Courseiva

200-901 Infrastructure and Automation Practice Question

A network automation team is evaluating tools to manage configuration drift across a fleet of Cisco IOS XE devices. They want to ensure that device configurations remain in the desired state and that any unauthorized changes are detected and remediated. Which two capabilities are essential for a configuration drift detection and remediation solution in this environment? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse operational monitoring (like telemetry or SNMP traps) with configuration drift detection, which requires active baseline comparison and automated remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated remediation that pushes the baseline configuration back to the device when drift is detected.

A configuration drift detection and remediation solution must first identify when a device's configuration deviates from the baseline. This requires periodic collection and comparison. Once drift is found, the solution must be able to automatically restore the correct configuration. These two capabilities form the core loop of detect and remediate. Other features like telemetry, version control, or SNMP traps are useful supplements but not essential for the fundamental task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use of SNMP traps to alert on configuration change events.

    Why it's wrong here

    SNMP traps can notify about certain events, but they are not reliable for detecting all configuration changes, especially those made via CLI or API that do not generate traps. Relying solely on SNMP traps would miss many drift scenarios. A robust solution requires active configuration collection and comparison. Thus, SNMP traps alone are not an essential capability for comprehensive drift detection.

  • ✓

    Automated remediation that pushes the baseline configuration back to the device when drift is detected.

    Why this is correct

    Detecting drift is only half the solution; the team must also be able to remediate it. Automated remediation involves generating and applying the necessary configuration commands to restore the device to the baseline. This can be achieved with tools like Ansible playbooks or custom scripts that use NETCONF edit-config. Without automated remediation, drift would require manual intervention, which is error-prone and slow. This capability is essential for a complete solution.

  • ✗

    Real-time streaming telemetry with sub-second granularity for all interface counters.

    Why it's wrong here

    Streaming telemetry provides high-frequency operational data, which is valuable for performance monitoring, but it is not essential for configuration drift detection. Drift detection focuses on configuration state, not real-time counters. While telemetry can alert on some changes, it does not provide a full configuration baseline comparison. Therefore, this capability is not a core requirement for drift detection and remediation.

  • ✗

    Integration with a version control system to store configuration history and track changes.

    Why it's wrong here

    Version control is highly beneficial for auditing and rollback, but it is not strictly essential for detecting and remediating drift. Drift detection can function by comparing current configurations to a baseline stored anywhere, and remediation can push a known-good configuration without version control. While version control adds significant value, it is not a mandatory capability for the core drift detection and remediation workflow.

  • ✓

    Periodic collection of device configurations and comparison against a baseline.

    Why this is correct

    To detect drift, the solution must regularly gather the current running configuration from each device and compare it to a known-good baseline. This periodic collection can be scheduled via tools like Ansible, Python scripts using NETCONF/RESTCONF, or dedicated platforms. Without this continuous comparison, unauthorized changes would go unnoticed. This capability is fundamental to any drift detection strategy, making it a correct choice.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.