A network engineer is using the ncclient Python library to send NETCONF RPCs to a Cisco IOS XE device. The engineer wants to lock the running configuration datastore before making changes to prevent other NETCONF sessions from modifying it concurrently. Which NETCONF operation should be used?
The <lock> operation is used to lock a datastore, preventing other sessions from modifying it. The <target> element specifies which datastore to lock, in this case <running/>. This ensures exclusive access for the session. The lock must be released with <unlock> after changes are made. This is the correct operation to prevent concurrent modifications.
Why this answer
NETCONF provides a <lock> operation to lock a datastore, preventing other sessions from modifying it. The <target> element specifies the datastore to lock. On Cisco IOS XE, only the running datastore is supported, so the correct target is <running/>.
Locking ensures that no other NETCONF session can edit the configuration until the lock is released with <unlock>. This is essential for maintaining configuration integrity during automation.
Exam trap
The trap here is assuming that Cisco IOS XE supports the candidate datastore like some other vendors; IOS XE only supports the running datastore.