Courseiva

200-901 Infrastructure and Automation Practice Question

A network automation team wants to run a Python script that uses the ncclient library to retrieve configuration from a Cisco IOS XE device over NETCONF. The device is reachable on TCP port 830. Which transport and port combination must the script use?

⚠ Common exam trap

It's easy for candidates to confuse the standard SSH CLI port 22 with the dedicated NETCONF-over-SSH port 830, which serve different services on the same device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH transport on TCP port 830

NETCONF on Cisco IOS XE is exposed as an SSH subsystem on TCP port 830. The ncclient library negotiates the SSH transport and then exchanges XML capabilities and RPCs. Using SSH on the NETCONF port is the documented combination, so the script must target TCP 830 rather than the standard CLI port or a TLS-based alternative.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTP transport on TCP port 80

    Why it's wrong here

    NETCONF is not carried over plain HTTP, and port 80 is used by web services, not by the NETCONF subsystem. A script attempting an HTTP transport to port 80 would not speak the NETCONF framing and would be rejected or time out long before any configuration could be retrieved.

  • ✗

    SSH transport on TCP port 22

    Why it's wrong here

    Port 22 carries the normal CLI SSH service on IOS XE, not the NETCONF subsystem. Connecting there with ncclient would open an interactive shell rather than a NETCONF session, so capability exchange and get-config operations would fail even though the TCP connection succeeds.

  • ✓

    SSH transport on TCP port 830

    Why this is correct

    NETCONF runs over an SSH subsystem and Cisco IOS XE listens on TCP port 830 for NETCONF sessions. The ncclient library's connect method uses the SSH transport by default, so specifying port 830 with SSH is the correct combination for retrieving configuration from the device.

  • ✗

    TLS transport on TCP port 6513

    Why it's wrong here

    NETCONF over TLS exists as a separate standard and uses TCP port 6513, but this scenario describes a Cisco IOS XE device with NETCONF reachable on port 830. Choosing TLS on 6513 would connect to the wrong service, if anything, and ncclient would fail to establish a session.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.