Courseiva
Automation →hardMultiple Select

CCNP Automation Practice Question

A network automation team is using the NETCONF protocol to manage a fleet of Cisco IOS XE devices. They need to ensure that configuration changes are applied atomically and that they can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities must be supported and used to achieve these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that :validate or :writable-running alone can provide atomicity and rollback, when they only offer validation or direct editing without transactional guarantees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

:rollback-on-error

To achieve atomic configuration changes and rollback, the :candidate and :rollback-on-error capabilities are required. The :candidate capability enables editing a candidate datastore and committing changes atomically. The :rollback-on-error capability ensures that if any part of the commit fails, the entire transaction is rolled back. Together, they provide the transactional integrity and error recovery the team needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    :validate

    Why it's wrong here

    The :validate capability allows the client to validate a configuration against the device's YANG models before committing. While it helps prevent errors, it does not provide atomicity or rollback by itself. Validation is a separate step; even if validation passes, a commit could still fail. It does not guarantee atomic application or automatic rollback, so it alone is insufficient.

  • ✗

    :startup

    Why it's wrong here

    The :startup capability provides access to the startup configuration datastore, allowing the client to copy configurations to and from it. It does not enable atomic transactions or rollback. While it can be used to save configurations, it does not provide the transactional guarantees needed. Therefore, it is not suitable for achieving atomic configuration changes with rollback.

  • ✓

    :rollback-on-error

    Why this is correct

    The :rollback-on-error capability ensures that if any operation within a <commit> fails, the server automatically rolls back the entire transaction to the previous state. This provides automatic error recovery and guarantees atomicity. Without it, a partial commit could leave the device in an inconsistent state. This capability is crucial for the team's requirement to roll back on error.

  • ✗

    :writable-running

    Why it's wrong here

    The :writable-running capability allows direct editing of the running configuration. While useful, it does not provide atomicity or rollback. Changes are applied immediately and individually, so an error mid-way could leave the configuration partially applied. It does not support the candidate datastore or automatic rollback, so it fails to meet the requirements of atomic changes and rollback.

  • ✓

    :candidate

    Why this is correct

    The :candidate capability allows the client to edit a candidate configuration datastore without affecting the running configuration. Changes are applied atomically with the <commit> operation. This enables the team to prepare and validate changes before committing, and if an error occurs, they can discard the candidate. This directly supports atomicity and rollback, making it essential for the scenario.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.