mediumMultiple Choice
CCNP Practice Question: Given the following Ansible playbook snippet: ---…
Given the following Ansible playbook snippet: --- - name: Configure SNMP hosts: routers gather_facts: no tasks: - name: SNMP community ios_config: lines: - snmp-server community public RO What is the result of this playbook?
⚠ Common exam trap
350-401 often tests whether candidates know that 'RO' is a valid IOS abbreviation and that ios_config is idempotent and does not save to startup-config by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It configures an SNMP community string 'public' with read-only access.
The ios_config module pushes the line 'snmp-server community public RO' into the device's running configuration. On Cisco IOS, 'RO' is the valid abbreviation for read-only when defining an SNMP community string, so the playbook successfully creates a read-only community named 'public'. The playbook does not gather facts and does not specify a 'save_when' parameter, so it modifies the running config only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It configures an SNMP community string 'public' with read-only access.
Why this is correct
The ios_config module pushes the listed configuration lines verbatim to the device, so 'snmp-server community public RO' creates community string 'public' with read-only access. Because gather_facts is disabled, no fact collection interferes; the task simply applies the SNMP community as specified.
- ✗
It fails because 'RO' is not a valid keyword; it should be 'read-only'.
Why it's wrong here
RO is the valid IOS keyword for a read-only community string; read-only is not accepted syntax, so the task succeeds rather than failing. It is tempting because read-only describes the permission accurately in plain English, but IOS expects the abbreviated RO form on the command line.
- ✗
It configures the community string only for SNMPv3.
Why it's wrong here
The snmp-server community command configures SNMPv1/v2c community strings; SNMPv3 uses users and groups with authentication and privacy, not community strings. It is tempting because SNMPv3 is the secure alternative to community-based access, but the syntax shown belongs to the v1/v2c model.
- ✗
It removes any existing SNMP community strings.
Why it's wrong here
ios_config with only lines adds or updates the specified command; it does not negate other snmp-server community entries, so existing strings remain. It is tempting because ios_config can remove lines when a parent or match parameter is used, but that behaviour is not triggered by this snippet.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.