Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 151–225

975 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQeasy

What is the primary benefit of using HTTP/2 over HTTP/1.1?

A.It is connectionless
B.It uses plain text for headers
C.It eliminates the need for TLS
D.It supports multiplexing
AnswerD

HTTP/2 introduces binary framing with streams, letting many concurrent requests and responses share one TCP connection. HTTP/1.1 requires separate connections or serialised pipelining, so head-of-line blocking delays later requests. Multiplexing removes that per-connection queueing, which is the primary performance gain.

Why this answer

HTTP/2 introduces binary framing with a multiplexing layer that allows many concurrent request/response streams to share a single TCP connection. This eliminates HTTP/1.1's head-of-line blocking at the application layer and reduces the need for multiple parallel connections or domain sharding. Multiplexing is the headline feature that delivers HTTP/2's performance gains over HTTP/1.1.

Exam trap

The trap here is confusing HTTP/2's TCP-based multiplexing with HTTP/3's connectionless QUIC transport — candidates who see 'connectionless' may incorrectly associate it with modern HTTP performance features.

How to eliminate wrong answers

Option A is wrong because HTTP/2, like HTTP/1.1, runs over TCP and is connection-oriented; 'connectionless' describes UDP-based protocols such as HTTP/3 (QUIC), not HTTP/2. Option B is wrong because HTTP/2 uses a binary framing layer, not plain-text headers — HPACK compresses headers into binary form, which is a key efficiency gain over HTTP/1.1's plain-text headers. Option C is wrong because HTTP/2 does not eliminate TLS; while the spec technically permits cleartext h2c, all major browsers require TLS (h2 over ALPN), so TLS remains essential.

152
MCQmedium

A network automation engineer is using the NETCONF protocol to configure a Cisco IOS XE device. The engineer sends an <edit-config> RPC with a candidate datastore, but the configuration does not take effect until a <commit> operation is performed. Which NETCONF capability must be supported by the device to allow this workflow?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:rollback-on-error:1.0
C.urn:ietf:params:netconf:capability:confirmed-commit:1.0
D.urn:ietf:params:netconf:capability:writable-running:1.0
AnswerA

The candidate datastore capability allows a device to support a candidate configuration that can be edited and then committed to the running datastore. This matches the workflow described, where changes are made to a candidate and only applied after a commit. Without this capability, the device would not support the candidate datastore, and the <edit-config> targeting candidate would fail.

Why this answer

The candidate datastore capability enables a two-step configuration process where changes are made to a candidate datastore and then applied to the running datastore via a commit. This is exactly the workflow described. The other capabilities provide additional features like confirmed commit, direct running edits, or error rollback, but they are not the fundamental requirement for using a candidate datastore.

Exam trap

The trap here is confusing the candidate datastore capability with related features like confirmed-commit or rollback-on-error, which are not required to use a candidate datastore.

153
MCQeasy

Which HTTP method is used to partially update an existing resource in a RESTful API?

A.UPDATE
B.POST
C.PATCH
D.PUT
AnswerC

PATCH applies a partial modification, sending only the fields being changed rather than a full replacement representation. PUT would overwrite the entire resource, so PATCH is the method that satisfies the requirement to update part of an existing resource.

Why this answer

PATCH is the HTTP method defined for partial modifications to a resource, sending only the fields that need to change. Unlike PUT, which replaces the entire resource representation, PATCH applies a partial update, making it the correct choice for updating a subset of a resource's attributes in a RESTful API.

Exam trap

200-901 often tests the PUT vs PATCH distinction — candidates incorrectly assume PUT can be used for partial updates, when PUT replaces the entire resource and PATCH is the method specifically designed for partial modification.

How to eliminate wrong answers

Option A is wrong because UPDATE is not a standard HTTP method; HTTP defines GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS, and TRACE, but not UPDATE. Option B is wrong because POST is used to create a new resource or submit data to be processed, not to partially update an existing resource. Option D is wrong because PUT replaces the entire resource with the supplied representation; if you send only some fields with PUT, the omitted fields may be removed or reset, so it is not a partial update.

154
Multi-Selecthard

Which three statements about Webex API webhooks are true? (Choose three.)

Select 3 answers
A.Webhooks deliver event data via HTTP POST to a specified URL.
B.Webhooks require OAuth 2.0 client credentials grant for security.
C.Webhooks can be filtered to trigger only on specific resources and events.
D.Webhooks are created by sending a POST request to the /webhooks endpoint.
E.Webhooks use long polling to receive events.
AnswersA, C, D

Webhooks push notifications by sending an HTTP POST containing event payload data to the subscriber's configured target URL. This satisfies the stem's requirement for a true statement about Webex webhook delivery, distinguishing push-based event delivery from polling the API.

Why this answer

Option A is correct because Webex webhooks push event notifications as an HTTP POST request containing a JSON payload to the target URL you register. Option C is correct because when creating a webhook you specify the resource (e.g., messages, meetings, memberships) and the event (e.g., created, updated, deleted), so it only fires for those matching events. Option D is correct because webhooks are registered programmatically by sending an authenticated POST request to the Webex REST endpoint https://webexapis.com/v1/webhooks with fields such as name, targetUrl, resource, and event.

Option B is not required: webhook creation uses an OAuth 2.0 access token (often from an integration or bot), not specifically the client credentials grant, and webhook delivery itself is secured via a secret/signature rather than that grant. Option E is incorrect because Webex webhooks are push-based HTTP callbacks, not long polling.

155
Multi-Selecthard

Which THREE of the following are true about HTTP/2 compared to HTTP/1.1? (Select three.)

Select 3 answers
A.Text-based protocol
B.Requires TLS/SSL encryption
C.Header compression using HPACK
D.Server push capability
E.Multiplexing multiple streams over a single connection
AnswersC, D, E

HTTP/2 compresses request and response header fields with HPACK, which uses static and dynamic tables plus Huffman coding. HTTP/1.1 sends headers as uncompressed plaintext on every request, so repetitive headers waste bandwidth that HPACK eliminates.

Why this answer

Option C is correct because HTTP/2 introduces HPACK (RFC 7541), a header compression scheme that uses static and dynamic tables plus Huffman encoding to shrink repetitive header fields, which HTTP/1.1 sends uncompressed as plain text on every request. Option D is correct because HTTP/2 adds server push, allowing the server to proactively send resources (e.g., via PUSH_PROMISE frames) that the client will likely need, a feature absent from HTTP/1.1. Option E is correct because HTTP/2 multiplexes many concurrent streams over one TCP connection using binary framing, eliminating HTTP/1.1's head-of-line blocking at the request level and its need for multiple parallel connections.

