Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 76–150

975 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
Multi-Selectmedium

Which TWO of the following are commonly used when implementing pagination in REST APIs? (Select TWO)

Select 2 answers
A.Cursor-based token in response
B.Rate limiting headers
C.OAuth 2.0 token
D.Offset and limit query parameters
E.Webhook callback URL
AnswersA, D

Cursor-based pagination returns an opaque token pointing to the next page, avoiding skipped or duplicated records when data changes between requests. The server supplies the cursor in the response, which the client echoes back, satisfying the requirement for a commonly used pagination technique.

Why this answer

Option A (cursor-based token in response) is correct because cursor pagination returns an opaque token (often in a 'next_cursor' or Link header) that the client sends back to fetch the next page, giving stable results even when records are inserted or deleted. Option D (offset and limit query parameters) is correct because it is the most common pagination pattern, e.g. GET /items?offset=20&limit=10, where limit caps page size and offset skips records.

Option B (rate limiting headers) is wrong because headers like X-RateLimit-Remaining or Retry-After govern request throttling, not page navigation. Option C (OAuth 2.0 token) is wrong because it is an authorization credential (bearer token), unrelated to paginating result sets. Option E (webhook callback URL) is wrong because webhooks push event notifications to a subscriber endpoint, not retrieve successive pages of a collection.

77
MCQhard

An engineer wants to trigger an EEM applet when a specific syslog message appears. Which event detector should be used?

A.event timer cron
B.event interface
C.event cli pattern
D.event syslog pattern
AnswerD

The event syslog pattern detector matches incoming syslog messages against a regular expression, triggering the applet when the specified text appears. This directly satisfies the requirement to react to a specific syslog message rather than a timer or interface event.

Why this answer

EEM's syslog event detector triggers on syslog messages matching a pattern.

78
Multi-Selecthard

A team is reviewing its CI/CD pipeline for security weaknesses. The pipeline builds and deploys a containerized application. Which TWO practices best reduce the risk of a compromised build environment affecting the deployed application? (Choose two.)

Select 2 answers
A.Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.
B.Use short-lived, scoped credentials issued to the pipeline at runtime instead of persistent secrets.
C.Allow the build to push directly to the production registry without any image signing or verification.
D.Store long-lived cloud credentials as environment variables in the CI/CD platform for all pipeline runs.
E.Reuse the same build agent for all pipelines to save time and avoid environment setup.
AnswersA, B

This is correct because an isolated, ephemeral build environment limits the persistence of any compromise. If an attacker compromises the build, the environment is destroyed after the run, so they cannot maintain access or tamper with future builds. It also prevents cross-contamination between pipeline runs and reduces the blast radius of a compromised build.

Why this answer

Isolated, ephemeral build environments and short-lived scoped credentials both limit the impact of a compromised build. The ephemeral environment prevents persistence, while short-lived credentials reduce the value of any stolen secrets. Persistent agents and long-lived credentials increase risk because a compromise can persist and be reused, and unsigned images remove verification of the deployed artifact.

Exam trap

The trap here is assuming that reusing build agents and storing long-lived credentials is efficient, when both increase the persistence and blast radius of a compromise.

79
Multi-Selecthard

Which TWO of the following are valid ways to handle errors in a Python program that uses the Cisco Meraki API?

Select 2 answers
A.Checking the response body for an 'errors' key and handling accordingly
B.Checking the HTTP status code and raising an exception for 4xx and 5xx
C.Assuming the API always returns 200 and logging success
D.Retrying the request indefinitely until success
E.Using a try-except block around the API call and catching generic Exception
AnswersA, B

The Meraki API returns structured JSON error payloads, so inspecting the response body for an 'errors' key lets the program read the specific failure reason and branch accordingly, satisfying the requirement to handle API-level errors rather than only transport failures.

Why this answer

Option A is correct because the Cisco Meraki API returns structured JSON error payloads that include an 'errors' key (for example, {"errors":["Invalid API key"]}), so inspecting the response body for that key lets the program detect and handle API-level failures even when the HTTP status alone is ambiguous. Option B is correct because the Meraki API uses standard HTTP status codes, returning 4xx for client errors such as 400 Bad Request, 401 Unauthorized, 404 Not Found, and 429 Too Many Requests, and 5xx for server errors, so checking the status code and raising an exception for those ranges is a reliable, idiomatic error-handling pattern. Option C is wrong because assuming a 200 response and logging success ignores real failure conditions like 401, 404, or 429 and would silently mask errors.

Option D is wrong because retrying indefinitely can hammer the API, trigger rate limiting (429) or account suspension, and never terminate; retries should be bounded and ideally use exponential backoff. Option E is wrong because catching a generic Exception is overly broad and can swallow unrelated bugs such as TypeError or KeyError, rather than handling specific HTTP or API errors precisely.

Exam trap

Cisco often tests the distinction between handling errors via HTTP status codes versus parsing the response body for API-specific error fields, and the trap here is that candidates may think catching a generic Exception is sufficient, but the exam expects specific, layered error handling that respects both the HTTP protocol and the API's documented response format.

80
MCQhard

A developer is integrating with Cisco SD-WAN vManage using REST APIs. After successfully submitting credentials, the API returns a 401 Unauthorized error for subsequent requests. What is the most likely missing step?

A.The request URL must include an API key parameter.
B.The API call must use the HTTPS protocol.
C.The password must be sent in base64 encoding.
D.The session token (X-XSRF-TOKEN) must be obtained and included in subsequent requests.
AnswerD

Cisco SD-WAN vManage uses cookie-based session authentication: the login response sets a JSESSIONID cookie plus an X-XSRF-TOKEN header value. Subsequent REST calls must replay both, otherwise vManage rejects them with 401 despite valid credentials. Capturing the token from the authentication response satisfies the stem's requirement for authenticated follow-up requests.

Why this answer

Cisco SD-WAN vManage uses a two-step authentication process: first, credentials are submitted to obtain a session token (X-XSRF-TOKEN) and a JSESSIONID cookie. If subsequent API requests do not include the X-XSRF-TOKEN in the HTTP header, vManage rejects them with a 401 Unauthorized error, as the token is required for CSRF protection and session validation.

Exam trap

Cisco often tests the distinction between session cookies and CSRF tokens, trapping candidates who assume that a successful login alone (cookie) is enough for all subsequent API calls.

How to eliminate wrong answers

Option A is wrong because vManage does not require an API key parameter in the URL; it relies on session-based tokens (X-XSRF-TOKEN) and cookies for authentication. Option B is wrong while HTTPS is strongly recommended for security, its absence would typically cause a connection failure or redirect, not a 401 Unauthorized error after successful credential submission. Option C is wrong because vManage expects credentials in JSON format (plain text or hashed), not base64 encoding; base64 is used for HTTP Basic Authentication, which is not the default for vManage REST APIs.

81
Multi-Selecthard

A network engineer is using Cisco DNA Center to automate network changes. Which THREE operations are part of the 'Change your network' API category? (Choose three.)

Select 3 answers
A.Create and assign a site to a device
B.Run a command on a device via Command Runner
C.Initiate a Plug and Play (PnP) device provisioning
D.Deploy a configuration template to devices
E.Retrieve the list of network devices
AnswersA, C, D

Site creation is part of changing the network topology.

Why this answer

The 'Change your network' API category in Cisco DNA Center includes operations that actively modify the network state. Creating and assigning a site to a device is a configuration change that associates a physical location with a device, which directly alters the network's logical topology and is part of the site management workflow under this API category.

Exam trap

Cisco often tests the distinction between read-only (query/inventory) and write (change) API operations, and the trap here is that candidates mistakenly classify 'Run a command on a device' as a change because it interacts with a device, but it is a transient troubleshooting action, not a persistent configuration change.

82
MCQhard

A large enterprise uses Cisco DNA Center to manage its campus network. The network team has automated wireless SSID provisioning using the Intent API. Recently, a new SSID was created but it does not appear on the wireless LAN controllers. The Python script that calls the API returns a 200 OK response, but the SSID is not deployed. The script uses the POST /dna/intent/api/v1/ssid endpoint with a JSON body containing the SSID name and security settings. A day later, the SSID is still missing. The engineer checks the DNA Center GUI and sees the SSID in the 'Design' section but with a 'Provisioning Failed' status. Which step should the engineer take next to resolve the issue?

A.Re-run the same API call and ignore the 200 response
B.Use the 'Provision' API endpoint to deploy the SSID to the targeted sites
C.Delete the SSID and recreate it with a different name
D.Wait for the next scheduled provisioning cycle
AnswerB

The 200 OK confirms the SSID was created in the Design inventory, not deployed. Cisco DNA Center separates design from provisioning, so the engineer must call the Provision API to push the SSID to targeted sites, resolving the 'Provisioning Failed' status.

Why this answer

The 200 OK response from the POST /dna/intent/api/v1/ssid endpoint only confirms that the API request was accepted and the SSID configuration was created in the DNA Center design database. It does not automatically trigger deployment to the wireless LAN controllers. The 'Provisioning Failed' status in the GUI indicates that the SSID was designed but not successfully deployed to the targeted sites.

To complete the deployment, the engineer must use the Intent API's 'Provision' endpoint (e.g., POST /dna/intent/api/v1/provision) to push the SSID configuration to the specific sites or devices, which is the missing step.

Exam trap

Cisco often tests the distinction between design and provisioning phases in the Intent API, and the trap here is that candidates assume a 200 OK response means the configuration is fully deployed, when in reality it only confirms the design was accepted.

How to eliminate wrong answers

Option A is wrong because re-running the same API call will only recreate the design object and return another 200 OK, but it will not trigger deployment; the provisioning step is separate and required. Option C is wrong because deleting and recreating the SSID with a different name does not address the root cause—the design object already exists, and the failure is in the provisioning workflow, not the SSID name. Option D is wrong because DNA Center does not have a scheduled provisioning cycle; provisioning is an explicit action that must be initiated via the API or GUI, and waiting will not resolve the issue.

83
MCQhard

A developer is implementing a Cisco Intersight API solution to manage multiple UCS domains. They receive an HTTP 403 Forbidden response when trying to create an organization. What is the most likely issue?

A.The request body is malformed
B.The user account does not have sufficient privileges
C.The API key is invalid
D.The organization already exists
AnswerB

403 means the server understands the request but refuses to authorize it.

Why this answer

An HTTP 403 Forbidden response indicates that the server understood the request but is refusing to authorize it. In the context of Cisco Intersight, this typically means the API key or user account associated with the request lacks the required privileges to perform the action, such as creating an organization. Only accounts with administrative or appropriate role-based access control (RBAC) permissions can create organizations.

Exam trap

Cisco often tests the distinction between HTTP 401 (authentication failure) and 403 (authorization failure) to trap candidates who confuse invalid credentials with insufficient privileges.

How to eliminate wrong answers

Option A is wrong because a malformed request body would typically result in a 400 Bad Request error, not a 403 Forbidden. Option C is wrong because an invalid API key would result in a 401 Unauthorized error, indicating authentication failure rather than authorization failure. Option D is wrong because attempting to create an organization that already exists would result in a 409 Conflict error, not a 403 Forbidden.

84
Multi-Selectmedium

A developer is writing unit tests for a Python function that parses JSON responses from a Cisco Meraki API. The function takes a JSON string and returns a dictionary. The developer wants to follow best practices for unit testing. Which TWO of the following are recommended practices when writing these tests? (Choose two.)

Select 2 answers
A.Include at least one test case for invalid JSON input to verify error handling.
B.Use a test double to simulate the API response instead of making real HTTP calls.
C.Assert only on the final output of the function, ignoring intermediate states.
D.Write tests that depend on the order of execution to save time.
E.Use a single test function that covers all possible edge cases to reduce the number of tests.
AnswersA, B

Testing invalid input ensures that the function handles errors gracefully, such as raising appropriate exceptions or returning meaningful error messages. This is a key aspect of robust unit testing, as it validates the function's behavior under unexpected conditions and helps prevent crashes in production.

