Courseiva

CCNA Automation Questions

75 of 122 questions · Page 1/2 · Automation · Answers revealed

1
MCQmedium

A network engineer is using a Python script to retrieve the operational status of all interfaces on a Cisco IOS XE device via RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state but receives an HTTP 401 Unauthorized response. The engineer can successfully ping the device and has verified that the RESTCONF feature is enabled with 'restconf' in global configuration. Which action will resolve the issue?

A.Configure a local username with privilege level 15 and ensure the script includes valid Basic Authentication credentials.
B.Configure an ACL to permit TCP port 830 on the device to allow RESTCONF traffic.
C.Enable the 'ip http secure-server' command to allow HTTPS access to the RESTCONF API.
D.Add the 'restconf' command under the interface configuration mode for the management interface.
AnswerA

RESTCONF on Cisco IOS XE requires HTTP authentication. A 401 Unauthorized indicates missing or invalid credentials. Creating a local user with sufficient privilege and including the credentials in the Authorization header (Basic Auth) allows the request to be authenticated. This is the standard method for RESTCONF access when no AAA server is configured.

Why this answer

The 401 Unauthorized response indicates that the HTTP request lacks valid authentication credentials. RESTCONF on Cisco IOS XE uses HTTP Basic Authentication by default when no AAA is configured. The engineer must create a local user with appropriate privileges and include the credentials in the request.

Enabling HTTPS or adjusting ACLs does not address authentication.

Exam trap

The trap here is assuming that a 401 error is caused by a transport or feature configuration issue rather than missing or incorrect authentication credentials.

2
MCQeasy

A network engineer is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS XE switches. The engineer prefers to write the automation tasks in YAML and does not want to install any software on the switches. Which tool should be used?

A.Puppet
B.Ansible
C.SaltStack
D.Chef
AnswerB

Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to network devices via SSH or other protocols without requiring any software installation on the managed devices. This matches the engineer's requirements: simple, agentless, and YAML-based configuration management for Cisco IOS XE switches.

Why this answer

Ansible is an agentless automation tool that uses YAML playbooks, making it ideal for simple configuration pushes to network devices without installing agents. Puppet and Chef typically require agents and use different DSLs, while SaltStack, although YAML-based, often involves a more complex architecture. Ansible's simplicity and native support for Cisco IOS XE modules align with the scenario.

Exam trap

The trap here is assuming that all configuration management tools are agentless or use YAML; in reality, Puppet and Chef require agents and use their own DSLs, while Ansible is known for being agentless and YAML-based.

3
MCQeasy

A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS devices. The administrator prefers a tool that uses YAML for playbooks and does not require installing software on the managed devices. Which tool should the administrator use?

A.Puppet
B.Ansible
C.Chef
D.SaltStack
AnswerB

Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to managed devices over SSH or NETCONF, so no agent software needs to be installed on the Cisco IOS devices. This makes it ideal for simple, push-based configuration management. Ansible modules like 'ios_config' allow network engineers to automate configuration changes across multiple devices efficiently.

Why this answer

Ansible is the correct choice because it is agentless, uses YAML for playbooks, and connects to Cisco IOS devices over SSH without requiring any software installation on the devices. It has a rich set of network modules, such as 'ios_config', that simplify configuration management. Other tools like Puppet and Chef use different languages and often require agents, making them less suitable for this scenario.

Exam trap

The trap here is confusing Ansible with other configuration management tools that also support agentless operation but use different languages or require more setup; Ansible uniquely uses YAML playbooks and is agentless.

4
MCQmedium

A network engineer is writing a Python script using the ncclient library to retrieve the running configuration from a Cisco IOS XE device. The script connects using NETCONF over SSH on port 830. The engineer wants to filter the response to only include interface configuration data. Which NETCONF operation should be used to retrieve the configuration with a filter?

A.<get> with a <filter> element.
B.<copy-config> with a <source> of <running>.
C.<edit-config> with a <target> of <running>.
D.<get-config> with a <source> of <running> and a <filter> element.
AnswerD

<get-config> is the NETCONF operation used to retrieve configuration data. It requires a <source> element specifying the configuration datastore (e.g., <running>) and can include a <filter> to limit the data returned. This is the correct way to retrieve a subset of the running configuration, such as interface configuration.

Why this answer

The <get-config> operation is specifically designed to retrieve configuration data from a datastore. It supports a <filter> element to select specific portions of the configuration, such as interfaces. This allows the engineer to retrieve only the desired data, reducing payload size and processing time.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both configuration and state data, while <get-config> retrieves only configuration.

5
MCQeasy

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices. The engineer sends a GET request to /dataservice/device but receives a 403 Forbidden error. The engineer has already authenticated successfully and obtained a valid session cookie. What is the most likely reason for this error?

A.The session cookie has expired and needs to be renewed.
B.The request must include an X-XSRF-TOKEN header to prevent CSRF attacks.
C.The user account does not have the necessary permissions to access the device inventory.
D.The API endpoint /dataservice/device requires a POST request instead of GET.
AnswerC

A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. Even with a valid session, the user's role must include permission to access the /dataservice/device endpoint. The engineer should check the user's role and group permissions in vManage to ensure they have read access to device inventory.

Why this answer

A 403 Forbidden error indicates that the authenticated user does not have the required permissions to access the requested resource. In vManage, user roles and group permissions control access to API endpoints. The engineer must ensure the account has read access to device inventory.

Exam trap

The trap here is confusing 403 Forbidden with 401 Unauthorized; the former means authenticated but not authorized, so re-authenticating will not help.

6
MCQeasy

A network administrator is new to automation and wants to start using Ansible to manage a group of Cisco IOS XE switches. The administrator has installed Ansible on a Linux control node and created an inventory file listing the switches. The administrator now needs to create a playbook that will gather facts from the switches and display them. Which Ansible module should the administrator use in the playbook to collect operational facts from the Cisco IOS XE devices?

A.ios_facts
B.ios_config
C.ios_command
D.setup
AnswerA

The ios_facts module is specifically designed to collect facts from Cisco IOS devices, including IOS XE. It gathers information such as hostname, version, interfaces, and hardware details. Using this module, the administrator can retrieve operational data and display it using the debug or other output mechanisms. It is the correct choice for fact gathering on Cisco IOS XE platforms.

Why this answer

Ansible provides platform-specific modules for network devices. For Cisco IOS XE, the ios_facts module is designed to collect a wide range of operational facts, such as version, interfaces, and hardware. It returns structured data that can be used in playbooks.

This module is the standard way to gather facts from IOS XE devices without manual parsing.

Exam trap

The trap here is assuming that the generic setup module works for network devices, but it only works for Linux/Unix hosts; network devices require vendor-specific fact modules.

7
MCQmedium

A network engineer is using Python with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script connects successfully but receives an RPC error when trying to apply a candidate configuration. The engineer inspects the device capabilities and sees 'urn:ietf:params:netconf:capability:candidate:1.0' is NOT listed. What is the most likely reason for the failure?

A.The device does not support the NETCONF candidate datastore, so candidate configuration operations cannot be used.
B.The device requires a YANG model to be loaded before candidate configuration can be used.
C.The NETCONF session must use SSH version 2, but the device is using SSH version 1.
D.The ncclient library version is incompatible with the IOS XE NETCONF implementation.
AnswerA

The absence of the 'candidate' capability in the NETCONF capabilities list means the device does not support the candidate datastore. NETCONF operations like edit-config with candidate target or commit will fail. The engineer must use the running datastore directly or enable candidate support if available.

Why this answer

The NETCONF capabilities exchange advertises supported features. The candidate datastore capability indicates whether the device supports a candidate configuration that can be edited and committed. Without it, operations targeting the candidate datastore will fail.

The engineer should verify capabilities before attempting candidate-based workflows and use the running datastore instead.

Exam trap

The trap here is assuming that a successful NETCONF connection implies full feature support, when in fact capabilities must be checked to confirm datastore and operation support.

8
MCQeasy

A network administrator is using Cisco SD-WAN to manage a large enterprise network. They want to automate the deployment of a new branch site using a template. Which component of Cisco SD-WAN is responsible for pushing the configuration to the WAN edge devices?

A.vSmart
B.vManage
C.vAnalytics
D.vBond
AnswerB

vManage is the centralized management plane in Cisco SD-WAN. It hosts the templates and orchestrates configuration pushes to WAN edge devices via the vBond and vSmart controllers. When a template is attached to a device, vManage generates the configuration and sends it to the device. This makes vManage the correct component for automating branch deployment.

Why this answer

In Cisco SD-WAN, vManage is the management plane component that centralizes configuration and policy. It stores templates and orchestrates their deployment to WAN edge devices. The other components have different roles: vBond handles orchestration and NAT traversal, vSmart manages control plane policies, and vAnalytics provides reporting.

Only vManage is responsible for pushing configurations.

Exam trap

The trap here is confusing the roles of the SD-WAN controllers, particularly assuming that vSmart or vBond might handle configuration pushes because they are involved in device onboarding.

9
MCQeasy

A company uses Cisco Catalyst Center (formerly DNA Center) for intent-based networking. After upgrading the Catalyst Center appliance, the engineer notices that some devices are unreachable via the network, but the Catalyst Center GUI shows them as 'Managed'. What is the most likely cause?

A.SNMP community strings are misconfigured
B.Devices were reassigned to different roles
C.Certificate trust between devices and Catalyst Center expired
D.The IP address of the Catalyst Center appliance changed after the upgrade
AnswerD

If the Catalyst Center appliance's IP address is changed after an upgrade, the management network's routing and ARP entries are disrupted. Devices that are configured to send telemetry or accept management commands to/from the old IP address will no longer be reachable, because their ARP caches, DHCP reservations, or static routes still reference the previous address. Additionally, any access control lists on the devices that permit management traffic from the appliance's old IP will silently drop the new source address. This directly explains why all devices become unreachable after the upgrade, even though the appliance itself is up.

Why this answer

When the Catalyst Center appliance is upgraded, its IP address may change if the upgrade process resets network configuration or if the appliance is redeployed with a new IP. Devices are managed via IP-based communication (e.g., SSH, SNMP, NETCONF), and if the Catalyst Center IP changes, devices will still show as 'Managed' in the GUI because the database retains the device state, but the devices themselves cannot be reached because they are trying to communicate with the old IP address. This mismatch causes unreachability despite the managed status.

Exam trap

Cisco often tests the distinction between GUI state (which can be stale) and actual network reachability, leading candidates to focus on protocol misconfigurations (like SNMP or certificates) rather than the underlying IP connectivity change.

How to eliminate wrong answers

Option A is wrong because SNMP community string misconfigurations would cause polling failures and likely show devices as 'Unmanaged' or with errors, not as 'Managed' while being unreachable. Option B is wrong because reassigning devices to different roles is a configuration change that would not inherently cause unreachability; it would affect policy application, not basic connectivity. Option C is wrong because certificate trust expiration would affect secure communication (e.g., for NETCONF or RESTCONF), but Catalyst Center uses IP-based management and would typically show a certificate error or authentication failure, not a simple unreachability while still showing 'Managed'.

10
MCQeasy

A network automation team is evaluating configuration management tools. They need a tool that uses a declarative, agentless architecture and communicates over SSH to push configuration to Cisco IOS XE devices. Which tool best fits these requirements?

A.Puppet with the Cisco IOS module
B.Ansible with the ios_config module
C.SaltStack with the napalm proxy minion
D.Chef Infra with the Cisco IOS cookbook
AnswerB

Ansible is agentless, uses SSH as its transport, and employs declarative playbooks. The ios_config module specifically manages configuration on Cisco IOS devices. It requires no software installed on the managed device, aligning perfectly with the requirement. This combination is widely used for network automation and directly satisfies the scenario's constraints.

Why this answer

Ansible is designed as an agentless automation tool that connects over SSH and uses declarative YAML playbooks. The ios_config module is purpose-built for Cisco IOS configuration management. This combination meets all stated requirements: declarative, agentless, and SSH-based.

Other tools either require agents or add architectural complexity that makes them less suitable for this scenario.

Exam trap

The trap here is conflating agentless operation with tools that can optionally run without agents but typically rely on agent-based architecture.

