CCNP Automation Practice Question
A network engineer at a logistics company is building a Python script that must retrieve the running configuration of a Cisco IOS XE router without parsing CLI screen-scraping output. The engineer wants a programmatic, model-driven interface that returns structured data over HTTPS. Which approach best satisfies this requirement?
⚠ Common exam trap
The trap here is assuming any model-driven protocol uses HTTPS, when NETCONF is actually carried as an SSH subsystem on port 830.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use RESTCONF over HTTPS on TCP port 443 with the Accept header set to application/yang-data+json to read the configuration datastore.
RESTCONF is the IETF-defined protocol that exposes YANG-modeled data through HTTP methods and runs over HTTPS on port 443. By setting the Accept header to application/yang-data+json, the client receives JSON-encoded structured data instead of XML, avoiding CLI parsing entirely. NETCONF uses SSH on port 830, SNMP does not expose the configuration datastore, and Telnet screen-scraping is neither secure nor model-driven.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use SNMPv3 with the get-bulk operation to walk the ifTable and reconstruct the running configuration from MIB objects.
Why it's wrong here
SNMPv3 is not a configuration-management interface for retrieving the full running configuration. MIB objects cover operational statistics and a limited set of writable parameters, not the complete configuration datastore. Reconstructing a running configuration from ifTable walks is impractical and does not produce a model-driven, structured representation of the device configuration as required.
- ✗
Use NETCONF over an SSH subsystem on TCP port 830 and parse the XML reply for the running configuration datastore.
Why it's wrong here
NETCONF is model-driven and returns structured XML, but it is not carried over HTTPS. It runs as an SSH subsystem, typically on TCP port 830, so a script expecting an HTTPS URL and JSON-style structured data would not match this transport. It also returns XML rather than JSON, which conflicts with the engineer's stated preference for a lightweight HTTPS-based interface.
- ✗
Use the Cisco IOS XE CLI over a Telnet session and capture the output of 'show running-config' with a regular expression parser.
Why it's wrong here
Telnet is unencrypted and CLI screen-scraping is exactly what the engineer wants to avoid. Parsing 'show running-config' output with regular expressions is brittle because output formats change between IOS XE releases and platforms. It is also not model-driven and does not return structured data, so it fails the stated requirement for a programmatic, structured interface.
- ✓
Use RESTCONF over HTTPS on TCP port 443 with the Accept header set to application/yang-data+json to read the configuration datastore.
Why this is correct
RESTCONF is the IETF model-driven interface that maps YANG models onto HTTP methods and runs over HTTPS on TCP port 443. Setting the Accept header to application/yang-data+json tells the device to return JSON-encoded structured data rather than XML. This directly satisfies the requirement for a programmatic, model-driven interface over HTTPS without CLI screen-scraping.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.