Why this answer

Best practices for unit testing include isolating the code under test from external dependencies using test doubles, and covering edge cases such as invalid input. These practices ensure tests are fast, reliable, and comprehensive. The other options describe anti-patterns like order dependence and monolithic tests, which reduce test effectiveness.

Exam trap

The trap here is thinking that testing with real API calls is more realistic and therefore better, when it actually makes tests fragile and slow.

85
MCQhard

A developer is using the Meraki Dashboard API to retrieve a list of clients for a network. After a successful request, the response includes a Link header with rel="next" pointing to the next page. What does this indicate about the API's pagination?

A.The API uses page-based pagination with page and perPage parameters.
B.The API uses offset-based pagination and the next page can be retrieved by incrementing an offset parameter.
C.The API uses Link header pagination and the next page can be retrieved by following the URL in the Link header.
D.The API uses cursor-based pagination with startingAfter/endingBefore parameters.
AnswerC

The Link header with rel="next" signals cursor-based pagination: the API returns a partial result set plus a URL for the following page. Following that URL directly retrieves the next batch, so the developer iterates until no rel="next" link remains.

Why this answer

Meraki API uses Link headers for pagination, and a rel="next" link indicates there are additional pages to fetch.

86
MCQmedium

Which Git command is used to switch to an existing branch named 'feature-x' and update the working directory?

A.git merge feature-x
B.git branch feature-x
C.git switch -c feature-x
D.git checkout feature-x
AnswerD

git checkout with a branch name switches HEAD to that existing branch and updates the working directory to match its committed tree, satisfying the stem's requirement to both switch branches and refresh files. git branch alone only lists or creates branches without changing the working directory.

Why this answer

`git checkout feature-x` is the traditional Git command that switches the HEAD reference to the existing branch 'feature-x' and updates the working directory to match that branch's commit history. This command performs both the branch switch and the working tree update in one operation, which is the core requirement of the question.

Exam trap

Cisco often tests the distinction between `git checkout` for switching to an existing branch versus `git checkout -b` (or `git switch -c`) for creating and switching to a new branch, and candidates frequently confuse the `-c` flag as a switch-only option rather than a creation flag.

How to eliminate wrong answers

Option A is wrong because `git merge feature-x` integrates changes from 'feature-x' into the current branch, rather than switching to 'feature-x'. Option B is wrong because `git branch feature-x` creates a new branch named 'feature-x' from the current HEAD, but does not switch to it or update the working directory. Option C is wrong because `git switch -c feature-x` creates and switches to a new branch named 'feature-x', but the question specifies switching to an existing branch, and the `-c` flag is for creation, not for an existing branch.

87
Multi-Selecthard

Which two statements about the Cisco DevNet Sandbox are true?

Select 2 answers
A.Sandboxes cannot be used for learning APIs
B.Sandboxes require a paid subscription for basic access
C.Sandboxes can be reserved for a fixed time period
D.Sandboxes provide always-on access to a limited set of devices
E.Sandboxes only support Cisco IOS XE devices
AnswersC, D

Many sandboxes require reservation.

Why this answer

Cisco DevNet Sandboxes allow users to reserve a sandbox for a fixed time period, typically ranging from 2 to 4 hours, providing exclusive access to a pre-configured lab environment. This reservation model ensures that users have dedicated resources without contention, which is essential for testing APIs, automation scripts, or network configurations. The fixed-time reservation is a core feature of the DevNet Sandbox service, distinguishing it from always-on sandboxes.

Exam trap

Cisco often tests the distinction between 'always-on' sandboxes (which provide persistent but limited access) and 'reserved' sandboxes (which offer full, time-limited access), and candidates may incorrectly assume all sandboxes require payment or only support a single OS.

88
MCQhard

A developer is using the Meraki Dashboard API and receives a 429 Too Many Requests error. The API documentation states a rate limit of 5 calls per second. What is the best practice to handle this?

A.Ignore the error and retry immediately.
B.Use a different API key to bypass the limit.
C.Increase the number of concurrent requests to exhaust the rate limit quickly.
D.Implement exponential backoff and honor the Retry-After header.
AnswerD

Exponential backoff spaces retries progressively, preventing repeated collisions with the 5 calls per second limit, while honouring Retry-After respects the server's stated wait. Together they satisfy the rate-limit constraint without hammering the Meraki Dashboard API.

Why this answer

Implementing exponential backoff with retry-after headers is the recommended approach for rate-limited APIs. Ignoring or simply retrying immediately may worsen the situation.

89
MCQmedium

A developer is using the Cisco Meraki Dashboard API to retrieve the list of organizations associated with an API key. The script must handle the response and avoid exposing the API key. Which HTTP header should be used to supply the API key?

A.Cookie: meraki_api_key=<API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.Authorization: Bearer <API_KEY>
D.X-Auth-Token: <API_KEY>
AnswerB

The Meraki Dashboard API authenticates requests with the X-Cisco-Meraki-API-Key header containing the API key. Supplying it in this header keeps the key out of the URL and query string. The endpoint for listing organizations then returns the organizations the key is authorized to access.

Why this answer

The Meraki Dashboard API authenticates each request with the X-Cisco-Meraki-API-Key header. Placing the key in a header rather than a URL keeps it out of server logs and browser history. Other header names belong to different Cisco platforms or authentication schemes and would not authenticate against Meraki.

Exam trap

The trap here is assuming all Cisco APIs use the same authentication header, when Meraki uses a platform-specific API key header.

90
Multi-Selecthard

A DevOps engineer is automating network configuration using REST APIs. The engineer needs to choose between NETCONF and OpenFlow as southbound protocols. Which TWO statements are correct?

Select 2 answers
A.OpenFlow allows the controller to install flow entries in switches
B.NETCONF provides real-time packet forwarding control
C.Both protocols are used exclusively for northbound APIs
D.OpenFlow is primarily used for configuration management
E.NETCONF uses YANG data models and XML encoding
AnswersA, E

OpenFlow is a southbound protocol where the controller pushes match-action flow entries directly into switch flow tables, governing forwarding behaviour. This programmatic control of forwarding matches the automation scenario, distinguishing it from NETCONF's configuration-focused role.

Why this answer

Option A is correct because OpenFlow is a southbound protocol in SDN in which the controller pushes flow entries (match/action rules) into the flow tables of OpenFlow-enabled switches to dictate forwarding behavior. Option E is correct because NETCONF is a configuration protocol that models device data with YANG and encodes messages in XML over SSH (port 830), making it well suited for automated configuration management. Option B is wrong because NETCONF handles configuration and state retrieval, not real-time per-packet forwarding control, which is OpenFlow's role.

Option C is wrong because both NETCONF and OpenFlow are southbound protocols, not northbound APIs. Option D is wrong because OpenFlow is primarily a forwarding-plane control protocol, whereas configuration management is NETCONF's domain.

91
MCQeasy

A Python script using the Cisco Meraki API must update the SSID settings for a network. Which HTTP method should be used to modify an existing SSID?

A.PUT
B.POST
C.DELETE
D.GET
AnswerA

PUT replaces the existing SSID configuration resource with the supplied representation, which is the Meraki Dashboard API's documented method for updating SSID settings. POST would create a new resource rather than modify the existing SSID.

Why this answer

To modify an existing SSID in the Cisco Meraki API, the HTTP PUT method is used because it performs an idempotent update of the resource at the specified URI. The Meraki API follows RESTful conventions where PUT replaces the entire representation of the SSID object, making it the correct choice for updating an existing SSID's settings (e.g., name, encryption, or splash page).

Exam trap

Cisco often tests the distinction between PUT and POST in REST APIs, and the trap here is that candidates mistakenly think POST can be used for updates because they confuse it with 'update' in general CRUD terminology, but POST is specifically for creation in RESTful design.

How to eliminate wrong answers

Option B (POST) is wrong because POST is used to create a new resource (e.g., add a new SSID to a network), not to update an existing one; using POST on an existing SSID would typically result in a 409 Conflict or create a duplicate. Option C (DELETE) is wrong because DELETE is used to remove an SSID entirely, not to modify its settings; calling DELETE on an SSID would remove it from the network. Option D (GET) is wrong because GET is a read-only method used to retrieve the current configuration of an SSID, not to change it.

92
MCQhard

A Python script using ncclient to configure a Cisco IOS XE device fails with an error that the capability 'urn:ietf:params:xml:ns:netconf:base:1.0' is missing. What is the most likely cause?

A.The device does not have NETCONF enabled
B.The username or password is incorrect
C.The edit-config operation should be on candidate instead of running
D.The host key verification is disabled incorrectly
AnswerA

The NETCONF subsystem must be explicitly enabled on Cisco IOS XE using the `netconf-yang` command before ncclient can connect. Without it, the device never advertises the base NETCONF 1.0 capability in its hello message, so the session fails during capability exchange. Enabling NETCONF satisfies the stem's missing-capability constraint.

Why this answer

The error indicates that the NETCONF base capability (urn:ietf:params:xml:ns:netconf:base:1.0) is not advertised by the device. This capability is mandatory for any NETCONF server; its absence means the device is not running a NETCONF server or NETCONF is not enabled. On Cisco IOS XE, NETCONF must be explicitly enabled via the 'netconf-yang' feature, and the error occurs when the ncclient client attempts to establish a session but the device does not respond with the required capability.

Exam trap

Cisco often tests the distinction between authentication/SSH errors and NETCONF capability negotiation errors, trapping candidates who confuse a missing capability with a credential or transport issue.

How to eliminate wrong answers

Option B is wrong because incorrect username or password would result in an authentication failure (e.g., 'Authentication error' or 'SSHException'), not a missing capability error. Option C is wrong because the error is about the base capability not being present during session establishment, not about the target datastore (candidate vs. running) used in an edit-config operation. Option D is wrong because host key verification issues would cause an SSH connection failure (e.g., 'Host key not found' or 'SSHException'), not a missing NETCONF capability error.

93
MCQeasy

A network engineer wants to automate the configuration of multiple Cisco IOS devices using Ansible. What is the minimum requirement on the control node to execute Ansible playbooks against these devices?

A.Ansible Tower license for automated network configuration
B.A PostgreSQL database to store inventory and credentials
C.A dedicated management server with Ansible Tower installed
D.A Linux or macOS control node with Python installed
AnswerD

Ansible runs agentlessly from a control node, which must be Linux or macOS with Python installed; no agent is needed on managed Cisco IOS devices. This satisfies the minimum control-node requirement for executing playbooks over SSH or network APIs.

Why this answer

Ansible uses a push-based architecture where the control node must be a Linux or macOS system with Python installed to execute playbooks. Python is required because Ansible itself is written in Python and relies on it for modules, SSH connections, and Jinja2 templating. No additional database, license, or dedicated management server is needed for basic network automation against Cisco IOS devices.

Exam trap

Cisco often tests the misconception that Ansible requires a dedicated server or commercial product like Ansible Tower, when in fact the minimum requirement is simply a Linux/macOS host with Python and the Ansible package installed.

How to eliminate wrong answers

Option A is wrong because Ansible Tower (now Red Hat Ansible Automation Platform) is a commercial web UI and API layer that adds RBAC, scheduling, and auditing, but it is not a minimum requirement; the open-source Ansible Engine can run playbooks directly from any control node. Option B is wrong because a PostgreSQL database is only required if you use Ansible Tower's inventory and credential storage; the default flat-file inventory and SSH keys or vault-encrypted credentials work without any database. Option C is wrong because a dedicated management server with Ansible Tower installed is an enterprise deployment pattern, not a minimum requirement; a standard Linux or macOS workstation with Ansible installed via pip or package manager suffices.

94
MCQhard

Refer to the exhibit. This JSON response was received from the Cisco DNA Center API. A developer wants to extract the software version of the first device. Which Python expression correctly retrieves '16.12.5' from the variable `data`?

A.data[0]['softwareVersion']
B.data['response'][0]['version']
C.data['response']['softwareVersion']
D.data['response'][0]['softwareVersion']
AnswerD

The JSON nests devices inside the 'response' array, so indexing [0] selects the first device before the 'softwareVersion' key is accessed. Chained bracket notation traverses each level precisely, returning the string '16.12.5' rather than the whole device object.