11
MCQmedium

A network engineer is using the Python 'requests' library to interact with a Cisco DNA Center controller. The engineer wants to retrieve a list of all network devices. Which HTTP method and URL should be used?

A.POST https://<dnac-ip>/dna/intent/api/v1/network-device
B.GET https://<dnac-ip>/api/v1/network-device
C.PUT https://<dnac-ip>/dna/intent/api/v1/network-device
D.GET https://<dnac-ip>/dna/intent/api/v1/network-device
AnswerD

Cisco DNA Center's Intent API uses the base path '/dna/intent/api/v1/'. The endpoint '/network-device' returns a list of all network devices. A GET request is used to retrieve data. This is the correct method and URL for fetching device inventory. Authentication is required via a token, but the method and path are correct.

Why this answer

Cisco DNA Center's Intent API provides RESTful endpoints for managing network devices. To retrieve a list of devices, a GET request to '/dna/intent/api/v1/network-device' is used. This returns JSON data with device details.

Other HTTP methods like POST, PUT, or DELETE are for creating, updating, or deleting resources. The correct base path is essential; omitting '/dna/intent' leads to failure.

Exam trap

The trap here is using an incorrect base path or HTTP method, such as omitting '/dna/intent' or using POST to retrieve data.

12
Multi-Selecthard

A network automation engineer is using NETCONF to configure a Cisco IOS XE device. The engineer wants to ensure that the configuration changes are applied atomically and that the device can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities should the engineer verify are supported by the device? (Choose two.)

Select 2 answers
A.:writable-running
B.:validate
C.:startup
D.:rollback-on-error
E.:candidate
AnswersD, E

:rollback-on-error is a NETCONF capability that ensures if any part of a configuration transaction fails, the entire transaction is rolled back to the previous state. This directly supports the requirement for atomicity and automatic rollback. It works in conjunction with the candidate datastore. Therefore, verifying this capability is necessary to guarantee that errors do not leave the device in a partially configured state.

Why this answer

To achieve atomic configuration changes and rollback on error with NETCONF, the device must support the :candidate and :rollback-on-error capabilities. The :candidate capability provides a staging area for changes, allowing them to be applied as a single transaction. The :rollback-on-error capability ensures that if any part of the transaction fails, the entire change set is discarded, reverting to the previous configuration.

Together, they enable reliable and safe configuration management.

Exam trap

The trap here is confusing validation or writable-running with atomicity and rollback, which are specifically provided by :candidate and :rollback-on-error.

13
MCQhard

A healthcare provider runs a Python script that issues a RESTCONF PATCH to a Cisco IOS XE switch to modify an interface description. The device returns HTTP 400 with an error-tag of 'invalid-value'. The JSON body is syntactically valid and the URI targets the correct interface. Which action most directly resolves this error?

A.Increase the RESTCONF request timeout on the client because the switch is slow to apply configuration changes.
B.Correct the payload so the description node matches the YANG model's expected type and namespace, then resend the PATCH.
C.Change the HTTP method from PATCH to GET and re-read the interface container before writing.
D.Add a Content-Type header of application/yang-data+xml while keeping the existing JSON body unchanged.
AnswerB

An 'invalid-value' error-tag means the server rejected a data value in the payload, usually because it violates the YANG leaf's type, length, or pattern constraints, or because the leaf is placed under the wrong namespace. Aligning the JSON structure and value with the model definition resolves the rejection. The URI and HTTP method are already correct in the scenario, so the payload content is the remaining cause.

Why this answer

RESTCONF error-tags are diagnostic: 'invalid-value' points to a data value that violates the YANG model's constraints, such as a wrong type, an out-of-range number, or a leaf placed under the wrong namespace. Since the URI and method are correct and the JSON is syntactically valid, the remaining cause is the payload content. Correcting the value and its model placement makes the PATCH succeed.

Exam trap

The trap here is treating any HTTP 400 as a URL problem, when the error-tag 'invalid-value' specifically implicates the payload content.

14
MCQmedium

A network engineer is building a Python script that must retrieve the operational state of all interfaces from a Cisco IOS XE device using RESTCONF. The engineer sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state and receives an HTTP 401 Unauthorized response. The device is reachable, RESTCONF is enabled, and the correct credentials are being used in the request. What is the most likely cause of the 401 response?

A.The device's RESTCONF service is configured to use NETCONF over SSH instead of HTTPS, so the request must be sent to port 830.
B.The RESTCONF API requires the Accept header to be set to application/yang-data+json.
C.The HTTP Basic Authentication credentials are not being sent because the Authorization header is missing or malformed.
D.The URL path should be /restconf/data/ietf-interfaces:interfaces instead of interfaces-state.
AnswerC

A 401 Unauthorized response indicates the server did not receive valid authentication credentials. RESTCONF over HTTPS typically uses HTTP Basic Authentication, which requires a properly formatted Authorization header containing base64-encoded username and password. If the script omits this header or encodes it incorrectly, the device rejects the request with 401 even though the credentials themselves are valid.

Why this answer

An HTTP 401 Unauthorized response is returned when authentication credentials are missing or invalid. With RESTCONF on Cisco IOS XE, authentication is performed using HTTP Basic Authentication, so the request must include a correctly formed Authorization header. Since the credentials are known to be correct, the failure must stem from the header not being transmitted or being malformed, which is a common scripting oversight.

Exam trap

The trap here is assuming a 401 error is caused by wrong credentials rather than by the Authorization header being absent or incorrectly formatted in the HTTP request.

15
MCQmedium

A network engineer is automating the deployment of VLANs across multiple switches using Ansible. The playbook runs successfully on most switches, but one switch fails with an error indicating that the VLAN configuration command is not recognized. What is the most likely cause?

A.Ansible lacks the appropriate module for VLAN configuration
B.The inventory file has a syntax error for that specific host
C.The switch runs a different IOS version with different VLAN CLI syntax
D.SSH connectivity to the switch is blocked by an ACL
AnswerC

VLAN configuration syntax is not identical across all Cisco IOS versions: older IOS releases traditionally used 'vlan database' mode, while modern IOS-XE and many IOS 15.x train support interface configuration mode with 'vlan <vlan-id>'. If the playbook uses commands like 'vlan <id>' inside interface config or relies on VTP-related syntax that the specific IOS version does not recognize, the switch will return a '% Invalid input' error at the CLI. This failure would occur only on switches running that divergent IOS version, while other switches with compatible syntax execute successfully.

Why this answer

The most likely cause is that the switch runs a different IOS version with different VLAN CLI syntax. Ansible executes commands via SSH, and if the switch expects a different command format (e.g., 'vlan 10' vs. 'vlan database' on older CatOS), the playbook will fail with a command-not-recognized error. This is a common issue when automating across heterogeneous network devices.

Exam trap

The trap here is that candidates may assume a module or connectivity issue, but Cisco tests the understanding that different IOS versions or platforms (e.g., IOS vs. CatOS) have distinct VLAN CLI syntax, which Ansible modules must handle via conditional logic or version-specific variables.

How to eliminate wrong answers

Option A is wrong because Ansible has dedicated modules like 'ios_vlan' for VLAN configuration on Cisco IOS devices, so lacking a module is not the issue. Option B is wrong because an inventory file syntax error would typically cause a connection failure or host-not-found error, not a command-not-recognized error during execution. Option D is wrong because if SSH connectivity were blocked by an ACL, the playbook would fail at the connection stage with a timeout or authentication error, not after successfully sending a command.

16
MCQhard

A network engineer is using Ansible to manage a fleet of Cisco IOS XE devices. The engineer wants to ensure that the playbook is idempotent and only makes changes when necessary. The playbook uses the ios_config module with a set of lines to configure an interface. After running the playbook, the engineer notices that the task always reports 'changed' even when the configuration is already present. What is the most likely reason for this behavior?

A.One of the configuration lines contains a value that the device automatically modifies, such as a timestamp or a sequence number, causing a mismatch.
B.The Ansible control node is using an outdated version of the ios_config module that has a known bug with idempotency.
C.The playbook is using the 'lines' parameter without the 'parents' parameter, causing the module to miscompare the configuration.
D.The ios_config module does not support idempotency; it always applies the configuration and reports changed.
AnswerA

If a configuration line includes a value that the device changes automatically (e.g., 'description Configured on 2025-01-01' or an ACL sequence number), the module will see a difference each time and reapply the line. This results in a 'changed' status even when the intent is already met. The engineer should avoid such dynamic values or use templates that account for them.

Why this answer

The ios_config module achieves idempotency by comparing the desired lines with the running configuration. If a line contains a value that the device automatically alters, such as a timestamp or a sequence number, the comparison will always show a difference, causing the task to report 'changed' and reapply the line. The engineer should remove or template such dynamic values to restore idempotency.

Exam trap

The trap here is blaming the module for lacking idempotency when the real issue is a configuration line that the device dynamically modifies.

17
MCQhard

A network automation team is using YANG models with NETCONF to configure a Cisco IOS XE device. They want to change the description of a loopback interface. The engineer writes an <edit-config> RPC with the 'operation' attribute set to 'merge' on the <description> leaf. The RPC is accepted, but the description is not changed. The engineer verifies that the YANG path is correct and that the interface exists. What is the most likely reason the description was not updated?

A.The <edit-config> RPC was sent to the 'candidate' datastore, but a <commit> operation was not performed.
B.The description leaf is read-only in the YANG model and cannot be modified via NETCONF.
C.The 'merge' operation requires the parent container to be specified with a namespace, which was omitted.
D.The 'operation' attribute must be set to 'replace' instead of 'merge' to change a leaf value.
AnswerA

If the device is configured to use the candidate datastore, changes made via <edit-config> are not active until a <commit> RPC is issued. The RPC would be accepted without error, but the running configuration remains unchanged. This is a common oversight when using NETCONF with candidate datastores. Issuing a <commit> applies the changes.

Why this answer

When using NETCONF with a candidate datastore, <edit-config> modifies the candidate configuration but does not affect the running configuration until a <commit> RPC is executed. The RPC being accepted without error indicates the edit was valid but not applied. The engineer must send a <commit> to activate the change.

Other options like namespace or operation type would typically produce errors, not silent acceptance.

Exam trap

The trap here is assuming that a successful <edit-config> RPC immediately changes the running configuration, forgetting that candidate datastores require an explicit commit.

18
MCQmedium

A network automation team is using Cisco DNA Center's Intent API to retrieve a list of all network devices. The team writes a Python script that sends a GET request to the /dna/intent/api/v1/network-device endpoint. The script includes a valid authentication token in the headers, but the response returns a 403 Forbidden error. The token was obtained successfully using the /dna/system/api/v1/auth/token endpoint. What is the most likely reason for the 403 error?

A.The API endpoint requires a different HTTP method, such as POST.
B.The API request is missing the required 'X-Auth-Token' header.
C.The authentication token has expired and must be refreshed.
D.The user account associated with the token does not have the necessary RBAC permissions to access the network device API.
AnswerD

Cisco DNA Center enforces role-based access control (RBAC). Even with a valid token, if the user account lacks the required permissions for the Intent API, the request will be denied with 403 Forbidden. The team must ensure the user has a role that includes access to the network device inventory, such as SUPER-ADMIN-ROLE or a custom role with appropriate privileges.

Why this answer

In Cisco DNA Center, authentication tokens are obtained via the /dna/system/api/v1/auth/token endpoint. However, possessing a valid token does not guarantee access to all APIs. Each API endpoint requires specific RBAC permissions.

A 403 Forbidden error indicates that the authenticated user does not have the required role or permission to access the network-device API. The team should verify the user's role and adjust RBAC settings accordingly.

Exam trap

The trap here is assuming that a valid authentication token automatically grants access to all API endpoints, overlooking the role-based access control (RBAC) requirements.

19
MCQeasy

A network engineer is writing a Python script to interact with a Cisco IOS XE device using RESTCONF. The engineer wants to retrieve the current configuration of a specific interface. Which HTTP method and URI should be used?

A.PUT https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
B.POST https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
C.GET https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
D.GET https://<device>/restconf/data/ietf-interfaces:interfaces/interface/GigabitEthernet1
AnswerC

RESTCONF uses the GET method to retrieve data. The URI path /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 correctly targets a specific interface using the YANG model ietf-interfaces. This is the standard way to read configuration data via RESTCONF. The other methods and URIs are either incorrect HTTP verbs or malformed paths.

