200-901 Infrastructure and Automation Practice Question
A developer is writing a Python script to interact with a Cisco IOS XE device using the NETCONF protocol. The script must retrieve the running configuration and then modify it. Which two actions must the script perform to establish a NETCONF session and retrieve the running configuration? (Choose two.)
⚠ Common exam trap
Many candidates confuse NETCONF with RESTCONF, leading to assumptions about HTTPS and port 443, or mixing up the <get> and <get-config> RPCs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Open an SSH session to the device on port 830 and exchange <hello> messages.
To establish a NETCONF session, the client opens an SSH connection to port 830 and exchanges <hello> messages with the server. Once the session is established, the client can send RPCs. To retrieve the running configuration, the client sends a <get-config> RPC with <source><running/></source>. The other options either use the wrong RPC, the wrong transport, or an operation that does not read configuration into the session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Open an SSH session to the device on port 830 and exchange <hello> messages.
Why this is correct
NETCONF uses SSH as its transport, and the default port is 830. After the SSH connection is established, the server and client exchange <hello> messages to advertise capabilities and session IDs. This handshake is mandatory before any RPCs can be sent, so opening the SSH session and exchanging hellos is a required step.
- ✗
Send a <get> RPC with a filter of <config/> to retrieve the running configuration.
Why it's wrong here
The <get> RPC retrieves both state data and configuration data, but it does not take a datastore source. Using a filter of <config/> is not a standard way to target the running configuration. The correct operation for retrieving configuration from a specific datastore is <get-config> with <source><running/></source>, so this option is incorrect.
- ✓
Send a <get-config> RPC with a <source> of <running/> to retrieve the running configuration.
Why this is correct
The <get-config> RPC is used to retrieve configuration data from a specified datastore. To get the running configuration, the <source> element must contain <running/>. This is the standard NETCONF operation for reading configuration, and it is required to obtain the running config as described in the scenario.
- ✗
Authenticate using the NETCONF username and password over HTTPS on port 443.
Why it's wrong here
NETCONF over SSH uses port 830 by default, not HTTPS on port 443. While NETCONF can be tunneled over TLS in some implementations, the standard and most common transport for Cisco IOS XE is SSH. HTTPS is associated with RESTCONF, not NETCONF. Therefore, this option does not describe a valid NETCONF session establishment step.
- ✗
Use the <copy-config> RPC to copy the running datastore to a local file.
Why it's wrong here
The <copy-config> RPC copies configuration between datastores or to a specified target. It is not used to retrieve configuration for display or further processing in the way described. The scenario requires reading the running configuration, which is done with <get-config>, not by copying it to a file.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.