Option A is wrong because HTTP/2 is a binary protocol, whereas HTTP/1.1 is text-based. Option B is wrong because HTTP/2 does not mandate TLS; it can run over cleartext TCP (h2c), although browsers only implement it over TLS.

156
Multi-Selecthard

A developer is using the Cisco Webex Teams API to manage memberships in a space. Which two HTTP methods and corresponding endpoints are used to add a new member and to remove an existing member? (Choose two.)

Select 2 answers
A.POST /v1/memberships to add a member
B.DELETE /v1/memberships/{membershipId} to remove a member
C.PUT /v1/memberships/{membershipId} to update a member
D.DELETE /v1/rooms/{roomId}/members/{personId} to remove a member
E.POST /v1/rooms/{roomId}/members to add a member
AnswersA, B

To add a member to a Webex space, you send a POST request to /v1/memberships with a JSON body containing 'roomId', 'personEmail', and optionally 'isModerator'. This creates a new membership. The API returns the membership details. This is the correct method and endpoint for adding a member.

Why this answer

Adding a member to a Webex space is done with POST /v1/memberships, providing roomId and personEmail. Removing a member is done with DELETE /v1/memberships/{membershipId}. These are the standard methods for managing memberships.

Other methods like PUT are for updates, and the room-based endpoints do not exist.

Exam trap

The trap here is confusing membership management with room management, leading to incorrect endpoints under /v1/rooms.

157
MCQmedium

A developer is deploying a containerized application to a Kubernetes cluster. The application must be accessible from outside the cluster on a stable IP address that does not change if the underlying pods are rescheduled. Which Kubernetes Service type should be used?

A.ExternalName
B.LoadBalancer
C.NodePort
D.ClusterIP
AnswerB

LoadBalancer provisions an external load balancer (typically via the cloud provider) that assigns a stable, externally reachable IP address. This IP remains consistent even if pods are rescheduled or nodes are replaced. It automatically routes traffic to the appropriate NodePort and ClusterIP, fulfilling the requirement for stable external access to the application.

Why this answer

A LoadBalancer Service integrates with the underlying cloud provider to provision an external load balancer with a stable IP address. This IP persists independently of pod or node lifecycle events, ensuring consistent external access. ClusterIP, NodePort, and ExternalName each fail to provide a stable external IP for the application.

Exam trap

The trap here is assuming that NodePort provides a stable external IP, when in fact the IP is tied to individual nodes and can change.

158
Multi-Selecthard

A Python developer is working on a microservices project where one service needs to communicate with another service that exposes a GraphQL API. Which THREE statements about GraphQL compared to REST are accurate? (Choose three.)

Select 3 answers
A.GraphQL allows clients to request exactly the fields they need.
B.GraphQL is a database query language.
C.GraphQL has a strongly typed schema that defines the API.
D.GraphQL typically uses multiple endpoints for different resources.
E.GraphQL uses HTTP POST for queries and mutations.
AnswersA, C, E

GraphQL queries declare precisely the fields required, so the server returns only those fields, eliminating the over-fetching inherent in REST's fixed resource representations. This satisfies the microservice's need to minimise payload size when calling the GraphQL API.

Why this answer

Option A is correct because GraphQL's core advantage over REST is that the client specifies the exact fields it wants in a single query, avoiding over-fetching and under-fetching of data. Option C is correct because a GraphQL API is defined by a strongly typed schema (SDL) that declares types, queries, mutations, and subscriptions, enabling validation and introspection. Option E is correct because GraphQL operations (queries and mutations) are typically sent as a single HTTP POST request to one endpoint with a JSON body containing the query string.

Option B is incorrect because GraphQL is an API query language and runtime, not a database query language like SQL; it is datastore-agnostic. Option D is incorrect because GraphQL normally exposes a single endpoint (e.g., /graphql) rather than multiple resource-specific endpoints as REST does.

159
MCQhard

An engineer needs to troubleshoot a RESTCONF request that returns a 409 Conflict error when trying to modify a YANG data node. What is the most likely cause?

A.The data node is read-only
B.Authentication failure
C.The resource was modified by another client during the operation
D.The YANG model version mismatch
AnswerC

409 Conflict indicates a conflict with the current state.

Why this answer

A 409 Conflict error in RESTCONF specifically indicates a resource state conflict, typically caused by a YANG data store version mismatch detected via the 'if-match' header or ETag validation. When another client modifies the same resource between the time a client retrieves it and attempts to update it, the server rejects the request to prevent lost updates, enforcing optimistic locking as defined in RFC 8040.

Exam trap

Cisco often tests the distinction between HTTP status codes in RESTCONF, and the trap here is that candidates confuse a 409 Conflict with a generic 'modification failure' and incorrectly attribute it to permissions (401) or model issues (400/404), rather than recognizing it as a concurrency control mechanism.

How to eliminate wrong answers

Option A is wrong because a read-only data node would return a 405 Method Not Allowed or a 403 Forbidden, not a 409 Conflict, as RESTCONF explicitly rejects write operations on read-only nodes. Option B is wrong because authentication failure results in a 401 Unauthorized error, not a 409 Conflict, which is a resource state issue unrelated to credentials. Option D is wrong because a YANG model version mismatch would typically cause a 400 Bad Request or a 404 Not Found if the data node is unrecognized, not a 409 Conflict, which is specific to concurrent modification conflicts.

160
MCQhard

A network engineer is analyzing a packet capture and notices that a host is sending a TCP segment with the SYN flag set and the ACK flag not set. The destination port is 443. Which of the following best describes what the host is attempting to do?

A.The host is terminating an existing TCP connection to port 443.
B.The host is acknowledging a previous SYN-ACK and completing the three-way handshake.
C.The host is initiating a TCP connection to a server on port 443.
D.The host is responding to an incoming connection request on port 443.
AnswerC

A TCP segment with the SYN flag set and the ACK flag not set is the first step of the three-way handshake, used to initiate a connection. The destination port 443 indicates the host is attempting to connect to an HTTPS service. This is the standard behavior for a client opening a TCP connection to a web server.

Why this answer

The SYN flag without ACK is used to initiate a TCP connection. When a host sends a segment with SYN set and ACK not set to port 443, it is starting the three-way handshake to establish a connection to an HTTPS server. The server would respond with a SYN-ACK, and the client would complete the handshake with an ACK.