Why this answer

To retrieve configuration data via RESTCONF, the GET method must be used with a URI that correctly identifies the resource. The URI must follow the RESTCONF syntax for list keys, which uses key=value. The correct option uses GET and the proper URI format to access the specific interface.

The other options use incorrect HTTP methods or malformed URIs, which would not retrieve the desired data.

Exam trap

The trap here is mixing up HTTP methods or using the wrong syntax for list keys; RESTCONF requires key=value, not key/value.

20
Matchingmedium

Match each network automation tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Agentless automation using YAML playbooks

Agent-based configuration management using Puppet DSL

Agent-based using Ruby recipes

Agent-based with remote execution

Standard for network configuration and state data

Why these pairings

Correct matches: Ansible is agentless and uses SSH/YAML; Puppet uses client-server with DSL; Chef uses server and Ruby DSL; SaltStack uses master-minion and can be agentless. Common confusions involve mixing agentless and agent-based models.

21
MCQmedium

A network automation engineer is developing a Python script that will retrieve interface statistics from a Cisco IOS XE device using NETCONF. The engineer needs to discover which YANG models are supported by the device before constructing the RPC. Which NETCONF capability exchange message should the script send first to obtain this information?

A.Send a RESTCONF GET request to the /restconf/data/ietf-yang-library:modules-state endpoint.
B.Establish an SSH session and read the <hello> message sent by the device immediately after the NETCONF subsystem is started.
C.Issue a NETCONF <get-config> RPC with a filter specifying the urn:ietf:params:xml:ns:yang:ietf-interfaces namespace.
D.Send an <rpc> message with a <get> operation targeting the ietf-netconf-monitoring model.
AnswerB

When a NETCONF session is established over SSH, both the client and server exchange <hello> messages. The server's <hello> contains a <capabilities> element listing all supported YANG models and protocol features. This is the standard mechanism for capability discovery, and the client must parse this message to learn which models are available.

Why this answer

The NETCONF protocol requires a capability exchange during session establishment. The server sends a <hello> message containing a <capabilities> element that lists all supported YANG models and protocol features. The client must parse this message to discover available models before sending any RPCs.

This is fundamental to NETCONF operation and is defined in RFC 6241.

Exam trap

The trap here is assuming that capability discovery requires an explicit RPC or RESTCONF query, when it is actually part of the initial NETCONF session handshake.

22
Multi-Selecteasy

Which THREE benefits does network automation provide over manual configuration?

Select 3 answers
A.Increased security by eliminating the need for SSH access
B.Lower initial investment compared to manual processes
C.Reduced risk of configuration errors
D.Consistent configuration across all devices
E.Faster deployment of configuration changes
AnswersC, D, E

Automation eliminates manual mistakes.

Why this answer

Network automation eliminates human error during repetitive configuration tasks. By using tools like Ansible, Python scripts, or NETCONF/YANG models, configurations are applied consistently without typos or missed commands, which are common in manual CLI entry. This directly reduces the risk of syntax errors, missing parameters, or inconsistent settings that can lead to network outages.

Exam trap

Cisco often tests the misconception that automation eliminates all manual access methods like SSH, but in reality, automation relies on SSH or similar transports for device communication, and the trap is assuming automation reduces security risks by removing SSH entirely.

23
Multi-Selectmedium

A network engineer is evaluating Cisco SD-WAN (Viptela) for a large enterprise. The engineer needs to automate the deployment of vEdge routers using zero-touch provisioning. Which two components are required to enable zero-touch provisioning for vEdge routers? (Choose two.)

Select 2 answers
A.vSmart controller
B.vManage NMS
C.vBond orchestrator
D.APIC-EM
E.Cisco DNA Center
AnswersB, C

vManage is the management plane that stores device configurations and policies. During zero-touch provisioning, the vEdge router obtains its configuration from vManage after being directed by vBond. vManage is essential for pushing the initial configuration and managing the device thereafter.

Why this answer

Zero-touch provisioning for vEdge routers requires the vBond orchestrator and vManage. vBond authenticates the vEdge and provides the addresses of the other controllers. vManage then delivers the configuration. vSmart is not required for initial provisioning, though it is needed for control plane functionality. DNA Center and APIC-EM are unrelated to SD-WAN.

Exam trap

The trap here is confusing the roles of the SD-WAN controllers and assuming that all are required for zero-touch provisioning, or mixing in components from other Cisco solutions.

24
MCQmedium

A financial services firm wants to automate configuration backups of 200 Cisco IOS XE switches. The team prefers an imperative, script-driven approach where Python code calls a structured API and stores the retrieved configuration in a version-controlled repository. Which method best aligns with this goal?

A.Write a Python script using the requests library to issue RESTCONF GET requests against each switch and save the JSON responses to files.
B.Schedule a TFTP copy of the startup configuration from each switch to a central server using a cron job.
C.Use SNMP set operations to write the running configuration into a management server's MIB database.
D.Enable the Cisco IOS XE guest shell and run a Bash script that executes 'show running-config' on a schedule.
AnswerA

RESTCONF GET returns structured JSON or XML over HTTPS, and Python's requests library can call it directly from a script. Saving the responses into a repository gives the team version-controlled, structured backups. This matches the imperative, script-driven preference and avoids CLI parsing, making it the most aligned approach for programmatic configuration retrieval at scale.

Why this answer

RESTCONF GET requests return model-driven, structured data over HTTPS, and Python's requests library can issue them programmatically from a central control host. Saving the structured responses to a repository supports version control and diffing. Guest shell Bash scripting, SNMP, and TFTP all either rely on CLI output, cannot retrieve full configurations, or lack structured API semantics, so they miss the stated goal.

Exam trap

The trap here is equating any configuration backup method with an API-driven one, when TFTP and SNMP cannot return structured configuration data.

25
MCQmedium

A network automation engineer is using the ncclient Python library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The engineer writes a script that establishes a NETCONF session and sends a <get-config> RPC. However, the script fails with an error indicating the source datastore is not specified. What should the engineer do to correct the script?

A.Add a <filter> element to specify the configuration subtree.
B.Change the RPC to <get> instead of <get-config>.
C.Include a <target> element with <running/> in the RPC.
D.Add a <source> element with <running/> inside the <get-config> RPC.
AnswerD

The <get-config> RPC requires a <source> element to specify which datastore to retrieve configuration from. The running datastore is commonly used. Without it, the NETCONF server cannot determine which configuration to return, resulting in an error. Adding <source><running/></source> resolves the issue.

Why this answer

The <get-config> RPC in NETCONF requires a <source> element to identify the datastore (e.g., running, candidate, startup). Without it, the server cannot process the request. The correct fix is to include <source><running/></source> in the RPC.

This is a common oversight when building NETCONF scripts.

Exam trap

The trap here is assuming that <get-config> works like <get> and does not need a source, or confusing the <target> element used in edit-config with the <source> element needed for get-config.

26
Multi-Selecthard

Which TWO statements are true about RESTCONF and NETCONF in a Cisco IOS XE environment? (Choose two.)

Select 2 answers
A.RESTCONF uses HTTP methods (GET, POST, PUT, DELETE) and supports JSON and XML encoding.
B.RESTCONF supports the candidate datastore for editing configurations.
C.NETCONF uses HTTP as its transport protocol.
D.RESTCONF and NETCONF both support JSON and XML encoding.
E.NETCONF uses XML-encoded RPCs over a secure SSH session.
AnswersA, E

RESTCONF indeed uses HTTP methods and supports JSON and XML.

Why this answer

RESTCONF is designed to use standard HTTP methods (GET, POST, PUT, DELETE, PATCH) for CRUD operations on YANG-defined data, and it supports both JSON and XML encoding formats. This aligns with its goal of providing a simpler, web-friendly interface compared to NETCONF.

Exam trap

Cisco often tests the misconception that both protocols support JSON and XML equally, or that NETCONF uses HTTP, leading candidates to select option D or C incorrectly.

27
MCQeasy

A network engineer is writing a Python script using the ncclient library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The script uses the <get-config> RPC with the source datastore set to 'running'. After running the script, the engineer receives a large XML response but needs to extract only the interface configuration. Which NETCONF capability allows the engineer to filter the response to include only specific configuration data?

A.The 'rollback-on-error' capability, which reverts changes if an error occurs and returns only the changed data.
B.The 'candidate' datastore, which contains only the differences from the running configuration.
C.The 'with-defaults' capability, which allows the server to return only non-default configuration.
D.The <filter> element within the <get-config> RPC, specifying a subtree filter or XPath filter.
AnswerD

NETCONF supports filtering of <get-config> and <get> responses using the <filter> element. The filter can be a subtree filter (matching XML structure) or an XPath filter (using XPath expressions). By specifying a filter, the engineer can limit the response to only the desired configuration, such as interfaces. This is a standard NETCONF capability and is essential for efficient data retrieval.

Why this answer

NETCONF provides a <filter> element within <get-config> and <get> RPCs to restrict the response to specific data. The filter can be a subtree filter or an XPath filter. This allows the engineer to retrieve only the interface configuration, reducing the payload and processing time.

The other capabilities mentioned do not serve this purpose.

Exam trap

The trap here is confusing capabilities that affect data representation (like with-defaults) with those that filter data (like filter).

28
MCQmedium

A network engineer is using Ansible to manage a group of Cisco IOS XE devices. The engineer wants to ensure that the playbook can securely connect to the devices without prompting for passwords and without storing passwords in plaintext in the playbook. Which method should be used to provide the credentials?

A.Use the ansible_ssh_pass variable in the inventory file and encrypt the inventory with Ansible Vault.
B.Use the --ask-pass command-line option when running the playbook.
C.Store the passwords in an encrypted file using Ansible Vault and reference them in the playbook.
D.Set the ANSIBLE_PASSWORD environment variable on the control node before running the playbook.
AnswerC

Ansible Vault allows encrypting sensitive data such as passwords. The encrypted file can be decrypted at runtime with a vault password, which can be provided via a file or prompt. This keeps passwords out of plaintext in the playbook and enables secure, non-interactive automation. This is the recommended method for securing credentials in Ansible.

Why this answer

Ansible Vault provides a secure way to encrypt sensitive data like passwords. By storing credentials in an encrypted file and referencing them in the playbook, the engineer can run playbooks without interactive prompts and without exposing passwords in plaintext. This is the standard best practice for securing credentials in Ansible automation, including for Cisco IOS XE devices.

Exam trap

The trap here is thinking that environment variables or interactive prompts are secure enough, when they either expose passwords or require manual intervention.

29
MCQeasy

A network engineer is using Cisco SD-WAN vManage APIs to automate the deployment of a new branch site. The engineer needs to retrieve a list of all devices in the overlay network. Which REST API endpoint should the engineer use?

A.GET /dataservice/network/connections
B.GET /dataservice/template/device
C.GET /dataservice/system/device
D.GET /dataservice/device
AnswerD

The /dataservice/device endpoint in vManage REST API returns a list of all devices managed by vManage, including their system IP, hostname, and status. This is the correct endpoint for retrieving device inventory. It supports filtering and pagination. The engineer can use this to identify devices for further automation tasks.

Why this answer

The vManage REST API provides the /dataservice/device endpoint to retrieve a list of all devices in the SD-WAN overlay. This endpoint returns details such as device IP, hostname, model, and status. It is the standard way to obtain device inventory for automation scripts.

Other endpoints serve different purposes, such as templates or connections.

Exam trap

The trap here is confusing the device inventory endpoint with the device template endpoint, which manages configuration templates rather than listing devices.

30
MCQhard

A network automation team is using the Cisco DNA Center Intent API to create a new site hierarchy and assign devices. The API call to create the site returns HTTP 202 Accepted, but a subsequent call to assign a device to that site fails with an error that the site does not exist. The team is polling the task endpoint but has not yet received a success status. What is the most likely explanation?

A.The 202 response means the request is processed asynchronously, and the site is not available until the associated task completes successfully
B.The site creation API requires a PUT instead of a POST, so the site was never created
C.The device assignment must be performed before site creation, so the order of operations is reversed
D.The API token expired between the two calls, causing the second call to fail with a site-not-found error
AnswerA

Cisco DNA Center returns HTTP 202 Accepted for asynchronous operations, including site creation. The response includes a task ID, and the site is not fully created until that task reaches a success state. The device assignment fails because the site does not yet exist. The team must poll the task endpoint until completion before proceeding.

