200-901 Network Fundamentals Practice Question
A network automation script on a Cisco IOS XE device needs to retrieve the current running configuration and then compare it against a known-good baseline stored on a Git server. The script must use a protocol that encrypts all data in transit and supports programmatic, structured retrieval of the configuration without screen-scraping. Which approach should the script use?
⚠ Common exam trap
The trap here is assuming that SSH alone makes a CLI-scraping approach acceptable, when the structured, programmatic retrieval requirement rules out parsing show running-config.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use NETCONF over SSH on port 830 with the <get-config> operation and source <running/>.
NETCONF over SSH provides an encrypted, standards-based transport on port 830 and represents configuration as structured XML in datastores. The <get-config> operation with a running source returns the device configuration in a machine-parseable form, avoiding the fragility of CLI scraping. This satisfies both the encryption requirement and the need for reliable, programmatic retrieval for baseline comparison.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use NETCONF over SSH on port 830 with the <get-config> operation and source <running/>.
Why this is correct
NETCONF over SSH encrypts the session and exposes configuration as structured XML, so the script can retrieve the running datastore with <get-config> and parse it reliably. It avoids parsing CLI text and matches the requirement for programmatic, structured retrieval over an encrypted transport, which is exactly what the scenario demands for automated comparison.
- ✗
Use SSH on port 22 and parse the output of the show running-config command.
Why it's wrong here
SSH encrypts the session, but parsing show running-config is still screen-scraping rather than structured retrieval. The output can include banners, pagination prompts, and formatting that vary by platform and version, making automated comparison unreliable. The scenario explicitly requires structured programmatic retrieval, which this method does not provide.
- ✗
Use SNMPv3 with authPriv to walk the ifTable and reconstruct the configuration.
Why it's wrong here
SNMPv3 authPriv does encrypt and authenticate, but MIB objects expose operational and interface data, not the full running configuration. Reconstructing a device configuration from SNMP tables is neither complete nor reliable, so this approach cannot satisfy the requirement to retrieve and compare the running configuration against a baseline.
- ✗
Use Telnet on port 23 and parse the output of the show running-config command.
Why it's wrong here
Telnet sends all data, including credentials and configuration, in cleartext, which violates the encryption requirement. Screen-scraping show running-config is also brittle because output formatting and pagination can change, so it cannot provide the structured, programmatic retrieval the script needs for reliable baseline comparison.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.