Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 1–75

975 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQmedium

A developer is creating a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. Which HTTP method should be used to get the data?

A.GET
B.POST
C.PUT
D.DELETE
AnswerA

GET retrieves representations of a resource without altering device state, satisfying the read-only requirement for interface statistics. RESTCONF maps this to the NETCONF `<get>` operation, returning data in JSON or XML. POST, PUT, PATCH and DELETE would create, replace, modify or remove configuration, which the scenario does not request.

Why this answer

RESTCONF uses standard HTTP methods to perform CRUD operations on YANG-defined data. To retrieve interface statistics without modifying any resource, the GET method is correct, as it maps directly to the NETCONF <get> or <get-config> operation for reading data.

Exam trap

Cisco often tests the distinction between HTTP methods in RESTCONF, and the trap here is that candidates may confuse POST (used for creating resources) with GET, especially when thinking of sending a 'request' for data.

How to eliminate wrong answers

Option B is wrong because POST is used to create a new data resource or invoke an operation, not to retrieve existing data. Option C is wrong because PUT is used to replace or update an entire resource, not to read data. Option D is wrong because DELETE is used to remove a resource, which is the opposite of retrieving statistics.

2
MCQmedium

An application uses Cisco DNA Center APIs and needs to receive notifications when a new device is added. Which DNA Center API category should be used to set up event-driven notifications?

A.Platform
B.Change your network
C.Know your network
D.Run your network
AnswerA

Platform APIs include the event notification and webhook services that register subscribers and deliver DNA Center events, such as device-added, to an external endpoint. This satisfies the stem's event-driven requirement, unlike intent, command runner or integration APIs, which handle policy, CLI execution or third-party connectivity rather than push notifications.

Why this answer

The Platform API category in Cisco DNA Center provides the necessary endpoints for subscribing to event notifications, including the ability to create webhook subscriptions for events such as new device additions. This category includes the Event Management and Notification APIs that allow applications to receive real-time updates. The other categories focus on network operations, not event-driven integration.

Exam trap

The trap here is confusing the functional categories of DNA Center APIs with the Platform category, which specifically handles event subscriptions and notifications, leading candidates to choose a network operations category instead.

How to eliminate wrong answers

Option B is wrong because 'Change your network' APIs are used for configuration changes and provisioning, not for receiving event notifications. Option C is wrong because 'Know your network' APIs are for retrieving network inventory and topology information, not for subscribing to events. Option D is wrong because 'Run your network' APIs are for monitoring and troubleshooting network health, not for setting up event-driven notifications.

3
MCQmedium

An application sends many requests to the Meraki API and receives HTTP 429 errors. The response includes a 'Retry-After' header. What does this status code indicate?

A.The requested resource was not found
B.The server encountered an internal error
C.The API key is invalid
D.The client has exceeded the rate limit
AnswerD

HTTP 429 is 'Too Many Requests', returned when the client exceeds the Meraki API's rate limit. The Retry-After header tells the client how long to wait before retrying, confirming the request was throttled rather than rejected for authentication or syntax.

Why this answer

HTTP 429 status code means 'Too Many Requests', indicating that the client has exceeded the rate limit set by the API. The 'Retry-After' header tells the client how long to wait before making another request.

Exam trap

200-901 often tests the confusion between HTTP 429 and other 4xx/5xx codes, expecting candidates to know that 429 specifically means rate limiting and to use the Retry-After header.

How to eliminate wrong answers

Option A is wrong because 404 Not Found indicates the requested resource does not exist. Option B is wrong because 500 Internal Server Error indicates a server-side error. Option C is wrong because 401 Unauthorized or 403 Forbidden indicate invalid API key or insufficient permissions, not 429.

4
MCQhard

A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?

A.Implicit grant
B.Authorization code grant
C.Resource owner password credentials grant
D.Client credentials grant
AnswerB

The authorization code grant redirects each user to Cisco Webex to authenticate and consent, then returns a short-lived code the app exchanges for an access token and a refresh token. The refresh token enables long-term access without further user interaction, and each organization consents separately, matching the stated requirements.

Why this answer

Delegated access across many organizations requires each user to authenticate and consent at Cisco Webex, which the authorization code grant accomplishes. Exchanging the returned code yields both an access token and a refresh token, so the integration can renew access silently afterward. The other grants either lack refresh capability, require unsafe password handling, or represent the app rather than the user.

Exam trap

The trap here is choosing client credentials because it needs no user interaction, overlooking that it cannot represent delegated per-organization user consent.

5
MCQmedium

A company uses Ansible to automate configuration of its Cisco IOS XE routers. The network team recently upgraded the routers' software from IOS 15.x to IOS XE 17.x. Since the upgrade, the Ansible playbook fails intermittently with the message: 'Failed to connect to the host via ssh: timed out'. However, the team can SSH manually to the routers from the Ansible control node without issues. The playbook uses the 'cisco.ios.ios_config' module with default SSH options. The routers have been configured with SSH version 2 and local authentication. The Ansible control node runs Red Hat Enterprise Linux 8. Which action should the network engineer take to resolve the issue?

A.Increase the SSH timeout in the Ansible configuration file (ansible.cfg) to 60 seconds.
B.Configure the routers to use SSH version 1 only.
C.Set the 'host_key_checking' option to False in ansible.cfg.
D.Use the 'ios_command' module instead of 'ios_config' to perform the tasks.
AnswerA

IOS XE 17.x introduces slower SSH negotiation, so Ansible's default connection timeout expires before authentication completes, while manual SSH succeeds because it waits longer. Raising the timeout in ansible.cfg lets the cisco.ios.ios_config module complete the handshake.

Why this answer

The intermittent SSH timeout after upgrading to IOS XE 17.x is likely due to slower key exchange algorithms (e.g., diffie-hellman-group-exchange-sha256) that increase connection setup time. Increasing the SSH timeout in ansible.cfg (e.g., setting timeout=60) gives the SSH handshake enough time to complete, avoiding the timeout. Forcing SSHv1 is not recommended as it is deprecated and may not be supported.

Host key checking (option C) does not affect timeout, and using a different module (option D) does not solve the underlying connectivity issue.

Exam trap

Candidates may think SSH timeout is always due to network latency or firewall drops, but it can be caused by slower cryptographic handshakes in newer IOS XE versions. Increasing SSH timeout is a simple fix.

How to eliminate wrong answers

Option A is wrong because increasing the SSH timeout in ansible.cfg would only mask the symptom; the underlying cause is the slow SSH key exchange negotiation, not a general timeout setting. Option C is wrong because disabling host_key_checking only skips the verification of the remote host's SSH key fingerprint; it does not affect the SSH transport layer timeout or the speed of the cryptographic handshake. Option D is wrong because the ios_command module also uses the same SSH transport and would experience the identical timeout issue; the problem is not specific to the ios_config module.

6
Multi-Selectmedium

Which TWO practices help prevent hardcoded credentials in application code? (Choose TWO.)

Select 2 answers
A.Use a secrets management tool like HashiCorp Vault to retrieve credentials at runtime
B.Share secrets via email and paste them into the code during deployment
C.Store secrets in environment variables from a .env file that is not committed to version control
D.Commit a .env file with placeholder values to the repository
E.Embed secrets directly in the source code with comments
AnswersA, C

HashiCorp Vault injects credentials dynamically at runtime, so no secret ever resides in source code or version control. This directly satisfies the stem's requirement to prevent hardcoded credentials, since applications authenticate to Vault and receive short-lived, rotated secrets instead of embedding static passwords or API keys.

Why this answer

Option A is correct because a secrets management tool such as HashiCorp Vault stores credentials outside the codebase and injects them at runtime via API calls or dynamic secrets, so no credential value ever appears in source files or version control. Option C is correct because keeping secrets in environment variables loaded from a .env file that is excluded from version control (e.g., listed in .gitignore) removes the credential from the code itself while still making it available to the running process. Option B is wrong because emailing secrets and pasting them into code during deployment is exactly the hardcoding anti-pattern and exposes credentials in mail systems and source history.

Option D is wrong because committing even a placeholder .env file to the repository normalizes storing secrets in version control and risks real values being committed later. Option E is wrong because embedding secrets directly in source code with comments is the definition of hardcoded credentials and leaks them to anyone with repository access.

7
Multi-Selectmedium

A platform team is hardening a containerized application before production. They want to reduce the attack surface of the running containers themselves. Which two practices directly reduce the privileges available to a compromised container process? (Choose two.)

Select 2 answers
A.Run the container process as a non-root user via the USER instruction or --user flag
B.Drop unnecessary Linux capabilities with --cap-drop and add back only what is required
C.Set the read-only flag on the container filesystem with --read-only
D.Add a HEALTHCHECK instruction to the Dockerfile so the orchestrator can restart unhealthy containers
E.Use a smaller base image such as alpine to reduce the image size
AnswersA, B

Running as an unprivileged user means a process that escapes the application cannot perform root-only operations such as binding low ports, modifying system files, or loading kernel modules. This is one of the most effective single mitigations because most container escapes assume root inside the namespace. It directly limits the capabilities available after compromise.

Why this answer

Privilege reduction focuses on what the process is allowed to do at runtime. Running as a non-root user removes the broad powers of uid 0, and dropping Linux capabilities strips specific kernel-level abilities even from processes that retain elevated identity. Read-only filesystems, smaller images, and health checks improve other properties such as immutability, vulnerability count, and availability, but none of them lower the privilege ceiling of a compromised process.

Exam trap

The trap here is conflating general hardening measures like read-only filesystems or slim base images with actual privilege reduction.

8
MCQeasy

A Python script uses the Cisco Webex API to list all rooms. The response includes pagination via the 'Link' header with 'rel="next"'. What is the correct way to retrieve the next page of rooms?

A.Parse the 'Link' header for the URL with 'rel="next"' and send a GET request to that URL.
B.Increment a page counter and append '?page=2' to the original URL.
C.Use the total count returned in the response to calculate the offset.
D.Send a POST request to the same endpoint with the 'cursor' parameter.
AnswerA

The Webex API returns the next-page URL in the Link header, so parsing it for the rel="next" entry and issuing a GET to that exact URL respects the server-supplied cursor rather than guessing page offsets or parameters.

Why this answer

The Webex API uses HTTP Link headers for pagination, as specified in RFC 5988. The 'Link' header contains a URL with 'rel="next"' that points directly to the next page of results. To retrieve the next page, you must parse this header, extract the URL, and send a GET request to that URL.

This is the standard approach for cursor-based or token-based pagination, which is common in RESTful APIs that avoid offset-based pagination for consistency.

Exam trap

Cisco often tests the misconception that pagination always uses simple page numbers or offsets, but the trap here is that the Webex API uses the Link header with 'rel="next"' for cursor-based pagination, and candidates may incorrectly assume a traditional page counter or offset approach.

How to eliminate wrong answers

Option B is wrong because the Webex API does not use simple page counters; incrementing a page number and appending '?page=2' assumes a fixed page-based pagination scheme that is not supported by the API. Option C is wrong because the Webex API does not return a total count in the response for pagination; even if it did, calculating an offset would be unreliable due to potential data changes between requests. Option D is wrong because the Webex API uses GET requests for pagination, not POST requests, and the 'cursor' parameter is not part of the standard pagination mechanism; the correct mechanism uses the 'Link' header with 'rel="next"'.

9
MCQhard

A developer is writing a REST API client in Python that authenticates to a controller using HTTP Basic authentication over the network. The developer wants to ensure credentials are never exposed on the wire in readable form. Which implementation detail is required?

A.Send the credentials in a custom request header that the server is configured to read.
B.Hash the password with SHA-256 and send the digest in place of the password.
C.Base64-encode the username and password and place the result in the Authorization header.
D.Send the request only over HTTPS so the TLS session encrypts the Authorization header in transit.
AnswerD

HTTP Basic authentication transmits credentials in an easily decoded form, so confidentiality must come from the transport. TLS encrypts the entire request, including the Authorization header, between client and server. This is the standard and expected way to protect Basic credentials, and it also protects the response and any tokens exchanged during the session.

Why this answer

HTTP Basic authentication provides no confidentiality of its own; it merely encodes the credentials. Protecting them requires an encrypted transport, which TLS provides for the whole request and response. Encoding, relocating, or hashing the credential on the client changes its representation without hiding it from an observer, so only a TLS-protected connection keeps credentials unreadable in transit.