This is fundamental TCP behavior.

Exam trap

The trap here is confusing the initial SYN with other TCP flags or handshake steps, such as SYN-ACK or ACK, which have different flag combinations.

161
MCQmedium

A Python function is designed to fetch device data from multiple sources. It uses *args to accept variable number of API endpoints and **kwargs for optional parameters like timeout. Which function definition correctly implements this?

A.def fetch_devices(**endpoints, *options):
B.def fetch_devices(endpoints, **options):
C.def fetch_devices(*endpoints, **options):
D.def fetch_devices(*endpoints, options):
AnswerC

The signature `def fetch_devices(*endpoints, **options)` satisfies both stem constraints: `*endpoints` collects positional API endpoint arguments into a tuple, while `**options` gathers keyword arguments such as `timeout` into a dictionary. This is the only syntax Python permits for combining arbitrary positional and keyword parameters in one definition.

Why this answer

It uses *endpoints to accept a variable number of positional arguments (the API endpoint strings) and **options to accept any number of keyword arguments (like timeout=30). This matches the requirement for a function that can handle multiple sources with optional parameters, following Python's standard *args/**kwargs pattern.

Exam trap

Cisco often tests the distinction between *args (variable positional arguments) and **kwargs (variable keyword arguments), and the trap here is that candidates confuse the syntax or order, thinking **endpoints can appear before *options or that a simple parameter name like options can accept keyword arguments without the double asterisk.

How to eliminate wrong answers

Option A is wrong because it places **endpoints before *options, which is syntactically invalid in Python — keyword-only arguments must follow positional ones, and **kwargs must be the last parameter. Option B is wrong because it defines endpoints as a single positional parameter, not allowing a variable number of API endpoints; it would require the caller to pass a list or tuple explicitly. Option D is wrong because it uses *endpoints correctly but defines options as a regular positional parameter, not as **kwargs, so optional parameters like timeout cannot be passed as keyword arguments.

162
MCQmedium

A developer is writing a Python script that uses the requests library to call a REST API. The API requires an API key in the header 'X-API-Key'. The developer wants to ensure the key is not hardcoded in the script and is instead read from an environment variable. Which code snippet correctly implements this?

A.import os import requests api_key = os.environ['API_KEY'] headers = {'X-API-Key': api_key} response = requests.get('https://api.example.com/data', headers=headers)
B.import os import requests api_key = os.getenv('API_KEY') headers = {'Authorization': api_key} response = requests.get('https://api.example.com/data', headers=headers)
C.import os import requests api_key = os.environ['API_KEY'] response = requests.get('https://api.example.com/data', params={'X-API-Key': api_key})
D.import os import requests api_key = os.getenv('API_KEY') response = requests.get('https://api.example.com/data', auth=(api_key, ''))
AnswerA

This snippet reads the API key from the environment variable 'API_KEY' using os.environ, then passes it in the headers dictionary to requests.get. This avoids hardcoding the key and follows security best practices. It correctly sets the custom header 'X-API-Key' as required by the API.

Why this answer

The correct approach reads the API key from an environment variable and includes it in the 'X-API-Key' header as required. Using os.environ or os.getenv is secure. Passing the key as a query parameter, in Basic Auth, or in the Authorization header does not meet the API's authentication scheme.

Exam trap

The trap here is assuming that any header can be used for an API key, but the API specifically requires the 'X-API-Key' header, not Authorization or query parameters.

163
MCQeasy

A network technician runs the command 'ping 8.8.8.8' from a workstation and receives 'Reply from 192.168.1.1: Destination host unreachable.' What does this indicate?

A.There is a routing issue beyond the local network.
B.DNS resolution is failing.
C.The default gateway is misconfigured.
D.The workstation has no internet connectivity.
E.The remote server is down.
AnswerA

The reply originates from the local gateway 192.168.1.1, meaning the packet reached the default router but no route existed onward to 8.8.8.8. This confirms a routing failure beyond the local subnet, matching the stem's destination-unreachable output.

Why this answer

The 'Reply from 192.168.1.1: Destination host unreachable' message indicates that the local router (192.168.1.1) received the ICMP echo request for 8.8.8.8 but could not find a route to that destination in its routing table. This means the router has a valid path back to the workstation (so the default gateway is reachable), but it lacks a route to the remote network, pointing to a routing issue beyond the local subnet.

Exam trap

Cisco often tests the distinction between 'Destination host unreachable' (routing issue at a router) and 'Request timed out' (no response received), leading candidates to incorrectly assume the default gateway is misconfigured or that there is no connectivity at all.

How to eliminate wrong answers

Option B is wrong because DNS resolution is not involved in a ping to an IP address; the command uses a raw IP address, so no DNS query occurs. Option C is wrong because if the default gateway were misconfigured, the workstation would not receive any reply (or would get 'Request timed out'), as the ICMP echo request would never leave the local network. Option D is wrong because the workstation does have internet connectivity to its local router (192.168.1.1), as evidenced by the reply; the issue is beyond the local network.

Option E is wrong because the remote server (8.8.8.8) is not necessarily down; the router cannot even attempt to reach it due to missing routing information.

164
MCQmedium

A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application needs to read a database password at runtime, and the team wants the value to be injected as an environment variable without storing it in the container image or the Deployment manifest. Which Kubernetes resource should be used?

A.An initContainer that writes the password into the main container's filesystem.
B.A ConfigMap mounted as a volume and read by the application at startup.
C.A PersistentVolumeClaim that stores the password in a file on shared storage.
D.A Secret referenced by the container's envFrom or valueFrom field.
AnswerD

A Kubernetes Secret stores sensitive data separately from the image and manifest, and it can be injected into a container as an environment variable using envFrom or valueFrom. This keeps the password out of the container image and out of the Deployment YAML. It is the standard mechanism for supplying runtime secrets in Kubernetes.

Why this answer

Kubernetes Secrets are designed to hold sensitive data and can be consumed as environment variables through envFrom or valueFrom, which keeps the password out of the image and the Deployment manifest. ConfigMaps, volumes, and initContainers do not provide the same separation of sensitive data from application artifacts, so they fail the scenario's security and injection requirements.

Exam trap

The trap here is assuming that any externalized configuration mechanism, such as a ConfigMap or a volume, is equivalent to a Secret for sensitive values.

