mediumMultiple Choice
CCNP Practice Question: Writes the following Ansible playbook to…
A network engineer writes the following Ansible playbook to configure an interface on a Cisco IOS-XE device:
--- - hosts: routers gather_facts: no tasks: - name: Configure interface cisco.ios.ios_config: lines: - ip address 192.168.1.1 255.255.255.0 parents: interface GigabitEthernet0/1
What is the issue with this playbook?
⚠ Common exam trap
Cisco often tests the requirement for 'connection: network_cli' with network modules, and the trap here is that candidates assume the module will work with the default connection plugin or that the module name is invalid, when in fact the module is correct but the connection method is missing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook will fail because the 'cisco.ios.ios_config' module requires the 'connection: network_cli' parameter in the play or inventory.
The 'cisco.ios.ios_config' module requires the connection type to be set to 'network_cli' (or 'ansible.netcommon.network_cli') in the play or inventory, because it uses a persistent SSH connection to send CLI commands to the device. Without this setting, Ansible defaults to the 'smart' connection plugin, which does not support the network-specific module's requirements, causing the playbook to fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The playbook will fail because the 'cisco.ios.ios_config' module requires the 'connection: network_cli' parameter in the play or inventory.
Why this is correct
ios_config is a network module in the cisco.ios collection, and Ansible must establish a persistent network_cli connection before it can send configuration commands. Without `ansible_connection: network_cli` in inventory or `connection: network_cli` at the play level, Ansible uses the default 'smart' connection, which cannot initialize the IOS CLI terminal plugin. The playbook therefore fails with a connection error rather than reaching the module logic.
- ✗
The playbook will work correctly because the module automatically detects the device type.
Why it's wrong here
The ios_config module does not probe the target or auto-detect that it is a Cisco device; it executes only after Ansible selects the correct connection and terminal plugins. Auto-detection would still require an initial connection type, and without network_cli Ansible cannot even negotiate a device prompt. Even if the inventory group is named 'cisco', group names have no effect on connection selection, so the play fails before any type detection can occur.
- ✗
The playbook will fail because 'cisco.ios.ios_config' is not a valid module name.
Why it's wrong here
cisco.ios.ios_config is a valid fully qualified collection module name, so a name-resolution failure is not the problem. The module is installed as part of the cisco.ios collection and appears in its documentation; an invalid name would yield an 'undefined module' error before execution. The actual failure happens during connection setup, because the play has not provided the network_cli connection required by all modules in that collection.
- ✗
The playbook will work but only if the device is running IOS-XE 16.9 or later.
Why it's wrong here
Whether the device runs IOS-XE 16.9, an older IOS 15.x, or an IOS-XE 17.x version does not change how the module connects. The missing `ansible_connection: network_cli` setting is independent of software version, so the playbook will fail on any version until the connection parameter is fixed. Even if the version is correct, Ansible still cannot use its standard SSH connection to handle IOS CLI prompts, so version alone never satisfies the connection requirement.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.