Exam trap

The trap here is believing that Base64 encoding or client-side hashing conceals credentials, when only transport encryption actually prevents an observer from reading them.

10
MCQmedium

A Webex bot needs to send a message to a room. The bot has the room ID. Which API endpoint should be used, and what is the correct HTTP method?

A.POST /v1/messages
B.PUT /v1/messages/{messageId}
C.GET /v1/messages
D.POST /v1/rooms
AnswerA

Sending a message to a room is a create operation on the messages collection, so the bot calls POST /v1/messages with the roomId in the JSON body. The room ID alone does not form a resource path for a GET or PUT.

Why this answer

The Webex Teams API uses POST /v1/messages to create and send a new message to a room. The request body must include the roomId and either text or markdown. This is the standard endpoint for sending messages, and it returns a 200 OK with the message details upon success.

Exam trap

200-901 often tests the distinction between HTTP methods and their typical CRUD operations, so candidates might incorrectly choose PUT for updating a message or GET for retrieving messages, but the question specifically asks for sending a message, which requires POST to the correct resource.

How to eliminate wrong answers

Option B is wrong because PUT /v1/messages/{messageId} is not a valid Webex API endpoint; messages cannot be updated via PUT. Option C is wrong because GET /v1/messages is used to list messages, not send them, and it requires query parameters like roomId. Option D is wrong because POST /v1/rooms is used to create a new room, not to send a message to an existing room.

11
MCQmedium

In a microservices architecture, which communication pattern is typically asynchronous and decoupled?

A.REST over HTTP
B.SOAP
C.gRPC
D.Event-driven architecture
AnswerD

Event-driven architecture decouples producers from consumers via a broker, so services publish events without waiting for responses. This asynchronous, non-blocking exchange satisfies the decoupling requirement, unlike synchronous request-response patterns such as REST or gRPC that couple caller and callee.

Why this answer

Event-driven architecture (D) is the correct answer because it is inherently asynchronous and decoupled: services communicate by publishing events to a message broker (e.g., Kafka, RabbitMQ) without needing to know about the consumers. This pattern allows the producer to emit an event and continue processing immediately, while consumers react to events at their own pace, achieving loose coupling and high scalability.

Exam trap

Cisco often tests the misconception that any HTTP-based communication (like REST) is inherently asynchronous, but REST over HTTP is synchronous by default unless combined with additional patterns like webhooks or message queues.

How to eliminate wrong answers

Option A is wrong because REST over HTTP is typically synchronous and tightly coupled: the client sends a request and waits for a response, creating a direct dependency between services. Option B is wrong because SOAP is a synchronous, tightly coupled protocol that relies on XML messaging over HTTP or other transports, often with strict contract definitions (WSDL) that create strong coupling. Option C is wrong because gRPC, while efficient with HTTP/2 and protobufs, is primarily designed for synchronous request-response communication (though it supports streaming, the default pattern is still coupled and blocking).

12
MCQeasy

Which tool can be used to explore YANG models locally?

A.yangcatalog.org
B.Cisco DevNet sandbox
C.Postman
D.pyang
AnswerD

pyang is an open-source YANG validator and converter that parses YANG modules locally, letting engineers inspect tree structures, verify syntax and explore model hierarchies without a live device. It directly satisfies the requirement to explore YANG models offline.

Why this answer

pyang is a tool for validating and converting YANG models.

13
MCQhard

A DevOps team manages network infrastructure using Infrastructure as Code (IaC). They store configuration files in a Git repository and use CI/CD to deploy changes. What is the best practice to ensure that only validated configurations are applied to production devices?

A.Require a pull request with at least one approval before merging to the main branch
B.Allow any team member to push directly to the main branch after testing locally
C.Use a manual approval gate in the CI/CD pipeline that requires manager sign-off
D.Automate the deployment of every commit directly to production
AnswerA

Branch protection requiring an approving pull request gates merges, so unvalidated configuration never reaches the main branch that CI/CD deploys from. This enforces peer review before production devices receive changes, satisfying the constraint that only validated configurations are applied.

Why this answer

Requiring a pull request with at least one approval before merging to the main branch enforces peer review and validation of configuration changes. This ensures that only code that has been reviewed for correctness, syntax, and adherence to standards is merged, preventing erroneous or malicious configurations from reaching production via the CI/CD pipeline.

Exam trap

The trap here is that candidates may confuse a manual approval gate (Option C) with a technical validation step, but Cisco tests the understanding that peer code review (via pull requests) is the best practice for ensuring configuration correctness in IaC, not managerial sign-off.

How to eliminate wrong answers

Option B is wrong because allowing direct pushes to the main branch bypasses any review or validation, risking the deployment of untested or erroneous configurations. Option C is wrong because a manual approval gate by a manager does not guarantee technical validation of the configuration; it adds a non-technical bottleneck without ensuring code correctness. Option D is wrong because automating deployment of every commit directly to production eliminates all validation gates, making it impossible to catch errors before they impact production devices.

14
MCQeasy

Which Cisco platform uses NX-API to allow programmatic access to CLI commands via JSON?

A.Cisco Meraki
B.Cisco NX-OS
C.Cisco DNA Center
D.Cisco IOS XE
AnswerB

Cisco NX-OS exposes NX-API, which wraps CLI commands and returns structured JSON or XML over HTTP/HTTPS, enabling programmatic access. IOS, IOS-XE and ASA lack this native JSON CLI wrapper, so NX-OS is the platform matching the stem.

Why this answer

Cisco NX-OS is the network operating system that runs on Nexus switches and supports NX-API, which allows programmatic access to CLI commands via JSON (or XML) over HTTP/HTTPS. NX-API exposes the /ins endpoint for CLI execution and /api for model-driven REST access.

Exam trap

The trap is that candidates confuse NX-API (NX-OS) with RESTCONF (IOS XE) or DNA Center's Intent API, assuming all Cisco platforms use the same programmatic interface.

How to eliminate wrong answers

Option A is wrong because Cisco Meraki is a cloud-managed platform with its own REST API, not NX-API; NX-API is specific to NX-OS. Option C is wrong because Cisco DNA Center is a network controller with a REST API (Intent API), not NX-API. Option D is wrong because Cisco IOS XE supports RESTCONF and NETCONF/YANG, but not NX-API, which is exclusive to NX-OS.

15
MCQhard

In an SDN architecture, which API is used by the controller to communicate with network devices to install forwarding rules?

A.Southbound API
B.REST API
C.East-West API
D.Northbound API
AnswerA

The southbound API connects the SDN controller downward to forwarding devices, programming flow tables and installing forwarding rules. This satisfies the requirement to communicate with network devices, whereas northbound APIs face applications and management planes.

Why this answer

In SDN, the southbound API is the interface between the controller and the network devices (switches, routers). It allows the controller to install forwarding rules, such as flow entries in OpenFlow switches, enabling centralized control of the data plane.

Exam trap

Cisco often tests the distinction between northbound and southbound APIs; the trap here is confusing the REST API (commonly northbound) with the southbound API that directly programs device forwarding tables.

How to eliminate wrong answers

Option B (REST API) is wrong because REST APIs are typically used as northbound APIs for applications to communicate with the SDN controller, not for the controller to program network devices. Option C (East-West API) is wrong because east-west APIs are used for communication between multiple SDN controllers in a distributed control plane, not for device rule installation. Option D (Northbound API) is wrong because northbound APIs allow applications and orchestration tools to interact with the controller, abstracting the underlying network; they do not directly install forwarding rules on devices.

16
MCQmedium

A network engineer is using the Cisco Meraki API to retrieve a list of SSIDs for a specific network. The API returns an HTTP 200 status but an empty array for the SSIDs. Which of the following is the most likely cause?

A.The network exists but has no SSIDs configured.
B.The network ID is incorrect.
C.The API key is invalid.
D.The request body is malformed.
AnswerA

HTTP 200 confirms the request succeeded and the network identifier is valid; an empty JSON array is a legitimate response, not an error. The SSID collection for that network simply contains no entries, so no configuration change or authentication fix is required.

Why this answer

An HTTP 200 status indicates the request was successfully processed by the Meraki API, meaning the API key, network ID, and request format were all valid. An empty array for SSIDs specifically means the network exists and the API queried it correctly, but no SSIDs have been configured on that network. This is the expected behavior when a network has no wireless profiles defined.

Exam trap

Cisco often tests the misconception that an HTTP 200 always means data exists, but the trap here is that a successful API response can legitimately return an empty array when the resource has no configured items.

How to eliminate wrong answers

Option B is wrong because an incorrect network ID would result in an HTTP 404 (Not Found) or HTTP 400 (Bad Request) error, not a 200 with an empty array. Option C is wrong because an invalid API key would return an HTTP 401 (Unauthorized) status, not a successful 200 response. Option D is wrong because a malformed request body would typically cause an HTTP 400 (Bad Request) error, as the Meraki API validates the request structure before processing.

17
MCQmedium

A network administrator is configuring DNS for a corporate domain. An MX record is required to specify the mail server responsible for handling email. Which of the following is a correct example of an MX record?

A.mail.example.com. A 192.0.2.1
B.example.com. MX 10 mail.example.com.
C.example.com. CNAME mail.example.com.
D.example.com. TXT "v=spf1 include:_spf.google.com ~all"
AnswerB

The record maps the domain to mail.example.com with preference 10, the standard MX syntax of priority followed by mail exchanger. This satisfies the requirement to name the mail server handling email for the corporate domain, since MX records exist solely to direct SMTP delivery.

Why this answer

An MX record specifies the mail server responsible for handling email for a domain, using the format: domain. MX priority mailserver. The priority value (10) indicates preference, with lower values being higher priority.

This record directs email delivery to mail.example.com for the example.com domain.

Exam trap

Cisco often tests the distinction between record types by presenting an A or CNAME record as a distractor, exploiting the common misconception that any record pointing to a mail server is sufficient for email routing.

How to eliminate wrong answers

Option A is wrong because it uses an 'A' record type, which maps a hostname to an IPv4 address, not a mail exchanger; MX records require the 'MX' type and a priority value. Option C is wrong because a CNAME record creates an alias for a hostname, but MX records cannot point to a CNAME per RFC 2181; they must point directly to an A or AAAA record. Option D is wrong because a TXT record stores text data like SPF policies, not mail server routing information; MX records are specifically for mail exchange.

18
MCQmedium

A network automation engineer uses Terraform to manage Cisco Catalyst Center (formerly DNA Center) resources. What is the purpose of the Cisco Catalyst Center Terraform provider?

A.To execute a series of CLI commands on network devices in sequence
B.To write imperative scripts that configure network devices via SSH
C.To directly manage routers and switches without using Catalyst Center
D.To define and manage network infrastructure resources in a declarative state file
AnswerD

The Catalyst Center Terraform provider exposes network infrastructure as declarative resources, letting the engineer define intended device, site and template configuration in HCL state files rather than imperative API calls. Terraform reconciles actual Catalyst Center state against that declared configuration, satisfying the stem's requirement to manage resources through Terraform's declarative workflow.

Why this answer

The Cisco Catalyst Center Terraform provider allows network automation engineers to define and manage network infrastructure resources in a declarative state file. Terraform uses a desired-state approach where the configuration file describes the intended end state of resources, and the provider communicates with Catalyst Center's REST API to enforce that state, enabling idempotent and version-controlled infrastructure management.

Exam trap

The trap here is that candidates often confuse Terraform's declarative, API-driven model with imperative scripting or CLI-based automation, leading them to select options that describe procedural SSH or CLI workflows instead of recognizing the provider's role as an abstraction layer over Catalyst Center's REST API.

How to eliminate wrong answers

Option A is wrong because executing a series of CLI commands on network devices in sequence describes a procedural automation approach (e.g., using Ansible or a Python script with Netmiko), not the declarative, API-driven model of Terraform. Option B is wrong because writing imperative scripts that configure network devices via SSH is a traditional, non-declarative method that lacks Terraform's state management and idempotency; Terraform does not use SSH for device configuration. Option C is wrong because the Terraform provider for Catalyst Center does not directly manage routers and switches; it manages resources through Catalyst Center's northbound REST API, which in turn orchestrates device configurations via protocols like NETCONF or CLI.