165
MCQmedium

A developer must build a Python script that reads a list of devices from a YAML inventory file and then pushes configuration to each device using NETCONF over SSH. The script must be reusable and must not hardcode credentials. Which approach best satisfies these requirements?

A.Use paramiko to open an interactive SSH shell and type configuration commands into the CLI prompt.
B.Use the requests library to POST XML configuration directly to the device management IP on port 830.
C.Use the ncclient library and hardcode the device list and credentials inside the script for simplicity.
D.Use the ncclient library, load the inventory with PyYAML, and retrieve credentials from environment variables.
AnswerD

ncclient is the standard Python library for NETCONF sessions and supports SSH transport. PyYAML parses the inventory file without hardcoding device data. Reading credentials from environment variables keeps secrets out of source code, which satisfies the reusability and security requirements described in the scenario.

Why this answer

The scenario requires a NETCONF client, a YAML parser, and externalized credentials. ncclient provides the NETCONF over SSH capability, PyYAML reads the inventory, and environment variables keep secrets out of the code. Together these choices meet both the protocol and the reusability requirements without embedding sensitive data.

Exam trap

The trap here is assuming that any SSH-based library can speak NETCONF, when NETCONF requires specific XML framing and capability negotiation that generic SSH tools do not provide.

166
Multi-Selecthard

A developer is building a Python application that uses the Cisco Meraki Dashboard API to update VLAN settings on a network. The application must handle API errors gracefully and avoid being rate-limited. The developer wants to implement logic that inspects the response status code and the Retry-After header. Which two actions should the developer take when the API returns HTTP 429? (Choose two.)

Select 2 answers
A.Immediately resend the same request with an incremented X-Retry-Count header to bypass the rate limit.
B.Read the Retry-After response header and pause requests for the specified number of seconds before retrying.
C.Implement exponential backoff starting from the Retry-After value and add jitter to spread retries across concurrent clients.
D.Switch the request from HTTPS to HTTP to reduce overhead and avoid rate limiting.
E.Rotate to a different API key for the same organization to reset the rate-limit counter.
AnswersB, C

Meraki's Dashboard API returns a Retry-After header on 429 responses that indicates how many seconds the client must wait. Honoring this header prevents further throttling and aligns with Meraki's documented rate-limit behavior. Simply pausing for a fixed interval without reading the header may retry too soon or waste time.

Why this answer

Meraki's Dashboard API enforces rate limits and returns HTTP 429 with a Retry-After header when exceeded. The robust client reads that header, waits the indicated time, and then retries using exponential backoff with jitter to avoid synchronized retries. Rotating keys or switching protocols does not change the per-organization limit and can introduce security or reliability problems.

Exam trap

The trap here is assuming that rate limits are tied to the API key or that a custom retry header can bypass them, when Meraki enforces limits per organization and expects clients to honor Retry-After.

167
MCQmedium

In Software-Defined Networking (SDN), which interface is used for communication between the controller and the network devices (e.g., switches) to forward traffic?

A.Northbound API
B.Control plane
C.Southbound API
D.East-West API
AnswerC

The southbound API connects the SDN controller to underlying switches, letting it push flow rules and forwarding instructions directly to the data plane. This satisfies the stem's requirement for controller-to-device communication, whereas northbound interfaces serve applications and management layers instead.

Why this answer

The southbound API (e.g., OpenFlow, NETCONF) is used to communicate between the SDN controller and the data plane devices.

168
MCQmedium

A Meraki dashboard API request to list networks returns a paginated response. The engineer notices a Link header in the response. What does this header typically contain?

A.The rate limit remaining
B.The total number of resources
C.A URL to the next page of results
D.An error message
AnswerC

Meraki's REST API paginates large collections, returning a Link header containing the URL of the next page of results, often with rel="next". The engineer follows that URL to retrieve subsequent networks until no Link header remains, indicating the final page.

Why this answer

Meraki uses Link headers for pagination, providing URLs for the next and previous pages.

169
MCQeasy

A script is using the Cisco Meraki API to fetch a list of organizations. The script needs to authenticate with an API key. Where should the API key be included in the request?

A.In the HTTP Authorization header using Bearer scheme.
B.In the request body as a JSON field.
C.In the request URL as a query parameter.
D.In the request header as 'X-Cisco-Meraki-API-Key'.
AnswerD

Meraki's REST API expects the key in a custom request header named X-Cisco-Meraki-API-Key, not as a query parameter or body field. This satisfies the stem's requirement to authenticate the organisation-listing call, since Meraki validates that header on every request before returning the organisations list.

Why this answer

The Cisco Meraki API requires the API key to be sent in a custom HTTP header named 'X-Cisco-Meraki-API-Key'. This is a vendor-specific authentication mechanism, not a standard Bearer token. Including the key in this header ensures the request is authenticated without exposing the key in the URL or body.

Exam trap

Cisco often tests the fact that many APIs use standard Bearer tokens, but the Meraki API specifically uses a custom header, so candidates mistakenly choose the Authorization header option without reading the vendor-specific documentation.

How to eliminate wrong answers

Option A is wrong because the Meraki API does not use the standard HTTP Authorization header with the Bearer scheme; it uses a custom header. Option B is wrong because API keys should never be sent in the request body as a JSON field, as this would require parsing the body for authentication and violates RESTful stateless design. Option C is wrong because including the API key as a query parameter in the URL exposes it in logs, browser history, and network traffic, which is a security risk and not supported by the Meraki API.

170
MCQhard

A developer is using NX-API on a Cisco Nexus switch to execute CLI commands via JSON. Which endpoint and method should be used?

A.GET /restconf/data/Cisco-NX-OS-device:cli
B.POST /api/cli with XML body
C.GET /ins?cmd=show version
D.POST /ins with JSON body
AnswerD

NX-API's JSON-RPC interface accepts commands at the /ins endpoint via HTTP POST, with the CLI commands supplied in the JSON body. GET is unsuitable because it cannot carry the command payload, and /cli returns plain text rather than JSON.

Why this answer

NX-API on Cisco Nexus switches exposes a REST endpoint at /ins that accepts POST requests with a JSON body containing the CLI commands to execute. The JSON body includes parameters such as 'ins_api' with 'version', 'type' (cli_show), 'chunk', 'sid', 'input' (the command), and 'output_format' (json). This is the standard way to run show commands programmatically via NX-API.

Exam trap

The trap is that candidates confuse NX-API's /ins endpoint with RESTCONF paths or assume a GET request with a query parameter, when NX-API requires POST with a JSON body.

