Courseiva

200-901 Infrastructure and Automation Practice Question

A network engineer is troubleshooting an Ansible playbook that targets Cisco IOS XE devices over SSH. The playbook connects successfully but fails when applying configuration, and the engineer suspects the connection plugin and transport settings. Which TWO actions should the engineer take to verify and correct the connection configuration? (Choose two.)

⚠ Common exam trap

The trap here is treating a network device like a Linux host, assuming local execution or sudo-style escalation applies, when network_cli and enable mode are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confirm that ansible_connection is set to network_cli for the device group.

Network automation with Ansible requires the network_cli connection plugin and a correct ansible_network_os value so the right terminal and module behavior is selected. Using the local connection, switching to the NETCONF port, or applying Linux privilege escalation semantics all misrepresent how IOS XE devices are managed. Confirming the connection type and platform identifier addresses the most common causes of successful login but failed configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Confirm that ansible_connection is set to network_cli for the device group.

    Why this is correct

    Network devices are not managed like Linux hosts with an SSH shell that Ansible can script arbitrarily. The network_cli connection plugin opens an interactive CLI session, handles prompts, and enables the platform-specific modules to push configuration. If the connection is left at the default ssh or paramiko setting, configuration modules may load but fail to apply changes because they cannot drive the device CLI correctly.

  • ✗

    Increase the ansible_port value to 830 to enable configuration over SSH.

    Why it's wrong here

    Port 830 is the default for NETCONF over SSH, not for the CLI-based network_cli transport, which connects on port 22. Changing the port to 830 for IOS XE devices managed with network_cli would cause connection failures because the device is not listening for CLI sessions there. This action misidentifies the transport and would not resolve configuration application problems.

  • ✓

    Verify that ansible_network_os is set to ios for the IOS XE hosts.

    Why this is correct

    The ansible_network_os variable tells Ansible which platform-specific module set and terminal behavior to use. For Cisco IOS and IOS XE devices, the value is ios, which selects the correct terminal plugin for prompts, paging, and privilege escalation. Without it, the network_cli plugin cannot determine how to interact with the device, and tasks fail during connection or configuration parsing.

  • ✗

    Configure ansible_become_method to enable and use sudo on the device.

    Why it's wrong here

    Cisco IOS XE does not use sudo; privilege escalation is handled through the enable mode and the ansible_become and ansible_become_method settings configured for the network platform. Applying sudo semantics to a network operating system is incorrect and would not grant the privileges needed to enter configuration mode. The correct approach is to supply enable credentials through the appropriate network variables.

  • ✗

    Set ansible_connection to local and run all modules on the control node.

    Why it's wrong here

    The local connection runs tasks on the Ansible control node itself rather than on the target device. While legacy provider-based modules sometimes ran locally, modern network modules expect a persistent connection to the device through network_cli. Forcing local execution would cause configuration tasks to target the control node's environment, not the IOS XE device, and the playbook would not apply changes as intended.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.