Why this answer

The JSON response from Cisco DNA Center's API is structured with a 'response' key containing an array of device objects. To access the software version of the first device, you must first index into the array with [0] to get the first device object, then use the key 'softwareVersion' to retrieve the value '16.12.5'. The variable `data` holds the entire JSON object, so `data['response'][0]['softwareVersion']` correctly navigates this nested structure.

Exam trap

The trap here is that candidates often forget the 'response' wrapper and treat the JSON as a flat list, or confuse the key name 'version' with 'softwareVersion', which Cisco deliberately uses to test attention to exact field names in the API schema.

How to eliminate wrong answers

Option A is wrong because it assumes `data` is a list (using `data[0]`), but the JSON response is a dictionary with a 'response' key, not a top-level array. Option B is wrong because it uses the key 'version' instead of 'softwareVersion', which does not exist in the device object; the correct key is 'softwareVersion'. Option C is wrong because it omits the array index [0], attempting to access 'softwareVersion' directly on the 'response' list, which would cause a TypeError since lists are not subscriptable by string keys.

95
MCQhard

A developer is integrating a Python application with the Cisco DNA Center API. The application must handle rate limiting gracefully. The API returns HTTP 429 Too Many Requests with a 'Retry-After' header indicating the number of seconds to wait before retrying. Which approach best implements exponential backoff with jitter to respect the rate limit and avoid overwhelming the server?

A.Upon receiving 429, wait for the number of seconds specified in Retry-After, then retry the request. If it fails again, double the wait time and add a random jitter between 0 and 1 second.
B.Upon receiving 429, wait for a fixed 60 seconds before retrying, regardless of the Retry-After header. Repeat this fixed wait for each retry.
C.Upon receiving 429, log the error and abort the request permanently, as rate limiting indicates a fatal error.
D.Upon receiving 429, immediately retry the request in a tight loop until it succeeds, ignoring the Retry-After header.
AnswerA

This approach respects the server's Retry-After header, which is the authoritative wait time. Then, for subsequent retries, it implements exponential backoff with jitter by doubling the wait and adding randomness. This combination is a best practice for handling rate limits and transient errors, reducing the chance of repeated collisions.

Why this answer

The best practice for handling 429 responses is to honor the Retry-After header and then apply exponential backoff with jitter for subsequent retries. This respects the server's guidance while preventing synchronized retries from multiple clients. The other options either ignore the header, use fixed waits, or give up permanently, all of which are suboptimal.

Exam trap

The trap here is either ignoring the Retry-After header or implementing backoff without jitter, which can lead to thundering herd problems.

96
MCQhard

A developer is deploying an application to a Kubernetes cluster and must ensure that the application's configuration values, such as a database hostname and port, are injected as environment variables without storing them in the container image. Which Kubernetes resource should be used?

A.ServiceAccount
B.Secret
C.ConfigMap
D.PersistentVolumeClaim
AnswerC

A ConfigMap stores non-confidential key-value configuration data and can be consumed as environment variables via envFrom or valueFrom. This keeps configuration out of the image and allows changes by updating the ConfigMap. It directly matches the requirement for database hostname and port values that are not sensitive.

Why this answer

A ConfigMap is designed for non-sensitive configuration data and can be referenced by a pod to populate environment variables. This decouples configuration from the image and allows the same image to run in different environments. Secrets are for confidential values, while storage and identity resources serve entirely different purposes.

Exam trap

The trap here is reaching for a Secret whenever configuration must be externalized, even when the values are explicitly non-sensitive.

97
MCQmedium

A developer is writing a Python script that must call a Cisco DNA Center REST API. The script must authenticate with a username and password over HTTPS and receive a token that is valid for subsequent API calls. The developer wants to avoid embedding the credentials in the script. Which approach should be used?

A.Read the username and password from environment variables and POST them to the DNA Center authentication endpoint to obtain a token.
B.Hardcode the credentials in a configuration file and commit the file to the Git repository so the script can read it at runtime.
C.Use an OAuth 2.0 authorization code flow with a browser-based redirect to obtain an access token for the DNA Center API.
D.Send the username and password as query parameters on every API call instead of obtaining a token first.
AnswerA

DNA Center authentication uses a POST to the /dna/system/api/v1/auth/token endpoint with HTTP Basic authentication, returning a token used in the X-Auth-Token header. Reading credentials from environment variables keeps them out of source code and allows the same script to run in different environments without modification.

Why this answer

DNA Center issues a time-limited token when valid credentials are POSTed to its authentication endpoint. Supplying those credentials through environment variables keeps them out of source control and supports rotation across environments. The token is then supplied on subsequent requests, which is exactly the behavior the scenario requires without embedding secrets in the script.

Exam trap

The trap here is assuming that any HTTPS API must use a browser-based OAuth flow, when DNA Center issues tokens directly from a Basic-authenticated token endpoint.

98
MCQmedium

Which HTTP status code indicates that a POST request successfully created a new resource?

A.204 No Content
B.301 Moved Permanently
C.201 Created
D.200 OK
AnswerC

HTTP 201 Created is returned when a POST request results in a new resource being created on the server, typically accompanied by a Location header identifying the new resource's URI. It precisely signals successful creation, unlike 200 OK, which merely indicates general success.

Why this answer

HTTP 201 Created is the standard response indicating that a request (typically POST) has succeeded and resulted in the creation of a new resource. The response often includes a Location header pointing to the URI of the newly created resource, per RFC 7231.

Exam trap

200-901 often tests the confusion between 200 OK and 201 Created, since both indicate success — candidates must remember that 201 specifically signals resource creation.

How to eliminate wrong answers

Option A is wrong because 204 No Content indicates success but no body to return, commonly used for DELETE or PUT updates, not for resource creation. Option B is wrong because 301 Moved Permanently is a redirection status indicating the resource has permanently moved to a new URL. Option D is wrong because 200 OK is a generic success response that does not specifically signal resource creation — it is used for successful GET, PUT, or POST when no more specific code applies.

99
MCQeasy

A developer is integrating a monitoring application with Cisco Meraki API to retrieve network health data. The application needs to ensure it doesn't exceed the API rate limit of 5 requests per second. What is the best practice for handling this limitation?

A.Increase the rate limit by contacting Cisco support.
B.Use a single API key for all requests to reduce overhead.
C.Implement exponential backoff and retry after receiving a 429 status code.
D.Send all requests in a loop without delay to complete quickly.
AnswerC

A 429 response signals the rate limit was breached; exponential backoff progressively lengthens the wait between retries, letting the client recover without hammering the API. This directly satisfies the 5 requests per second ceiling by pacing retries rather than dropping data.

Why this answer

The Cisco Meraki API returns HTTP 429 (Too Many Requests) when the rate limit of 5 requests per second is exceeded. Implementing exponential backoff—where the application waits progressively longer intervals between retries—is the standard best practice for handling rate limits gracefully, as it reduces server load and increases the chance of successful retries without overwhelming the API.

Exam trap

Cisco often tests the misconception that rate limits can be bypassed by technical tricks like using a single API key or sending requests faster, when the correct approach is to respect the 429 response with exponential backoff.

How to eliminate wrong answers

Option A is wrong because the rate limit is a fixed server-side policy enforced by Cisco Meraki; contacting support will not increase it, and the developer must work within the documented limits. Option B is wrong because using a single API key does not affect the rate limit—rate limiting is applied per API key or per organization, and a single key cannot reduce overhead or bypass the 5 requests per second cap. Option D is wrong because sending all requests in a loop without delay will immediately trigger 429 responses, causing all requests to fail and potentially leading to temporary IP blocking or account throttling.

100
Multi-Selectmedium

A development team is adopting container security practices for their Docker-based microservices. They want to reduce the attack surface of their running containers. Which TWO practices should they implement? (Choose two.)

Select 2 answers
A.Use minimal base images such as distroless or Alpine to reduce installed packages
B.Mount the Docker socket into every container to simplify orchestration
C.Run containers as a non-root user by setting the USER instruction in the Dockerfile
D.Disable the Docker content trust feature to allow unsigned images
E.Set the container to privileged mode so it can access all host devices
AnswersA, C

Minimal base images contain far fewer packages, libraries, and shells, which reduces the number of potential vulnerabilities and removes tools an attacker could use after gaining access. Fewer components mean fewer patch obligations and a smaller footprint. This is a widely recommended practice for shrinking container attack surface.

Why this answer

Running as a non-root user and using minimal base images both reduce what an attacker can do inside a compromised container and how many components could contain vulnerabilities. Together they shrink the attack surface without breaking normal application function. The other listed practices either grant excessive privileges or weaken supply chain verification.

Exam trap

The trap here is equating convenience features like socket mounts or privileged mode with security, when they actually expand the attack surface.

101
MCQmedium

An application needs to authenticate to Cisco DNA Center. Which authentication method is used?

A.API key in X-Cisco-DNA-Center-API-Key header
B.OAuth2 with client credentials grant
C.Bearer token in Authorization header with no prior step
D.Basic Auth over HTTPS to obtain a token
AnswerD

Correct. Basic Auth is used to get a token for subsequent API calls.

Why this answer

DNA Center uses Basic Auth to obtain a token via POST /dna/system/api/v1/auth/token.

102
MCQhard

A DevOps team is developing a CI/CD pipeline for a microservices application that uses Cisco NSO (Network Services Orchestrator) for network configuration. The application code is stored in a Git repository. The pipeline must automatically trigger a test suite when a pull request is merged to the main branch, but only if the tests pass, then deploy to a staging environment. The team is using Jenkins. A junior engineer suggests using a single Jenkinsfile with a declarative pipeline that includes all stages. However, a senior engineer notes that the pipeline should be designed for reusability and maintainability, especially as the number of microservices grows. Which approach best meets these requirements?

A.Use shared libraries to define common stages like testing and deployment, and reference them in each microservice's Jenkinsfile.
B.Create separate Jenkinsfiles for each microservice and call them from a main pipeline using the "build" step.
C.Use a single scripted pipeline that uses "parallel" for microservices and "stage" for testing and deployment.
D.Use a single declarative pipeline with all stages defined in the Jenkinsfile and use "when" conditions to control execution.
AnswerA

Shared libraries extract common pipeline stages into a versioned, centrally maintained repository, so each microservice's Jenkinsfile references them rather than duplicating logic. This directly satisfies the reusability and maintainability constraint as the number of microservices grows, unlike a single monolithic declarative pipeline.

Why this answer

Shared libraries in Jenkins allow common pipeline logic (e.g., testing and deployment stages) to be defined once and reused across multiple microservices. This promotes reusability and maintainability, as changes to the shared library automatically propagate to all Jenkinsfiles, reducing duplication and simplifying updates as the number of microservices grows.

Exam trap

The trap here is that candidates often choose a monolithic pipeline (Option D) because it seems simpler, but Cisco tests the understanding that reusability and maintainability in a microservices architecture require decoupling pipeline logic via shared libraries, not centralizing it.

How to eliminate wrong answers

Option B is wrong because creating separate Jenkinsfiles for each microservice and calling them from a main pipeline using the 'build' step still leads to duplication of pipeline logic across microservices, which undermines maintainability and reusability. Option C is wrong because using a single scripted pipeline with 'parallel' for microservices tightly couples all microservices into one pipeline, making it difficult to manage individual service updates and reducing reusability. Option D is wrong because using a single declarative pipeline with all stages defined in the Jenkinsfile and 'when' conditions results in a monolithic pipeline that is hard to maintain as microservices proliferate, violating the principles of reusability and modularity.

103
Drag & Dropmedium

Drag and drop the steps to configure OSPF on a Cisco router into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

OSPF configuration requires enabling the OSPF process, setting a router ID, and advertising networks in specific areas.

104
MCQmedium

A developer runs `python -c "import requests; r=requests.get('https://api.example.com/v1/status'); print(r.json())"` on a Linux host. The command returns a JSON payload instantly, but when the same request is sent to `http://api.example.com/v1/status` the client hangs and later times out with no response. Which network-layer behavior best explains why the HTTPS URL succeeds while the HTTP URL fails?