How to eliminate wrong answers

Option A is wrong because /restconf/data/Cisco-NX-OS-device:cli is a RESTCONF/YANG path, not the NX-API endpoint; NX-API uses /ins, not RESTCONF. Option B is wrong because NX-API accepts JSON (or XML) but the endpoint is /ins, not /api/cli, and XML is not required. Option C is wrong because GET /ins?cmd=show version uses the wrong HTTP method and query-string style; NX-API requires POST with a structured JSON body, not a GET with a cmd parameter.

171
MCQeasy

A network engineer is using Ansible to automate the configuration of a Cisco IOS XE device. The playbook must ensure that a specific banner is present on the device. Which Ansible module should the engineer use to accomplish this task in a vendor-supported way?

A.ios_banner
B.ios_user
C.ios_command
D.ios_config
AnswerA

The ios_banner module is specifically designed to manage banners on Cisco IOS devices. It allows you to configure the login, motd, exec, and other banners with idempotent behavior. This module is part of the cisco.ios collection and is the vendor-supported way to ensure a banner is present. Using it simplifies the playbook and ensures proper handling of device interactions.

Why this answer

Ansible provides vendor-specific modules for Cisco IOS, and the ios_banner module is designed to manage banner configurations. It ensures idempotency and handles the proper syntax for banners. While ios_config could push banner lines, it is less specialized and may not be idempotent without additional logic.

Using ios_banner is the recommended and supported approach for this task.

Exam trap

The trap here is thinking that ios_config is always the go-to module for any configuration, when specialized modules like ios_banner exist for specific tasks.

172
Multi-Selectmedium

Which TWO of the following are characteristics of UDP compared to TCP? (Select two.)

Select 2 answers
A.Ordered data delivery
B.Reliable delivery with retransmission
C.Connection-oriented communication
D.Lower overhead
E.No flow control or congestion control
AnswersD, E

UDP's eight-byte header, versus TCP's minimum twenty bytes, cuts per-packet overhead, satisfying the stem's comparison of protocol characteristics. Omitting handshakes, acknowledgements and congestion control further reduces processing and bandwidth cost, which suits latency-sensitive traffic that tolerates loss.

Why this answer

Option D (Lower overhead) is correct because UDP has a fixed 8-byte header containing only source port, destination port, length, and checksum, with no sequence/acknowledgment fields, handshake, or connection state, whereas TCP's 20-byte (or larger) header and connection tracking add significant overhead. Option E (No flow control or congestion control) is correct because UDP simply sends datagrams without windowing, slow-start, or congestion-avoidance algorithms, so it does not throttle the sender based on receiver capacity or network congestion. Options A, B, and C are TCP characteristics: TCP provides ordered delivery via sequence numbers, reliable delivery with acknowledgments and retransmission, and connection-oriented communication via the three-way handshake, none of which UDP offers.

173
MCQhard

A developer is integrating a Python application with the Cisco Webex API. The application must act on behalf of users to create messages in Webex spaces. The developer wants to avoid storing user credentials. Which OAuth 2.0 flow is most appropriate for this scenario?

A.Implicit Grant
B.Authorization Code Grant
C.Resource Owner Password Credentials Grant
D.Client Credentials Grant
AnswerB

The Authorization Code Grant is ideal for applications that need to act on behalf of users without storing their credentials. The user authenticates directly with Webex, and the application receives an authorization code, which it exchanges for an access token. This flow is secure because the application never sees the user's password, and tokens can be scoped and revoked. It is the recommended flow for web and mobile apps requiring user context.

Why this answer

The Authorization Code Grant is the most secure and appropriate OAuth 2.0 flow for applications that need to act on behalf of users without handling their credentials. It involves redirecting the user to Webex for authentication, receiving an authorization code, and exchanging it for an access token. This flow supports refresh tokens and fine-grained scopes, making it ideal for integrations that create messages on behalf of users.

Exam trap

The trap here is assuming that the Client Credentials Grant can be used for user-context operations, when it is only for machine-to-machine.

174
MCQmedium

Given the following Python code snippet: with open('config.json', 'r') as f: data = json.load(f) print(data['interfaces'][0]['name']) What is the expected output if config.json contains {"interfaces": [{"name": "GigabitEthernet0/1"}]}?

A.GigabitEthernet0/1
B.None
C.interfaces
D.Error: list indices must be integers
AnswerA

The code parses the JSON file into a Python dictionary, then indexes the `interfaces` list to retrieve its first element and reads that dictionary's `name` key. Given the supplied file content, this resolves to the string `GigabitEthernet0/1`, which `print` outputs without quotes.

Why this answer

json.load() reads the file and returns a dict; then accessing the nested structure yields 'GigabitEthernet0/1'.

175
MCQmedium

A developer needs to create a Postman collection that uses a variable for the base URL and a token variable for authentication. The token is obtained from a login request and must be reused across requests. Where should the token variable be defined to persist across all requests in the collection?

A.As a data variable from a CSV file
B.As a global variable
C.As a collection variable
D.As a local variable in the login request
AnswerC

Collection variables persist across every request in the collection, so a token captured from the login response remains accessible to all subsequent requests. This satisfies the requirement to reuse the token collection-wide rather than per-request.

Why this answer

Collection variables in Postman are scoped to the entire collection, meaning they persist across all requests within that collection. By storing the token as a collection variable after the login request, it can be reused in subsequent requests without re-authentication. This is the recommended approach for sharing authentication tokens across requests in a Postman collection.

Exam trap

Cisco often tests the distinction between variable scopes in Postman, and the trap here is that candidates confuse global variables (which are too broad) with collection variables (which are correctly scoped), or mistakenly think local variables persist beyond the request in which they are defined.

How to eliminate wrong answers

Option A is wrong because data variables from a CSV file are used for data-driven testing and are only available during the execution of a single request iteration, not persisted across all requests. Option B is wrong because global variables are shared across all collections and workspaces, which is too broad and can lead to unintended overwrites or conflicts; collection variables provide the correct scope for a single collection. Option D is wrong because local variables are scoped to a single request or script execution and are not accessible outside that request, so the token would be lost after the login request completes.

176
MCQmedium

A DevNet engineer is building a Python script that calls the Cisco Webex Teams API to post a message. The script currently stores the access token in a plain text variable at the top of the file, which is committed to a Git repository. The team wants to keep the token out of source control while still allowing the script to authenticate. Which approach should be used?