19
MCQhard

Based on the NAT translation table, what type of NAT is being used?

A.Dynamic NAT
B.Static PAT
C.Static NAT
D.PAT (overload)
AnswerD

PAT (overload) maps many inside local addresses to a single inside global address, differentiating sessions by source port number. The translation table showing multiple private IPs sharing one public IP with distinct port entries confirms port-level multiplexing rather than static or dynamic one-to-one mapping.

Why this answer

The NAT translation table shows multiple internal IP addresses (e.g., 10.1.1.1, 10.1.1.2) being translated to the same public IP address (e.g., 203.0.113.1) but with different source ports. This is the defining characteristic of Port Address Translation (PAT), also known as NAT overload, where a single public IP is shared among many internal hosts by multiplexing on layer-4 port numbers.

Exam trap

Cisco often tests the distinction between Dynamic NAT (which uses a pool of public IPs) and PAT (which overloads a single public IP with port numbers), and the trap here is that candidates see multiple translations and assume Dynamic NAT, missing the key clue that the public IP is identical across entries.

How to eliminate wrong answers

Option A is wrong because Dynamic NAT translates internal addresses to a pool of public IPs, one-to-one, and does not reuse a single public IP with different ports. Option B is wrong because Static PAT is not a standard term; static NAT with port forwarding is sometimes mislabeled, but the table shows dynamic port assignments, not a fixed mapping. Option C is wrong because Static NAT maps a single internal IP to a single external IP permanently, which would not show multiple internal IPs sharing the same public IP.

20
MCQmedium

A network engineer needs to automate the deployment of QoS policies across multiple campus switches using Cisco DNA Center. The engineer decides to use the Cisco DNA Center Intent API to create a policy tag and bind it to a group of devices. After sending the PUT request to /dna/intent/api/v1/policy-tag, the API returns a 202 Accepted status. However, the engineer notices that the policy is not being applied consistently across all devices. What is the most likely reason?

A.The payload was not in JSON format, causing a silent failure.
B.The API token expired before the request was processed.
C.The request was asynchronous, and the engineer did not check the task status for completion.
D.The engineer used an incorrect API endpoint for policy tags.
AnswerC

The 202 Accepted response confirms the Intent API processed the request asynchronously, returning a task ID rather than applying the policy immediately. Without polling that task status, the engineer cannot confirm completion, so binding may still be pending on some devices.

Why this answer

The 202 Accepted status indicates that the request was accepted for asynchronous processing, not that it has completed. Cisco DNA Center Intent API uses asynchronous tasks for operations like policy tag binding, and the engineer must poll the task status endpoint to verify completion and success. Without checking the task status, the engineer cannot know if the policy was applied consistently across all devices, as some tasks may have failed or are still in progress.

Exam trap

Cisco often tests the distinction between synchronous (2xx success) and asynchronous (202 Accepted) responses, and the trap here is that candidates assume a 202 Accepted means the operation completed successfully, when in fact it only means the request was accepted for processing.

How to eliminate wrong answers

Option A is wrong because if the payload were not in JSON format, the API would typically return a 400 Bad Request error, not a 202 Accepted, and the failure would be explicit, not silent. Option B is wrong because an expired API token would cause a 401 Unauthorized error when the request is sent, not a 202 Accepted; the token is validated at request time, not during async processing. Option D is wrong because the endpoint /dna/intent/api/v1/policy-tag is the correct endpoint for creating and updating policy tags in Cisco DNA Center Intent API, as documented in the API reference.

21
MCQmedium

A developer is building a Python script that authenticates to the Cisco DNA Center REST API. The script must avoid hardcoding credentials in source control and must run unattended in a CI pipeline. The team already stores secrets in environment variables on the build agent. Which approach best meets these requirements?

A.Store the credentials in a plaintext YAML file in the repository and load it with a relative path.
B.Embed the username and password as string literals in the script and commit it to a private Git repository.
C.Prompt the operator for credentials with input() each time the pipeline executes.
D.Read the credentials with os.environ at runtime and pass them to the DNA Center authentication endpoint to obtain a token.
AnswerD

Pulling credentials from environment variables keeps them out of the codebase while allowing the script to run unattended, because the CI agent injects the values at execution time. The script then authenticates to the DNA Center token endpoint and uses the returned token for subsequent calls, which matches both the security and automation requirements.

Why this answer

Credentials supplied through environment variables let the same script run locally and in CI without modification, and they never land in the repository. The script authenticates against the DNA Center token service and reuses the resulting token for the API calls it needs, satisfying both the secrecy and unattended-execution constraints.

Exam trap

The trap here is assuming that a private repository or a separate config file makes stored credentials safe, when any committed secret is still exposed and violates the no-hardcoding requirement.

22
MCQeasy

A network engineer wants to retrieve the list of organizations associated with their API key from the Cisco Meraki Dashboard API. The API base URL is https://api.meraki.com/api/v1. Which HTTP request should the engineer send?

A.POST https://api.meraki.com/api/v1/organizations with the API key in the request body.
B.GET https://api.meraki.com/api/v1/organizations with the X-Cisco-Meraki-API-Key header set to the API key.
C.GET https://api.meraki.com/api/v1/organization with the API key as a query parameter.
D.GET https://api.meraki.com/api/v1/organizations with Basic authentication using the API key as the password.
AnswerB

The Meraki Dashboard API exposes organizations at the /organizations path, and authentication uses the X-Cisco-Meraki-API-Key header. A GET request to that endpoint returns the organizations the key can access. This is the documented, correct way to enumerate organizations before drilling into networks and devices.

Why this answer

The Meraki Dashboard API lists organizations at GET /api/v1/organizations and authenticates via the X-Cisco-Meraki-API-Key request header. Using the correct path and header ensures the API key is recognized and the list of accessible organizations is returned. Alternative methods such as POST, Basic auth, or query-parameter keys are not supported for this operation.

Exam trap

The trap here is confusing the plural /organizations collection endpoint with a singular path or assuming Meraki accepts the API key as a query string, when it requires a dedicated header.

23
MCQeasy

A developer is using Cisco Meraki API to retrieve a list of networks. What is the correct HTTP method and endpoint path for listing networks in an organization?

A.DELETE /organizations/{orgId}/networks
B.POST /organizations/{orgId}/networks
C.PUT /organizations/{orgId}/networks
D.GET /organizations/{orgId}/networks
AnswerD

The Meraki dashboard API exposes GET /organizations/{orgId}/networks, returning the networks belonging to that organisation. GET is the correct HTTP method for a read-only listing operation, satisfying the requirement to retrieve rather than modify network data.

Why this answer

The HTTP GET method is used to retrieve or list resources, and the endpoint /organizations/{orgId}/networks is the standard Meraki API path for fetching all networks within a specified organization. This follows RESTful conventions where GET requests are idempotent and safe for data retrieval.

Exam trap

Cisco often tests the fundamental RESTful mapping of HTTP methods to CRUD operations, and the trap here is confusing the GET method with POST or PUT because candidates may think 'listing' requires sending data in the request body, when in fact GET is the correct method for read-only retrieval.

How to eliminate wrong answers

Option A is wrong because DELETE is used to remove a resource, not to list networks; using DELETE on this endpoint would attempt to delete all networks in the organization, which is not the intended operation. Option B is wrong because POST is used to create a new resource, such as adding a network to an organization, not to retrieve an existing list. Option C is wrong because PUT is used to update or replace an existing resource, not to retrieve a list; it would attempt to replace the entire collection of networks, which is incorrect.

24
MCQmedium

A developer writes a Python script using Cisco's pyATS framework to test network reachability after a configuration change. What is a key advantage of using pyATS over a simple script that uses ping?

A.pyATS requires less code than a ping script
B.pyATS can test multiple devices in parallel
C.pyATS allows writing reusable test scripts with built-in test libraries
D.pyATS automatically generates test reports
AnswerC

pyATS provides reusable test scripts with built-in libraries such as Genie, offering structured parsing, assertions and reporting across devices. A plain ping script returns only reachability output, so pyATS satisfies the stem's need for maintainable, repeatable post-change verification rather than ad hoc checks.

Why this answer

PyATS is a test automation framework designed for network engineers, providing built-in test libraries (e.g., `pyats.aetest`) that enable writing reusable, modular test scripts. Unlike a simple ping script, pyATS supports structured test cases, data-driven testing, and integration with Cisco devices via libraries like `Genie`, allowing for comprehensive validation beyond basic reachability.

Exam trap

The trap here is that candidates confuse pyATS's parallel execution capability (which is achievable with other tools) with its core value proposition of providing a structured, reusable test framework with built-in libraries for network-specific validation.

How to eliminate wrong answers

Option A is wrong because pyATS typically requires more code to set up test infrastructure (e.g., testbed files, test cases) compared to a simple ping script, which can be a single line. Option B is wrong because while pyATS can test multiple devices in parallel, this is not a unique advantage—a simple script using threading or asyncio can also achieve parallel pings; the key advantage is the framework's test management and reusability. Option D is wrong because pyATS does not automatically generate test reports; it provides libraries to create custom reports (e.g., via `pyats.log` or integration with tools like `ATS`), but report generation requires explicit implementation.

25
MCQmedium

A development team is implementing a microservices architecture. They need to ensure that services can discover each other dynamically without hardcoding IP addresses. Which technology should they use?

A.A centralized load balancer
B.A service registry like Consul
C.An API gateway
D.DNS-based service discovery
AnswerB

Consul provides a dynamic service registry where instances register themselves and query peers by name, eliminating hardcoded IP addresses. Its health-checking and DNS/HTTP interfaces let microservices resolve current endpoints at runtime, satisfying the dynamic discovery requirement.

Why this answer

A service registry like Consul provides a centralized directory where microservices register their network locations (IP and port) and health status. Other services query the registry to discover available instances dynamically, eliminating the need for hardcoded addresses. Consul supports health checks, multi-datacenter replication, and integrates with tools like Envoy for service mesh functionality.

Exam trap

Cisco often tests the distinction between an API gateway (which handles external traffic) and a service registry (which handles internal service discovery), leading candidates to incorrectly choose the API gateway when the question focuses on inter-service communication.

How to eliminate wrong answers

Option A is wrong because a centralized load balancer distributes traffic but does not inherently provide dynamic service discovery; it typically requires manual configuration or integration with a registry to know backend endpoints. Option C is wrong because an API gateway handles routing, authentication, and rate limiting for external requests, but it is not designed for internal service-to-service discovery and often relies on a registry or DNS for backend resolution. Option D is wrong because DNS-based service discovery (e.g., using SRV records) can resolve service names to IPs but lacks real-time health checking, TTL-based caching can cause stale entries, and it does not support advanced features like weighted routing or metadata-based filtering that a dedicated registry provides.

26
Multi-Selecthard

A network engineer is analyzing traffic patterns and wants to identify characteristics of UDP that affect real-time applications such as VoIP and video streaming. Which two characteristics of UDP make it suitable for these applications? (Choose two.)

Select 2 answers
A.Ordered delivery of packets
B.Guaranteed delivery of packets
C.Low overhead due to a minimal header
D.Connectionless communication
E.Built-in congestion control
AnswersC, D

UDP has a fixed 8-byte header, which is much smaller than TCP's minimum 20-byte header. This reduces overhead and processing time, making it ideal for real-time applications where speed is critical and small delays are unacceptable. The minimal header contributes to lower latency and higher throughput.

Why this answer

UDP is suitable for real-time applications because it has low overhead from a minimal header and is connectionless, which reduces latency. These characteristics allow VoIP and video streaming to prioritize speed over reliability, as retransmissions would cause unacceptable delays.

Exam trap

The trap here is assuming that UDP provides reliability features like guaranteed delivery or ordered delivery, which it does not; those are TCP characteristics.

27
MCQhard

In a CI/CD pipeline for network automation, a change is rolled back using a Git revert commit that triggers a new pipeline. The rollback playbook fails because the 'previous' configuration snapshot is missing. What should be implemented to prevent this?

A.Use a single source of truth like NetBox
B.Store configuration backups in a version-controlled repository before each change
C.Use the 'check mode' only
D.Disable rollback pipelines
AnswerB

A revert commit restores the previous configuration, but only if that snapshot was captured beforehand. Committing configuration backups to a version-controlled repository before each change guarantees the prior state exists and can be reapplied by the rollback pipeline.

