Courseiva

200-901 Infrastructure and Automation Practice Question

A developer must build a Python script that reads a list of devices from a YAML inventory file and then pushes configuration to each device using NETCONF over SSH. The script must be reusable and must not hardcode credentials. Which approach best satisfies these requirements?

⚠ Common exam trap

The trap here is assuming that any SSH-based library can speak NETCONF, when NETCONF requires specific XML framing and capability negotiation that generic SSH tools do not provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the ncclient library, load the inventory with PyYAML, and retrieve credentials from environment variables.

The scenario requires a NETCONF client, a YAML parser, and externalized credentials. ncclient provides the NETCONF over SSH capability, PyYAML reads the inventory, and environment variables keep secrets out of the code. Together these choices meet both the protocol and the reusability requirements without embedding sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use paramiko to open an interactive SSH shell and type configuration commands into the CLI prompt.

    Why it's wrong here

    paramiko opens a generic SSH channel, but NETCONF requires specific framing and XML capabilities negotiation. Trying to type CLI commands into an SSH shell does not use the NETCONF protocol and would not work against a NETCONF-only endpoint. It also ignores the YAML inventory requirement.

  • ✗

    Use the requests library to POST XML configuration directly to the device management IP on port 830.

    Why it's wrong here

    NETCONF uses SSH on port 830, not HTTP, so the requests library cannot speak the NETCONF protocol. Sending raw XML over HTTP to that port would fail because no HTTP server is listening. This option also does not address reading the YAML inventory or avoiding hardcoded credentials.

  • ✗

    Use the ncclient library and hardcode the device list and credentials inside the script for simplicity.

    Why it's wrong here

    ncclient is the correct library, but hardcoding the device list and credentials directly contradicts the requirement that the script be reusable and not embed secrets. Any credential rotation or inventory change would require editing the script, which is exactly what the scenario forbids.

  • ✓

    Use the ncclient library, load the inventory with PyYAML, and retrieve credentials from environment variables.

    Why this is correct

    ncclient is the standard Python library for NETCONF sessions and supports SSH transport. PyYAML parses the inventory file without hardcoding device data. Reading credentials from environment variables keeps secrets out of source code, which satisfies the reusability and security requirements described in the scenario.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.