A.HTTP/1.1 requires a three-way handshake that TCP port 443 avoids by using UDP.
B.TCP port 80 is filtered by an intermediate device, while TCP port 443 is permitted.
C.The server's default gateway is missing, so replies to port 80 are dropped.
D.The DNS A record for api.example.com resolves only for TLS connections.
AnswerB

The client hangs on port 80 and times out, which is the classic signature of silently dropped TCP SYN segments on an ACL or firewall policy. Because the same hostname and application reach the service over 443, routing and name resolution are already proven correct, so the only variable left is the destination port being filtered between client and server.

Why this answer

The only difference between the two attempts is the destination port: 443 succeeds and 80 times out. When a TCP connection times out rather than receiving an immediate RST, an intermediate firewall or ACL is silently discarding the SYN. Because the hostname resolved and the encrypted session completed, name resolution and routing are functioning, leaving port-level filtering as the cause.

Exam trap

The trap here is assuming HTTPS is inherently more reliable or uses a different transport, when the real difference is that port 80 is being silently blocked while port 443 is allowed.

105
MCQeasy

A developer runs a Python script that uses the requests library to call a REST API endpoint. The script receives an HTTP 401 Unauthorized response. The developer confirms the URL is correct and the server is reachable. Which action should the developer take to resolve the issue?

A.Verify that the API endpoint URL includes the correct query parameters.
B.Change the HTTP method from GET to POST.
C.Increase the request timeout value in the Python script.
D.Include a valid authentication token in the request's Authorization header.
AnswerD

A 401 Unauthorized response indicates that the request lacks valid authentication credentials for the target resource. The developer must supply a proper token, such as a Bearer token, in the Authorization header. Adding the header allows the server to authenticate the client and return a successful response, assuming the token has the required permissions.

Why this answer

An HTTP 401 Unauthorized status means the request lacks valid authentication credentials. The developer must provide a valid token or credentials, typically in the Authorization header. Changing the method, query parameters, or timeout does not address the authentication failure, so including a valid token is the correct resolution.

Exam trap

The trap here is assuming that a 401 error is caused by an incorrect URL or method rather than missing or invalid authentication credentials.

106
Multi-Selectmedium

Which TWO of the following are southbound protocols in SDN?

Select 2 answers
A.OSPF
B.NETCONF
C.SNMP
D.OpenFlow
E.REST
AnswersB, D

NETCONF is a southbound protocol: the SDN controller uses it to configure and retrieve state from managed network devices. It runs over SSH and exchanges XML-encoded configuration data, sitting below the controller in the architecture, which satisfies the stem's southbound requirement.

Why this answer

NETCONF (B) is correct because it is a southbound protocol used between an SDN controller and managed network devices, allowing configuration data to be retrieved, edited, and committed via YANG-modeled operations over SSH. OpenFlow (D) is correct because it is the classic southbound protocol that lets an SDN controller program the forwarding tables of switches in the data plane. OSPF (A) is a routing protocol used between routers to exchange topology information, not a controller-to-device SDN southbound interface.

SNMP (C) is a network management protocol for monitoring and managing devices, but it is not the standard SDN southbound control protocol. REST (E) is typically a northbound API style used by applications to communicate with the SDN controller, not a southbound protocol.

Exam trap

The trap is confusing northbound with southbound — REST and SNMP are commonly (mis)selected as southbound, but REST is northbound and SNMP is a management protocol, not a controller-to-data-plane SDN interface.

107
MCQeasy

An engineer needs to automate the backup of configuration files from multiple Cisco IOS devices to a central server. Which protocol is most appropriate for pushing configurations from the devices to the server?

A.TFTP
B.FTP
C.HTTP
D.SCP
AnswerD

SCP runs over SSH, providing encrypted, authenticated file transfer from IOS devices to a central server. Cisco IOS supports SCP natively via the archive or copy commands, satisfying the requirement to push configuration files securely.

Why this answer

SCP (Secure Copy Protocol) is the most appropriate choice because it provides encrypted, authenticated file transfers over SSH, ensuring the confidentiality and integrity of Cisco IOS configuration backups. It is natively supported on Cisco IOS devices and allows secure push operations to a central server without requiring additional software.

Exam trap

Cisco often tests the distinction between secure and insecure file transfer protocols in automation contexts, and the trap here is that candidates may choose TFTP due to its simplicity and common use in lab environments, overlooking the security requirements for production backups.

How to eliminate wrong answers

Option A is wrong because TFTP lacks any security mechanisms (no encryption or authentication) and is typically used for local network transfers like booting or initial configs, not for secure backups to a central server. Option B is wrong because FTP transmits credentials and data in cleartext and requires complex firewall configurations, making it insecure and less suitable for automated, secure backups. Option C is wrong because HTTP is not designed for file transfers in this context; it is stateless and insecure without HTTPS, and Cisco IOS devices do not natively support HTTP-based config push operations to a server.

108
MCQeasy

What is the output of the following code? my_list = [1, 2, 3] for i in range(len(my_list)): my_list[i] += 1 print(my_list)

A.[2, 3, 4]
B.[1, 2, 3, 1]
C.[1, 2, 3]
D.Error
AnswerA

range(len(my_list)) yields indices 0, 1 and 2. Each iteration increments the element at that index in place via +=, transforming [1, 2, 3] into [2, 3, 4]. The list is mutated directly, so print outputs the updated values.

Why this answer

The loop iterates over indices 0, 1, and 2 using range(len(my_list)). On each iteration, my_list[i] += 1 increments the element at that index in place. Starting from [1, 2, 3], the three iterations produce [2, 3, 4], which is what gets printed.

Exam trap

The trap is assuming that modifying a loop variable inside a for loop has no effect on the underlying list — candidates confuse rebinding a local variable with index-based in-place assignment.

How to eliminate wrong answers

Option B is wrong because it describes appending a new element (1) to the list, but the code uses index assignment (+=), not append, so the list length stays at 3. Option C is wrong because it assumes no mutation occurred, but the += operator modifies each element in place during the loop. Option D is wrong because the code is syntactically and semantically valid — iterating by index with range(len(...)) and mutating elements is legal in Python and does not raise an error.

109
MCQeasy

The exhibit shows a JSON response from a Cisco NX-OS API query for interface status. What is the operational state of interface Ethernet1/1?

A.unknown
B.down
C.admin-down
D.up
AnswerB

The JSON response reports Ethernet1/1 with admin state enabled but oper state down, meaning the interface is administratively up yet has no link. This satisfies the stem's request for operational state, which reflects link-level status rather than configured intent.

Why this answer

The JSON response shows the interface Ethernet1/1 with an 'operState' value of 'down'. In Cisco NX-OS, the 'operState' field directly reflects the operational status of the interface, which is determined by Layer 1 and Layer 2 conditions such as cable connectivity, signal detection, and protocol state. Since the value is 'down', the interface is not passing traffic, making option B correct.

Exam trap

Cisco often tests the distinction between administrative state (adminState) and operational state (operState), where candidates mistakenly assume that an interface with adminState 'up' must also be operationally 'up', but the operational state depends on physical and protocol conditions.

How to eliminate wrong answers

Option A is wrong because 'unknown' would indicate that the operational state could not be determined, but the JSON explicitly provides 'down' as the operState, not 'unknown'. Option C is wrong because 'admin-down' refers to the administrative state (adminState), not the operational state; the JSON shows 'adminState' as 'up', meaning the interface is administratively enabled. Option D is wrong because 'up' would require the operState to be 'up', but it is explicitly 'down' in the response.

110
MCQmedium

A Docker container running a web application needs to be accessible on the host's port 8080. The application inside the container listens on port 80. Which docker run command achieves this?

A.docker run -d --expose 80 -p 8080 myapp
B.docker run -d -p 80:8080 myapp
C.docker run -d -P 8080:80 myapp
D.docker run -d -p 8080:80 myapp
AnswerD

Publishing with `-p 8080:80` maps host port 8080 to container port 80, satisfying the requirement that external traffic on 8080 reaches the application listening internally on 80. The `-d` flag runs the container detached, so the terminal returns immediately while the web app keeps serving.

Why this answer

The -p flag maps a host port to a container port using the format host:container. Since the host should listen on 8080 and the application inside the container listens on 80, the correct mapping is -p 8080:80. The -d flag runs the container detached, which is appropriate for a web service.

Exam trap

200-901 often tests the order of the -p flag — candidates reverse host and container ports or confuse -p with -P and --expose, leading to a mapping that does not match the application's listening port.

How to eliminate wrong answers

Option A is wrong because --expose 80 only documents the container port for inter-container communication and does not publish it to the host, so the host's port 8080 is never bound. Option B is wrong because -p 80:8080 reverses the mapping, binding host port 80 to container port 8080, which does not match the application's listening port and may require privileged access for port 80. Option C is wrong because -P (uppercase) publishes all exposed ports to random host ports and does not accept a port mapping argument; the syntax -P 8080:80 is invalid.

111
MCQmedium

A network engineer is designing a data center network with leaf-spine topology. The requirement is to minimize latency and maximize bandwidth for east-west traffic. Which type of links should be used between leaf and spine switches?

A.Multiple links with VSS
B.Single link with LACP
C.Multiple parallel links with ECMP routing
D.Single link with STP
AnswerC

Multiple parallel links with ECMP routing satisfy the east-west bandwidth and latency requirement by load-balancing traffic across several equal-cost paths between each leaf and spine switch. This increases aggregate throughput and provides redundancy, avoiding the oversubscription and single-path congestion that a lone uplink would impose on the data centre fabric.

Why this answer

In a leaf-spine topology, east-west traffic (server-to-server) must traverse the spine switches. Using multiple parallel links with Equal-Cost Multi-Path (ECMP) routing allows all links to be active simultaneously, maximizing bandwidth and minimizing latency by load-balancing traffic across all available paths. ECMP leverages Layer 3 routing (e.g., OSPF or BGP) to forward packets over multiple equal-cost paths, which is ideal for the non-blocking, high-throughput design of leaf-spine architectures.

Exam trap

Cisco often tests the misconception that link aggregation (LACP or VSS) is the best way to increase bandwidth in a leaf-spine design, but the trap is that these are Layer 2 solutions that do not provide the active-active multipath routing (ECMP) required for optimal east-west traffic in a Layer 3 leaf-spine topology.

How to eliminate wrong answers

Option A is wrong because VSS (Virtual Switching System) is a Cisco proprietary technology that bundles multiple physical switches into a single logical switch using a control plane, which introduces complexity and does not scale well in a leaf-spine design; it also relies on a single control plane that can become a bottleneck for east-west traffic. Option B is wrong because a single link with LACP (Link Aggregation Control Protocol) provides link redundancy and increased bandwidth only within a single aggregated link, but it does not provide the multiple parallel active paths needed for full bisectional bandwidth in a leaf-spine topology; LACP is a Layer 2 solution that does not leverage ECMP routing. Option D is wrong because a single link with STP (Spanning Tree Protocol) blocks redundant paths to prevent loops, resulting in only one active link at a time, which severely limits bandwidth and increases latency for east-west traffic; STP is designed for traditional tree topologies, not for the active-active multipath requirement of leaf-spine.

112
MCQmedium

A network administrator is configuring SNMPv3 on a router for secure monitoring. Which combination of parameters is required to ensure authentication and encryption?

A.SNMPv3 with authPriv
B.SNMPv3 with noAuthNoPriv
C.SNMPv3 with authNoPriv
D.SNMPv2c with a complex community string
AnswerA

authPriv enforces both authentication (MD5 or SHA) and encryption (DES or AES) for SNMPv3, satisfying the stem's dual requirement. Unlike authNoPriv, which authenticates but transmits data in cleartext, authPriv encrypts the payload, so credentials and monitored data remain confidential in transit.

Why this answer

SNMPv3 with authPriv is the correct combination because it enables both authentication (via HMAC-MD5 or HMAC-SHA) and encryption (via DES or AES) to ensure secure monitoring. The authPriv security level provides message integrity, origin authentication, and data confidentiality, meeting the requirement for both authentication and encryption.