A.Base64-encode the token and assign it to the variable so it is not readable as plain text.
B.Encrypt the token with a symmetric key stored in the same Python file and decode it at runtime.
C.Store the token in a comment above the function that uses it so only developers reading the code can see it.
D.Move the token to a .env file and add that file to .gitignore, then load it with python-dotenv.
AnswerD

Storing the token in a .env file that is excluded via .gitignore keeps it out of the repository while still making it available to the script at runtime through python-dotenv. This separates configuration from code and prevents accidental exposure in commits. It is a standard local development pattern that preserves authentication functionality without hardcoding secrets.

Why this answer

Keeping secrets out of source control requires storing them in an environment-specific location that is excluded from version control and loading them at runtime. A .env file ignored by Git, combined with python-dotenv, achieves this for local development while allowing the Webex Teams API call to authenticate normally. Encoding or hiding the token in the same file does not remove it from the repository.

Exam trap

The trap here is assuming that encoding or encrypting a secret inside the same committed file provides meaningful protection, when the real requirement is to keep the secret out of version control entirely.

177
MCQmedium

A developer is writing a Python script that authenticates to Cisco DNA Center using the token-based authentication API. The script must obtain a token and reuse it for subsequent REST calls until it expires. Which HTTP header should the script include in each subsequent API request to pass the token?

A.X-Auth-Token: <token>
B.Cookie: session=<token>
C.Authorization: Bearer <token>
D.X-Cisco-Token: <token>
AnswerA

Cisco DNA Center returns an authentication token in the response body when you POST to /dna/system/api/v1/auth/token with Basic Auth credentials. That token must then be supplied in the X-Auth-Token HTTP header on every subsequent API call. This is the documented and required header for token-based authentication with DNA Center, making it the correct choice for the script.

Why this answer

Cisco DNA Center's token-based authentication flow returns a token from the /auth/token endpoint, and that token must be presented in the X-Auth-Token header for all subsequent API requests. Other common authentication headers like Authorization: Bearer or custom cookie schemes are not recognized by DNA Center. Using the correct header ensures the script can reuse the token until it expires, avoiding repeated authentication calls.

Exam trap

The trap here is assuming that DNA Center follows the standard OAuth 2.0 Bearer token pattern, when it actually uses a custom X-Auth-Token header.

178
MCQeasy

A developer is using a REST API to retrieve data from a network controller. The API requires the client to include an API key in the HTTP request header for authentication. Which HTTP header is typically used to carry the API key?

A.User-Agent
B.Content-Type
C.Accept
D.Authorization
AnswerD

The Authorization header is the standard HTTP header used to carry credentials for authenticating a client with a server. When using an API key, it is common to include it in the Authorization header, often with a scheme like Bearer or Basic. This header is designed specifically for authentication and is the correct choice for passing an API key.

Why this answer

The Authorization header is the standard HTTP header for transmitting authentication credentials. API keys are commonly placed in this header, often with a prefix like Bearer. Other headers like Content-Type, Accept, and User-Agent serve different purposes such as content negotiation or client identification, and are not used for authentication.

Exam trap

The trap here is assuming that an API key must be sent in a custom header, when the standard Authorization header is the conventional and expected location.

179
MCQeasy

A DevOps team manages a hybrid cloud environment with on-premises Cisco Nexus switches and AWS VPCs using Terraform. They have a configuration management tool that pushes VLAN and interface configurations to the Nexus switches. Recently, they noticed that after a Terraform run that updates the AWS VPC subnets, some on-premises switches lose connectivity to the cloud. The team suspects a mismatch between the VLAN configurations on the Nexus switches and the AWS VPC subnets. They have a centralized source of truth stored in a Git repository containing YAML files for network definitions. Which action should the team take first to resolve the issue and prevent future occurrences?

A.Restore the Nexus switch configurations from the most recent backup.
B.Modify the Terraform scripts to automatically update Nexus switches when AWS VPC subnets change.
C.Compare the Git repository's YAML definitions with the actual switch configurations and AWS VPC subnets, then correct any discrepancies.
D.Manually reconfigure the VLANs on the Nexus switches to match the AWS VPC subnets.
AnswerC

Reconciling the Git YAML source of truth against live Nexus and AWS VPC state exposes the VLAN/subnet mismatch causing connectivity loss. This satisfies the requirement to identify the drift first before applying any corrective automation.

Why this answer

The team's centralized source of truth in Git (YAML files) should be the authoritative reference for network definitions. By comparing these definitions against both the actual Nexus switch configurations and AWS VPC subnets, the team can identify and correct any drift or mismatch. This aligns with Infrastructure as Code (IaC) best practices, ensuring that all environments are synchronized from a single, version-controlled source before making any changes.

Exam trap

The trap here is that candidates may assume the immediate fix is to restore or manually reconfigure the switches (options A or D), rather than first validating the source of truth (Git) to identify the root cause of the mismatch, which is a core DevOps principle of treating infrastructure as code.

How to eliminate wrong answers

Option A is wrong because restoring from a backup does not address the root cause of the mismatch; it may reintroduce outdated configurations that do not match the current AWS VPC subnets, and it ignores the centralized Git repository as the source of truth. Option B is wrong because modifying Terraform scripts to automatically update Nexus switches would bypass the configuration management tool and the Git-based source of truth, potentially causing further inconsistencies and breaking the separation of concerns between cloud provisioning and on-premises network management. Option D is wrong because manually reconfiguring VLANs on the Nexus switches is error-prone, not scalable, and does not leverage the Git repository as the single source of truth, making it impossible to prevent future occurrences through automation and version control.

180
MCQeasy

A developer is writing a Python script that calls a REST API. The script currently contains the API key as a string literal. The team wants to move the key out of source control and inject it at runtime in a CI/CD pipeline. Which approach best meets this requirement?

A.Read the API key from an environment variable populated by the pipeline's secret store
B.Store the API key in a configuration file committed to the repository
C.Base64-encode the API key and place it in the script as a constant
D.Have the script prompt the user for the API key on each execution
AnswerA

Environment variables populated from a CI/CD secret store keep the key out of the repository and inject it only at runtime. The application reads the value without hardcoding it, and the pipeline masks the value in logs. This is the standard pattern for separating configuration and secrets from code in automated builds.

Why this answer

Injecting secrets through environment variables supplied by the pipeline's secret store keeps credentials out of the codebase and version history. The application reads the value at runtime, and the CI/CD system can mask it in logs and restrict access. This is the recommended pattern for automated deployments.