Why this answer

Cisco DNA Center Intent API operations such as site creation are asynchronous and return HTTP 202 Accepted with a task ID. The site is not available for subsequent operations until the task completes successfully. The team must poll the task endpoint until it reports success before attempting to assign devices to the new site, which resolves the site-not-found error.

Exam trap

The trap here is treating a 202 Accepted response as immediate success, when it only means the request was queued for asynchronous processing.

31
Multi-Selectmedium

A network engineer is comparing YANG models used in Cisco IOS XE automation. The engineer needs to distinguish between standard IETF YANG models and Cisco-specific YANG models. Which two statements accurately describe these YANG model types? (Choose two.)

Select 2 answers
A.IETF YANG models can only be used with NETCONF, while Cisco-specific models can only be used with RESTCONF.
B.Cisco-specific YANG models are always required to configure any feature on Cisco IOS XE devices.
C.Cisco-specific YANG models are defined in RFCs and are open standards maintained by the IETF.
D.Cisco-specific YANG models often use a namespace that includes 'cisco' and are tailored to expose Cisco IOS XE features.
E.IETF YANG models are vendor-neutral and defined in RFCs, allowing consistent configuration across multi-vendor environments.
AnswersD, E

Cisco-specific YANG models typically have a namespace URI containing 'cisco.com' and are designed to expose Cisco IOS XE-specific features and operational data. They complement standard models by providing access to proprietary functionality. For example, Cisco-IOS-XE-native is a common model for native configuration. This statement accurately describes their naming and purpose.

Why this answer

IETF YANG models are vendor-neutral standards from the IETF, enabling multi-vendor consistency. Cisco-specific models have namespaces indicating Cisco and expose IOS XE features. Both can be used over NETCONF or RESTCONF.

The other statements are false: Cisco models are not always required, not limited to RESTCONF, and not IETF standards.

Exam trap

The trap here is assuming Cisco-specific models are always needed or that model type dictates the protocol, when in fact standard models can be used and both protocols support any YANG model.

32
MCQeasy

A network engineer is new to automation and wants to use a Python library that provides a simple, high-level interface for interacting with network devices, including Cisco IOS XE, without dealing with low-level SSH or NETCONF details. The engineer needs to quickly script configuration changes and command execution. Which Python library is best suited for this requirement?

A.Requests
B.Ncclient
C.Netmiko
D.Paramiko
AnswerC

Netmiko is a Python library built on top of Paramiko that simplifies SSH connections to network devices. It handles device-specific prompts, paging, and other nuances, allowing engineers to send configuration commands and retrieve output easily. It supports Cisco IOS XE and many other vendors. For a beginner needing a high-level interface without dealing with low-level details, Netmiko is ideal. It abstracts the complexities of SSH and device interaction.

Why this answer

Netmiko is designed to simplify SSH-based interactions with network devices. It provides a high-level, consistent interface across multiple vendors, handling device-specific behaviors like prompt detection and output paging. For a network engineer new to automation who needs to quickly script configuration changes and command execution on Cisco IOS XE, Netmiko is the most appropriate choice.

It reduces the complexity of low-level SSH libraries.

Exam trap

The trap here is selecting Paramiko because it is a common SSH library, but it lacks the high-level abstractions that Netmiko provides for network devices.

33
MCQmedium

A network engineer needs to programmatically retrieve the operational status of all GigabitEthernet interfaces on a Cisco IOS XE device. The engineer wants to use a REST-based protocol that returns data in JSON and uses HTTP methods. The device is configured with 'restconf' and 'ip http secure-server'. Which protocol should the engineer use?

A.SSH with CLI commands
B.RESTCONF over HTTPS
C.SNMPv3 with JSON output
D.NETCONF over SSH
AnswerB

RESTCONF is a REST-based protocol that uses HTTP methods (GET, POST, PUT, PATCH, DELETE) and supports JSON encoding. It is enabled on IOS XE with the 'restconf' command and uses the HTTPS server. This matches the requirement to retrieve interface status programmatically with JSON and HTTP.

Why this answer

RESTCONF is the correct choice because it is a REST-based protocol that uses HTTP methods and supports JSON encoding. It is enabled on Cisco IOS XE with the 'restconf' command and leverages the HTTPS server. The other options either use different transports (NETCONF over SSH), different data formats (SNMP), or are not REST-based (SSH CLI).

Exam trap

The trap here is assuming that NETCONF is the only model-driven programmatic interface for Cisco IOS XE, overlooking that RESTCONF provides a RESTful alternative with JSON support.

34
MCQhard

A network engineer uses Netmiko to connect to multiple Cisco IOS XE devices and execute commands. The script runs correctly for most devices but fails for one device with the error: 'ValueError: SSH session not active'. The device is reachable and SSH credentials are correct. What is the most likely cause?

A.The connection timeout is set too low
B.The device has reached the maximum number of SSH sessions
C.The device's SSH server is not fully initialized
D.The device requires an enable password but none was provided
AnswerC

This error from Netmiko/Paramiko means the SSHTransport object is not in an active state when invoke_shell() is called. On Cisco devices, this commonly occurs when the device is still booting and the SSH server has not fully initialized—for example, RSA keys are still being generated—so the server accepts TCP but aborts the SSH protocol handshake, leaving the client transport inactive.

Why this answer

The error 'ValueError: SSH session not active' indicates that Netmiko attempted to establish an SSH connection but the session was not fully active. The most likely cause is that the device's SSH server is not fully initialized, which can happen if the device is still booting or the SSH process has not completed startup. This is distinct from reachability or credential issues, as the device responds to pings but the SSH daemon is not ready to accept connections.

Exam trap

The trap here is that candidates often confuse network reachability or credential validity with SSH session state, assuming that if the device is pingable and credentials are correct, the SSH session must work, but Cisco tests the understanding that SSH session initialization is a separate process that can fail even when the device is reachable.

How to eliminate wrong answers

Option A is wrong because a low connection timeout would typically result in a 'Connection timed out' or 'Timeout' error, not a 'ValueError: SSH session not active' which indicates the session was initiated but not active. Option B is wrong because reaching the maximum number of SSH sessions would produce an error like 'Too many connections' or 'Connection refused', not a ValueError about session inactivity. Option D is wrong because a missing enable password would cause an authentication failure or privilege escalation error after the SSH session is established, not a failure to activate the SSH session itself.

35
MCQeasy

A network engineer is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS XE switches. The engineer prefers to write playbooks in YAML and use SSH for connectivity. Which tool should the engineer choose?

A.Ansible
B.Puppet
C.SaltStack
D.Chef
AnswerA

Ansible is an agentless automation tool that uses SSH to connect to managed devices. It uses YAML-based playbooks, which match the engineer's preference. For Cisco IOS XE, Ansible provides modules like ios_config and ios_command that run over SSH. This makes Ansible the ideal choice for simple, agentless configuration management with YAML playbooks.

Why this answer

Ansible is an agentless automation tool that uses SSH for connectivity and YAML for playbooks. It provides dedicated modules for Cisco IOS XE, such as ios_config and ios_command, enabling straightforward configuration pushes. The engineer's requirements for agentless operation, YAML playbooks, and SSH align perfectly with Ansible's design, making it the correct choice among the options.

Exam trap

The trap here is assuming that any configuration management tool can use YAML and SSH, when only Ansible natively combines both for agentless network automation.

36
MCQhard

A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE router via NETCONF. The script sends an <edit-config> RPC with a candidate datastore, but the router returns an error indicating the candidate datastore is not supported. The team wants to make configuration changes without affecting the running configuration until they are verified. Which NETCONF capability should the team ensure is enabled on the router to allow this workflow?

A.:writable-running
B.:rollback-on-error
C.:confirmed-commit
D.:candidate
AnswerD

The :candidate capability indicates support for a candidate configuration datastore, which allows changes to be staged and validated before being committed to the running configuration. Without this capability, the router cannot accept edits to a candidate datastore, resulting in the error. Enabling :candidate enables the desired workflow of testing configurations before applying them.

Why this answer

To use a candidate datastore for staging configuration changes, the NETCONF server must support the :candidate capability. This allows the client to edit the candidate configuration, validate it, and then commit it to the running configuration. Other capabilities like :confirmed-commit and :rollback-on-error enhance commit behavior but require :candidate as a prerequisite.

Thus, enabling :candidate is necessary.

Exam trap

The trap here is assuming that :writable-running allows staging changes without impact, but it directly modifies the running configuration, which is not the desired workflow.

37
MCQeasy

A network automation engineer is using the Python 'ncclient' library to manage a Cisco IOS XE device via NETCONF. The engineer wants to retrieve the running configuration. Which NETCONF operation should be used to accomplish this?

A.<get-config> with a source of <running/>
B.<get> with a filter for <config>
C.<edit-config> with a target of <running/>
D.<copy-config> from <running/> to <startup/>
AnswerA

The <get-config> operation is designed to retrieve configuration data from a specified datastore, such as <running/>. It returns the configuration in XML format. This is the correct NETCONF operation for reading configuration, as it does not include state data. The engineer can then parse the XML to extract the running configuration.

Why this answer

NETCONF provides specific operations for different tasks. To retrieve configuration data, the <get-config> operation is used with a source datastore, such as <running/>. This returns the configuration without state data.

Other operations like <get> retrieve both config and state, while <edit-config> and <copy-config> are for writing or copying. The correct choice is <get-config>.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both configuration and state data, but <get-config> is specifically for configuration.

38
MCQeasy

A network team is evaluating automation tools to manage a large Cisco IOS XE environment. They need a tool that uses a declarative, agentless approach and can be run from a central server without installing software on managed devices. Which tool best fits this requirement?

A.Puppet
B.SaltStack
C.Chef
D.Ansible
AnswerD

Ansible is an agentless automation tool that uses SSH or NETCONF to connect to devices, requiring no agent installation on managed nodes. It uses declarative playbooks written in YAML. This aligns perfectly with the requirement for an agentless, declarative tool run from a central server. Ansible is widely used for Cisco network automation.

Why this answer

Ansible is agentless, using SSH or NETCONF to connect to devices, and uses declarative YAML playbooks. It runs from a central control node without installing agents on managed devices. Puppet, Chef, and SaltStack typically require agents, making them less suitable for this specific requirement.

Exam trap

The trap here is confusing agentless operation with tools that can optionally run agentless; Ansible is inherently agentless, while others are primarily agent-based.

39
MCQhard

A network automation engineer is using Cisco DNA Center's Intent API to retrieve a list of all network devices. The engineer writes a Python script that sends a GET request to the /dna/intent/api/v1/network-device endpoint. The script receives an HTTP 403 Forbidden response. The engineer has verified that the username and password are correct and that the user has the SUPER-ADMIN-ROLE. What is the most likely cause of the issue?

A.The API endpoint requires a valid X-Auth-Token header, which the script did not include.
B.The script must use HTTPS instead of HTTP to access the API.
C.The user account is locked due to multiple failed login attempts.
D.The API endpoint URL is incorrect and should be /dna/intent/api/v1/network-device/count.
AnswerA

Cisco DNA Center's Intent API uses token-based authentication. After authenticating via /dna/system/api/v1/auth/token, the script must include the returned token in the X-Auth-Token header for subsequent requests. Without this header, the server returns 403 Forbidden even if credentials are correct. The script likely omitted this step, causing the authorization failure.

Why this answer

Cisco DNA Center's Intent API requires token-based authentication. The script must first obtain a token from the authentication endpoint and then include it in the X-Auth-Token header for all subsequent API calls. Without this header, the server returns 403 Forbidden, indicating the request lacks proper authorization.

Correct credentials alone are insufficient; the token is mandatory.

Exam trap

The trap here is assuming that correct username and password are sufficient for API access, overlooking the need for a token in the X-Auth-Token header.

40
MCQmedium

An organization uses Cisco DNA Center to automate network provisioning. A network engineer deploys a new access switch but finds that the switch does not receive the intended configuration template. The switch appears in DNA Center inventory with status 'Managed'. What is the most likely cause?

