200-901 Infrastructure and Automation Practice Question
A network engineer is using Ansible to automate configuration changes on a group of Cisco IOS XE devices. The engineer wants to ensure that the playbook only makes changes if the device configuration differs from the desired state, and that the playbook reports whether any changes were made. Which Ansible feature should the engineer rely on?
⚠ Common exam trap
The trap here is thinking that any Ansible feature that controls execution, like tags or conditionals, also provides idempotency, when idempotency is a property of the module itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Idempotent modules that report changed status
Ansible network modules like ios_config are idempotent and report a changed status. They compare the desired configuration with the running configuration and only apply differences, then indicate whether any change occurred. This satisfies both the need to avoid unnecessary changes and to know when changes were made. Handlers, tags, and conditionals serve different purposes and do not provide this behavior on their own.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditionals using the when clause
Why it's wrong here
The when clause allows tasks to be skipped based on conditions, but it does not inherently make a module idempotent. The engineer would have to write complex conditions to compare configurations, which is unnecessary because Ansible network modules already handle idempotency internally. Conditionals are useful for other logic but are not the primary feature for this requirement.
- ✗
Tags that limit which tasks run
Why it's wrong here
Tags allow selective execution of tasks or roles, but they do not affect whether a task makes changes based on current state. Even with tags, a non-idempotent module could still apply changes every time it runs. Tags are about controlling execution scope, not about idempotency or change reporting.
- ✗
Handlers that run only when notified
Why it's wrong here
Handlers are tasks that run only when notified by another task that reports a change. While they can be used to trigger actions after a change, they do not themselves ensure idempotency or prevent unnecessary configuration changes. The core idempotency comes from the modules used in the tasks, not from handlers.
- ✓
Idempotent modules that report changed status
Why this is correct
Ansible modules such as ios_config are designed to be idempotent, meaning they only apply changes when the current configuration differs from the desired state. They also return a 'changed' status that indicates whether any modification occurred. This directly supports the requirement to avoid unnecessary changes and to report whether changes were made.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.