mediumMultiple Choice
CCNP Practice Question: Uses NAPALM to retrieve the ARP table from a…
A network engineer uses NAPALM to retrieve the ARP table from a Cisco IOS-XE device:
```python
from napalm import get_network_driver
driver = get_network_driver('ios') device = driver('192.168.1.1', 'admin', 'cisco123') device.open() arp_table = device.get_arp_table()
print(arp_table)
device.close() ```
What is the expected data type of arp_table?
⚠ Common exam trap
Cisco often tests the misconception that NAPALM returns raw CLI output (Option C) or a nested dictionary (Option B), when in fact it returns a list of dictionaries for table-like data such as ARP tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of dictionaries, each with keys such as 'interface', 'ip', 'mac', and 'age'.
NAPALM's `get_arp_table()` method returns a list of dictionaries, where each dictionary represents a single ARP entry with keys such as 'interface', 'ip', 'mac', and 'age'. This is the standardized data structure across all NAPALM-supported platforms, including Cisco IOS-XE, ensuring consistent programmatic access to ARP table data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A list of dictionaries, each with keys such as 'interface', 'ip', 'mac', and 'age'.
Why this is correct
NAPALM's get_arp_table() method returns a list of dictionaries, not raw text or a custom wrapper. Each dictionary represents a single ARP entry and includes structured keys such as 'interface', 'ip', 'mac', and 'age', making the data directly usable in Python logic such as filtering or comparison. This is the expected data model for NAPALM across multiple network platforms, because it normalizes vendor-specific CLI output into a consistent, machine-readable format.
- ✗
A dictionary with keys 'arp_table' and a list of tuples.
Why it's wrong here
NAPALM does not wrap the ARP result in a top-level dictionary with a key like 'arp_table'; that pattern might be seen in other libraries or custom scripts, but NAPALM's get_arp_table() returns the list itself. Additionally, even if a wrapper existed, the entries would be dictionaries, not tuples, because NAPALM uses key-value pairs to represent each structured field. This option conflates the library's return type with an arbitrary dict-of-tuples structure that is not part of NAPALM's API contract.
- ✗
A string containing the raw CLI output of 'show arp'.
Why it's wrong here
NAPALM's primary purpose is to return structured, vendor-neutral data, so it parses the underlying CLI output into native Python objects rather than passing through the raw string from 'show arp'. NAPALM internally relies on network drivers (e.g., napalm-ios, napalm-eos) that use tools like TextFSM or vendor APIs to extract and convert the output. A raw string would force users to write their own regex or parser, defeating the automation value that NAPALM provides, so this option incorrectly describes the library's output type.
- ✗
A list of strings, each representing an ARP entry.
Why it's wrong here
Each ARP entry in NAPALM's return value is not a simple string; it is a dictionary whose keys ('interface', 'ip', 'mac', 'age') map to the corresponding attribute values for that entry. A list of strings would lack the structured, per-field access that network automation tasks require, such as checking a specific MAC address or sorting by age. NAPALM deliberately returns dictionaries because they allow clear, maintainable data access by key rather than relying on string indexing or parsing, making this option an incorrect characterization of the data format.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.