Courseiva
mediumMultiple Select

CCNP Practice Question: Which two statements about Ansible modules and…

Which two statements about Ansible modules and idempotency are true? (Choose two.)

⚠ Common exam trap

The trap here is assuming that all Ansible modules are idempotent by default; the command and shell modules are the classic counterexamples that exam writers use to test whether candidates understand idempotency is implementation-specific.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Idempotency means that running a playbook multiple times will always result in the same final state on the managed node.

Option A is correct because idempotency in Ansible means that executing the same playbook repeatedly converges the managed node to the same desired final state without making unnecessary changes on subsequent runs. Option C is correct because the copy module compares the checksum (SHA-1 by default) of the source content against the destination file and only transfers the file when they differ, so repeated runs report 'ok' instead of 'changed'. Option B is wrong because the command module is not idempotent by default—it executes the given command every time unless you add guards such as creates, removes, or changed_when. Option D is wrong because idempotency is a property of how each module is implemented, not an automatic guarantee for all modules. Option E is wrong because idempotency applies broadly across module types, including Linux system modules like yum, apt, service, and file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Idempotency means that running a playbook multiple times will always result in the same final state on the managed node.

    Why this is correct

    Idempotency means a module checks the managed node's current state and only applies changes needed to reach the declared state, so repeated playbook runs converge on the same result without duplicating actions. This matches the statement that multiple runs produce an identical final state.

  • ✗

    The 'command' module is idempotent by default because it always runs the given command.

    Why it's wrong here

    The command module runs the given command every time, so it is not idempotent by default; it reports changed on each execution unless creates or removes is supplied. It is tempting because command execution appears deterministic, but Ansible cannot infer desired state from an arbitrary command string.

  • ✓

    The 'copy' module is idempotent because it checks the checksum of the destination file before copying.

    Why this is correct

    The copy module compares the source and destination checksums; when they match, no write occurs and the task reports no change, which is precisely what idempotency requires — repeated runs converge on the same state without side effects.

  • ✗

    All Ansible modules are inherently idempotent regardless of how they are implemented.

    Why it's wrong here

    Idempotency depends on how each module is written, not on Ansible itself; many modules such as command and shell re-run unconditionally. It is tempting because Ansible's design goal encourages idempotent modules, so people assume the property is automatic, but only modules deliberately coded to check current state achieve it.

  • ✗

    Idempotency only applies to network modules, not to Linux system modules.

    Why it's wrong here

    Idempotency is a property of individual module implementation, applying equally to Linux system modules like apt, yum and service, which are typically idempotent. It is tempting because network modules often need explicit state handling, suggesting the concept is network-specific, but the mechanism is module code, not platform.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.