A.The switch has not been discovered by DNA Center
B.The switch is not in Plug and Play mode
C.The switch does not have a valid DNA license
D.The switch is not assigned to a site
AnswerD

In DNA Center, CLI templates are created and then associated with a site, and devices that are not assigned to a site cannot be targeted by the provisioning workflow that applies those templates. Template configuration via the 'Provision' workflow only operates on devices that belong to a selected site in the network hierarchy. Thus the correct fix is to assign the switch to a site, after which the templates and compliance checks become applicable.

Why this answer

In Cisco DNA Center, configuration templates are applied based on site assignment. A switch that appears as 'Managed' in inventory has been discovered and is under DNA Center's control, but if it is not assigned to a specific site, DNA Center cannot determine which template to push. Site assignment is a prerequisite for template-based provisioning; without it, the intended configuration will not be deployed.

Exam trap

Cisco often tests the distinction between 'Managed' and 'Provisioned' states, trapping candidates who assume that a device being managed automatically means it has received its configuration.

How to eliminate wrong answers

Option A is wrong because the switch appears in inventory with status 'Managed', which means it has already been discovered by DNA Center. Option B is wrong because Plug and Play (PnP) is a separate provisioning method; DNA Center can apply templates to switches that are not in PnP mode as long as they are managed and site-assigned. Option C is wrong because a valid DNA license is required for advanced features but not for basic template application; the switch being 'Managed' indicates it has the necessary licensing to be under DNA Center control.

41
MCQmedium

A network engineer is writing a Python script to retrieve the operational status of all GigabitEthernet interfaces from a Cisco IOS XE device using NETCONF. The script establishes an SSH session to the device on port 830 and sends a <get> RPC with a subtree filter. The device responds with an <rpc-error> indicating 'unknown-element' for the filter. Which action should the engineer take to resolve this issue?

A.Verify that the YANG model for the interface operational data is supported and use the correct namespace in the filter.
B.Convert the subtree filter to an XPath filter and resend the <get> RPC.
C.Change the NETCONF transport from SSH to TLS by enabling the netconf-tls feature on the device.
D.Increase the NETCONF session timeout on the device using the netconf max-sessions command.
AnswerA

The 'unknown-element' error occurs when the filter references a data node that is not defined in any YANG model supported by the device or when the namespace is incorrect. The engineer must confirm that the device supports the ietf-interfaces or Cisco-specific interface YANG model and that the filter uses the exact namespace and node names from that model.

Why this answer

The 'unknown-element' error in NETCONF indicates that the filter references a data node that the device does not recognize. This typically happens when the YANG model is not supported or the namespace is incorrect. The engineer must verify that the device supports the relevant YANG model and that the filter uses the correct namespace and node names.

Exam trap

The trap here is assuming that changing the NETCONF transport or session parameters will fix a filter validation error, when the issue is actually a mismatch between the filter and the supported YANG models.

42
MCQeasy

A network engineer is using Cisco SD-WAN vManage APIs to automate the creation of a new VPN template. The engineer needs to authenticate to the vManage REST API using a Python script. Which authentication method is natively supported by the vManage API for programmatic access?

A.Session-based authentication using a cookie obtained from /j_security_check
B.API key authentication using a static key generated in the vManage GUI
C.Certificate-based authentication using X.509 client certificates
D.OAuth 2.0 with JWT tokens issued by vManage
AnswerA

The vManage REST API uses session-based authentication where the client posts credentials to /j_security_check and receives a JSESSIONID cookie. This cookie must be included in subsequent API requests. This is the standard method for programmatic access to vManage, allowing scripts to authenticate and perform operations.

Why this answer

The vManage REST API uses session-based authentication. A client sends a POST request to /j_security_check with username and password, receives a JSESSIONID cookie, and includes it in subsequent requests. This method is standard for automating vManage operations.

Other methods like OAuth or API keys are not natively supported for the vManage API.

Exam trap

The trap here is assuming that vManage supports OAuth or API keys like some other Cisco platforms, but it actually uses session cookies for API authentication.

43
MCQeasy

A retail company wants its network engineers to push consistent OSPF configurations to dozens of Cisco IOS XE routers using a declarative, agentless automation tool that connects over SSH and does not require installing software on the managed devices. Which tool best fits these requirements?

A.Ansible, using modules such as ios_config with an inventory of IOS XE devices and SSH credentials.
B.Puppet, using a master-agent architecture with the Puppet agent installed on each IOS XE router.
C.Chef, using a Chef client installed directly on each Cisco IOS XE router to converge configuration.
D.SaltStack, using Salt minions installed locally on every IOS XE device to receive configuration commands.
AnswerA

Ansible is declarative, agentless, and connects to managed nodes over SSH without installing any agent software. Its network modules, including ios_config and ios_ospf, target Cisco IOS and IOS XE devices and push configuration from playbooks. This matches the requirement for consistency across many routers, no on-device agent, and SSH-based transport exactly as described.

Why this answer

Ansible is the agentless, declarative tool that connects over SSH and uses network-specific modules to configure Cisco IOS XE devices. It needs no software installed on the routers, relying instead on SSH and Python executed on the control node. Puppet, Chef, and SaltStack in their default forms require an agent on the managed node, which IOS XE cannot host, so they fail the stated agentless requirement.

Exam trap

The trap here is assuming all configuration-management tools are agentless, when Puppet, Chef, and SaltStack default to agent-based designs.

44
Multi-Selecthard

A network engineer is designing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) appliance using its Intent API. The script must retrieve a list of all network devices and then update the location of a specific device. Which two steps are required to authenticate and authorize the API requests? (Choose two.)

Select 2 answers
A.Send a POST request to /dna/system/api/v1/auth/token with Basic Authentication credentials to obtain a token.
B.Configure a separate API user with role-based access control (RBAC) permissions to allow read and write operations.
C.Enable the Intent API on the Catalyst Center appliance by running the intent-api enable command in the CLI.
D.Use the token obtained from the authentication endpoint in the X-Auth-Token header for subsequent API calls.
E.Include the username and password in every API request as query parameters.
AnswersA, D

The Catalyst Center Intent API uses token-based authentication. The engineer must first authenticate by sending a POST request to the /dna/system/api/v1/auth/token endpoint with Basic Authentication (username and password). The response contains a token that must be included in subsequent API calls as an X-Auth-Token header. This is the standard method for API access.

Why this answer

To authenticate with the Catalyst Center Intent API, the engineer must first obtain a token by sending a POST request to the authentication endpoint with Basic Authentication. Then, that token must be included in the X-Auth-Token header for all subsequent API calls. This two-step process ensures secure, token-based access to the API.

Exam trap

The trap here is assuming that credentials can be passed directly in each API call or that the API needs to be enabled manually, when actually a token must be obtained and reused.

45
MCQhard

A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script establishes a session and sends an <edit-config> RPC with a candidate datastore. After sending the RPC, the script immediately sends a <commit> RPC, but the device returns an error indicating that the candidate datastore is not supported. Which statement explains the cause of this error?

A.The device requires the use of NETCONF over SSH instead of TLS for candidate datastore operations.
B.The script must first send a <lock> RPC on the candidate datastore before editing.
C.The script must send a <validate> RPC before the <commit> to ensure the candidate configuration is valid.
D.The device does not support the candidate datastore, so the script must use the running datastore directly.
AnswerD

The error explicitly states that the candidate datastore is not supported. Many Cisco IOS XE devices support only the running datastore for NETCONF edits, not the candidate datastore. The candidate datastore allows staging changes before committing, but if it is unsupported, the <edit-config> must target the running datastore. The script should be modified to use the running datastore instead of candidate, and the <commit> operation is unnecessary because changes take effect immediately.

Why this answer

The error indicates that the candidate datastore is not supported by the device. Cisco IOS XE devices often support only the running datastore for NETCONF edits. The candidate datastore allows a two-phase commit, but if it is not available, the script must target the running datastore.

The <commit> operation is only for the candidate datastore. Therefore, the script should be changed to edit the running datastore directly, which applies changes immediately.

Exam trap

The trap here is assuming all NETCONF devices support the candidate datastore, when many Cisco IOS XE devices only support the running datastore.

46
MCQeasy

A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to Cisco IOS XE devices. The administrator prefers using YAML for playbook definitions and wants to avoid installing software on the managed devices. Which tool best fits these requirements?

A.Ansible
B.Chef
C.SaltStack
D.Puppet
AnswerA

Ansible is an agentless automation tool that uses YAML for playbooks. It connects to devices over SSH or NETCONF and does not require installing agents on managed nodes. It has modules like ios_config for Cisco IOS XE. This matches the administrator's requirements for simplicity and no agent installation.

Why this answer

Ansible is an agentless automation tool that uses YAML for playbooks, making it easy to learn and use. It connects to network devices via SSH or NETCONF and does not require installing software on the devices. This aligns perfectly with the administrator's need for a simple, agentless solution.

Exam trap

The trap here is assuming that all configuration management tools are agentless and use YAML; only Ansible is agentless by default and uses YAML for playbooks.

47
MCQmedium

A network engineer is using Cisco DNA Center's Intent API to create a new site hierarchy for a branch office. The engineer sends a POST request to the /dna/intent/api/v1/site endpoint with a JSON payload containing the site name and parent site. The API returns HTTP 202 Accepted. The engineer immediately sends a GET request to retrieve the newly created site but receives a 404 Not Found. What is the most likely explanation?

A.The site creation is an asynchronous operation, and the GET request was sent before the task completed.
B.The POST request must use the PUT method to create a new site.
C.The GET request must include the same JSON payload as the POST to retrieve the site.
D.The site name must be unique across all sites, and a duplicate name caused the creation to fail silently.
AnswerA

Cisco DNA Center often processes site creation asynchronously. A 202 Accepted response indicates the request was accepted but not yet completed. The API typically returns a task ID in the response body. The engineer must poll the task status until it succeeds before the site is available. Sending a GET immediately can result in 404 because the site does not exist yet.

Why this answer

Cisco DNA Center's Intent API uses asynchronous operations for many tasks, including site creation. A 202 Accepted response means the request is being processed. The response usually contains a task ID.

The engineer should poll the task endpoint until the task completes successfully, then retrieve the site. A GET immediately after the POST can return 404 because the site is not yet available.

Exam trap

The trap here is treating a 202 Accepted response as immediate completion, leading to a premature GET that returns 404.

48
MCQmedium

A network engineer is writing a Python script to retrieve the configured hostname from a Cisco IOS XE device using RESTCONF. The device has RESTCONF enabled, and the engineer sends a GET request to https://10.1.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname with the header 'Accept: application/yang-data+json'. However, the request fails with HTTP 401 Unauthorized. The engineer verifies that the device is reachable and RESTCONF is enabled. What is the most likely reason for the failure?

A.The RESTCONF URI is incorrect; it should be /restconf/data/ietf-interfaces:interfaces to retrieve hostname information.
B.The RESTCONF API requires the use of HTTPS with a valid certificate, and the device's certificate is self-signed.
C.The engineer did not include valid authentication credentials in the request, such as a username and password or a token.
D.The request is missing the 'Content-Type' header, which is required for all RESTCONF requests.
AnswerC

HTTP 401 Unauthorized specifically indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication or token-based methods. Without proper credentials, the device rejects the request. The engineer must include an Authorization header with valid credentials to succeed.

Why this answer

The 401 Unauthorized status code is a clear indication that authentication failed. RESTCONF on Cisco IOS XE requires the client to provide credentials, usually via HTTP Basic Authentication. Without a valid Authorization header, the device denies access.

The other options describe issues that would produce different error codes or are irrelevant to authentication.

Exam trap

The trap here is assuming that a self-signed certificate or missing Content-Type header causes a 401 error, when in fact 401 is strictly about missing or invalid authentication credentials.

49
MCQmedium

A network automation team needs to securely retrieve the running configuration from 200 Cisco IOS XE routers daily using a Python script. The script must authenticate with individual user credentials, use a structured data format, and avoid screen-scraping. Which approach best meets these requirements?