Exam trap

Cisco often tests the distinction between authNoPriv and authPriv, where candidates mistakenly think authentication alone is sufficient for 'secure monitoring' and overlook the encryption requirement.

How to eliminate wrong answers

Option B (noAuthNoPriv) is wrong because it provides no authentication or encryption, offering only a username for identification with no security. Option C (authNoPriv) is wrong because it enables authentication but no encryption, leaving the SNMP payload in cleartext and vulnerable to eavesdropping. Option D (SNMPv2c with a complex community string) is wrong because SNMPv2c uses community strings for authentication only, which are transmitted in plaintext and provide no encryption, failing the encryption requirement.

113
MCQeasy

A network engineer wants to retrieve a list of all network devices from Cisco DNA Center using REST API. Which URL and HTTP method should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/topology/l2/{vlanID}
D.GET /dna/intent/api/v1/network-device
AnswerD

GET requests to `/dna/intent/api/v1/network-device` return the full device inventory from Cisco DNA Center's intent API, satisfying the requirement to retrieve, not modify, all network devices. The GET method is idempotent and read-only, matching the stem's retrieval constraint without side effects.

Why this answer

Cisco DNA Center provides the GET /dna/intent/api/v1/network-device endpoint to list all network devices.

114
MCQhard

In the context of microservices for network automation, which pattern ensures that each service has a separate database to avoid tight coupling?

A.Circuit breaker
B.Database per service
C.API gateway
D.Shared database
AnswerB

Database per service gives each microservice private, dedicated storage, so no service reads or writes another's schema directly. This satisfies the stem's constraint of avoiding tight coupling, since changes to one service's data model cannot break others. Services then integrate only through APIs or events, preserving independent deployment and scaling.

Why this answer

The Database per service pattern ensures each microservice owns its private database, preventing tight coupling by eliminating shared schema dependencies. This aligns with the bounded context principle in domain-driven design, where each service manages its own data model independently, enabling autonomous deployments and scaling.

Exam trap

Cisco often tests the Database per service pattern by contrasting it with the Shared Database anti-pattern, where candidates mistakenly think sharing a database simplifies development, but the exam emphasizes that it creates tight coupling and violates microservices design principles.

How to eliminate wrong answers

Option A is wrong because the Circuit Breaker pattern handles fault tolerance by preventing cascading failures when a service is unresponsive, not database isolation. Option C is wrong because the API Gateway pattern provides a single entry point for routing, authentication, and rate limiting, but does not dictate database ownership per service. Option D is wrong because a Shared Database pattern creates tight coupling by forcing multiple services to access the same schema, violating microservices independence and leading to coordination overhead.

115
MCQeasy

A DevOps engineer is using the Cisco Meraki API to retrieve a list of networks. Which HTTP method should be used?

A.PUT
B.POST
C.DELETE
D.GET
AnswerD

GET retrieves representations of resources without altering state, matching the requirement to list networks. The Meraki API exposes network collections at a REST endpoint, and retrieval is a safe, idempotent read operation, so GET is the method the stem's scenario demands.

Why this answer

The GET method is the correct HTTP verb for retrieving a list of networks from the Cisco Meraki API because it is a read-only operation that fetches existing resources without modifying server state. The Meraki API follows RESTful conventions where GET requests are used to query collections or individual resources, and the endpoint for listing networks is typically a GET to /organizations/{organizationId}/networks.

Exam trap

Cisco often tests whether candidates confuse POST with GET for read operations, especially when the API documentation uses POST for non-standard actions like generating reports or running queries, leading candidates to incorrectly assume POST is acceptable for retrieving lists.

How to eliminate wrong answers

Option A (PUT) is wrong because PUT is used to update or replace an existing resource, not to retrieve data; using PUT for a read operation would violate REST semantics and could cause unintended side effects. Option B (POST) is wrong because POST is used to create a new resource or submit data for processing, not to fetch a list; the Meraki API uses POST for actions like creating networks or generating API keys. Option C (DELETE) is wrong because DELETE is used to remove a resource, which is the opposite of retrieving a list; sending a DELETE to a collection endpoint would attempt to delete the entire collection.

116
MCQmedium

A developer is writing a Python script that uses the Cisco SD-WAN (vManage) API to create a device template. The API requires the request body to include the template configuration and the device model. Which HTTP method and resource path should the developer use?

A.PUT /dataservice/template/device/feature
B.DELETE /dataservice/template/device
C.POST /dataservice/template/device
D.GET /dataservice/template/device
AnswerC

POST to /dataservice/template/device creates a new device template in vManage. The request body must include the device model and the template configuration. This matches the requirement to create a device template, and POST is the correct method for resource creation on the vManage REST API.

Why this answer

Creating a device template in Cisco SD-WAN vManage requires an HTTP POST to the /dataservice/template/device resource. The request body must contain the device model and the configuration. GET retrieves, PUT updates, and DELETE removes, so only POST aligns with the create operation described in the scenario.

Exam trap

The trap here is confusing the feature template endpoint with the device template endpoint, or assuming that any write method such as PUT can create a resource.

117
MCQmedium

A developer is integrating a Python script with Cisco Webex Teams. The script must create a new space and then immediately post a message to that space. After the POST to /v1/rooms, the API returns HTTP 200 with a JSON body containing the new room's id. The script then needs to send a message. Which approach correctly uses the API response to post the message to the newly created room?

A.Parse the 'Link' header from the response and use its URL as the 'roomId' in a subsequent POST to /v1/messages.
B.Use the HTTP status code 200 as the 'roomId' in a subsequent POST to /v1/messages.
C.Use the 'title' of the room as the 'roomId' in a subsequent POST to /v1/messages.
D.Extract the 'id' field from the JSON response and use it as the 'roomId' in a subsequent POST to /v1/messages.
AnswerD

The Webex Teams API returns the unique room identifier in the 'id' field of the JSON response. To post a message to that room, the developer must include that id as the 'roomId' parameter in the POST body to /v1/messages. This is the standard pattern for chaining API calls, where one response supplies the necessary identifier for the next request.

Why this answer

When creating a resource via a REST API, the response typically includes the unique identifier of the new resource. For the Webex Teams API, the POST to /v1/rooms returns a JSON object with an 'id' field. To post a message to that room, the developer must pass that 'id' as the 'roomId' in the message creation request.

This demonstrates understanding of API chaining and resource identification.

Exam trap

The trap here is assuming that a human-readable field like the room title can serve as a unique identifier, when the API requires the system-generated id.

118
MCQeasy

What is the primary function of a switch in a network?

A.Forward frames based on MAC addresses
B.Amplify wireless signals
C.Forward packets based on IP addresses
D.Convert data to electrical signals
AnswerA

Forwarding frames by MAC address is the defining function of a Layer 2 switch, satisfying the stem's requirement for the primary role. It builds a MAC address table from source addresses and forwards each frame only out the port leading to the destination, rather than flooding every port as a hub does.

Why this answer

Switches operate at Layer 2 and forward frames based on MAC addresses within a LAN.

119
MCQmedium

A developer is automating network configuration using Cisco DNA Center. They want to deploy a configuration template to multiple devices. Which API category should they use?

A.Change your network
B.Platform
C.Run your network
D.Know your network
AnswerA

Correct. Template deployment, plug and play are part of 'change your network'.

Why this answer

Template deployment falls under 'change your network' API category.

120
MCQmedium

A developer is integrating with the Cisco Meraki Dashboard API. They need to update the name of an existing network. Which HTTP method should they use to modify only the name attribute without affecting other attributes?

A.PATCH
B.GET
C.PUT
D.POST
AnswerA

PATCH is designed for partial updates, allowing the client to send only the fields that need to be changed. In Cisco Meraki Dashboard API, using PATCH on the network endpoint with a JSON body containing just the name will update that attribute while leaving others intact. This is the correct method for modifying a single attribute without affecting the rest of the resource.

Why this answer

PATCH is the correct HTTP method for partial updates. It allows sending only the changed attribute, such as the network name, without affecting other fields. PUT replaces the entire resource, POST creates, and GET retrieves.

In Cisco Meraki API, PATCH is used to update specific attributes of a network.

Exam trap

The trap here is confusing PUT with PATCH; PUT replaces the whole resource, while PATCH only modifies specified fields.

121
MCQmedium

A developer wants to deploy a containerized application on a Cisco Container Platform (CCP) cluster. The application requires persistent storage. Which Kubernetes resource should be used to provision storage?

A.Secret
B.Service
C.PersistentVolumeClaim
D.ConfigMap
AnswerC

A PersistentVolumeClaim requests storage from a StorageClass, which dynamically provisions a PersistentVolume that outlives the pod. Binding the claim to the deployment's pod spec gives the application persistent storage across restarts, matching the stem's requirement on the CCP cluster.

Why this answer

PersistentVolumeClaim (PVC) is the correct Kubernetes resource for requesting persistent storage. A PVC binds to a PersistentVolume (PV) that provides storage independent of pod lifecycle. ConfigMap is for configuration data, not persistent storage.

Secrets store sensitive data, Services enable network access, and neither provides persistent storage.

Exam trap

Candidates often confuse ConfigMap with PersistentVolumeClaim because both can be mounted into pods. However, ConfigMap is only for configuration data and does not provide persistent storage; PersistentVolumeClaim is the correct resource for requesting storage that survives pod restarts.

How to eliminate wrong answers

Option A is wrong because a Secret is used to store sensitive data like passwords or tokens, not to provision storage. Option B is wrong because a Service is a networking abstraction that exposes a set of Pods as a network service, not a storage resource. Option D (ConfigMap) is incorrect because ConfigMaps store non-sensitive configuration data as key-value pairs or files, not persistent storage volumes.

122
MCQmedium

When making API calls to Cisco Meraki Dashboard, what header must be included for authentication?

A.Authorization: Basic <base64>
B.Authorization: Bearer <token>
C.X-Cisco-Meraki-API-Key: <key>
D.Api-Key: <key>
AnswerC

Meraki Dashboard authenticates REST calls solely through the `X-Cisco-Meraki-API-Key` request header carrying the generated API key; no OAuth bearer token or session cookie is accepted. This satisfies the stem's requirement for the mandatory authentication header on every Dashboard API call.

Why this answer

Cisco Meraki Dashboard API uses a custom header for authentication rather than standard HTTP authentication schemes. The header `X-Cisco-Meraki-API-Key` must be included with the API key as its value. This is explicitly documented in the Meraki API reference and is required for all API requests to authenticate the caller.

Exam trap

Cisco often tests the fact that Meraki uses a custom header (`X-Cisco-Meraki-API-Key`) rather than the standard `Authorization` header, leading candidates to mistakenly choose `Authorization: Bearer <token>` or `Authorization: Basic <base64>`.

How to eliminate wrong answers

Option A is wrong because `Authorization: Basic <base64>` uses HTTP Basic Authentication, which is not supported by the Meraki Dashboard API; Meraki requires a custom header, not the standard Authorization header. Option B is wrong because `Authorization: Bearer <token>` uses OAuth 2.0 Bearer token authentication, which is not how Meraki authenticates API calls; Meraki uses a static API key in a custom header. Option D is wrong because `Api-Key: <key>` is a generic header name used by some other APIs (e.g., certain cloud services), but Meraki specifically requires the header name `X-Cisco-Meraki-API-Key`.

123
Multi-Selecthard

Which TWO statements accurately describe characteristics of infrastructure as code (IaC) in network automation?

Select 2 answers
A.IaC eliminates the need for manual review of configuration changes before deployment.
B.IaC requires that all network devices be replaced with software-based equivalents.
C.IaC is only applicable to virtual network functions, not physical devices.
D.IaC tools use declarative or imperative models to define the desired state of network infrastructure.
E.IaC allows network configurations to be stored in version control and tested before deployment.
AnswersD, E

Declarative models specify the intended end state and let the tool reconcile differences, while imperative models issue explicit step-by-step commands. Both are genuine IaC approaches, so this statement correctly captures how IaC defines network infrastructure desired state rather than relying on manual configuration.

