CCNP Automation Practice Question
A network engineer is developing a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. The script sends a GET request to the URI https://10.1.1.1/restconf/data/ietf-interfaces:interfaces. The device returns a 401 Unauthorized error. The engineer verifies that the RESTCONF API is enabled and the URI is correct. Which action should the engineer take to resolve this issue?
⚠ Common exam trap
The trap here is assuming that enabling NETCONF or adjusting headers will fix an authentication error, when the real issue is missing credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the HTTP client to use Basic authentication with valid user credentials.
A 401 Unauthorized response from a RESTCONF API indicates that the request lacks valid authentication credentials. Cisco IOS XE RESTCONF uses HTTP Basic authentication, so the client must include an Authorization header with a base64-encoded username and password. Without this, the device rejects the request regardless of the URI or method. Therefore, configuring Basic authentication is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the HTTP client to use Basic authentication with valid user credentials.
Why this is correct
RESTCONF requires authentication, and a 401 Unauthorized indicates missing or invalid credentials. Cisco IOS XE supports Basic authentication over HTTPS, so the engineer must include a valid username and password in the request headers. This directly addresses the authentication failure without altering device configuration.
- ✗
Enable the NETCONF protocol on the device using the netconf-yang command.
Why it's wrong here
NETCONF is a separate protocol from RESTCONF. Enabling NETCONF would not resolve a RESTCONF authentication error. The device already responded to the RESTCONF request with a 401, indicating that RESTCONF is operational but requires valid credentials. This action is irrelevant to the problem.
- ✗
Change the request method from GET to POST to retrieve interface statistics.
Why it's wrong here
RESTCONF uses GET to retrieve data. Changing to POST would be incorrect because POST is used to create or invoke operations, not to read data. The 401 error is unrelated to the HTTP method; it is an authentication issue. This change would not fix the problem and could cause further errors.
- ✗
Add the header 'Content-Type: application/yang-data+json' to the request.
Why it's wrong here
While Content-Type is important for requests with a body, a GET request typically does not require it. The 401 error indicates an authentication failure, not a content negotiation issue. Adding this header would not provide credentials and thus would not resolve the unauthorized error.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.