A.Use SNMPv3 GET requests with the OID for the running configuration MIB object to retrieve the full configuration.
B.Use the requests library to send HTTP GET requests to the device's web UI login page, then scrape the configuration page HTML.
C.Use the ncclient Python library to send NETCONF <get-config> RPCs over SSH, requesting the <running> datastore with a YANG-modeled filter.
D.Use the paramiko library to open an SSH session and execute the 'show running-config' command, then parse the raw text output.
AnswerC

NETCONF over SSH provides secure, authenticated access with structured XML payloads defined by YANG models. The <get-config> RPC retrieves the running configuration in a machine-readable format, eliminating screen-scraping. ncclient is a standard Python library for NETCONF, and individual credentials are supported. This directly satisfies all stated requirements.

Why this answer

NETCONF over SSH with ncclient delivers secure, credential-based access and returns configuration data as structured XML governed by YANG models. This eliminates the fragility of parsing CLI text and avoids screen-scraping. The other approaches either return unstructured output, cannot retrieve full configurations reliably, or rely on UI scraping, so they do not meet the stated automation requirements.

Exam trap

The trap here is assuming that any SSH-based method (such as Paramiko running show commands) counts as structured automation, when only model-driven APIs like NETCONF return schema-validated data.

50
MCQmedium

A network automation engineer is using the Cisco DNA Center Intent API to retrieve a list of all network devices. The engineer needs to authenticate to the API. Which authentication method should be used to obtain a token for subsequent API calls?

A.OAuth 2.0 client credentials grant flow.
B.POST to the /dna/system/api/v1/auth/token endpoint with Basic authentication.
C.API key passed in the X-Auth-Token header.
D.Basic authentication with username and password in the Authorization header.
AnswerB

Cisco DNA Center's Intent API requires a POST request to the /dna/system/api/v1/auth/token endpoint, using Basic authentication with the username and password. The response contains a token that must be included in subsequent requests in the X-Auth-Token header. This is the standard authentication flow for the Intent API.

Why this answer

The Cisco DNA Center Intent API uses token-based authentication. The client must POST to the /dna/system/api/v1/auth/token endpoint with Basic authentication credentials. The response includes a token that is then used in the X-Auth-Token header for subsequent API calls.

This is the documented and required method for API access.

Exam trap

The trap here is assuming that standard authentication methods like Basic auth or OAuth are used directly, when DNA Center requires a specific token retrieval step.

51
MCQmedium

A network engineer is using the Cisco DNA Center Intent API to create a new site hierarchy. The engineer sends a POST request to /dna/intent/api/v1/site with a JSON payload defining the site. The API returns a 202 Accepted response with a task ID. What should the engineer do next to confirm the site was created successfully?

A.Check the DNA Center audit logs to see if the site creation was logged.
B.Resend the POST request with the same payload to ensure the site is created.
C.Use the task ID to poll the GET /dna/intent/api/v1/task/{taskId} endpoint until the task status is 'SUCCESS'.
D.Immediately send a GET request to /dna/intent/api/v1/site to verify the site exists.
AnswerC

The 202 Accepted response includes a task ID for asynchronous operations. The engineer should poll the task endpoint using that ID to check the status. Once the task status is 'SUCCESS', the site creation is complete. This is the standard pattern for DNA Center Intent API operations that are long-running.

Why this answer

When the DNA Center Intent API returns 202 Accepted, it means the request is being processed asynchronously. The response includes a task ID. The engineer must poll the task endpoint with that ID until the status indicates success.

This ensures the site creation is complete before proceeding with dependent tasks.

Exam trap

The trap here is assuming the operation is synchronous and immediately checking for the site, when the 202 response signals asynchronous processing requiring task polling.

52
MCQeasy

A network engineer is using the Python requests library to interact with a Cisco IOS XE device's RESTCONF API. The engineer wants to retrieve the configured hostname. Which HTTP method and URI should be used?

A.PUT https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
B.POST https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
C.GET https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
D.GET https://<device-ip>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
AnswerC

This is the correct RESTCONF URI to retrieve the hostname from the Cisco IOS XE native YANG model. The GET method is used to read data. The URI path follows the YANG model structure, starting with the module name and then the data node. This will return the hostname if configured.

Why this answer

To retrieve the hostname via RESTCONF, the engineer must use the GET method with the correct URI that points to the hostname leaf in the Cisco IOS XE native YANG model. The URI structure includes the module name (Cisco-IOS-XE-native), the container (native), and the leaf (hostname). This is a straightforward read operation.

Exam trap

The trap here is confusing the HTTP methods for reading versus writing, and mixing up YANG models for different data.

53
Multi-Selecthard

A network automation team is evaluating RESTCONF as a replacement for CLI scraping on Cisco IOS XE devices. They need to understand the operational characteristics of RESTCONF to design their tooling. Which two statements accurately describe RESTCONF behavior on Cisco IOS XE? (Choose two.)

Select 2 answers
A.RESTCONF uses HTTP methods such as GET, POST, PUT, PATCH, and DELETE to manipulate YANG-modeled data.
B.RESTCONF requires a candidate datastore to be enabled before any configuration changes can be made.
C.RESTCONF uses SSH as its transport protocol and does not support HTTPS.
D.RESTCONF messages are encoded in XML or JSON, with JSON support available on Cisco IOS XE.
E.RESTCONF automatically translates YANG models into SNMP MIBs for monitoring.
AnswersA, D

RESTCONF is a RESTful protocol that maps CRUD operations to HTTP methods. GET retrieves data, POST creates, PUT replaces, PATCH modifies, and DELETE removes. This aligns with the RESTCONF RFC and is how IOS XE exposes YANG-modeled configuration and state. The team can rely on these standard methods for automation, making this statement accurate and essential for designing tooling.

Why this answer

RESTCONF is a RESTful protocol that uses HTTP methods to manipulate YANG-modeled data and supports both XML and JSON encodings. On Cisco IOS XE, JSON is supported, which is advantageous for modern automation. The other statements are false: candidate datastore is not mandatory, SSH is not the transport, and there is no automatic YANG-to-MIB translation.

Exam trap

The trap here is confusing RESTCONF's transport and encoding with those of NETCONF, leading to incorrect assumptions about SSH usage or mandatory candidate datastores.

54
MCQmedium

A network automation engineer is writing a Python script to retrieve interface statistics from a Cisco IOS XE device using NETCONF. The script uses the 'ncclient' library and connects to the device on port 830. However, the connection fails with a 'Could not open socket' error. The engineer confirms that the device is reachable via ping and SSH on port 22. What is the most likely reason for the failure?

A.NETCONF is not enabled on the device.
B.The 'ncclient' library requires Python 2, but the script is using Python 3.
C.The firewall is blocking outbound connections on port 830.
D.The device's SSH server is configured to use a non-standard port.
AnswerA

NETCONF uses TCP port 830, which is separate from the standard SSH port 22. If NETCONF is not enabled on the Cisco IOS XE device via the 'netconf-yang' command, the device will not listen on port 830, and the connection attempt will fail with a socket error. The engineer's ability to SSH on port 22 does not guarantee NETCONF is active. Enabling 'netconf-yang' is required to start the NETCONF SSH server.

Why this answer

The 'Could not open socket' error when connecting to port 830 typically means the NETCONF service is not enabled on the device. NETCONF uses a separate SSH server on port 830, which is activated by the 'netconf-yang' command. The engineer's successful SSH on port 22 only confirms the standard SSH server is running, not NETCONF.

Therefore, enabling NETCONF is the required fix.

Exam trap

The trap here is assuming that if SSH on port 22 works, NETCONF should also work; however, NETCONF requires a separate service on port 830 that must be explicitly enabled.

55
MCQeasy

A network administrator wants to use a declarative, agentless automation tool to push VLAN configurations to a group of Cisco IOS XE switches. The tool should connect over SSH, use YAML playbooks, and require no software installation on the switches. Which tool best fits these requirements?

A.SaltStack with minions deployed on each switch and states written in YAML
B.Chef Infra Client installed on each switch with recipes written in Ruby
C.Puppet with the Cisco IOS module installed on each switch
D.Ansible with the cisco.ios collection and an inventory of the switches
AnswerD

Ansible is agentless, connecting over SSH, and uses YAML playbooks. The cisco.ios collection provides modules like ios_vlan and ios_config to manage IOS XE devices. No software needs to be installed on the switches beyond SSH and proper credentials. This matches all requirements: declarative, agentless, YAML-based, and SSH connectivity.

Why this answer

Ansible is the only option that is agentless, connects via SSH, and uses YAML playbooks. The cisco.ios collection supplies modules purpose-built for IOS XE VLAN and configuration management. Puppet, Chef, and SaltStack all generally require an agent on managed nodes, which cannot be installed on Cisco IOS XE switches, so they do not satisfy the agentless requirement.

Exam trap

The trap here is assuming any configuration management tool with a Cisco module is agentless, when Puppet, Chef, and SaltStack typically require agents that cannot run on IOS XE.

56
MCQhard

A DevOps team is implementing a CI/CD pipeline that automates network configuration changes. Which design principle is most important to ensure that a failed deployment does not cause prolonged outages?

A.Use a single source of truth for all configurations
B.Ensure the automation framework supports rollback to a known good state
C.Implement idempotent configuration scripts
D.Run the deployment in a lab environment first
AnswerB

Rollback to a known good state is the critical safety net in a CI/CD pipeline because it directly addresses the recovery-time objective after a failed deployment. The automation framework should preserve the last-known-good configuration (e.g., a snapshot, a config replace file, or a rollback token) and be able to reapply it automatically or on-demand when health checks fail. This minimizes mean time to recovery and is the only option that actively restores service rather than merely preventing or mitigating the impact of a failure.

Why this answer

In a CI/CD pipeline for network automation, the ability to roll back to a known good state is the most critical design principle for minimizing downtime. If a deployment fails (e.g., a misapplied ACL or BGP configuration), the automation framework must be able to revert the network device to its previous stable configuration—often by reapplying a saved startup config or using a tool like Ansible's `network_backup` role or Cisco NSO's rollback mechanism. Without this, a failed deployment could leave the network in a broken state until manual intervention, causing prolonged outages.

Exam trap

Cisco often tests the distinction between 'preventing errors' (idempotency, single source of truth) and 'recovering from errors' (rollback), and the trap here is that candidates confuse idempotency with rollback, thinking that re-running a script will fix a failure, when in fact idempotency only ensures consistency, not recovery from a broken state.

How to eliminate wrong answers

Option A is wrong because a single source of truth (e.g., a Git repository for configurations) is important for consistency and auditability, but it does not directly address recovery from a failed deployment; it prevents drift but not the need for rollback. Option C is wrong because idempotent scripts ensure that repeated runs produce the same result, which helps avoid unintended changes, but they do not provide a mechanism to revert to a previous state if a deployment introduces a fault. Option D is wrong because running a deployment in a lab environment first is a best practice for testing, but it does not guarantee that a production deployment won't fail; the question specifically asks about ensuring that a failed deployment does not cause prolonged outages, which requires a rollback capability in production.

57
Multi-Selecthard

A network automation team is designing a solution to manage configuration changes across a fleet of Cisco IOS XE devices. They want to use model-driven programmability with YANG data models. Which two protocols can be used to programmatically retrieve and modify configuration using YANG models on these devices? (Choose two.)

Select 2 answers
A.RESTCONF over HTTPS
B.NETCONF over SSH
C.SSH with CLI commands
D.CLI over Telnet
E.SNMPv3 with YANG models
AnswersA, B

RESTCONF is a RESTful protocol that also uses YANG models. It maps YANG data to HTTP methods (GET, POST, PUT, PATCH, DELETE) and uses JSON or XML. Cisco IOS XE supports RESTCONF over HTTPS. It is ideal for web-based automation and integrates well with modern tooling. It is a valid protocol for model-driven configuration.

Why this answer

NETCONF and RESTCONF are the two primary protocols for model-driven programmability using YANG models on Cisco IOS XE. NETCONF uses SSH and XML, while RESTCONF uses HTTPS and JSON/XML. Both allow structured configuration and state retrieval.

SNMP, Telnet, and CLI-based SSH do not natively support YANG and are not considered model-driven.

Exam trap

The trap here is assuming that any remote management protocol can use YANG models, when only NETCONF and RESTCONF are designed for model-driven programmability.

58
Multi-Selectmedium

A network engineer is building a Python script to interact with a Cisco IOS XE device using RESTCONF. The script must authenticate, retrieve interface configuration, and handle the response. Which two actions are required to successfully complete this task? (Choose two.)