Why this answer

Option D is correct because IaC tools such as Terraform, Ansible, and Puppet/Chef operate on either declarative models (defining the desired end state, e.g., Terraform HCL) or imperative models (defining step-by-step commands, e.g., shell scripts), so both paradigms are valid ways to express the intended state of network infrastructure. Option E is correct because a core IaC practice is treating configuration as code: storing templates and playbooks in version control systems like Git, enabling peer review, diffing, and automated testing (e.g., CI pipelines, linters, and unit/integration tests) before pushing changes to production devices. Option A is wrong because IaC does not remove human review; change control, pull-request approvals, and validation remain essential safeguards even when automation applies the change.

Option B is wrong because IaC manages existing physical and virtual devices via APIs, SSH, NETCONF, or CLI—it does not require replacing hardware with software equivalents. Option C is wrong because IaC applies broadly to physical routers, switches, firewalls, and other appliances, not only to virtual network functions.

Exam trap

Cisco often tests the misconception that IaC is only for virtual or cloud environments, when in fact it is designed to manage any programmable network device, including physical hardware, via standard interfaces like NETCONF/RESTCONF.

124
MCQmedium

A developer wants to run a Docker container in detached mode, mapping host port 8080 to container port 80, and mounting a host directory for persistent data. Which command accomplishes this?

A.docker run -it -p 8080:80 -v /host/data:/container/data myapp
B.docker run -d -p 8080:80 -v /host/data:/container/data myapp
C.docker start -d -p 8080:80 -v /host/data:/container/data myapp
D.docker compose up -d -p 8080:80 -v /host/data:/container/data myapp
AnswerB

The -d flag detaches the container, -p 8080:80 maps host port 8080 to container port 80, and -v /host/data:/container/data mounts the host directory for persistence. Together these satisfy the detached, port-mapped, volume-mounted requirements in one command.

Why this answer

The correct command is `docker run -d -p 8080:80 -v /host/data:/container/data myapp`. The `-d` flag runs the container in detached mode (in the background), `-p 8080:80` maps host port 8080 to container port 80, and `-v /host/data:/container/data` mounts the host directory `/host/data` to the container directory `/container/data`. This combination directly satisfies all requirements: detached mode, port mapping, and persistent volume mount.

Exam trap

200-901 often tests the distinction between `docker run` and `docker start`, and the correct flags for detached mode and port/volume mapping, causing candidates to confuse interactive mode (`-it`) with detached mode (`-d`) or to incorrectly use `docker start` with creation flags.

How to eliminate wrong answers

Option A is wrong because it uses `-it` (interactive with a pseudo-TTY) instead of `-d`, which runs the container in the foreground and attaches the terminal, not detached mode. Option C is wrong because `docker start` is used to start an existing stopped container and does not support flags like `-p` or `-v`; those must be specified during container creation with `docker run`. Option D is wrong because `docker compose up` is used with a Compose file and does not accept `-p` or `-v` flags directly on the command line; port and volume mappings are defined in the `docker-compose.yml` file.

125
MCQmedium

Which DNS record type is used to verify domain ownership for email security (SPF) and is stored as a text string?

A.TXT record
B.CNAME record
C.A record
D.MX record
AnswerA

TXT records hold arbitrary text strings, which is exactly how SPF policies are published: a domain owner adds a TXT record containing the authorised sending hosts. This satisfies the stem's requirement for verifying domain ownership for email security while being stored as text.

Why this answer

TXT records store arbitrary text strings and are the record type used for SPF (Sender Policy Framework), DKIM, and domain verification. SPF is published as a TXT record containing a list of authorized sending hosts, allowing receiving mail servers to verify that email originates from approved sources.

Exam trap

200-901 often tests whether candidates confuse MX records (which route inbound mail) with TXT records (which store SPF/DKIM/DMARC policies), causing them to pick MX when the question mentions email security.

How to eliminate wrong answers

Option B is wrong because a CNAME record creates an alias from one domain name to another — it cannot store the text string required for SPF. Option C is wrong because an A record maps a hostname to an IPv4 address; it has no text payload capability. Option D is wrong because an MX record specifies mail exchange servers for a domain — it directs where email should be delivered, not which hosts are authorized to send email on behalf of the domain.

126
MCQmedium

A developer is preparing a Python application for deployment to a Kubernetes cluster. The application reads configuration values such as the database host and API endpoint from a file mounted at /etc/config/app.conf. The values differ between the staging and production clusters. Which Kubernetes resource should the developer use to inject these values into the pod without baking them into the container image?

A.ServiceAccount
B.Secret
C.PersistentVolumeClaim
D.ConfigMap
AnswerD

A ConfigMap stores non-confidential key-value data and can be mounted as a volume or exposed as environment variables. Mounting it at /etc/config lets the pod read app.conf from the expected path, and the same Deployment manifest can reference different ConfigMaps per cluster. This keeps environment-specific configuration out of the image, which is exactly what the scenario requires.

Why this answer

Configuration that varies between clusters but is not sensitive should live outside the container image. A ConfigMap holds non-confidential key-value pairs and can be mounted as a file or consumed as environment variables, allowing the same image to run in staging and production with different settings. Secrets, volumes, and service accounts serve different purposes and do not address plain configuration injection.

Exam trap

The trap here is assuming any mounted configuration file must come from a Secret, when non-sensitive settings belong in a ConfigMap.

127
MCQmedium

In a Kubernetes deployment, a developer needs to expose a set of pods internally within the cluster on a stable IP address. The pods are stateless and serve HTTP traffic. Which Service type should be used?

A.LoadBalancer
B.ExternalName
C.NodePort
D.ClusterIP
AnswerD

ClusterIP assigns a stable virtual IP reachable only from inside the cluster, exactly matching the internal exposure requirement. It load-balances HTTP traffic across the stateless pods via kube-proxy rules, without provisioning external load balancers or node ports. NodePort and LoadBalancer would expose the service externally, which the scenario does not request.

Why this answer

ClusterIP exposes the service on a cluster-internal IP, making it reachable only within the cluster. NodePort and LoadBalancer expose externally. ExternalName maps to an external DNS name.

128
Multi-Selecthard

A network engineer is deploying a new application that requires low-latency, high-throughput communication between two data centers. The engineer decides to use UDP instead of TCP for the application's transport protocol. Which two characteristics of UDP make it suitable for this scenario? (Choose two.)

Select 2 answers
A.UDP guarantees packet ordering and delivery.
B.UDP provides reliable delivery through acknowledgments and retransmissions.
C.UDP has a smaller header size compared to TCP, reducing bandwidth overhead.
D.UDP performs congestion control to avoid network congestion.
E.UDP has lower overhead because it does not establish a connection before sending data.
AnswersC, E

The UDP header is 8 bytes, while the TCP header is at least 20 bytes. This smaller header reduces per-packet overhead, which can improve efficiency for high-throughput applications. In scenarios where many small packets are sent, the reduced overhead can lead to better bandwidth utilization and lower latency.

Why this answer

UDP is suitable for low-latency, high-throughput communication because it is connectionless, avoiding the overhead of establishing and maintaining a connection, and it has a smaller header size, reducing per-packet overhead. These characteristics make UDP ideal for real-time applications where speed is critical and some packet loss is tolerable. The other options describe features of TCP or incorrectly attribute reliability and congestion control to UDP.

Exam trap

The trap here is assuming that UDP provides reliability or ordering, which are TCP features, or that its lack of congestion control is always beneficial without considering network conditions.

129
MCQmedium

A developer is building a container image for a Node.js API. The Dockerfile currently starts with FROM node:18, copies source code, and runs npm install. Builds are slow because dependencies are reinstalled on every code change. The developer wants to leverage Docker layer caching so that npm install runs only when package.json changes. Which change should be made to the Dockerfile?

A.Use a multi-stage build with a builder stage that runs npm install
B.Place COPY package*.json ./ and RUN npm install before COPY . .
C.Add a .dockerignore file that excludes the node_modules directory
D.Add RUN npm cache clean --force before npm install
AnswerB

Docker caches each layer; if package.json and package-lock.json are copied first and npm install runs before the rest of the source is copied, that layer is reused unless the dependency manifests change. Copying all source first invalidates the cache on every code edit, forcing npm install to rerun. This ordering is the standard best practice for Node.js Dockerfiles.

Why this answer

Docker builds images layer by layer, and a layer is rebuilt only when its instruction or the content it depends on changes. Copying only the dependency manifests and running npm install before copying application source keeps the install layer stable across code edits. This ordering minimizes rebuild time and is the recommended pattern for Node.js images.

Exam trap

The trap here is assuming that any Dockerfile optimization, such as multi-stage builds or .dockerignore, automatically improves layer caching when only instruction ordering actually controls cache reuse.

130
MCQmedium

Which header is used to pass an API key in Meraki Dashboard API requests?

A.X-API-Key: <key>
B.Authorization: Bearer <token>
C.Authorization: Basic <base64>
D.X-Cisco-Meraki-API-Key: <key>
AnswerD

Meraki Dashboard API authenticates requests by requiring the API key in a custom X-Cisco-Meraki-API-Key request header. This satisfies the stem's constraint of passing an API key, rather than using Authorization bearer tokens or query-string credentials.

Why this answer

Meraki API uses the X-Cisco-Meraki-API-Key header for authentication.

131
MCQmedium

During a security audit, it is found that a microservice exposes its internal IP address in error responses. This could help attackers map the network. What is the BEST remediation?

A.Use a service mesh to encrypt traffic.
B.Log the errors and monitor them.
C.Configure the application to return generic error messages without internal details.
D.Add a firewall to block external access to the service.
AnswerC

Returning generic error messages strips internal IP addresses, stack traces, and hostnames from responses, denying attackers network-mapping detail. This satisfies the audit's remediation requirement by removing the information disclosure at its source rather than merely filtering at the perimeter.

Why this answer

Exposing internal IP addresses in error responses violates the principle of least information disclosure. The best remediation is to configure the application to return generic error messages (e.g., HTTP 500 with a generic body) that strip out internal details like IP addresses, stack traces, or debug data. This prevents attackers from using error responses to map the internal network topology, a common information-gathering technique.

Exam trap

Cisco often tests the misconception that network-level controls (firewalls, encryption) are sufficient to fix application-layer information disclosure, when in fact the application itself must sanitize its output.

How to eliminate wrong answers

Option A is wrong because a service mesh (e.g., Istio, Linkerd) encrypts traffic between microservices (mTLS) but does not modify the content of error responses returned to clients; the internal IP would still leak in the response body. Option B is wrong because logging errors and monitoring them only helps with detection and post-incident analysis, not prevention; the internal IP is still exposed in the live response to the attacker. Option D is wrong because a firewall blocks external access at the network layer, but if the service is meant to be externally accessible (e.g., a public API), the firewall cannot be applied; even if it could, the internal IP would still be exposed to legitimate external clients who receive the error.

132
MCQhard

A developer is building a Python application that calls the Cisco DNA Center Intent API to retrieve device health. The application must handle pagination and rate limiting gracefully. After receiving an HTTP 429 response, which action should the application take?

A.Read the Retry-After header and wait that many seconds before retrying the request.
B.Switch from HTTPS to HTTP to bypass the rate limiting mechanism.
C.Delete the existing authentication token and request a new one to reset the rate limit counter.
D.Immediately resend the same request in a tight loop until a 200 response is received.
AnswerA

An HTTP 429 indicates the client exceeded a rate limit, and well-behaved APIs include a Retry-After header specifying how long to wait. Honoring that value avoids hammering the service and prevents escalating throttling. This is the correct, standards-aligned response for the Cisco DNA Center Intent API and similar REST APIs.

Why this answer

When an API returns 429, the client must back off according to the server's Retry-After header rather than retrying aggressively or trying to evade the limit. Immediate retries, transport downgrades, and token rotation do not address the throttling and can worsen it. Respecting Retry-After is the standard, reliable way to recover from rate limiting against the Cisco DNA Center Intent API.

Exam trap

The trap here is treating a 429 like a transient network error that can be fixed by immediate retries, when it actually signals a deliberate throttle that requires honoring Retry-After.