Exam trap

The trap here is believing that encoding a secret, such as Base64, provides protection, when it is reversible and still counts as hardcoding.

181
MCQeasy

A network automation engineer is writing a YAML playbook to push a banner configuration to a group of Cisco IOS XE routers. The engineer wants to use an agentless tool that connects over SSH and requires no software installed on the managed devices. Which tool fits this description?

A.Ansible
B.Chef Infra Client running on each router
C.A custom Bash script using scp to copy configuration files
D.Puppet with a master-agent architecture
AnswerA

Ansible is agentless by design: it connects to managed nodes over SSH, pushes modules and playbooks from the control node, and requires no long-running agent on the target. For Cisco IOS XE it uses modules such as ios_config to apply banner and other configuration. This matches every constraint in the scenario, including the YAML playbook format.

Why this answer

Ansible satisfies the agentless, SSH-based, YAML-driven requirements in one tool. Its ios_config and related modules push configuration changes to Cisco IOS XE devices without installing anything on them, and playbooks express the desired banner state declaratively. Competing configuration management tools rely on agents that cannot run on the routers themselves.

Exam trap

The trap here is treating Puppet or Chef as equally agentless because both can target network devices indirectly, when their standard architectures depend on an installed agent that Cisco routers do not host.

182
MCQeasy

A developer wants to retrieve a list of network devices from Cisco DNA Center. Which HTTP method and URL structure should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/network-device
C.DELETE /dna/intent/api/v1/network-device
D.PUT /dna/intent/api/v1/network-device
AnswerB

GET requests retrieve data without modifying server state, matching the read-only intent of listing network devices. The path `/dna/intent/api/v1/network-device` is Cisco DNA Center's Intent API endpoint for device inventory, satisfying the requirement to fetch the device collection. POST, PUT or DELETE would alter resources or target the wrong operation.

Why this answer

To retrieve a list of network devices from Cisco DNA Center's Intent API, the correct HTTP method is GET, which is idempotent and used for read operations. The URL path /dna/intent/api/v1/network-device is the documented endpoint for listing network devices. GET requests do not modify server state, making them appropriate for retrieval.

Exam trap

200-901 often tests REST method semantics; candidates who associate POST with 'query' or 'search' because some APIs use POST for complex queries will incorrectly choose POST instead of GET for a simple list retrieval.

How to eliminate wrong answers

Option A is wrong because POST is used to create resources or submit data, not to retrieve a list; using POST on a collection endpoint would typically create a new device entry or trigger an action. Option C is wrong because DELETE removes a resource and is not used for listing; issuing DELETE on the collection endpoint could attempt to delete devices, which is destructive. Option D is wrong because PUT is used to update or replace an existing resource, not to read a collection; it requires a resource identifier and a payload.

183
MCQmedium

A developer is using the Meraki Dashboard API to list the organizations accessible by the API key. They send a GET request to https://api.meraki.com/api/v1/organizations. What is the correct way to pass the API key?

A.In the Authorization header as Bearer token
B.In the URL as a query parameter: ?apiKey=...
C.In the request body as JSON
D.In the X-Cisco-Meraki-API-Key header
AnswerD

The Meraki Dashboard API authenticates every call with a dedicated request header rather than a query string or bearer token. Supplying the key as X-Cisco-Meraki-API-Key satisfies the stem's requirement for the correct method when issuing GET https://api.meraki.com/api/v1/organizations, keeping credentials out of the URL and logs.

Why this answer

Meraki Dashboard API uses the X-Cisco-Meraki-API-Key header for authentication.

184
Multi-Selectmedium

Which TWO of the following are commonly used HTTP methods for a RESTful API to retrieve and update a resource? (Select TWO)

Select 2 answers
A.GET
B.POST
C.PUT
D.DELETE
E.HEAD
AnswersA, C

GET retrieves a resource representation from the server without modifying it, satisfying the retrieval half of the requirement. It is safe and idempotent, returning the current state of the target resource identified by the request URI.

Why this answer

Option A (GET) is correct because GET is the standard HTTP method used to retrieve a representation of a resource from a RESTful API, and it is defined as safe and idempotent, meaning it should not modify server state. Option C (PUT) is correct because PUT is commonly used to update a resource by replacing it at a known URI, and it is idempotent, so repeated identical requests produce the same result. POST (B) is not selected because it is typically used to create a new resource or submit data for processing, not primarily to retrieve or update an existing resource.

DELETE (D) is not selected because it removes a resource rather than retrieving or updating it. HEAD (E) is not selected because it only returns response headers without a body, so it is not used to retrieve or update resource content.

Exam trap

Cisco often tests the misconception that POST can be used for both creation and update, but in a strictly RESTful API, PUT is the standard method for updating a resource, while POST is reserved for creation or non-idempotent operations.

185
MCQhard

A developer is using the Cisco Meraki Dashboard API to update the configuration of a wireless SSID. The API requires a PUT request to /networks/{networkId}/wireless/ssids/{number}. Which HTTP header is mandatory to include the API key for authentication?

A.Content-Type: application/json
B.X-Auth-Token
C.X-Cisco-Meraki-API-Key
D.Authorization: Bearer <token>
AnswerC

The Cisco Meraki Dashboard API uses a custom header named X-Cisco-Meraki-API-Key to authenticate requests. The API key generated in the Meraki Dashboard must be included in this header for all API calls. Without it, the server returns a 401 Unauthorized error. This header is specific to Meraki and is the correct way to authenticate.

Why this answer

The Meraki Dashboard API requires the API key to be sent in the X-Cisco-Meraki-API-Key header. This custom header is the only accepted method for authentication. Other headers like Authorization or X-Auth-Token are used by different Cisco APIs and will not work with Meraki.

Content-Type is for the request body, not authentication.

Exam trap

The trap here is assuming that all Cisco APIs use the same authentication header, when Meraki specifically uses a custom X-Cisco-Meraki-API-Key header.

186
MCQmedium

A network engineer is designing a subnet that needs to support 30 usable hosts. Which subnet mask should be used?

A.255.255.255.240 (/28)
B.255.255.255.0 (/24)
C.255.255.255.224 (/27)
D.255.255.255.192 (/26)
AnswerC

A /27 mask leaves five host bits, yielding 32 addresses minus network and broadcast, so exactly 30 usable hosts. It is the smallest subnet satisfying the stated requirement without waste, whereas /28 would provide only 14 usable addresses.