Select 2 answers
A.Configure the device with an SNMP community string so RESTCONF can authenticate the API session.
B.Use the 'ncclient' library to establish a NETCONF session on port 830 and then issue RESTCONF calls through that session.
C.Enable the RESTCONF agent on the device by entering the 'restconf' global configuration command and ensuring the HTTPS server is active.
D.Install the 'yangsuite' package on the IOS XE device to validate the RESTCONF payloads before sending them.
E.Send an HTTP GET request to the appropriate RESTCONF URI, such as /restconf/data/ietf-interfaces:interfaces, with the Accept header set to application/yang-data+json.
AnswersC, E

RESTCONF is not enabled by default on IOS XE. The 'restconf' global command starts the RESTCONF agent, and it depends on the HTTPS server being active via 'ip http secure-server'. Without these, the device will not accept RESTCONF requests, resulting in connection failures or 401 errors. This step is mandatory before any RESTCONF API call can succeed.

Why this answer

Successful RESTCONF interaction requires enabling the RESTCONF agent and HTTPS server on the device, then issuing proper HTTP requests to the correct RESTCONF data URIs with appropriate media type headers. NETCONF libraries, SNMP settings, and client-side YANG tools do not enable or perform RESTCONF operations, so only enabling RESTCONF and using correct HTTP GET requests are required.

Exam trap

The trap here is conflating NETCONF and RESTCONF tooling, assuming that a NETCONF library or SNMP configuration contributes to RESTCONF access when RESTCONF is purely HTTP-based.

59
MCQeasy

A network administrator is comparing configuration management tools and wants to use one that is agentless, uses YAML for playbooks, and communicates with Cisco IOS XE devices over SSH. Which tool best meets these requirements?

A.Puppet
B.Chef
C.SaltStack
D.Ansible
AnswerD

Ansible is agentless, connecting to devices over SSH, and uses YAML-formatted playbooks to define automation tasks. It includes modules such as ios_config and ios_command that specifically target Cisco IOS XE devices. This matches all stated requirements: no agent, YAML syntax, and SSH communication, making it the correct choice for this scenario.

Why this answer

Ansible is designed as an agentless automation tool that communicates over SSH and uses YAML playbooks. It provides network-specific modules for Cisco IOS XE, allowing configuration and command execution without installing software on the managed devices. This combination of agentless architecture, YAML syntax, and SSH transport exactly matches the administrator's requirements, distinguishing it from agent-based tools like Puppet, Chef, and SaltStack.

Exam trap

The trap here is assuming that any tool using YAML or supporting SSH is equivalent, when in fact Ansible is uniquely agentless with YAML playbooks as its core design.

60
MCQmedium

A network engineer at a logistics company is building a Python script that must retrieve the running configuration of a Cisco IOS XE router without parsing CLI screen-scraping output. The engineer wants a programmatic, model-driven interface that returns structured data over HTTPS. Which approach best satisfies this requirement?

A.Use SNMPv3 with the get-bulk operation to walk the ifTable and reconstruct the running configuration from MIB objects.
B.Use NETCONF over an SSH subsystem on TCP port 830 and parse the XML reply for the running configuration datastore.
C.Use the Cisco IOS XE CLI over a Telnet session and capture the output of 'show running-config' with a regular expression parser.
D.Use RESTCONF over HTTPS on TCP port 443 with the Accept header set to application/yang-data+json to read the configuration datastore.
AnswerD

RESTCONF is the IETF model-driven interface that maps YANG models onto HTTP methods and runs over HTTPS on TCP port 443. Setting the Accept header to application/yang-data+json tells the device to return JSON-encoded structured data rather than XML. This directly satisfies the requirement for a programmatic, model-driven interface over HTTPS without CLI screen-scraping.

Why this answer

RESTCONF is the IETF-defined protocol that exposes YANG-modeled data through HTTP methods and runs over HTTPS on port 443. By setting the Accept header to application/yang-data+json, the client receives JSON-encoded structured data instead of XML, avoiding CLI parsing entirely. NETCONF uses SSH on port 830, SNMP does not expose the configuration datastore, and Telnet screen-scraping is neither secure nor model-driven.

Exam trap

The trap here is assuming any model-driven protocol uses HTTPS, when NETCONF is actually carried as an SSH subsystem on port 830.

61
Multi-Selectmedium

A network engineer is designing a Python script to automate configuration changes on a fleet of Cisco IOS XE devices using the NETCONF protocol. The script must ensure that changes are atomic and that the device validates the configuration before committing. Which two NETCONF capabilities must the script check for during the capability exchange to guarantee these requirements? (Choose two.)

Select 2 answers
A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:startup:1.0
C.urn:ietf:params:netconf:capability:rollback-on-error:1.0
D.urn:ietf:params:netconf:capability:validate:1.0
E.urn:ietf:params:netconf:capability:writable-running:1.0
AnswersA, D

The candidate capability allows the script to edit the candidate datastore, validate changes, and commit them atomically. Without it, direct edits to the running datastore may not support rollback or validation, violating the atomicity requirement. Checking for this capability ensures the device supports the candidate configuration workflow.

Why this answer

To ensure atomic changes and pre-commit validation, the script must use the candidate datastore and the validate capability. The candidate capability allows editing a separate configuration, validating it, and committing atomically. The validate capability provides the <validate> RPC to check the candidate before commit.

Together, they satisfy both requirements; other capabilities do not provide both atomicity and validation.

Exam trap

The trap here is assuming that rollback-on-error alone guarantees atomicity and validation, but it only handles errors after commit and does not validate beforehand.

62
MCQeasy

A network engineer is new to automation and wants to use a Python script to configure a Cisco IOS XE device. The engineer prefers a protocol that uses HTTP methods and JSON for data encoding, as it is easier to read and debug. Which protocol should the engineer choose?

A.NETCONF
B.SNMP
C.RESTCONF
D.SSH with CLI commands
AnswerC

RESTCONF is designed to use HTTP methods (GET, POST, PUT, PATCH, DELETE) and supports both XML and JSON encoding. It is built on the same YANG models as NETCONF but provides a RESTful interface that is easier to work with, especially for those familiar with JSON and HTTP. This matches the engineer's preferences.

Why this answer

RESTCONF is the protocol that uses HTTP methods and supports JSON encoding, making it ideal for engineers who prefer a RESTful API. It leverages YANG models to structure data, providing a modern and readable way to automate Cisco IOS XE devices. The other protocols either use different encodings or are not based on HTTP.

Exam trap

The trap here is confusing RESTCONF with NETCONF, as both use YANG models; however, only RESTCONF is inherently HTTP- and JSON-friendly.

63
MCQhard

A network automation team is using Ansible to push configuration changes to a fleet of Cisco IOS XE devices. The playbook uses the 'ios_config' module with the 'backup: yes' option. During a recent run, the playbook failed on one device due to a syntax error in the configuration lines. The team wants to ensure that if a failure occurs, the device automatically reverts to its previous configuration without manual intervention. Which Ansible feature should be used to achieve this?

A.Use the 'ios_config' module with the 'rollback' parameter set to 'yes'.
B.Implement a 'block' and 'rescue' section in the playbook to run a rollback task if the configuration fails.
C.Set the 'ansible_command_timeout' to a higher value to prevent premature failure.
D.Enable 'config' mode with the 'save_when' parameter set to 'modified'.
AnswerB

Ansible's block/rescue structure allows error handling. The configuration task can be placed in a block, and if it fails, the rescue section can execute a rollback task, such as using 'cli_command' to run 'configure replace' with a previously saved configuration file. This provides automatic rollback without manual intervention, directly addressing the requirement.

Why this answer

To automatically revert to the previous configuration upon failure, the playbook must include error handling. Ansible's block/rescue construct allows tasks to be grouped, and if any task in the block fails, the rescue section runs. Within rescue, a task can invoke 'configure replace' using a saved configuration file, restoring the device to its prior state.

This approach ensures atomic rollback without manual intervention.

Exam trap

The trap here is assuming that the ios_config module has built-in rollback capabilities or that saving the configuration provides automatic recovery.

64
MCQeasy

A network engineer is using a Python script with the requests library to retrieve interface information from a Cisco IOS XE device via RESTCONF. The script sends a GET request to https://192.168.1.1/restconf/data/ietf-interfaces:interfaces but receives a 401 Unauthorized error. The engineer has verified that the device has RESTCONF enabled and the URL is correct. Which action should the engineer take to resolve the error?

A.Enable the RESTCONF-YANG feature on the device using the restconf-yang command in global configuration mode.
B.Change the request method from GET to POST to retrieve the interface information.
C.Configure the device to allow unauthenticated access by adding the 'restconf no-auth' command.
D.Include a valid username and password in the request using HTTP Basic Authentication.
AnswerD

A 401 Unauthorized error indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication. The engineer must include the username and password in the request headers. This is the standard method to authenticate RESTCONF requests. Without credentials, the device rejects the request, resulting in a 401 error.

Why this answer

A 401 Unauthorized error means the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires HTTP Basic Authentication. The engineer must include a valid username and password in the request headers.

This is the correct and secure way to authenticate RESTCONF requests.

Exam trap

The trap here is thinking that enabling RESTCONF is sufficient for access, when in fact authentication credentials must also be supplied with each request.

65
MCQhard

A large enterprise uses a centralized automation platform based on Ansible Tower to manage its network infrastructure. The network consists of 500 Cisco IOS XE routers and switches distributed across multiple sites. The automation team has created a playbook that configures BGP peerings on all devices. The playbook uses the ios_bgp module. Recently, during a maintenance window, the playbook was run against a subset of devices that were supposed to be upgraded to a new IOS XE version. However, after the run, several devices lost their BGP configurations entirely. The team discovers that the new IOS XE version introduced a new BGP configuration model that is not fully compatible with the ios_bgp module's expected CLI commands. The playbook failed silently on those devices, and the existing BGP configuration was removed. The team needs to prevent this from happening in future maintenance windows. Which action should be taken?

A.Add a pre-task that validates the device's OS version and conditionally applies the appropriate module or command set
B.Implement idempotency checks in the playbook using the 'check_mode' option
C.Set 'gather_facts: no' in the playbook to speed up execution and avoid version detection issues
D.Replace the ios_bgp module with the ios_config module and use raw CLI commands for BGP configuration
AnswerA

Running a pre-task that inspects ansible_net_version and then uses conditional logic to select either the native ios_bgp module or an alternative module (e.g., ios_config) ensures that the playbook aligns with the device's supported API and syntax. This avoids silent failures caused by module versions that do not recognize the running IOS release, and it is the recommended pattern for maintaining idempotent, OS-aware automation across a heterogeneous fleet.

Why this answer

It directly addresses the root cause: the new IOS XE version uses an incompatible BGP configuration model. By adding a pre-task that validates the OS version, the playbook can conditionally apply the correct module (e.g., ios_bgp for older versions or a different module/CLI for the new model), preventing silent failures and configuration loss. This ensures the automation adapts to version-specific changes, maintaining idempotency and safety.

Exam trap

Cisco often tests the misconception that idempotency (check_mode) or simply using raw CLI commands (ios_config) solves version incompatibility, when the real solution is version-aware conditional logic to handle model changes.

How to eliminate wrong answers

Option B is wrong because 'check_mode' only simulates changes without applying them; it does not prevent the ios_bgp module from removing existing BGP configs due to incompatibility, nor does it handle version-specific behavior. Option C is wrong because setting 'gather_facts: no' would skip version detection entirely, making the playbook blind to the OS version and increasing the risk of applying incompatible commands. Option D is wrong because replacing ios_bgp with ios_config and raw CLI commands bypasses Ansible's structured module logic, losing idempotency and validation, and still requires version-aware logic to avoid the same incompatibility issue.

66
MCQmedium

A network engineer is writing a Python script to retrieve the operational state of all GigabitEthernet interfaces from a Cisco IOS XE device using RESTCONF. The device is configured with HTTPS and the engineer has valid credentials. The script uses the 'requests' library to send a GET request to the RESTCONF API. Which HTTP header must be included in the request to specify that the client expects JSON-formatted data in the response?

