CCNP Automation Practice Question
A network engineer uses Netmiko to connect to multiple Cisco IOS XE devices and execute commands. The script runs correctly for most devices but fails for one device with the error: 'ValueError: SSH session not active'. The device is reachable and SSH credentials are correct. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates confuse network reachability or credential validity with SSH session state, assuming that if the device is pingable and credentials are correct, the SSH session must work, but Cisco tests the understanding that SSH session initialization is a separate process that can fail even when the device is reachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The device's SSH server is not fully initialized
The error 'ValueError: SSH session not active' indicates that Netmiko attempted to establish an SSH connection but the session was not fully active. The most likely cause is that the device's SSH server is not fully initialized, which can happen if the device is still booting or the SSH process has not completed startup. This is distinct from reachability or credential issues, as the device responds to pings but the SSH daemon is not ready to accept connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The connection timeout is set too low
Why it's wrong here
The 'SSH session not active' exception is distinct from a timeout. If connect_timeout were set too low, Netmiko would raise NetmikoTimeoutException with a socket time-out message, not an internal Paramiko state error. Timeout errors occur before or during the TCP/SSH handshake, while this specific exception indicates the Paramiko transport object exists but its SSH session has become inactive.
- ✗
The device has reached the maximum number of SSH sessions
Why it's wrong here
Hitting the maximum SSH sessions on a Cisco device causes the server to reject the transport-layer negotiation with a 'connection refused' or 'no more session' error, not an 'SSH session not active' error. Netmiko would surface this as a connection error or as an authentication failure during the handshake. The error implies the client-side transport has been closed, not that the server refused to establish a new session.
- ✓
The device's SSH server is not fully initialized
Why this is correct
This error from Netmiko/Paramiko means the SSHTransport object is not in an active state when invoke_shell() is called. On Cisco devices, this commonly occurs when the device is still booting and the SSH server has not fully initialized—for example, RSA keys are still being generated—so the server accepts TCP but aborts the SSH protocol handshake, leaving the client transport inactive.
- ✗
The device requires an enable password but none was provided
Why it's wrong here
An enable password governs the transition from user EXEC to privileged EXEC mode after SSH has already been authenticated. Netmiko's `secret` parameter is used only after the SSH session is up, so a missing enable password would cause a failure in entering enable mode, not an inactive SSH session. The SSH transport itself remains active and the error would be a separate failure message.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.