Why this answer

Storing configuration backups in a version-controlled repository before each change ensures that a known-good 'previous' snapshot is always available for rollback, even if the Git revert commit only reverts the playbook code and not the device configuration. In CI/CD for network automation, the pipeline must have access to the exact prior state to restore it; version-controlled backups provide an immutable, auditable history that can be checked out by commit hash. This directly prevents the failure described, where the rollback playbook cannot find the previous configuration snapshot.

Exam trap

The trap is assuming that a Git revert of the playbook code is sufficient for rollback; candidates often overlook that the actual device configuration state must also be versioned and retrievable, not just the automation code.

How to eliminate wrong answers

Option A is wrong because a single source of truth like NetBox stores intended state, not necessarily the actual running configuration snapshots needed for rollback; it does not guarantee that a previous configuration can be restored. Option C is wrong because 'check mode' only simulates changes and does not create or store backups, so it cannot provide a rollback snapshot. Option D is wrong because disabling rollback pipelines removes the safety net entirely and does not solve the missing snapshot problem; it increases risk rather than preventing the failure.

28
MCQeasy

A developer is writing a Python application that calls a REST API. The API requires an OAuth 2.0 bearer token. The token must not be stored in the source code. Which approach should the developer use to make the token available to the application at runtime?

A.Read the token from an environment variable that is injected by the deployment platform at runtime.
B.Hardcode the token in a configuration file that is committed to the repository so the application can read it on startup.
C.Store the token in a comment at the top of the main application file so it is easy for the developer to find.
D.Embed the token in the application's compiled bytecode so it is not visible in the plain source files.
AnswerA

This is correct because environment variables are injected at runtime and are not part of the source code or repository. The application can read the token from os.environ without embedding it in code, and the platform can rotate the value without a code change. This satisfies the requirement to keep the token out of source control.

Why this answer

The token must be provided at runtime and kept out of source control. Environment variables are a standard way to inject secrets into a running application without embedding them in code or configuration files committed to the repository. The other options either commit the secret to the repository or ship it inside the application artifact, both of which expose the token.

Exam trap

The trap here is thinking that hiding a secret in bytecode or a comment makes it safe, when any location inside the source or artifact is still exposed.

29
MCQeasy

A CI/CD pipeline for network automation includes stages for linting, unit testing, and deployment. Which stage typically validates the syntax of Ansible playbooks?

A.Integration testing stage
B.Deployment stage
C.Unit testing stage
D.Linting stage
AnswerD

Linting parses Ansible playbooks with tools such as ansible-lint or yamllint, flagging syntax errors, malformed YAML and deprecated constructs before execution. This satisfies the pipeline's syntax-validation requirement, since unit testing exercises logic and deployment applies configuration, neither of which checks playbook syntax beforehand.

Why this answer

Linting is the stage that validates syntax and style for code or configuration files. In a CI/CD pipeline for network automation, the linting stage uses tools like `ansible-lint` to check Ansible playbooks for syntax errors, best practices, and idempotency issues before any testing or deployment occurs.

Exam trap

Cisco often tests the distinction between linting (syntax/style checks) and unit testing (functional correctness of code), leading candidates to mistakenly choose unit testing for syntax validation.

How to eliminate wrong answers

Option A is wrong because integration testing validates the interaction between components (e.g., network devices and Ansible modules) after deployment, not syntax. Option B is wrong because the deployment stage applies the playbook to production or staging environments, assuming syntax is already correct. Option C is wrong because unit testing validates individual functions or modules in isolation (e.g., Python unit tests for custom modules), not the YAML syntax of Ansible playbooks.

30
MCQmedium

An application requires reliable, ordered delivery of data with error checking. Which transport protocol should be used, and what is a key characteristic of this protocol?

A.TCP, because it uses a 3-way handshake to establish a connection
B.TCP, because it has lower overhead than UDP
C.UDP, because it is connectionless and low-overhead
D.UDP, because it provides flow control
AnswerA

TCP satisfies the ordered, error-checked delivery requirement through sequence numbers, acknowledgements and retransmission of lost segments. The three-way handshake (SYN, SYN-ACK, ACK) establishes that reliable connection before data flows, directly meeting the stem's demand for dependable, in-order transport rather than best-effort delivery.

Why this answer

TCP (Transmission Control Protocol) is the correct choice because it provides reliable, ordered delivery of data with error checking. Its key characteristic is the 3-way handshake (SYN, SYN-ACK, ACK) used to establish a connection before data transfer, ensuring both endpoints are synchronized and ready for reliable communication.

Exam trap

Cisco often tests the misconception that TCP has lower overhead than UDP, or that UDP provides reliability or flow control, leading candidates to confuse the characteristics of connection-oriented vs. connectionless protocols.

How to eliminate wrong answers

Option B is wrong because TCP has higher overhead than UDP due to its connection establishment, acknowledgments, and sequencing mechanisms, not lower overhead. Option C is wrong because UDP is connectionless and low-overhead, but it does not provide reliable, ordered delivery or error checking—it offers no guarantees for delivery or ordering. Option D is wrong because UDP does not provide flow control; flow control is a feature of TCP, implemented via sliding window and advertised window mechanisms.

31
Multi-Selecteasy

Which TWO of the following are examples of application layer protocols?

Select 2 answers
A.HTTP
B.IP
C.FTP
D.TCP
E.ARP
AnswersA, C

HTTP is an application layer protocol used for web traffic.

Why this answer

HTTP (Hypertext Transfer Protocol) operates at the application layer (Layer 7) of the OSI model, enabling web browsers and servers to exchange hypertext documents. It defines how requests and responses are formatted and transmitted, relying on lower-layer protocols like TCP for reliable delivery.

Exam trap

Cisco often tests the distinction between transport layer protocols (TCP/UDP) and application layer protocols, trapping candidates who confuse TCP's role in reliable delivery with application-specific functions like HTTP or FTP.

32
MCQeasy

A network automation engineer is writing a Python script to interact with the Cisco Meraki Dashboard API. The script currently makes GET requests to retrieve a list of networks and then makes subsequent requests for each network to get device details. However, the script is slow due to network latency. The engineer wants to improve performance without changing the API's functionality. Which approach best addresses the performance issue?

A.Wrap all API calls in a single transaction.
B.Increase the timeout value in each request.
C.Use parallel requests with asyncio for concurrent API calls.
D.Use a POST request instead of GET to combine both operations.
AnswerC

Sequential GET requests serialise latency, so each round trip adds delay. asyncio dispatches the per-network device calls concurrently, overlapping network waits and cutting total runtime, which satisfies the performance requirement without altering API behaviour or endpoints.

Why this answer

Using asyncio with an async HTTP library (like aiohttp) allows the script to send multiple GET requests concurrently rather than sequentially, reducing the total wall-clock time dominated by network latency. This approach improves performance without altering the API's functionality or the data being retrieved.

Exam trap

Cisco often tests the distinction between concurrency (asyncio) and parallelism (multithreading/multiprocessing), and candidates may confuse increasing timeouts or changing HTTP methods as valid performance optimizations when they are not.

How to eliminate wrong answers

Option A is wrong because wrapping API calls in a single transaction is not a concept supported by RESTful APIs like the Meraki Dashboard API; transactions are a database concept and do not apply to independent HTTP requests. Option B is wrong because increasing the timeout value only prevents premature timeouts but does not reduce the latency of each request; it may even make the script slower if requests hang longer. Option D is wrong because using POST instead of GET does not combine multiple operations into one request; the Meraki API does not support combining a list-networks and list-devices call into a single POST, and POST is semantically incorrect for read-only operations.

33
MCQmedium

A developer is building a Python microservice that will run in a Docker container on a shared host. The application must read its database connection string and API token from environment variables at runtime, and the developer wants to avoid baking those secrets into the image. Which approach best satisfies this requirement?

A.Copy a .env file containing the secrets into the image with the COPY instruction.
B.Use the ENV instruction in the Dockerfile to set the connection string and token as defaults.
C.Pass the values at runtime with docker run --env or --env-file so the process reads them from the container environment.
D.Commit the secrets into the application's settings.py module so they load at import time.
AnswerC

Environment variables supplied at runtime are injected into the container process when it starts and are not stored in any image layer, so the published image stays free of secrets. The application reads them through the normal process environment, and rotating a credential only requires restarting the container with a new value, which matches the stated requirement exactly.

Why this answer

Secrets that must not persist in a distributed image should be supplied from outside the image at container start. Runtime environment injection keeps the image portable and secret-free, while Dockerfile instructions and source files permanently record whatever they contain. The requirement is about where the value lives, so the mechanism that never writes it into the image is the only one that satisfies it.

Exam trap

The trap here is assuming that any use of environment variables is safe, when the Dockerfile ENV instruction permanently bakes the value into the image layer.

34
Multi-Selectmedium

Which three configuration management tools can be used with Cisco devices for automation? (Choose three.)

Select 3 answers
A.Nagios
B.SaltStack
C.Puppet
D.Chef
E.Ansible
AnswersC, D, E

Puppet supports Cisco devices via agents.

Why this answer

Puppet is a configuration management tool that uses a declarative language to define system state. It can manage Cisco devices via the cisco_ios module, which uses SSH or NX-API to apply configurations, making it suitable for network automation.

Exam trap

Cisco often tests the distinction between monitoring tools (like Nagios) and configuration management tools, and candidates may confuse SaltStack as a primary Cisco automation tool due to its general-purpose nature, but it lacks the dedicated Cisco ecosystem support of Puppet, Chef, and Ansible.

35
MCQhard

Which Python exception would be raised by the following code? my_dict = {'a': 1} value = my_dict['b']

A.KeyError
B.ValueError
C.IndexError
D.AttributeError
AnswerA

Accessing a missing key in a dictionary raises KeyError, because Python's dict lookup requires the key to exist. The code requests 'b' from a dict containing only 'a', so the lookup fails immediately and KeyError propagates.

Why this answer

Accessing a dictionary key that does not exist raises a KeyError in Python. In the code, my_dict['b'] attempts to retrieve the value for key 'b', which is not present in the dictionary {'a': 1}, so Python raises KeyError.

Exam trap

Cisco often tests the distinction between KeyError and IndexError, trapping candidates who confuse dictionary key access with list index access, especially when the code uses square brackets in both contexts.

How to eliminate wrong answers

Option B is wrong because ValueError is raised when a function receives an argument of the correct type but an inappropriate value (e.g., int('abc')), not for missing dictionary keys. Option C is wrong because IndexError is raised when accessing an index out of range in a sequence like a list or tuple, not for dictionary key access. Option D is wrong because AttributeError is raised when an invalid attribute reference or assignment is made (e.g., my_dict.append), not for missing dictionary keys.

36
MCQhard

A Kubernetes pod has two containers: a main application and a sidecar proxy. They need to communicate via localhost. Which pod networking model allows this?

A.Host network
B.Bridge network
C.Overlay network
D.Pod network (containers share the same IP)
AnswerD

Containers within a single pod share one network namespace, hence one IP address and port space, so the sidecar proxy and main application reach each other over localhost. This shared pod network model is exactly what the stem's localhost communication requires.

Why this answer

Containers in the same pod share the same network namespace, so they can communicate via localhost.

37
MCQeasy

What is the purpose of the Authorization header in a REST API call?

A.To specify the content type of the request body
B.To specify the format of the response body
C.To indicate the desired language
D.To authenticate the client sending the request
AnswerD

The Authorization header carries credentials (such as a bearer token or Basic base64 pair) that the server validates to identify the calling client. It satisfies the stem's authentication requirement, distinct from content negotiation headers like Accept, which only declare the desired response format.

Why this answer

The Authorization header in an HTTP request carries credentials (such as a Bearer token, Basic auth, or API key) that the server uses to authenticate and authorize the client. It is the standard mechanism defined in RFC 7235 for transmitting authentication information with a REST API call.

Exam trap

200-901 often tests HTTP header semantics, tricking candidates into confusing Authorization with Content-Type or Accept, which control payload format rather than identity.

How to eliminate wrong answers

Option A is wrong because the content type of the request body is specified by the Content-Type header, not Authorization. Option B is wrong because the desired response format is specified by the Accept header. Option C is wrong because the desired language is specified by the Accept-Language header.