A.Accept: application/json
B.Content-Type: application/json
C.Content-Type: application/yang-data+json
D.Accept: application/yang-data+json
AnswerD

This header tells the RESTCONF server that the client expects the response body in JSON format according to the YANG data model. Cisco IOS XE RESTCONF uses the media type 'application/yang-data+json' for JSON-encoded YANG data. Without it, the server may return XML or an error. This is the correct header to include.

Why this answer

To retrieve JSON-formatted data from a RESTCONF API on Cisco IOS XE, the client must include the Accept header with the value 'application/yang-data+json'. This media type is defined by RFC 8040 for RESTCONF and ensures the server returns the response in JSON according to the YANG model. The Content-Type header is only for request bodies, and 'application/json' is not the correct media type for RESTCONF.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.

67
MCQmedium

A network engineer is writing a Python script using the requests library to interact with a Cisco IOS XE device's RESTCONF API. The script needs to authenticate using basic authentication and retrieve interface details. The engineer writes the following code snippet: import requests url = 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) However, the script returns a 401 Unauthorized error. What is the most likely cause?

A.The credentials are incorrect or the user does not have sufficient privileges.
B.The verify=False parameter disables SSL verification, which causes the server to reject the request.
C.The Accept header is set incorrectly; it should be application/yang-data+xml.
D.The URL is missing the .json extension, which is required for RESTCONF.
AnswerA

A 401 Unauthorized error indicates authentication failure. The most likely cause is that the username or password is wrong, or the user account lacks the necessary permissions to access the RESTCONF API. The engineer should verify the credentials and ensure the user has appropriate privilege level (e.g., privilege 15).

Why this answer

A 401 Unauthorized response from RESTCONF means the authentication credentials are missing or invalid. The script uses basic authentication with a username and password; if those are incorrect or the user lacks permissions, the server rejects the request. The engineer should confirm the credentials and user privilege level.

Exam trap

The trap here is focusing on headers or URL formatting when a 401 error specifically indicates an authentication problem, not a content or syntax issue.

68
Multi-Selecthard

A network automation team is evaluating YANG models to manage Cisco IOS XE devices. They need to ensure that the models they choose can be used with both NETCONF and RESTCONF. Which two statements about YANG models are true in this context? (Choose two.)

Select 2 answers
A.YANG models can be augmented to add vendor-specific data.
B.YANG models can only define configuration data, not operational state data.
C.YANG models are written in XML and must be converted to JSON for RESTCONF.
D.YANG models are specific to NETCONF and cannot be used with RESTCONF.
E.YANG models define the data structure and semantics for configuration and state data.
AnswersA, E

YANG supports augmentation, allowing vendors to extend standard models with proprietary data. Cisco IOS XE uses augmentations to add features not covered by IETF or OpenConfig models. This is essential for managing Cisco-specific functionality. The statement is true and highlights the flexibility of YANG for vendor customization.

Why this answer

YANG is a data modeling language that defines both configuration and state data, and it is used by both NETCONF and RESTCONF. It supports augmentations for vendor-specific extensions. These characteristics make YANG suitable for multi-protocol automation.

The other statements are incorrect because they misrepresent YANG's protocol independence, encoding, or scope.

Exam trap

The trap here is assuming that YANG is tied to a single protocol or that it cannot model operational data, when in fact it is protocol-agnostic and covers both config and state.

69
MCQmedium

A network engineer is writing a Python script to retrieve the list of interfaces from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces and receives a 401 Unauthorized response. The device is reachable, and RESTCONF is enabled. The engineer verifies that the username and password are correct. Which action should the engineer take to resolve the issue?

A.Configure the HTTP client to use basic authentication with the correct credentials.
B.Enable the RESTCONF API using the 'restconf' command under global configuration.
C.Change the request method from GET to POST.
D.Add the header 'Accept: application/yang-data+json' to the request.
AnswerA

A 401 Unauthorized response means the request lacks valid authentication credentials. RESTCONF uses HTTP authentication, typically basic auth. The engineer must include an Authorization header with the base64-encoded username:password. Even if the credentials are correct, they must be sent in the request. The script likely omitted the auth parameter, causing the server to reject the request. Adding basic authentication resolves the issue.

Why this answer

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. RESTCONF relies on HTTP authentication, so the client must include an Authorization header, typically using basic authentication. Even if the username and password are correct, they must be transmitted with the request.

The other options address different issues: content negotiation, API enablement, or HTTP method, none of which cause a 401. Therefore, configuring basic authentication is the correct fix.

Exam trap

The trap here is assuming that a 401 error means incorrect credentials, when it often means credentials were never sent.

70
Multi-Selecthard

A network engineer is designing a Python script that uses the YANG models supported by a Cisco IOS XE device to configure interface descriptions via RESTCONF. The engineer wants to ensure the script uses the correct data model and avoids errors. Which TWO actions should the engineer take? (Choose two.)

Select 2 answers
A.Verify the YANG module revision date to ensure compatibility with the IOS XE version running on the device.
B.Use the 'Content-Type: application/yang-data+xml' header for all RESTCONF requests to ensure compatibility with YANG models.
C.Use the Cisco IOS XE native YANG model 'Cisco-IOS-XE-native' for interface configuration, as it is always available and supports all features.
D.Retrieve the list of supported YANG modules using the RESTCONF API endpoint /restconf/data/ietf-yang-library:modules-state.
E.Assume that all YANG modules are available on all IOS XE devices, so no verification is needed.
AnswersA, D

YANG modules are versioned with revision dates. A module revision may change between IOS XE releases, and using an outdated or mismatched revision can cause errors. By checking the revision date from the yang-library, the engineer can ensure the script uses the correct model version for the device's software, preventing schema mismatches.

Why this answer

To configure interfaces via RESTCONF using YANG models, the engineer must first discover which YANG modules are supported by the device. The ietf-yang-library provides this information, including module names, revisions, and features. Checking the revision date ensures the script uses the correct version for the device's software.

These two actions prevent schema errors and ensure successful configuration.

Exam trap

The trap here is assuming that all YANG modules are universally available or that the native model is always the correct choice, without verifying support and revision compatibility.

71
Multi-Selectmedium

A network engineer is designing a Python script that uses the YANG models supported by a Cisco IOS XE device to retrieve interface statistics via NETCONF. The engineer wants to ensure the script can parse the response and extract the operational data. Which two steps are necessary when using the ncclient library to retrieve and process the data? (Choose two.)

Select 2 answers
A.Enable the :candidate capability on the device to retrieve statistics
B.Parse the XML response using a library like xml.etree.ElementTree or lxml
C.Convert the XML response to JSON using the ncclient library
D.Use the <get> RPC with a filter specifying the interface statistics subtree
E.Use the <edit-config> RPC to read the interface statistics
AnswersB, D

NETCONF returns data in XML format. To extract specific values, the script must parse the XML. Libraries such as xml.etree.ElementTree or lxml allow navigation of the XML tree. This step is necessary to process the response and retrieve the statistics values for further use.

Why this answer

To retrieve interface statistics via NETCONF, the script must send a <get> RPC with a filter to target the specific data. The response is XML, so parsing it with an XML library is required to extract values. Other options like <edit-config> or :candidate are for configuration management, not data retrieval.

Exam trap

The trap here is thinking that ncclient automatically converts XML to JSON or that <edit-config> can be used for reading data, but NETCONF uses XML and <get> for retrieval.

72
MCQmedium

A network engineer is building a Python script to configure a Cisco IOS XE device via RESTCONF. The script sends a POST request to the URI https://10.1.1.1/restconf/data/ietf-interfaces:interfaces with the JSON payload shown. The device returns HTTP 415 Unsupported Media Type. Which change to the script will resolve the error?

A.Add the header 'Accept: application/yang-data+json' to the request.
B.Include authentication credentials in the request body.
C.Change the HTTP method from POST to PUT.
D.Add the header 'Content-Type: application/yang-data+json' to the request.
AnswerD

RESTCONF requires the Content-Type header to be application/yang-data+json when sending a JSON payload. Without it, the device cannot determine the payload format and returns 415. Adding this header tells the server the body is YANG data encoded in JSON, allowing it to parse and apply the configuration.

Why this answer

RESTCONF uses HTTP and requires standard headers to indicate payload format. When sending JSON, the Content-Type header must be set to application/yang-data+json. The server uses this to select the correct parser.

Without it, the device returns 415 Unsupported Media Type, indicating it cannot process the body.

Exam trap

The trap here is confusing the Accept header (which specifies the desired response format) with the Content-Type header (which specifies the format of the request body).

73
MCQhard

A network automation engineer is using the ncclient Python library to retrieve configuration from a Cisco IOS XE device via NETCONF. The engineer sends a <get-config> RPC with a filter for the interface configuration. The device returns a large XML response, but the engineer only needs the interface description and IP address. Which NETCONF capability should the engineer use to filter the response to only the required data?

A.urn:ietf:params:netconf:capability:subtree:1.0
B.urn:ietf:params:netconf:capability:xpath:1.0
C.urn:ietf:params:netconf:capability:writable-running:1.0
D.urn:ietf:params:netconf:capability:rollback-on-error:1.0
AnswerA

The subtree filtering capability allows the client to specify a filter that selects only the desired subtrees of the configuration data. By using a subtree filter, the engineer can request only the interface description and IP address, reducing the response size and processing. This is the standard way to filter NETCONF responses.

Why this answer

NETCONF supports filtering of configuration data through capabilities. The subtree filtering capability allows a client to specify a filter that matches only the desired portions of the configuration tree. By using a subtree filter, the engineer can retrieve only the interface description and IP address, minimizing the response size and improving efficiency.

Other capabilities like writable-running or rollback-on-error do not provide filtering.

Exam trap

The trap here is confusing filtering capabilities with other NETCONF capabilities that deal with write operations or error handling, such as writable-running or rollback-on-error.

74
MCQeasy

A network administrator is introducing infrastructure as code for Cisco IOS XE switches. The team wants to store device configurations in a version-controlled repository and apply changes only after peer review. They need a tool that can enforce the desired state and report drift without making changes during the review phase. Which tool should they use to meet these requirements?

A.SNMP polling with a custom monitoring dashboard
B.Cisco Network Services Orchestrator (NSO) with commit queues
C.Ansible with the ios_config module in check mode
D.Python script using Netmiko to push configuration commands directly
AnswerC

Ansible's check mode (--check) allows the playbook to run without applying changes, reporting what would be modified. This supports peer review and drift detection. The ios_config module can compare the running configuration against the desired lines and indicate differences. This aligns with infrastructure as code principles by enabling safe validation before actual deployment, making it the correct choice.

Why this answer

Ansible's check mode allows the playbook to simulate changes and report drift without modifying the device. This supports peer review and infrastructure as code by validating the desired state before applying. The other tools either lack built-in dry-run capabilities or are not designed for configuration review workflows.

Exam trap

The trap here is assuming that any automation tool can perform dry runs, when in fact only some tools like Ansible have explicit check mode support.

75
MCQhard

A network engineer is developing a Python script that uses the requests library to send a RESTCONF PATCH request to a Cisco IOS XE device. The script includes the header 'Content-Type: application/yang-data+json' and sends a JSON payload to update the description of an interface. The device returns HTTP 400 Bad Request. Which is the most likely cause?

A.The PATCH method is not supported by RESTCONF; PUT should be used instead.
B.The Content-Type header should be 'application/json' instead of 'application/yang-data+json'.
C.The JSON payload is not formatted according to the YANG model structure for the interface description.
D.The device does not support RESTCONF and requires NETCONF for configuration changes.
AnswerC

RESTCONF requires the payload to conform to the YANG model. If the JSON structure does not match the expected hierarchy, such as missing the 'ietf-interfaces:interface' container or incorrect nesting, the device will reject it with HTTP 400. This is the most likely cause. The engineer must ensure the payload follows the YANG model exactly.

Why this answer

An HTTP 400 Bad Request from a RESTCONF PATCH typically indicates that the request body does not conform to the YANG model structure. The payload must be correctly nested according to the model, such as including the module name and proper containers. The Content-Type is correct for RESTCONF JSON.

The PATCH method is supported. Therefore, the most likely cause is a malformed JSON payload that violates the YANG model.

Exam trap

The trap here is assuming that any JSON is acceptable, when RESTCONF requires strict adherence to the YANG model structure.

Page 1 of 2 · 122 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Automation questions.