133
MCQeasy

A network administrator needs to assign IP addresses to devices on a subnet with a /25 prefix. How many usable host addresses are available?

A.254
B.126
C.64
D.128
AnswerB

A /25 prefix leaves 7 host bits (32 − 25), giving 2⁷ = 128 total addresses. Subtracting the network and broadcast addresses yields 126 usable host addresses, satisfying the subnet's requirement. This matches the standard formula 2^h − 2, where h is the number of host bits available.

Why this answer

A /25 subnet has 7 bits for hosts (32-25=7), giving 2^7 = 128 total addresses, minus 2 (network and broadcast) = 126 usable hosts.

134
MCQhard

During a network migration, an engineer needs to replace a legacy core switch with a new one without disrupting the existing STP topology. The new switch supports RSTP and will be connected via two trunk links. Which configuration should be applied to the new switch to prevent it from becoming the root bridge?

A.Enable root guard on the trunk ports
B.Configure the bridge priority to 61440
C.Enable BPDU guard on the trunk ports
D.Set the bridge priority to 0
AnswerB

High priority makes it less likely to become root.

Why this answer

Setting the bridge priority to 61440 (which is a valid priority value in increments of 4096) ensures the new switch has a higher numerical priority than the current root bridge, preventing it from becoming the root. In STP/RSTP, the switch with the lowest bridge priority becomes the root bridge; by configuring a high priority, the new switch will not disrupt the existing topology.

Exam trap

The trap here is that candidates often confuse root guard (which protects against becoming a root port) with preventing the switch from becoming the root bridge, or they mistakenly think setting priority to 0 (lowest) would prevent root election, when in fact it forces the switch to become root.

How to eliminate wrong answers

Option A is wrong because root guard is used to prevent a port from becoming a root port (i.e., it blocks BPDUs that would make the local switch the root), but it does not prevent the switch itself from becoming the root bridge; it only protects against superior BPDUs received on that port. Option C is wrong because BPDU guard is used to shut down a port if a BPDU is received (typically on access ports configured with PortFast), not to prevent the switch from becoming the root bridge. Option D is wrong because setting the bridge priority to 0 makes the switch the lowest possible priority, which would force it to become the root bridge, the exact opposite of the desired outcome.

135
MCQmedium

Which Cisco platform provides an Intent API for network automation, including endpoints for network-device, topology, and site hierarchy?

A.Cisco Catalyst Center
B.Cisco Webex
C.Cisco IOS XE
D.Meraki Dashboard
AnswerA

Cisco Catalyst Center exposes the Intent API with network-device, topology and site-hierarchy endpoints, matching the stem precisely. Competing platforms such as Meraki Dashboard or DNA Spaces expose different API surfaces, so Catalyst Center is the platform providing these specific intent endpoints.

Why this answer

Cisco Catalyst Center (formerly DNA Center) provides an Intent API that abstracts network intent into RESTful endpoints. This API includes specific endpoints for managing network devices, retrieving topology views, and interacting with site hierarchy, enabling declarative network automation without low-level device configuration.

Exam trap

Cisco often tests the distinction between device-level APIs (like IOS XE RESTCONF) and platform-level Intent APIs (like Catalyst Center), causing candidates to confuse direct device management with abstracted network automation.

How to eliminate wrong answers

Option B is wrong because Cisco Webex focuses on collaboration and messaging APIs, not network automation or device management. Option C is wrong because Cisco IOS XE provides model-driven APIs like NETCONF/RESTCONF for device-level configuration, but it does not offer a platform-level Intent API with endpoints for site hierarchy or topology. Option D is wrong because Meraki Dashboard provides a REST API for managing Meraki cloud-managed devices, but it lacks the Intent API abstraction and site hierarchy endpoints specific to Catalyst Center.

136
Multi-Selecthard

A developer is building a Python application that consumes the Cisco Webex Teams API. The application needs to handle rate limiting gracefully. Which TWO of the following are appropriate strategies when the API returns a 429 Too Many Requests status code? (Choose two.)

Select 2 answers
A.Ignore the 429 error and continue sending requests as fast as possible.
B.Implement exponential backoff, doubling the wait time after each consecutive 429 response.
C.Immediately retry the request without any delay.
D.Switch to a different API endpoint that is not rate limited.
E.Read the Retry-After header and wait for the specified number of seconds before retrying.
AnswersB, E

Exponential backoff is a robust strategy where the client increases the delay between retries after each failure, often doubling the wait time. This reduces the load on the server and increases the chance of success once the rate limit window resets. It is particularly useful when the Retry-After header is not provided or when multiple clients are competing.

Why this answer

When encountering a 429 Too Many Requests, the client should respect the Retry-After header if present, or implement exponential backoff to gradually increase wait times. These strategies prevent further rate limit violations and allow successful retries. Immediate retries, ignoring the error, or switching endpoints do not address the root cause and can lead to continued failures.

Exam trap

The trap here is thinking that retrying immediately or ignoring the error will eventually succeed, when in fact it will only prolong the rate limiting.

137
MCQeasy

A developer wants to automate the configuration of multiple Cisco IOS-XE devices using Ansible. Which protocol should be used to ensure secure and idempotent configuration updates?

A.Telnet
B.SSH
C.SNMP
D.HTTP
AnswerB

Ansible's ios_config and related modules connect over SSH, which IOS-XE supports natively and encrypts credentials and configuration traffic. SSH also underpins the idempotent module workflow, so repeated playbook runs converge devices to the declared state without insecure Telnet.

Why this answer

SSH (Secure Shell) is the correct protocol because it provides encrypted, authenticated remote access to Cisco IOS-XE devices, which is essential for secure automation. Ansible uses SSH to connect to network devices and execute configuration commands idempotently by comparing the desired state (defined in playbooks) against the current device state, ensuring only necessary changes are applied without duplication or disruption.

Exam trap

Cisco often tests the distinction between protocols used for monitoring (SNMP) versus those used for secure configuration management (SSH), and candidates may mistakenly choose SNMP because they associate it with network management, overlooking that Ansible specifically requires an interactive, secure shell for idempotent configuration pushes.

How to eliminate wrong answers

Option A (Telnet) is wrong because it transmits data in plaintext, including credentials and configuration commands, offering no encryption or security, and is not recommended for any production automation. Option C (SNMP) is wrong because it is primarily used for monitoring and retrieving device metrics (e.g., via MIBs), not for pushing idempotent configuration updates; SNMP Set operations are unreliable and lack the transactional, state-based idempotency that Ansible requires. Option D (HTTP) is wrong because it is unencrypted and insecure for configuration management; while HTTPS could be used with RESTCONF/NETCONF, the question specifies Ansible, which relies on SSH for network device automation, and HTTP alone does not provide the secure, idempotent configuration capabilities needed.

138
MCQhard

In the context of Cisco Webex APIs, which mechanism allows an application to receive real-time notifications when a message is created in a space?

A.Enabling Server-Sent Events (SSE)
B.Registering a webhook with the resource 'messages' and event 'created'
C.Polling the /messages endpoint every second
D.Using a long-lived HTTP connection
AnswerB

Registering a webhook targeting the 'messages' resource with the 'created' event makes Webex push an HTTP POST notification to your URL whenever a message is posted in a space, satisfying the stem's real-time notification requirement.

Why this answer

Cisco Webex APIs support webhooks, which are user-defined HTTP callbacks that the Webex cloud invokes when a specified event occurs. Registering a webhook with resource 'messages' and event 'created' causes Webex to POST a notification to your target URL whenever a new message is created in a space, enabling real-time, event-driven integration without polling. This is the standard mechanism for receiving real-time notifications in Webex.

Exam trap

200-901 often tests the misconception that real-time notifications require polling or persistent connections, when Cisco Webex specifically uses registered webhooks with resource/event pairs to deliver event-driven callbacks.

How to eliminate wrong answers

Option A is wrong because Webex does not expose Server-Sent Events (SSE) as a notification mechanism for message creation; SSE is a browser-oriented one-way streaming technology not used by the Webex webhook model. Option C is wrong because polling the /messages endpoint every second is inefficient, rate-limit-prone, and not real-time — it is an anti-pattern that Webex explicitly recommends replacing with webhooks. Option D is wrong because a long-lived HTTP connection is not how Webex delivers notifications; Webex uses discrete HTTP POST callbacks to a registered target URL, not persistent connections.

139
MCQmedium

A company uses Cisco DNA Center to manage their network. A developer wants to retrieve the overall health score of a specific site using the DNA Center REST API. Which API path should be used?

A./dna/intent/api/v1/network-health
B./dna/intent/api/v1/site-health
C./dna/intent/api/v1/assurance/site
D./dna/intent/api/v1/health-score
AnswerB

The site-health endpoint returns aggregated health metrics for a named site, matching the requirement to retrieve an overall health score. DNA Center's intent API exposes this under the v1 site-health path, distinct from device-health or network-health endpoints.

Why this answer

The correct API path to retrieve the overall health score of a specific site is /dna/intent/api/v1/site-health. This endpoint is part of the Cisco DNA Center Intent API and returns site-level health metrics, including overall health scores for network devices, clients, and applications at a given site. It is specifically designed to aggregate health data per site, unlike broader network-wide endpoints.

Exam trap

Cisco often tests the distinction between network-wide and site-specific health endpoints, and the trap here is that candidates confuse /dna/intent/api/v1/network-health (which returns overall network health) with the site-specific endpoint, or they invent plausible-sounding but non-existent paths like /health-score or /assurance/site.

How to eliminate wrong answers

Option A is wrong because /dna/intent/api/v1/network-health returns the overall network health score across all sites, not a specific site's health. Option C is wrong because /dna/intent/api/v1/assurance/site is not a valid Cisco DNA Center REST API path; the correct assurance-related endpoint for site health uses /site-health. Option D is wrong because /dna/intent/api/v1/health-score is not a valid endpoint; Cisco DNA Center uses specific resource paths like /site-health or /network-health, not a generic /health-score.

140
MCQmedium

A company is deploying a new application that requires low-latency communication between servers in the same data center. The network team is designing a leaf-spine architecture. What is the primary advantage of this topology over a traditional three-tier design?

A.Simpler redundancy with fewer layers.
B.Consistent low latency and high bandwidth between any two devices.
C.Easier to deploy with less cabling.
D.Reduced number of required switch ports.
AnswerB

A leaf-spine fabric gives every leaf an equal-cost path to every spine, so any server pair traverses the same number of hops. This removes the aggregation and core tiers' variable hop counts and oversubscription, delivering the consistent low latency and high bandwidth the design requires.

Why this answer

In a leaf-spine architecture, every leaf switch connects to every spine switch, creating a full-mesh topology. This ensures that any server-to-server path traverses exactly one leaf and one spine switch, providing consistent, predictable low latency and high bandwidth regardless of which servers communicate. This is the primary advantage over a traditional three-tier design, where traffic may need to traverse multiple aggregation and core layers, introducing variable latency and potential bottlenecks.

Exam trap

The trap here is that candidates confuse 'fewer layers' with 'simpler redundancy' (Option A), but Cisco tests that leaf-spine actually increases the number of switches and cabling to achieve consistent low latency, not to reduce complexity or hardware count.

How to eliminate wrong answers

Option A is wrong because leaf-spine does not simplify redundancy with fewer layers; it actually adds a spine layer and requires more interconnects to achieve full-mesh redundancy, whereas three-tier designs use fewer total switches but with more complex failover mechanisms. Option C is wrong because leaf-spine typically requires more cabling due to the full-mesh connections between every leaf and every spine, not less. Option D is wrong because leaf-spine often increases the total number of switch ports needed, as each leaf must have an uplink port for every spine switch, leading to higher port counts than a three-tier design.

141
MCQmedium

A company deploys a microservice using Kubernetes. The service must be accessible externally via a stable IP address and load-balanced across pods. Which Service type should be used?

A.NodePort
B.ClusterIP
C.LoadBalancer
D.ExternalName
AnswerC

LoadBalancer provisions an external cloud load balancer with a stable, routable IP that distributes traffic across the backing pods. ClusterIP is internal-only and NodePort exposes a high port on each node, neither meeting the stable external IP requirement.