38
MCQeasy

A developer is writing a Python script to interact with the Cisco DNA Center REST API. Which HTTP method should be used to retrieve a list of network devices?

A.GET
B.PUT
C.POST
D.DELETE
AnswerA

GET is the HTTP method defined for safe, read-only retrieval of a resource representation, so it returns the device list from the Cisco DNA Center REST API without altering server state. POST, PUT and DELETE would create, replace or remove data, violating the read-only requirement.

Why this answer

The GET method is the correct HTTP verb for retrieving data from a REST API without modifying server state. In Cisco DNA Center, the endpoint /dna/intent/api/v1/network-device is accessed via GET to fetch a list of network devices, as this operation is idempotent and read-only, aligning with RESTful principles.

Exam trap

Cisco often tests the distinction between safe (GET) and unsafe (PUT, POST, DELETE) HTTP methods, trapping candidates who confuse POST with GET for read operations due to the common misconception that POST can be used for any data-fetching request.

How to eliminate wrong answers

Option B (PUT) is wrong because PUT is used to update or replace an existing resource, not to retrieve data; using it for a read operation would violate REST semantics and likely return a 405 Method Not Allowed error. Option C (POST) is wrong because POST is intended for creating new resources or submitting data to be processed, not for idempotent retrieval; it would incorrectly imply a state change on the server. Option D (DELETE) is wrong because DELETE is used to remove a resource, which is the opposite of retrieving a list; it would result in unintended deletion of network devices.

39
MCQhard

A developer is designing a Python application that must handle failures when making REST API calls to a Cisco DNA Center controller. The application should retry a failed request only if the HTTP status code indicates a server-side error (5xx) or a timeout occurs, but should not retry on client errors (4xx). The developer wants to implement this using a decorator. Which Python library provides a ready-to-use retry decorator that can be configured to retry on specific exceptions and HTTP status codes?

A.urllib3
B.tenacity
C.functools
D.requests
AnswerB

Tenacity is a general-purpose retrying library that provides a decorator and can be configured to retry based on exceptions, including custom conditions. It supports retrying on specific HTTP status codes when integrated with requests, and can be set to stop after a number of attempts. It is widely used in network automation for robust API interactions.

Why this answer

Tenacity is a dedicated retrying library that offers a decorator with extensive configuration options, including retrying on specific exceptions and stop conditions. It can be easily integrated with HTTP status code checks. The other libraries either lack a retry decorator or require manual implementation, making tenacity the correct choice for this scenario.

Exam trap

The trap here is assuming that the requests library includes a built-in retry decorator, when it actually requires using urllib3's Retry with an adapter.

40
MCQeasy

An application needs to retrieve a list of network devices from Cisco DNA Center. Which HTTP method should be used against the /dna/intent/api/v1/network-device endpoint?

A.PUT
B.DELETE
C.GET
D.POST
AnswerC

GET retrieves a representation of the network-device collection without modifying server state, matching the read-only intent of listing devices. POST would create resources, PUT would replace them, and DELETE would remove them, none of which fit a retrieval request.

Why this answer

GET is used to retrieve resources in REST APIs.

41
MCQhard

During a TCP three-way handshake, which sequence of flags is sent from the client to initiate the connection?

A.SYN-ACK
B.SYN
C.ACK
D.FIN
AnswerB

The client begins the three-way handshake by transmitting a single TCP segment with the SYN flag set, carrying its initial sequence number. This synchronises sequence numbers and requests a connection before the server replies with SYN-ACK. Only after the client's final ACK does the connection become established, satisfying the initiation requirement.

Why this answer

The client sends a SYN segment to start the handshake.

42
MCQmedium

A developer is using the Meraki Dashboard API to list all organizations. The base URL is https://api.meraki.com/api/v1/. What is the correct endpoint and authentication method?

A.POST /organizations with Bearer token in Authorization header
B.GET /organizations with Basic Auth username and password
C.GET /organizations with X-Cisco-Meraki-API-Key header
D.GET /v1/organizations with Cookie authentication
AnswerC

The Meraki Dashboard API exposes organisations at GET /organizations under the /api/v1 base URL, and authentication uses the X-Cisco-Meraki-API-Key request header carrying the dashboard API key. This matches the stem's base URL and required listing operation exactly.

Why this answer

The Meraki Dashboard API uses a custom API key for authentication, sent via the `X-Cisco-Meraki-API-Key` header. To list all organizations, the correct HTTP method is GET, and the endpoint is `/organizations` (relative to the base URL `https://api.meraki.com/api/v1/`). This matches option C exactly.

Exam trap

The trap here is that candidates may confuse the Meraki API's custom header authentication with more common methods like Basic Auth or Bearer tokens, or incorrectly assume the endpoint path must include the version number again.

How to eliminate wrong answers

Option A is wrong because listing organizations is a read operation requiring GET, not POST; POST is used for creating resources. Option B is wrong because the Meraki API does not support Basic Auth; it requires a dedicated API key header. Option D is wrong because the endpoint includes `/v1/` redundantly (the base URL already contains the version), and the API uses a custom header, not cookie authentication.

43
MCQeasy

A developer needs to retrieve a list of all networks in a Meraki organization using the Dashboard API. Which API call should be made?

A.GET /organizations/{organizationId}/networks
B.POST /organizations/{organizationId}/networks
C.GET /networks
D.GET /organizations/{organizationId}/networks/{networkId}
AnswerA

GET /organizations/{organizationId}/networks targets the organisation-scoped networks collection, returning every network belonging to that organisation. The path parameter supplies the organisationId the stem requires, and the HTTP GET verb retrieves rather than modifies, satisfying the need to list all networks without additional filtering.

Why this answer

The correct API call to retrieve a list of all networks in a Meraki organization is GET /organizations/{organizationId}/networks. Option A shows this endpoint. Option B uses the wrong HTTP method (POST is for creating).

Option C is missing the organization scope, and option D retrieves a single network.

Exam trap

Cisco often tests the distinction between list and single-resource endpoints, so the trap here is confusing GET /organizations/{organizationId}/networks (list all networks) with GET /organizations/{organizationId}/networks/{networkId} (get one network), or assuming a root-level /networks endpoint exists without the required organization scope.

How to eliminate wrong answers

Option A is wrong because it is identical to the correct answer (B) but not marked as correct in the question; however, in practice, both A and B represent the same endpoint, so the distinction is artificial. Option C is wrong because GET /networks is not a valid Meraki Dashboard API endpoint; the API requires the organization ID in the path to identify the scope. Option D is wrong because GET /organizations/{organizationId}/networks/{networkId} retrieves a single specific network, not a list of all networks.

44
MCQmedium

A developer is building a Python application that uses the Cisco Webex API to send messages. The application must authenticate on behalf of a user without storing the user's password. Which OAuth 2.0 grant type should be used to obtain an access token?

A.Resource Owner Password Credentials Grant
B.Client Credentials Grant
C.Implicit Grant
D.Authorization Code Grant
AnswerD

The Authorization Code Grant is the most secure and appropriate flow for web applications that need to access a user's resources without handling their credentials. It involves redirecting the user to Webex for authentication, then exchanging an authorization code for an access token. This flow supports refresh tokens and is recommended for server-side applications.

Why this answer

To authenticate on behalf of a user without handling their password, the Authorization Code Grant is the correct OAuth 2.0 flow. It redirects the user to the authorization server, where they authenticate directly. The application receives an authorization code, which it exchanges for an access token.

This method is secure, supports refresh tokens, and is widely recommended for server-side applications like the Python app described.

Exam trap

The trap here is confusing the Client Credentials Grant, which is for application-only authentication, with user-delegated authentication, which requires the Authorization Code Grant.

45
MCQmedium

An application needs to discover the MAC address of another device on the same local network. Which protocol does it use?

A.DNS
B.ICMP
C.ARP
D.DHCP
AnswerC

ARP broadcasts a request containing the target IPv4 address, and the owning device replies with its MAC address. This resolves layer-3 to layer-2 addressing within the same broadcast domain, which is exactly what the application needs.

Why this answer

ARP (Address Resolution Protocol) is used to map an IP address to a MAC address on a local network.

46
MCQeasy

In the OSI model, which layer is responsible for logical addressing and routing of packets between networks?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 4 (Transport)
D.Layer 2 (Data Link)
AnswerB

Layer 3 provides logical addressing through IP addresses and determines packet forwarding between networks via routing protocols and routing tables. This satisfies the question's requirement, distinguishing it from Layer 2, which handles physical MAC addressing and local frame delivery.

Why this answer

Layer 3 (Network) of the OSI model handles logical addressing (IP addresses) and routing of packets between different networks via routers. Layer 2 uses physical MAC addresses for local delivery, and Layer 4 handles end-to-end transport (TCP/UDP ports and segmentation). Thus Layer 3 is the correct answer.

Exam trap

The trap here is confusing Layer 2 MAC addressing with Layer 3 logical addressing, or assuming Layer 4 handles routing because it deals with end-to-end communication.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) deals with raw bit transmission over media, not addressing or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end delivery, flow control, and port-based multiplexing (TCP/UDP), not logical addressing or routing. Option D is wrong because Layer 2 (Data Link) uses MAC addresses for node-to-node delivery within the same broadcast domain and does not route between networks.

47
Multi-Selectmedium

A developer is designing a Python script that needs to make multiple REST API calls to different endpoints sequentially. The script must handle the following requirements: (1) Use a variable timeout for each request, (2) Include an authorization token in every request, (3) Parse JSON responses. Which TWO features of the requests library should be used? (Choose two.)

Select 2 answers
A.Set the `data` parameter to JSON for request body.
B.Use the `timeout` parameter to specify a maximum wait time.
C.Use `verify=False` to speed up requests.
D.Set the `auth` parameter with a tuple (username, token).
E.Use the `headers` parameter to include the authorization token.
AnswersB, E

The `timeout` parameter sets a per-request maximum wait in seconds, satisfying requirement (1) for a variable timeout on each sequential call. Passing a distinct value to each `requests.get()` or `requests.post()` invocation prevents a slow endpoint from blocking the script indefinitely.

Why this answer

Option B is correct because the requests library's timeout parameter accepts a float or tuple (connect, read) value that sets the maximum number of seconds to wait for a response, directly satisfying the requirement for a variable timeout on each request. Option E is correct because the headers parameter takes a dictionary such as {'Authorization': 'Bearer <token>'}, which is the standard way to attach an authorization token to every request. Option A is not correct because the data parameter is used for form-encoded or raw request bodies, not for parsing JSON responses, and JSON bodies are typically sent via the json parameter.

Option C is not correct because verify=False disables TLS certificate verification, which is a security risk and unrelated to timeouts, tokens, or JSON parsing. Option D is not correct because the auth parameter expects an authentication handler or a (username, password) tuple for HTTP Basic/Digest auth, not a token, and tokens belong in headers.

Exam trap

Cisco often tests the distinction between the `auth` parameter (for Basic Auth) and the `headers` parameter (for bearer tokens), causing candidates to mistakenly choose Option D when they should use Option E.

48
MCQeasy

A developer needs to share a Docker image with a colleague. They decide to push the image to a registry. Which Docker command pushes an image to a registry?

A.docker export my-image:latest
B.docker commit my-image:latest
C.docker push my-image:latest
D.docker pull my-image:latest
AnswerC

docker push uploads a locally tagged image and its layers to the configured registry repository, making it available for the colleague to pull. Commands such as docker save or docker commit do not transfer the image to a registry, so they fail the sharing requirement.

Why this answer

The `docker push` command is specifically designed to upload a local Docker image to a registry, such as Docker Hub or a private registry. It takes the image name and tag, and sends the image layers to the registry, making it available for others to pull. This is the standard way to share images with colleagues or deploy to other environments.

Exam trap

200-901 often tests the confusion between commands that manipulate local images (commit, export) and those that interact with a registry (push, pull), so candidates must remember that push uploads and pull downloads.

How to eliminate wrong answers

Option A is wrong because `docker export` is used to export a container's filesystem as a tar archive, not to push an image to a registry. Option B is wrong because `docker commit` creates a new image from a container's changes, but does not push it to a registry. Option D is wrong because `docker pull` downloads an image from a registry to the local system, which is the opposite of what is needed.

