CCNP Automation Practice Question
A network team is using Ansible to manage a fleet of Cisco IOS XE switches. The team wants to ensure that the Ansible playbook can connect to the switches without prompting for passwords and without storing passwords in plaintext. The team has generated an SSH key pair and copied the public key to the switches. Which Ansible connection method and authentication mechanism should the team use?
⚠ Common exam trap
The trap here is choosing the generic ssh connection plugin for network devices, which is incorrect because network devices require the network_cli plugin for proper CLI interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the network_cli connection with SSH key-based authentication.
For Cisco IOS XE switches, Ansible uses the network_cli connection plugin to establish SSH sessions and send CLI commands. SSH key-based authentication allows passwordless login by using the private key on the control node, with the public key installed on the switches. This avoids plaintext passwords and interactive prompts. Other connection plugins like ssh or local are not suitable for network device CLI management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the local connection with SSH key-based authentication.
Why it's wrong here
The local connection plugin runs tasks on the Ansible control node itself, not on remote devices. It cannot connect to network switches. SSH key-based authentication is irrelevant because the connection is local. This would not manage the switches at all. The local connection is used for running commands on the controller.
- ✓
Use the network_cli connection with SSH key-based authentication.
Why this is correct
The network_cli connection plugin is designed for network devices and supports SSH key-based authentication. By copying the public key to the switches, Ansible can authenticate using the private key without passwords. This meets the requirement of no password prompts and no plaintext passwords. The network_cli plugin handles the SSH session and CLI interaction.
- ✗
Use the ssh connection with password authentication stored in an Ansible vault.
Why it's wrong here
The ssh connection plugin is for Linux hosts, not network devices. While storing passwords in an Ansible vault is secure, it still requires a password for authentication. The scenario specifies using SSH keys, so password authentication is not the desired method. The ssh plugin would not correctly interact with the network device CLI.
- ✗
Use the netconf connection with SSH key-based authentication.
Why it's wrong here
The netconf connection plugin is used for NETCONF-enabled devices, which requires the NETCONF subsystem to be enabled. While it supports SSH keys, it is not the standard method for CLI-based configuration on Cisco IOS XE switches. The scenario implies CLI-based management, so network_cli is more appropriate. NETCONF may not be enabled on all switches.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.