CCNP Automation Practice Question
A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE router via NETCONF. The script sends an <edit-config> RPC with a candidate datastore, but the router returns an error indicating the candidate datastore is not supported. The team wants to make configuration changes without affecting the running configuration until they are verified. Which NETCONF capability should the team ensure is enabled on the router to allow this workflow?
⚠ Common exam trap
The trap here is assuming that :writable-running allows staging changes without impact, but it directly modifies the running configuration, which is not the desired workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
:candidate
To use a candidate datastore for staging configuration changes, the NETCONF server must support the :candidate capability. This allows the client to edit the candidate configuration, validate it, and then commit it to the running configuration. Other capabilities like :confirmed-commit and :rollback-on-error enhance commit behavior but require :candidate as a prerequisite. Thus, enabling :candidate is necessary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
:writable-running
Why it's wrong here
The :writable-running capability allows direct editing of the running configuration, but it does not provide a candidate datastore for staging changes. The team specifically wants to avoid immediate impact on the running configuration, so using :writable-running would not meet the requirement and would not resolve the error about the candidate datastore.
- ✗
:rollback-on-error
Why it's wrong here
The :rollback-on-error capability automatically rolls back a configuration if an error occurs during commit. Like confirmed-commit, it depends on a candidate datastore. It does not provide the candidate datastore itself. The error is specifically about the candidate datastore not being supported, so this capability is not the solution.
- ✗
:confirmed-commit
Why it's wrong here
The :confirmed-commit capability allows a commit to be automatically rolled back if not confirmed within a timeout, but it requires a candidate datastore to be useful. Without :candidate, confirmed commit cannot be used. This capability alone does not enable the candidate datastore; it is an additional feature that builds upon it.
- ✓
:candidate
Why this is correct
The :candidate capability indicates support for a candidate configuration datastore, which allows changes to be staged and validated before being committed to the running configuration. Without this capability, the router cannot accept edits to a candidate datastore, resulting in the error. Enabling :candidate enables the desired workflow of testing configurations before applying them.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.