49
Matchingmedium

Match each HTTP status code to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

OK

Created

Unauthorized

Forbidden

Not Found

Why these pairings

The correct matches are: 200 OK = Request succeeded, 201 Created = Resource created successfully, 400 Bad Request = Malformed syntax or invalid request, 404 Not Found = Resource not found. Common confusions include swapping 200 and 201, as well as 400 and 404.

50
Multi-Selecteasy

Which TWO of the following protocols use UDP as the transport layer protocol? (Choose two.)

Select 2 answers
A.DNS
B.HTTP
C.DHCP
D.SMTP
E.SSH
AnswersA, C

DNS queries use UDP on port 53 for standard resolution, avoiding TCP's handshake overhead for small request-response exchanges. This connectionless transport matches the protocol's need for fast, lightweight lookups, though it falls back to TCP for large responses.

Why this answer

DNS (A) is correct because standard DNS queries and responses use UDP on port 53, since the small request/response exchange benefits from UDP's low overhead and the application handles retransmission itself. DHCP (C) is correct because DHCP operates over UDP, using ports 67 (server) and 68 (client) for its broadcast-based DORA (Discover, Offer, Request, Acknowledge) message exchange. HTTP (B) is not correct because HTTP uses TCP, typically on port 80 or 443, to guarantee ordered and reliable delivery of web content.

SMTP (D) is not correct because SMTP uses TCP on port 25 (or 587/465) to reliably transfer mail between servers. SSH (E) is not correct because SSH uses TCP on port 22 to provide a reliable, encrypted interactive session.

Exam trap

The trap is assuming DNS is TCP-only because of zone transfers, or forgetting that DHCP is UDP — candidates often pick HTTP or SMTP by reflex when asked about 'common protocols.'

51
MCQmedium

A security team wants to ensure that only signed Docker images are deployed in production. Which CI/CD pipeline step validates the image signature before deployment?

A.Use Docker Content Trust with Notary to verify signatures.
B.Compare the image SHA with a known good hash.
C.Run a vulnerability scan on the image.
D.Check the image size on registry.
AnswerA

Docker Content Trust enforces image signing through Notary, which validates the signature against the publisher's key before the image is pulled or run. This directly satisfies the stem's requirement that only signed images reach production, blocking unsigned or tampered images at the pipeline's verification step.

Why this answer

Docker Content Trust (DCT) integrates with Notary to provide a framework for signing and verifying Docker images. When DCT is enabled in the CI/CD pipeline, the Docker client verifies the image's signature against a trusted signing key before allowing the image to be pulled or deployed, ensuring only images signed by authorized parties are used in production.

Exam trap

The trap here is that candidates confuse integrity verification (hash comparison) with authenticity verification (digital signatures), assuming a simple SHA check provides the same security as a full PKI-based signing scheme like Docker Content Trust.

How to eliminate wrong answers

Option B is wrong because comparing the image SHA with a known good hash only verifies integrity (that the image hasn't been tampered with during transit), not authenticity (that the image was signed by a trusted publisher). Option C is wrong because a vulnerability scan checks for known security flaws in the image's packages, but does not validate any cryptographic signature or provenance. Option D is wrong because checking the image size on the registry is a trivial metadata check that provides no security assurance about the image's origin or integrity.

52
MCQmedium

In the TCP three-way handshake, which sequence of flags is exchanged to establish a connection?

A.SYN, ACK, SYN-ACK
B.ACK, SYN, SYN-ACK
C.SYN-ACK, SYN, ACK
D.SYN, SYN-ACK, ACK
AnswerD

The SYN, SYN-ACK, ACK exchange establishes a TCP connection by synchronising sequence numbers in both directions. The client sends SYN, the server replies SYN-ACK acknowledging it while sending its own SYN, then the client returns ACK. This satisfies the stem's requirement for the exact flag sequence of the three-way handshake.

Why this answer

The TCP three-way handshake begins with the client sending a SYN packet to the server, the server responds with a SYN-ACK acknowledging the client's SYN and sending its own SYN, and the client completes with an ACK. This sequence establishes a reliable, bidirectional connection and synchronizes sequence numbers. The correct order is SYN, SYN-ACK, ACK.

Exam trap

200-901 often tests the exact flag order of the handshake, so candidates who confuse the server's SYN-ACK with a separate ACK pick option A.

How to eliminate wrong answers

Option A is wrong because SYN, ACK, SYN-ACK reverses the server's response — the server sends a single SYN-ACK, not a separate ACK then SYN-ACK. Option B is wrong because ACK, SYN, SYN-ACK starts with an ACK, which is not how a new connection is initiated. Option C is wrong because SYN-ACK, SYN, ACK has the server initiating with SYN-ACK before the client sends SYN, which is backwards.

53
MCQmedium

Which authentication flow is most appropriate for a native mobile app that needs to access the Webex API on behalf of a user?

A.Client credentials grant
B.Resource owner password grant
C.Authorization code grant
D.Implicit grant
AnswerC

The authorization code grant returns a short-lived access token after the user authenticates in the browser, so the native app never handles the user's credentials directly. This satisfies the requirement to act on behalf of a user against the Webex API, unlike client credentials, which represents the app itself.

Why this answer

The authorization code grant is the correct flow because it is designed for confidential and public clients (like native mobile apps) that need to act on behalf of a user. It redirects the user to an authorization server, returns a short-lived code, and exchanges it for tokens via a secure back channel, keeping credentials out of the app. This flow supports refresh tokens and is the OAuth 2.0 recommended approach for user-delegated access to APIs like Webex.

Exam trap

The trap here is confusing the client credentials grant (for server-to-server) with user-delegated flows, or assuming the implicit grant is still acceptable for mobile apps despite its deprecation.

How to eliminate wrong answers

Option A is wrong because the client credentials grant is for machine-to-machine communication without a user context, so it cannot act on behalf of a user. Option B is wrong because the resource owner password grant requires the app to directly handle the user's credentials, which is discouraged and incompatible with modern OAuth 2.0 security best practices for third-party APIs. Option D is wrong because the implicit grant is deprecated and designed for browser-based apps, not native mobile apps, and it does not provide refresh tokens.

54
Multi-Selecthard

Which TWO of the following features are provided by Cisco DNA Center but NOT by Cisco Prime Infrastructure? (Choose two.)

Select 2 answers
A.Configuration compliance auditing
B.Software image management
C.Machine learning-based assurance analytics
D.Policy-based automation for SD-Access
E.Network Hierarchy and Site Management
AnswersC, D

DNA Center uses AI/ML for assurance; Prime does not.

Why this answer

Machine learning-based assurance analytics is a feature exclusive to Cisco DNA Center, which uses advanced telemetry and ML algorithms to proactively detect anomalies, predict network issues, and provide closed-loop assurance. Cisco Prime Infrastructure relies on traditional polling and threshold-based monitoring, lacking the predictive and adaptive analytics capabilities that DNA Center's Assurance engine offers.

Exam trap

Cisco often tests the misconception that Prime Infrastructure and DNA Center share all core management features, but the key differentiator is DNA Center's intent-based networking capabilities, including policy-based automation for SD-Access and ML-driven assurance, which are not present in Prime Infrastructure.

55
MCQmedium

A developer is building a Python script that calls the Cisco Webex REST API. The API requires an OAuth 2.0 access token that expires after 14 days. The script will run unattended on a server every hour. Which OAuth 2.0 grant type should the developer use to obtain tokens without user interaction?

A.Client Credentials grant
B.Resource Owner Password Credentials grant
C.Authorization Code grant
D.Implicit grant
AnswerA

Client Credentials is designed for machine-to-machine authentication where no user context is required. The script can exchange its client ID and client secret directly for an access token, allowing it to run unattended and refresh tokens as needed without any browser-based interaction.

Why this answer

The Client Credentials grant is the correct choice because it allows the application to authenticate itself directly with the authorization server using its client ID and secret, without any user involvement. This is ideal for server-to-server automation where the script acts on its own behalf and needs to run unattended.

Exam trap

The trap here is assuming that any OAuth 2.0 flow can be used for automation, when actually only Client Credentials is designed for machine-to-machine scenarios without user interaction.

56
MCQmedium

What is the correct URL path for retrieving the configuration of a network interface using RESTCONF on a Cisco device?

A./restconf/data/ietf-interfaces:interfaces
B./restconf/data/interfaces
C./api/restconf/data/interfaces
D./restconf/operations/get-config
AnswerA

The path `/restconf/data/ietf-interfaces:interfaces` satisfies RESTCONF's mandatory structure: the `/restconf/data` root, followed by the YANG module name (`ietf-interfaces`) and its container. This retrieves interface configuration from the Cisco device's datastore, matching the IETF standard model rather than a vendor-proprietary path.

Why this answer

RESTCONF uses /restconf/data/ followed by the YANG module path. The standard path for interfaces is /restconf/data/ietf-interfaces:interfaces.

57
MCQeasy

Which Docker network driver allows a container to share the host's network stack, giving it direct access to host interfaces?

A.none
B.overlay
C.bridge
D.host
AnswerD

The host driver removes network namespace isolation, so the container binds directly to the host's interfaces and ports rather than receiving its own IP address. This satisfies the requirement for direct access to host interfaces, unlike bridge or overlay drivers, which assign separate addresses and require explicit port publishing.

Why this answer

The 'host' network driver in Docker removes network isolation between the container and the host, allowing the container to use the host's network stack directly. This means the container binds to host interfaces and ports without NAT or port mapping, giving it direct access to the host's IP address and network configuration.

Exam trap

Cisco often tests the misconception that 'bridge' is the default and most common driver, leading candidates to choose it when the question specifically asks for sharing the host's network stack, which only the 'host' driver provides.

How to eliminate wrong answers

Option A is wrong because the 'none' driver disables all networking for the container, leaving it with only a loopback interface and no external connectivity. Option B is wrong because the 'overlay' driver creates a distributed network across multiple Docker hosts, enabling multi-host communication but not sharing the host's own network stack. Option C is wrong because the 'bridge' driver creates an isolated, private network on the host using NAT and port forwarding, preventing direct access to host interfaces.

58
MCQeasy

A developer is automating a Cisco IOS XE device with NETCONF over SSH. The developer must retrieve only the running configuration's hostname without pulling the entire configuration datastore. Which NETCONF operation should the developer use?

A.<copy-config> copying <running/> into <startup/> and then reading the response body
B.<get> with an empty filter, which returns operational and configuration state together
C.<edit-config> targeting <candidate/> with a merge operation on the hostname leaf
D.<get-config> with a source of <running/> and a subtree filter selecting the native hostname node
AnswerD

The get-config operation retrieves configuration data from a specified datastore, and the source element must name that datastore. Pairing <running/> with a subtree filter that matches the Cisco IOS XE native hostname leaf returns only that fragment instead of the whole running configuration, which is exactly what the scenario requires.

Why this answer

Reading a targeted piece of configuration from a NETCONF-capable device requires the read-oriented get-config operation, an explicit source datastore, and a filter that narrows the reply. Selecting the running datastore with a subtree filter that matches the IOS XE native hostname leaf returns exactly that value and nothing else, keeping the payload small and the device state unchanged.

Exam trap

The trap here is assuming the generic get operation is the right way to read configuration, when get-config is the operation designed for pulling filtered configuration from a named datastore.

59
MCQeasy

You are a junior network developer tasked with automating device inventory retrieval using the Cisco Meraki Dashboard API. You have already generated an API key with the appropriate scopes and have tested it successfully with simple GET requests. However, when you attempt to retrieve the list of all devices in your organization via the 'GET /organizations/{organizationId}/devices' endpoint, you receive a 403 Forbidden error. You verify that the API key is correctly included in the request header as 'X-Cisco-Meraki-API-Key'. You also confirm that the organization ID is correct. You are able to reach the Meraki Dashboard API server from your environment, as other endpoints (e.g., 'GET /organizations') work fine. What is the most likely cause of the 403 error, and what should you do to resolve it?

A.The network firewall is blocking the request; check firewall logs and allow outbound traffic to the Meraki API.
B.The API key lacks the required permissions; regenerate the API key with full read access for devices.
C.The request should use POST instead of GET; change the HTTP method to POST to retrieve device data.
D.The API endpoint URL is incorrect; verify the exact path and version in the API documentation.
AnswerB

A 403 on one endpoint while others succeed indicates the key's scopes are insufficient for device read access, not an authentication or connectivity fault. Regenerating the key with full read access for devices grants the missing permission.

