200-901 Infrastructure and Automation Practice Question
A network engineer is using Ansible to automate configuration changes on Cisco IOS XE devices. The engineer wants to ensure that the playbook applies a set of configuration lines only if they are not already present. Which Ansible module should be used to achieve idempotent configuration management?
⚠ Common exam trap
Candidates often confuse modules that execute commands or gather facts with those that enforce configuration state; only ios_config provides idempotent configuration line management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ios_config
The ios_config module is the correct choice because it is specifically built for idempotent configuration management on Cisco IOS devices. It checks the running configuration and only applies missing lines, ensuring the device reaches the desired state without redundant changes. The other modules either execute commands, manage specific resources like VLANs, or gather facts, none of which fulfill the requirement to apply arbitrary configuration lines idempotently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ios_command
Why it's wrong here
The ios_command module is used to execute arbitrary show commands and retrieve output. It does not modify configuration and is not idempotent for configuration changes. Using it to apply configuration would require manually checking and applying changes, which is error-prone and not the intended use.
- ✗
ios_vlan
Why it's wrong here
The ios_vlan module is specialized for managing VLANs on Cisco IOS devices. It is not suitable for applying arbitrary configuration lines. While it is idempotent for VLAN operations, it cannot handle the general configuration lines described in the scenario, making it incorrect for this task.
- ✗
ios_facts
Why it's wrong here
The ios_facts module gathers facts about the device, such as interfaces and configuration, but does not apply any configuration. It is read-only and cannot enforce desired state. Therefore, it cannot be used to ensure configuration lines are present, and it does not provide idempotent configuration management.
- ✓
ios_config
Why this is correct
The ios_config module is designed for managing configuration on Cisco IOS devices. It is idempotent by default: it compares the desired configuration lines with the running configuration and only applies changes if they are missing. This makes it the correct choice for ensuring configuration lines are present without duplication.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.