSH for some tasks. However, for network devices like Cisco IOS, Puppet often relies on proxy agents or specialized modules. The requirement for agentless operation and YAML playbooks points more directly to Ansible, as Puppet uses its own DSL (Puppet Language) for manifests, not YAML.

  • ✓

    Ansible

    Why this is correct

    Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to managed devices over SSH or NETCONF, so no agent software needs to be installed on the Cisco IOS devices. This makes it ideal for simple, push-based configuration management. Ansible modules like 'ios_config' allow network engineers to automate configuration changes across multiple devices efficiently.

  • ✗

    Chef

    Why it's wrong here

    Chef uses Ruby-based recipes and cookbooks, not YAML playbooks. It also typically requires a Chef agent installed on managed nodes. While Chef can manage network devices via specialized modules, it is not agentless in the same way as Ansible and does not use YAML for its configuration definitions. Therefore, it does not meet the administrator's criteria for simplicity and agentless operation.

  • ✗

    SaltStack

    Why it's wrong here

    SaltStack can operate in an agentless mode using SSH, but it uses YAML for its state files and typically requires a master-minion architecture. While it is powerful, it is more complex to set up than Ansible for simple push-based configuration. The administrator's preference for a simple, agentless tool with YAML playbooks aligns best with Ansible, which is widely used for network automation and has extensive Cisco IOS module support.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.