Why this answer

A 403 Forbidden error specifically indicates that the server understood the request but refuses to authorize it. Since other endpoints like 'GET /organizations' work, network connectivity and API key validity are confirmed. The most likely cause is that the API key lacks the required scope or permission to access the 'GET /organizations/{organizationId}/devices' endpoint.

Regenerating the API key with full read access (including device inventory) resolves this, as Meraki API keys are scoped at creation time and cannot be modified after generation.

Exam trap

Cisco often tests the distinction between authentication (401) and authorization (403) errors, where a 403 means the key is valid but lacks permissions, tricking candidates into blaming network issues or incorrect endpoints.

How to eliminate wrong answers

Option A is wrong because a network firewall blocking the request would typically result in a timeout or connection error (e.g., 0 bytes received), not a 403 Forbidden HTTP response from the server. Option C is wrong because the Meraki Dashboard API uses GET for retrieving data (as per RESTful conventions), and POST is used for creating resources; changing the method would return a 405 Method Not Allowed or 404, not a 403. Option D is wrong because the endpoint URL is verified correct (the organization ID is confirmed, and other endpoints work), and a wrong URL would produce a 404 Not Found, not a 403 Forbidden.

60
MCQeasy

Which transport protocol is connection-oriented and ensures reliable delivery through acknowledgments and retransmissions?

A.IP
B.HTTP
C.TCP
D.UDP
AnswerC

TCP establishes a session via a three-way handshake before data transfer, then uses sequence numbers, acknowledgments and retransmission of lost segments to guarantee ordered, reliable delivery. This connection-oriented design directly satisfies the stem's requirement for acknowledged, retransmitted transport, unlike connectionless UDP.

Why this answer

TCP is connection-oriented: it establishes a session via the three-way handshake (SYN, SYN-ACK, ACK), then guarantees reliable, ordered delivery using sequence numbers, acknowledgments, and retransmission of lost segments. These mechanisms ensure data arrives intact and in order.

Exam trap

The trap is conflating application-layer protocols like HTTP with transport-layer reliability — candidates must recognize that HTTP's reliability is inherited from TCP, not inherent to HTTP itself.

How to eliminate wrong answers

Option A is wrong because IP is a connectionless, best-effort network-layer protocol that provides no reliability, ordering, or acknowledgment — it merely routes packets. Option B is wrong because HTTP is an application-layer protocol that relies on TCP (or QUIC) for transport; it does not itself provide reliability or acknowledgments. Option D is wrong because UDP is connectionless and unreliable — it sends datagrams without handshakes, acknowledgments, or retransmission, making it suitable for latency-sensitive traffic like VoIP and DNS.

61
MCQmedium

A Python function needs to accept a variable number of keyword arguments. Which parameter syntax should be used?

A.*kwargs
B.**kwargs
C.*args
D.&kwargs
AnswerB

The double-asterisk prefix collects arbitrary keyword arguments into a dictionary, letting the function accept any number of named parameters. A single asterisk would instead gather positional arguments into a tuple, so **kwargs is the syntax that satisfies the variable keyword argument requirement.

Why this answer

In Python, the **kwargs syntax allows a function to accept a variable number of keyword arguments by collecting them into a dictionary. This is the correct parameter syntax for handling arbitrary keyword arguments, as specified in Python's function definition rules.

Exam trap

Cisco often tests the distinction between *args (positional arguments) and **kwargs (keyword arguments), and candidates mistakenly choose *kwargs or confuse the syntax with other operators like &.

How to eliminate wrong answers

Option A is wrong because *kwargs is not valid Python syntax; the correct syntax for variable positional arguments is *args, not *kwargs. Option C is wrong because *args collects extra positional arguments into a tuple, not keyword arguments. Option D is wrong because &kwargs is not a valid Python operator or syntax; Python uses ** for dictionary unpacking and keyword argument collection, not &.

62
MCQhard

A developer is writing a Python script to interact with a REST API that returns JSON. The script must handle rate limiting gracefully. The API returns a 429 status code with a Retry-After header when the limit is exceeded. Which approach should the developer take to ensure the script continues to function without being blocked?

A.Parse the Retry-After header and sleep for the specified number of seconds before retrying.
B.Switch to a different HTTP method to bypass the rate limit.
C.Ignore the 429 response and continue with the next request.
D.Immediately retry the request in a tight loop until it succeeds.
AnswerA

The Retry-After header indicates how long the client should wait before making another request. By sleeping for that duration, the script respects the server's rate limiting policy, avoids being blocked, and ensures that subsequent requests are likely to succeed without hitting the limit again.

Why this answer

Respecting the Retry-After header is the correct way to handle 429 responses. It tells the client exactly how long to wait before retrying, allowing the script to back off appropriately and avoid overwhelming the API. This approach ensures compliance with the API's rate limiting policy and maintains reliable operation.

Exam trap

The trap here is thinking that any retry will eventually work, but without honoring the Retry-After header, the client may be permanently blocked or cause more severe throttling.

63
Multi-Selecthard

A developer is implementing exception handling in Python for a function that makes an HTTP request. Which THREE exception types should be caught to handle common network and HTTP errors? (Choose three.)

Select 3 answers
A.requests.exceptions.ConnectionError
B.requests.exceptions.InvalidURL
C.requests.exceptions.Timeout
D.requests.exceptions.HTTPError
E.requests.exceptions.TooManyRedirects
AnswersA, C, D

ConnectionError is raised when the request cannot reach the server at all, such as DNS failure or refused connection. Catching it handles the transport-level failures the stem's HTTP request function will encounter before any response is received.

Why this answer

Option A, requests.exceptions.ConnectionError, is correct because it is raised when the HTTP request cannot establish a connection to the server, such as DNS resolution failures, refused connections, or other network-level problems that a developer must handle. Option C, requests.exceptions.Timeout, is correct because it is raised when a request exceeds the specified timeout period, covering both connect and read timeouts, which are common in unreliable network conditions. Option D, requests.exceptions.HTTPError, is correct because it is raised by Response.raise_for_status() when the server returns an unsuccessful HTTP status code (4xx or 5xx), representing common HTTP-level errors.

Option B, requests.exceptions.InvalidURL, is not among the marked answers because it typically indicates a malformed URL supplied by the developer rather than a common runtime network or HTTP error. Option E, requests.exceptions.TooManyRedirects, is also not marked because excessive redirects are a less common edge case compared to connection, timeout, and HTTP status failures.

Exam trap

Cisco often tests the distinction between exceptions that represent recoverable runtime errors (ConnectionError, Timeout, HTTPError) versus exceptions that indicate programming bugs (InvalidURL) or edge-case behavior (TooManyRedirects), leading candidates to over-select or under-select the correct set.

64
Multi-Selecthard

Which THREE steps are essential in a typical CI/CD pipeline for a containerized application? (Choose THREE.)

Select 3 answers
A.Perform code review
B.Build the Docker image
C.Push the image to a container registry
D.Run unit and integration tests
E.Deploy directly to production without testing
AnswersB, C, D

Building the Docker image is the foundational pipeline step, converting source code and a Dockerfile into a runnable artefact. Without this stage, subsequent testing and registry push actions have no image to operate on, so it is essential in a containerised CI/CD workflow.

Why this answer

Option B (Build the Docker image) is correct because a containerized CI/CD pipeline must compile the application and package it into an immutable Docker image artifact (e.g., via docker build) that can be versioned and promoted through environments. Option C (Push the image to a container registry) is correct because the built image must be stored in a registry such as Docker Hub, Amazon ECR, or Harbor so that downstream deployment stages and orchestrators like Kubernetes can pull the exact tested artifact. Option D (Run unit and integration tests) is correct because automated testing is a core CI gate that validates the code and image before promotion, catching regressions and ensuring quality prior to deployment.

Option A (Perform code review) is a valuable practice but is a human/process step typically handled in pull requests rather than an essential automated pipeline stage, and Option E (Deploy directly to production without testing) is incorrect because it bypasses the testing and validation gates that define a proper CI/CD pipeline.

Exam trap

Cisco often tests the distinction between development practices (like code review) and automated pipeline steps, so candidates mistakenly include code review as a CI/CD step when it is actually a prerequisite.

65
MCQmedium

A developer is working on a Python application that automates the configuration of multiple Cisco IOS-XE devices using RESTCONF. The application uses the requests library. The developer notices that sometimes the PUT request to update the interface description returns a 409 Conflict error. Upon investigation, the developer finds that the issue occurs when two instances of the application are running concurrently and attempt to update the same interface. The developer wants to implement a strategy to avoid conflicts. Which approach is most effective?

A.Implement a retry mechanism with exponential backoff and random jitter
B.Use a distributed lock mechanism to ensure exclusive access
C.Change the PUT to PATCH and hope for partial updates
D.Use a timestamp in the request to force overwrite
AnswerB

A distributed lock grants only one application instance exclusive access to a given interface resource at a time, serialising concurrent PUT requests. This prevents the race condition that produces the 409 Conflict, directly satisfying the stem's requirement to avoid conflicts between concurrent instances.

Why this answer

A distributed lock mechanism (Option B) is the most effective approach because it ensures exclusive access to the shared resource (the interface configuration) across multiple application instances. In a concurrent environment, retries (Option A) cannot prevent the fundamental race condition—both instances may still attempt conflicting writes. A distributed lock, such as one based on Redis or ZooKeeper, serializes access, guaranteeing that only one instance modifies the interface at a time, which directly resolves the 409 Conflict error from RESTCONF.

Exam trap

Cisco often tests the misconception that retries or changing HTTP methods (PUT to PATCH) can resolve concurrency conflicts, when in fact they do not address the root cause of simultaneous writes to the same resource.

How to eliminate wrong answers

Option A is wrong because a retry mechanism with exponential backoff and random jitter only handles transient conflicts (e.g., network glitches) but does not prevent the underlying race condition—both instances can still attempt to update the same interface concurrently, leading to repeated 409 errors. Option C is wrong because changing PUT to PATCH does not inherently avoid conflicts; RESTCONF PATCH still requires a consistent base state, and concurrent PATCH requests can still cause 409 Conflict errors if the resource changes between reads and writes. Option D is wrong because using a timestamp to force overwrite ignores the conflict detection mechanism of RESTCONF (which uses ETags or If-Match headers) and can lead to lost updates or data corruption, as the server may still reject the request if the timestamp does not match the expected state.

66
MCQmedium

During a security audit, an engineer discovers that a CI/CD pipeline is storing API keys in plain text in environment variables. Which best practice should be implemented to mitigate this risk?

A.Store secrets in a .env file and add it to the repository with restricted access.
B.Encrypt the environment variables using a tool like openssl and store the key elsewhere.
C.Use a dedicated secrets management service like HashiCorp Vault or AWS Secrets Manager and retrieve secrets at runtime.
D.Remove the API keys from the pipeline and require manual entry each time a build runs.
AnswerC

A dedicated secrets manager stores API keys encrypted at rest and issues them only at runtime, eliminating plain-text environment variables from the pipeline. HashiCorp Vault and AWS Secrets Manager also provide audit logging, automatic rotation and fine-grained access policies, directly satisfying the audit's requirement to remove hard-coded credentials from CI/CD configuration.

Why this answer

Dedicated secrets management services like HashiCorp Vault or AWS Secrets Manager provide secure storage, access control, and audit logging for sensitive data. They allow the CI/CD pipeline to retrieve API keys at runtime via authenticated API calls, ensuring secrets are never stored in plain text in environment variables or configuration files. This approach aligns with the principle of least privilege and eliminates the risk of exposure through source code or build logs.

Exam trap

Cisco often tests the misconception that encrypting secrets or storing them in a restricted repository is sufficient, when the correct answer is always to use a dedicated secrets management service that retrieves secrets at runtime, avoiding any persistent storage of sensitive data in the pipeline.

How to eliminate wrong answers

Option A is wrong because storing secrets in a .env file and adding it to the repository, even with restricted access, still embeds the secrets in version control history and exposes them to anyone with repository access, violating the principle of never storing secrets in code. Option B is wrong because encrypting environment variables with openssl and storing the key elsewhere introduces key management complexity and does not prevent the encrypted value from being exposed in logs or environment dumps; the decryption key must still be securely managed, which is often mishandled. Option D is wrong because requiring manual entry of API keys each time a build runs is impractical for automated CI/CD pipelines, introduces human error, and defeats the purpose of continuous integration and deployment.

