Courseiva

200-901 Infrastructure and Automation Practice Question

A network automation team is comparing configuration management tools for managing Cisco IOS XE devices. They want to understand which TWO statements accurately describe how Ansible differs from Puppet in this context. (Choose two.)

⚠ Common exam trap

The trap here is assuming both tools share the same agent model, when Ansible is agentless and Puppet's classic design depends on an agent checking in with a master.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ansible playbooks are written in YAML and executed in order, while Puppet manifests use a declarative DSL where resource ordering is largely determined by dependency metadata.

Ansible is agentless and push-based, using YAML playbooks executed in sequence, while Puppet traditionally uses agents and a declarative DSL with dependency-driven ordering. Those two architectural and authoring differences are accurate. The remaining statements invert the architectures, misstate module languages and transports, or wrongly claim both tools need a persistent agent on the network device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Puppet modules for network devices are executed as Python scripts over NETCONF, while Ansible modules for network devices are always compiled Ruby extensions.

    Why it's wrong here

    Both ecosystems use a mix of languages and transports. Ansible network modules are commonly Python and use SSH or API calls, while Puppet has Ruby-based providers and also supports transports like NETCONF and REST. Claiming a fixed language-to-transport mapping misrepresents how each tool actually integrates with network devices.

  • ✗

    Ansible requires a central server called a master, while Puppet runs entirely from a developer workstation without any server component.

    Why it's wrong here

    This reverses the architectures. Ansible typically runs from a control node without a mandatory central master service, whereas Puppet classically uses a Puppet master or Puppet Server to compile catalogs. Stating that Ansible needs a master and Puppet does not is factually inverted and does not describe the tools accurately.

  • ✗

    Ansible and Puppet both require the managed Cisco IOS XE device to run a persistent agent daemon for configuration changes to be applied.

    Why it's wrong here

    Requiring a persistent agent on IOS XE is not feasible for most deployments, and Ansible specifically avoids it. Puppet can use proxy or device-specific transports rather than a full agent on the switch. This statement is therefore inaccurate for both tools in the network automation context described.

  • ✓

    Ansible playbooks are written in YAML and executed in order, while Puppet manifests use a declarative DSL where resource ordering is largely determined by dependency metadata.

    Why this is correct

    Ansible tasks run top to bottom in the order written unless handlers or includes change flow, giving imperative-style sequencing. Puppet describes desired end state and uses relationships like require and notify to order resources. This difference affects how engineers reason about convergence and troubleshooting in network automation.

  • ✓

    Ansible uses an agentless architecture and connects to managed devices over SSH or API, while Puppet traditionally requires an agent installed on the managed node.

    Why this is correct

    Ansible pushes modules over SSH or HTTPS and needs no long-running agent on the target, which suits network devices that cannot host arbitrary software. Puppet's classic model relies on a puppet agent that checks in with a master. This architectural difference is a defining distinction between the two tools for network automation.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.