Why this answer

A LoadBalancer service type provisions an external load balancer through the cloud provider, assigning a stable public IP that distributes traffic across the backing pods. This directly satisfies both requirements: external accessibility via a stable IP and load balancing across pod replicas. NodePort exposes a static port on each node but does not provide a stable single IP or built-in load balancing.

Exam trap

The trap is choosing NodePort because it also exposes externally — candidates miss the 'stable IP address' and 'load-balanced' requirements that only LoadBalancer satisfies natively.

How to eliminate wrong answers

Option A is wrong because NodePort exposes the service on each node's IP at a high port (30000–32767), requiring clients to know node addresses and providing no stable single endpoint or cloud-level load balancing. Option B is wrong because ClusterIP is internal-only — it allocates a virtual IP reachable only within the cluster and cannot be accessed externally. Option D is wrong because ExternalName maps the service to an external DNS name via a CNAME record; it does not expose pods externally or load-balance traffic across them.

142
MCQmedium

An engineer is troubleshooting a Cisco DNA Center API call that returns a 401 error. What is the most likely cause?

A.The authentication token has expired
B.The network device is unreachable
C.The request body is invalid
D.The API endpoint is incorrect
AnswerA

A 401 response signals failed authentication, and Cisco DNA Center issues time-limited tokens that must accompany each API call. Once the token's validity window lapses, the platform rejects the request before authorisation is evaluated, so an expired token is the most likely cause of the 401.

Why this answer

A 401 Unauthorized error from the Cisco DNA Center API indicates that the request lacks valid authentication credentials. The most common cause is that the authentication token (JWT) obtained via the /dna/system/api/v1/auth/token endpoint has expired. Cisco DNA Center tokens have a default expiry of 60 minutes, after which the API rejects the request with a 401 status.

Exam trap

Cisco often tests the distinction between HTTP status codes (401 vs 400 vs 404 vs 502) to see if candidates understand that each code maps to a specific failure category in REST API interactions.

How to eliminate wrong answers

Option B is wrong because a network device being unreachable would typically result in a 502 Bad Gateway or 504 Gateway Timeout error from the API proxy, not a 401. Option C is wrong because an invalid request body usually produces a 400 Bad Request error, not a 401. Option D is wrong because an incorrect API endpoint typically returns a 404 Not Found error, as the server cannot route the request to a valid resource.

143
MCQhard

In a microservices architecture, which of the following is a key characteristic compared to a monolithic architecture?

A.Changes require rebuilding the entire application.
B.Services communicate via lightweight protocols such as HTTP/REST.
C.The entire application is deployed as a single unit.
D.All services share the same database.
AnswerB

Microservices decompose functionality into independently deployable units that interact over network calls rather than in-process method invocation. Using lightweight protocols such as HTTP/REST lets each service expose a language-agnostic interface, satisfying the loose-coupling and independent-scalability constraint that monolithic architectures cannot meet.

Why this answer

In a microservices architecture, services are independently deployable and typically communicate over lightweight protocols such as HTTP/REST or messaging queues. This contrasts with monolithic architectures where components are tightly coupled and communicate via internal method calls.

Exam trap

The trap is confusing microservices with monolithic characteristics, such as single deployment unit or shared database, which are actually traits of monolithic architectures.

How to eliminate wrong answers

Option A is wrong because in microservices, changes can be made to individual services without rebuilding the entire application; that is a characteristic of monolithic architectures. Option C is wrong because microservices are deployed independently, not as a single unit. Option D is wrong because each microservice often has its own database to ensure loose coupling, rather than sharing a single database.

144
MCQeasy

A developer is automating VLAN configuration on a Cisco switch using REST API. Which HTTP method should be used to create a new VLAN?

A.PUT
B.POST
C.GET
D.PATCH
E.DELETE
AnswerB

POST targets the VLAN collection resource, so the switch allocates the new VLAN identifier and returns it in the response. PUT would require the client to supply the VLAN ID in the URI, which suits replacement of an existing resource rather than creation.

Why this answer

To create a new VLAN resource on a Cisco switch via REST API, the POST method is correct because it is designed to create a subordinate resource under a parent collection. In RESTful APIs, POST is used to send data to the server to create a new entity, such as a VLAN, and the server assigns a unique identifier (e.g., VLAN ID) to the new resource. This aligns with the RESTful principle for resource creation, as specified in RFC 7231.

Exam trap

Cisco often tests the distinction between POST and PUT, where candidates mistakenly choose PUT because they think it can 'create or update' a resource, but in REST APIs for Cisco devices, PUT requires a known resource URI and is not used for server-assigned creation of new VLANs.

How to eliminate wrong answers

Option A (PUT) is wrong because PUT is used to replace or update an existing resource at a specific URI, not to create a new resource with a server-assigned identifier; using PUT for creation would require the client to specify the exact VLAN ID in the URI, which is not the standard approach for creating a new VLAN. Option C (GET) is wrong because GET is a safe, idempotent method used only to retrieve existing resources, not to create or modify them. Option D (PATCH) is wrong because PATCH is used for partial modifications to an existing resource, such as changing the name of an existing VLAN, not for creating a new one.

Option E (DELETE) is wrong because DELETE is used to remove an existing resource, such as deleting a VLAN, and has no role in creation.

145
MCQhard

A Kubernetes deployment is configured with replicas: 3. During a rolling update, the deployment strategy is set to RollingUpdate with maxSurge: 1 and maxUnavailable: 0. What is the maximum number of pods that will be running during the update?

A.4
B.6
C.5
D.3
AnswerA

With maxSurge: 1, the deployment may temporarily exceed the desired replica count by one pod, giving a ceiling of four. maxUnavailable: 0 guarantees all three original pods stay available throughout, so the surge pod is added alongside them rather than replacing any.

Why this answer

With maxSurge=1, one extra pod can be created above the desired 3, and maxUnavailable=0 ensures no pods are taken down before new ones are ready. So the maximum is 4 pods.

146
Multi-Selecthard

Which THREE of the following are features of HTTP/2?

Select 3 answers
A.Header compression (HPACK)
B.Plain text headers
C.Persistent connections
D.Binary framing
E.Multiplexed streams
AnswersA, D, E

HPACK compresses request and response header fields using static and dynamic tables plus Huffman coding, cutting the repeated header overhead that plagued HTTP/1.1. This satisfies HTTP/2's requirement for reduced latency over many concurrent streams, since headers previously dominated each request's bytes.

Why this answer

HTTP/2 introduces HPACK header compression (option A), which reduces overhead by compressing header fields using a static table, a dynamic table, and Huffman encoding, making it a defining feature of the protocol. It also uses binary framing (option D), splitting communication into binary-encoded frames (HEADERS, DATA, SETTINGS, etc.) instead of HTTP/1.1's textual format, which enables more efficient parsing and processing. Multiplexed streams (option E) allow many concurrent request/response exchanges over a single TCP connection, eliminating HTTP/1.1's head-of-line blocking at the application layer.

Option B is incorrect because HTTP/2 headers are binary-encoded, not plain text, and option C is incorrect because persistent connections already existed in HTTP/1.1 and are not a new or distinguishing feature of HTTP/2.

147
MCQhard

In gNMI, what is the difference between dial-in and dial-out streaming?

A.Dial-in is for configuration, dial-out for telemetry
B.Dial-in: device initiates the connection; dial-out: client initiates
C.Dial-in: client initiates subscription and receives data; dial-out: device pushes data to a configured receiver
D.Dial-in uses gRPC, dial-out uses HTTP
AnswerC

Dial-in has the client open the gNMI session and subscribe, so the client receives streamed telemetry. Dial-out reverses this: the network device initiates the connection and pushes data to a preconfigured collector. The stem asks for this directional difference.

Why this answer

In gNMI, dial-in streaming refers to the client initiating a subscription request to the device, which then streams telemetry data back over the same gRPC session. Dial-out streaming, on the other hand, is a server-initiated model where the device (gNMI target) pushes telemetry data to a pre-configured receiver (collector) without waiting for a client request. Option C correctly captures this distinction: dial-in has the client subscribe and receive data, while dial-out has the device push data to a configured receiver.

Exam trap

Cisco often tests the direction of connection initiation (client vs. device) as the key differentiator, and the trap here is confusing which side initiates the connection in dial-in versus dial-out, leading candidates to reverse the roles as in Option B.

How to eliminate wrong answers

Option A is wrong because both dial-in and dial-out are used for telemetry streaming, not configuration; gNMI uses separate RPCs (Set/Get) for configuration. Option B is wrong because it reverses the roles: in dial-in, the client initiates the connection and subscription, while in dial-out, the device initiates the connection to the receiver. Option D is wrong because both dial-in and dial-out use gRPC as the transport protocol; HTTP is not used for gNMI streaming.

148
Multi-Selecthard

An organization is planning to implement HTTPS for their web services. Which three statements accurately describe the HTTPS protocol? (Choose three.)

Select 3 answers
A.HTTPS uses UDP as the transport protocol.
B.HTTPS uses TLS to encrypt HTTP traffic.
C.HTTPS is stateless after the initial handshake.
D.HTTPS uses a certificate to verify the server's identity.
E.HTTPS negotiates a symmetric session key for encryption.
AnswersB, D, E

HTTPS secures HTTP by layering Transport Layer Security beneath it, so all request and response data is encrypted in transit. This satisfies the stem's requirement to describe the protocol accurately: TLS provides confidentiality and integrity, preventing eavesdropping or tampering between client and server.

Why this answer

HTTPS uses TLS for encryption, involves certificate verification, and negotiates a symmetric session key. It does not use UDP typically (TCP is used) and it is not stateless after the handshake.

149
MCQmedium

In the context of REST API design, which HTTP status code should be returned when a client sends a request that exceeds the API rate limit?

A.503 Service Unavailable
B.400 Bad Request
C.429 Too Many Requests
D.401 Unauthorized
AnswerC

429 Too Many Requests directly signals that the client has exceeded the API's rate limit, satisfying the stem's throttling constraint. Unlike 503, which indicates server unavailability, 429 specifically communicates quota exhaustion and typically accompanies a Retry-After header, letting clients back off and retry after the specified interval.

Why this answer

(429 Too Many Requests) is correct because RFC 6585 defines this status code specifically for cases where a client has sent too many requests in a given time frame, exceeding the API's rate limit. REST APIs use this response to enforce throttling and inform the client to back off, often including a Retry-After header to indicate when to retry.

Exam trap

Cisco often tests the distinction between server-side errors (5xx) and client-side rate-limit errors (429), where candidates mistakenly choose 503 Service Unavailable because they confuse server overload with client rate limiting.

How to eliminate wrong answers

Option A is wrong because 503 Service Unavailable indicates the server is temporarily unable to handle the request due to overload or maintenance, not specifically due to client rate limiting. Option B is wrong because 400 Bad Request indicates a malformed request syntax or invalid parameters, not a rate-limit violation. Option D is wrong because 401 Unauthorized indicates missing or invalid authentication credentials, not exceeding a rate limit.

150
MCQmedium

A developer is writing a Python script to interact with a Cisco device using NETCONF. Which library is most appropriate?

A.netmiko
B.requests
C.paramiko
D.ncclient
AnswerD

The `ncclient` library implements NETCONF over SSH, providing native RPC operations such as `<get-config>` and `<edit-config>` against Cisco devices. It satisfies the stem's requirement for a Python NETCONF client, unlike RESTCONF libraries or SSH-only tools such as Netmiko, which cannot speak the NETCONF protocol.

Why this answer

The most appropriate library for NETCONF operations in Python is ncclient (option D). ncclient is a Python library that provides a client for NETCONF, allowing interaction with network devices via NETCONF protocol. Option A (netmiko) is used for SSH/Telnet connections to network devices but does not natively support NETCONF. Option B (requests) is for HTTP requests, not NETCONF.

Option C (paramiko) is a pure Python SSH implementation, which is not suitable for NETCONF. Therefore, ncclient is the correct choice.

Page 1

Page 2 of 13

Page 3