200-901 Infrastructure and Automation Practice Question
A network automation team is evaluating tools to manage the configuration of Cisco IOS XE devices. They need a solution that uses a declarative, agentless approach and can be extended with custom modules. Which two characteristics describe Ansible in this context? (Choose two.)
⚠ Common exam trap
The trap here is mixing up Ansible with agent-based tools like Puppet or Chef, which use Ruby or a master-agent model and maintain a central database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It uses a declarative playbook written in YAML to define the desired state of the network.
Ansible is an agentless automation tool that connects to managed nodes over SSH or other protocols, and it uses declarative YAML playbooks to define desired state. These two characteristics distinguish it from agent-based tools like Puppet or Chef, which require agents and use their own domain-specific languages. The team's need for agentless and declarative automation is met by these features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It uses a declarative playbook written in YAML to define the desired state of the network.
Why this is correct
Ansible playbooks are written in YAML and describe the desired end state of the system. The playbook contains tasks that use modules to enforce that state. This declarative model allows the automation to be idempotent and readable, which aligns with the team's requirement for a declarative approach.
- ✗
It maintains a local database of device configurations and enforces them periodically.
Why it's wrong here
Ansible does not maintain a central database of configurations. It executes playbooks on demand and pushes changes to devices. Periodic enforcement would require scheduling, but the tool itself does not store configuration state in a database. This describes more of a pull-based system with a central store.
- ✗
It uses Ruby-based manifests to define infrastructure as code.
Why it's wrong here
Ruby-based manifests are used by Puppet. Ansible uses YAML playbooks, not Ruby. While Ansible modules are written in Python, the playbooks themselves are YAML. This option mischaracterizes the tool and would not meet the team's requirement.
- ✓
It uses SSH to connect to network devices and does not require a software agent on the managed nodes.
Why this is correct
Ansible is agentless and typically connects to network devices over SSH or NETCONF. For Cisco IOS XE, it uses SSH to run CLI commands or NETCONF for structured data. This eliminates the need to install and maintain agent software on the devices, which is a key advantage for network automation.
- ✗
It requires a central server called a master and agents installed on each managed device.
Why it's wrong here
This describes a pull-based configuration management tool like Puppet or Chef, not Ansible. Ansible is agentless and does not require a master-agent architecture. It pushes modules over SSH or other protocols, so no agent is installed on the managed devices.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.