67
Matchingmedium

Match each Python library to its typical use in network automation.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

HTTP library for REST API calls

SSH protocol implementation

NETCONF client for network devices

Validate JSON data structures

Parse and emit YAML files

Why these pairings

Netmiko, NAPALM, Paramiko, and PyEZ are common Python libraries in network automation. Netmiko simplifies SSH, NAPALM provides a vendor-agnostic API, Paramiko is a low-level SSH library, and PyEZ is Juniper-specific. Common confusions include mixing Netmiko with HTTP libraries and NAPALM with vendor-specific tools.

68
MCQhard

A network automation script uses RESTCONF to configure a router. The script receives an HTTP 409 Conflict response. What is the most likely cause?

A.The resource already exists
B.The router is unreachable
C.The request body is malformed
D.Incorrect authentication
AnswerA

HTTP 409 Conflict signals that the request conflicts with the current state of the target resource, typically because the resource already exists. RESTCONF returns this when creating an object that is already present on the device.

Why this answer

RESTCONF uses HTTP status codes to indicate the result of an operation. An HTTP 409 Conflict specifically means the request could not be completed due to a conflict with the current state of the resource. In the context of a network automation script using RESTCONF to configure a router, this most commonly occurs when the script attempts to create a resource (e.g., an interface or VLAN) that already exists, violating the resource's uniqueness constraint.

Exam trap

Cisco often tests the distinction between HTTP 409 Conflict (resource state conflict) and HTTP 400 Bad Request (malformed syntax), leading candidates to confuse a semantic conflict with a syntax error.

How to eliminate wrong answers

Option B is wrong because a router being unreachable would result in a connection timeout or an HTTP 503 Service Unavailable or 502 Bad Gateway error, not a 409 Conflict. Option C is wrong because a malformed request body would typically trigger an HTTP 400 Bad Request error, indicating the server cannot parse the request. Option D is wrong because incorrect authentication would result in an HTTP 401 Unauthorized or 403 Forbidden response, not a 409 Conflict.

69
Multi-Selectmedium

Which TWO statements about REST API design best practices are true? (Choose two.)

Select 2 answers
A.Avoid API versioning to keep the API simple
B.Include the HTTP method in the URI path, e.g., /getDevices
C.Always use file-based transfer for large payloads
D.Use nouns for resource endpoints, e.g., /devices instead of /getDevices
E.Use HTTP methods appropriately: GET for retrieval, POST for creation, etc.
AnswersD, E

Using nouns for resource endpoints treats each URI as a thing rather than an action, so HTTP verbs (GET, POST, PUT, DELETE) supply the operation. This satisfies REST's uniform-interface constraint and keeps endpoints predictable and cacheable, unlike verb-based paths such as /getDevices.

Why this answer

Option D is correct because REST best practice is to model endpoints as resources using nouns (e.g., /devices), letting the HTTP method express the action rather than embedding verbs in the URI. Option E is correct because REST relies on standard HTTP methods with their defined semantics: GET for safe retrieval, POST for creating resources, PUT/PATCH for updates, and DELETE for removal, which keeps the interface uniform and predictable. Options A, B, and C are not correct: versioning is generally recommended (e.g., /v1/devices or a version header) to allow evolution without breaking clients, so avoiding it is poor practice; putting the method in the path like /getDevices violates the noun-based resource convention and duplicates HTTP semantics; and file-based transfer is not a REST design rule—large payloads are typically handled with streaming, pagination, or chunked transfer rather than mandating file-based transfer.

Exam trap

Cisco often tests the misconception that verbs in URIs (like /getDevices) are acceptable, when in fact REST mandates nouns for resources and HTTP methods for actions, and that avoiding versioning is a shortcut that breaks backward compatibility.

70
Multi-Selectmedium

An application is secured using OAuth 2.0 for Cisco Webex API access. Which three components are involved in the authorization code grant flow? (Choose three.)

Select 3 answers
A.Client Secret
B.Client ID
C.Authorization Code
D.Refresh Token
E.API Key
AnswersA, B, C

The client secret authenticates the application itself when redeeming the authorization code at the token endpoint, satisfying the requirement that confidential clients prove their identity during the OAuth 2.0 authorization code grant. Without it, Webex cannot verify the requesting application, so token exchange fails.

Why this answer

In the OAuth 2.0 authorization code grant flow used for Cisco Webex API access, the Client ID (B) is the public identifier the application presents to the Webex authorization server to identify itself during the authorization request, making it a required component. The Client Secret (A) is the confidential credential the application uses when exchanging the authorization code at the token endpoint, authenticating the client to the Webex authorization server. The Authorization Code (C) is the short-lived credential returned to the redirect URI after the user grants consent, which the client then exchanges for access and refresh tokens, so it is central to this grant type.

The Refresh Token (D) is not part of the initial authorization code grant exchange itself—it is an optional token that may be issued alongside the access token for later use to obtain new access tokens. An API Key (E) is a separate static credential mechanism and is not a component of the OAuth 2.0 authorization code grant flow.

Exam trap

Cisco often tests the distinction between the components used in the initial authorization code grant flow versus those used in subsequent token refresh, causing candidates to incorrectly include the Refresh Token as a required component of the initial flow.

71
MCQmedium

An engineer is designing a CI/CD pipeline for a Python application. The pipeline should automatically run unit tests, build a Docker image, push it to a private registry, and deploy to a Kubernetes cluster. Which sequence of stages is correct?

A.Build -> Test -> Push -> Deploy
B.Test -> Push -> Deploy
C.Test -> Deploy -> Build -> Push
D.Test -> Build -> Push -> Deploy
AnswerD

Unit tests must pass before any artefact is produced, so Test precedes Build; the image can only be pushed after it exists, and deployment requires the pushed image. This ordering satisfies the pipeline's dependency chain and prevents broken code reaching the registry or cluster.

Why this answer

A CI/CD pipeline for a Python application must first run unit tests to validate code quality, then build the Docker image from the tested code, push the image to a private registry, and finally deploy to Kubernetes. This sequence ensures that only tested and built artifacts are deployed, preventing deployment of broken or untested code.

Exam trap

Cisco often tests the logical order of CI/CD stages, and the trap here is that candidates may think building before testing is acceptable, but the pipeline must validate code before creating artifacts to avoid deploying untested code.

How to eliminate wrong answers

Option A is wrong because it places Build before Test, which would build a Docker image from untested code, risking deployment of a broken image. Option B is wrong because it omits the Build stage entirely, meaning no Docker image is created before pushing to the registry, which is impossible. Option C is wrong because it attempts to Deploy before Build and Push, which would fail since no image exists in the registry to deploy to Kubernetes.

72
MCQeasy

A network engineer is writing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) REST API. They need to authenticate and obtain a token that will be used in subsequent API calls. Which HTTP header should be included in the authentication request to specify the expected response format?

A.Authorization: Basic <credentials>
B.Accept: application/json
C.Content-Type: application/xml
D.X-Auth-Token: <token>
AnswerB

The Accept header tells the server what media type the client expects in the response. For Cisco Catalyst Center APIs, specifying application/json ensures the authentication response is returned in JSON format, which is the standard for these APIs. This allows the script to parse the token easily and use it in later calls.

Why this answer

To request a JSON response from the Catalyst Center authentication endpoint, the client must include the Accept header with application/json. This header informs the server of the desired response format. Other headers serve different purposes: Content-Type describes the request body, Authorization provides credentials, and X-Auth-Token is used after authentication.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.

73
Multi-Selectmedium

A Python script is interacting with a REST API that returns JSON. The script needs to handle potential errors gracefully. Which TWO practices should be implemented? (Choose two.)

Select 2 answers
A.Use response.raise_for_status() to raise exceptions for HTTP errors.
B.Use a single try/except block to catch all exceptions without differentiation.
C.Check response.status_code to determine success or failure.
D.Assume the request always succeeds; errors are rare.
E.Always parse the response body with json.loads() regardless of content type.
AnswersA, C

Using `response.raise_for_status()` converts 4xx and 5xx HTTP status codes into `HTTPError` exceptions, satisfying the stem's requirement to handle API errors gracefully rather than silently processing failed responses. This lets the script catch failures explicitly instead of parsing error payloads as valid JSON data.

Why this answer

Option A is correct because response.raise_for_status() from the requests library inspects the HTTP status code and raises an HTTPError for 4xx and 5xx responses, letting the script handle failures via try/except instead of silently processing bad data. Option C is correct because explicitly checking response.status_code (e.g., comparing against 200 or using 200 <= status_code < 300) lets the script branch on success or failure and decide whether to parse JSON or handle the error, which is essential for graceful error handling. Option B is not appropriate because a single undifferentiated try/except hides the specific cause of failures and prevents tailored handling of HTTP errors, JSON decode errors, or connection issues.

Option D is wrong because assuming requests always succeed ignores network failures, timeouts, and 4xx/5xx responses, which defeats graceful error handling. Option E is wrong because calling json.loads() unconditionally can raise JSONDecodeError on non-JSON bodies (e.g., HTML error pages), so parsing should occur only after confirming a successful, JSON content-type response.

Exam trap

Cisco often tests the distinction between using `response.raise_for_status()` versus manually checking `response.status_code` — the trap is that candidates think only one is correct, but both are valid and complementary practices for robust error handling.

74
Multi-Selectmedium

Which TWO statements are true about VXLAN? (Choose two.)

Select 2 answers
A.VXLAN requires MPLS in the underlay
B.VXLAN encapsulates Ethernet frames in UDP packets
C.VXLAN uses IP-in-IP encapsulation
D.VXLAN operates at Layer 2 only
E.VXLAN supports up to 16 million logical networks
AnswersB, E

VXLAN uses MAC-in-UDP encapsulation, wrapping the original Layer 2 Ethernet frame inside a UDP datagram for transport across a Layer 3 underlay. This is the mechanism that lets Layer 2 segments extend over routed networks.

Why this answer

Option B is correct because VXLAN (RFC 7348) performs MAC-in-UDP encapsulation, taking an inner Layer 2 Ethernet frame and wrapping it in an outer UDP header (destination port 4789) carried over the IP underlay, which is what allows the Layer 2 overlay to traverse a routed Layer 3 network. Option E is correct because VXLAN uses a 24-bit VXLAN Network Identifier (VNI), yielding 2^24 = 16,777,216 distinct logical segments, far exceeding the 12-bit VLAN limit of 4094. Option A is wrong because VXLAN's underlay only needs IP reachability and multicast or unicast (e.g., via EVPN) for BUM traffic; MPLS is not required.

Option C is wrong because IP-in-IP is a different tunneling mechanism (protocol 4) that does not carry an inner Ethernet frame or a VNI. Option D is wrong because VXLAN is a Layer 2-over-Layer 3 overlay: it encapsulates Layer 2 frames but relies on Layer 3 IP routing in the underlay, so it does not operate at Layer 2 only.

Exam trap

Cisco often tests the misconception that VXLAN is a pure Layer 2 technology, but the trap here is that VXLAN encapsulates Layer 2 frames into Layer 3 UDP packets, making it a Layer 2 overlay over a Layer 3 underlay.

75
Multi-Selecteasy

Which TWO Ansible modules are commonly used for automating Cisco IOS devices?

Select 2 answers
A.junos_config
B.nxos_command
C.ios_config
D.ios_command
E.eos_config
AnswersC, D

Manages Cisco IOS configuration.

Why this answer

The `ios_config` module is correct because it is specifically designed to manage Cisco IOS device configurations by sending configuration commands via SSH or Telnet, using the CLI to apply changes to the running or startup configuration. This module is part of Ansible's `cisco.ios` collection and directly supports the IOS operating system, making it the standard choice for automating configuration tasks on Cisco IOS devices.

Exam trap

Cisco often tests the candidate's ability to distinguish between device-specific Ansible modules (e.g., `ios_config` vs. `nxos_command`) rather than generic command modules, so the trap here is assuming that any 'command' module works across all Cisco platforms, when in fact each OS family (IOS, NX-OS, IOS-XR) has its own dedicated modules in the Ansible collections.

Page 1 of 13

Page 2