Why this answer

(255.255.255.224, /27) provides 5 host bits, yielding 2^5 = 32 total addresses per subnet. Subtracting the network and broadcast addresses leaves exactly 30 usable hosts, meeting the requirement precisely.

Exam trap

Cisco often tests the formula 2^n - 2 for usable hosts, and the trap here is that candidates may forget to subtract the network and broadcast addresses, or they may confuse the number of host bits with the subnet mask value (e.g., thinking /28 supports 16 usable hosts instead of 14).

How to eliminate wrong answers

Option A is wrong because 255.255.255.240 (/28) provides only 4 host bits, giving 2^4 - 2 = 14 usable hosts, which is insufficient for 30 hosts. Option B is wrong because 255.255.255.0 (/24) provides 8 host bits, yielding 2^8 - 2 = 254 usable hosts, which is far more than needed and wastes address space. Option D is wrong because 255.255.255.192 (/26) provides 6 host bits, giving 2^6 - 2 = 62 usable hosts, which exceeds the requirement but is not the most efficient choice for exactly 30 hosts.

187
Multi-Selecthard

A security team is reviewing a CI/CD pipeline that builds container images and pushes them to a registry. They want to reduce the attack surface of the resulting images and ensure that only trusted images are deployed. Which TWO practices should be implemented? (Choose two.)

Select 2 answers
A.Sign images with a tool such as Docker Content Trust or cosign and enforce signature verification in the admission controller before workloads are scheduled.
B.Run the container as the root user inside the image so that package installation and file permission changes succeed during startup.
C.Disable the registry's vulnerability scanning feature to speed up pipeline execution and avoid false-positive build failures.
D.Use multi-stage builds and a minimal base image such as distroless or Alpine to exclude build tools and unnecessary packages from the final image.
E.Bake environment-specific secrets into the image at build time using ARG values so the container is self-contained.
AnswersA, D

Signing images produces cryptographic proof of who built and published them. Enforcing verification at admission time, for example with a policy engine or cosign-backed admission controller, ensures only images with valid signatures from trusted publishers can run. This satisfies the requirement that only trusted images are deployed, even if an attacker compromises the registry.

Why this answer

Reducing image attack surface comes from shipping only what the application needs, which multi-stage builds and minimal base images accomplish by stripping compilers, shells, and unused packages. Ensuring only trusted images deploy requires cryptographic signing plus enforcement, so verification happens before scheduling. Together these controls address both halves of the requirement, while root execution, embedded secrets, and disabled scanning all weaken the posture.

Exam trap

The trap here is treating image signing as sufficient on its own, when trust also depends on shrinking what actually runs inside the image.

188
MCQeasy

A developer uses Cisco Intersight API to manage UCS servers. Which authentication method is required for Intersight API calls?

A.API key with HMAC signature
B.OAuth2 token from Webex
C.Session cookie
D.Basic authentication with username/password
AnswerA

Intersight REST API calls authenticate using an API key ID paired with a secret key, signing each request with HMAC-SHA256. The signature is placed in the Authorization header, so no session token or basic credentials are used.

Why this answer

Cisco Intersight API requires API key authentication with HMAC (Hash-Based Message Authentication Code) signing for all REST API calls. The developer generates an API key pair (private and public) in the Intersight GUI, then uses the private key to create an HMAC-SHA256 signature over the request headers and payload. This signature is included in the Authorization header, ensuring request integrity and non-repudiation without transmitting the secret key over the network.

Exam trap

Cisco often tests the distinction between web UI authentication (session cookies) and API authentication (HMAC keys), and candidates mistakenly choose session cookies because they are familiar from the Intersight web interface, forgetting that API calls require a different, stateless mechanism.

How to eliminate wrong answers

Option B is wrong because OAuth2 tokens from Webex are used for Cisco Webex API authentication, not for Intersight; Intersight does not support OAuth2 token exchange from Webex. Option C is wrong because session cookies are used for browser-based web UI sessions, not for programmatic API calls; Intersight API calls are stateless and require per-request authentication via HMAC signatures. Option D is wrong because basic authentication with username/password is not supported for Intersight API calls; it would expose credentials in plaintext and violates Intersight's security model, which mandates key-based HMAC signing.

189
MCQeasy

A network automation engineer needs to retrieve the current interface configuration from a Cisco IOS XE device using RESTCONF. The device has RESTCONF enabled and the engineer wants to read the configuration data for interfaces in the 'ietf-interfaces' model. Which HTTP method and URL format should the engineer use?

A.GET https://device/restconf/data/ietf-interfaces:interfaces
B.GET https://device/restconf/operational/ietf-interfaces:interfaces
C.POST https://device/restconf/data/ietf-interfaces:interfaces
D.GET https://device/restconf/config/ietf-interfaces/interfaces
AnswerA

RESTCONF uses HTTP GET to read data, and the data resource is addressed under /restconf/data/ followed by the module name and a colon, then the container path. This URL matches the standard RESTCONF structure for retrieving the interfaces container from the ietf-interfaces YANG module, so it returns the requested configuration data.

Why this answer

RESTCONF maps YANG models to HTTP resources. To read configuration or state data, use GET with a URL rooted at /restconf/data/, followed by the module name and a colon, then the data node path. The ietf-interfaces module defines the interfaces container, so the correct URL is GET https://device/restconf/data/ietf-interfaces:interfaces.

Exam trap

The trap here is confusing RESTCONF's data path with NETCONF datastores or older draft URLs that used /restconf/config/ or /restconf/operational/.

190
MCQeasy

A YANG module defines a leaf named 'bandwidth' of type 'uint32'. What does this represent in the context of a network device?

A.A set of unique bandwidth values
B.A single integer value representing bandwidth in kilobits per second
C.A grouping of related bandwidth parameters
D.An ordered list of bandwidth values
AnswerB

A YANG leaf of type uint32 holds exactly one unsigned 32-bit integer, so 'bandwidth' represents a single scalar value rather than a list or container. The stem's constraint is the leaf keyword, which always models one atomic instance, here the interface's bandwidth expressed in kilobits per second.

Why this answer

In YANG, a 'leaf' node defines a single, scalar value of a specific data type. When the leaf is named 'bandwidth' with type 'uint32', it represents a single integer value, typically interpreted as kilobits per second (kbps) in the context of network device configuration (e.g., interface bandwidth). This aligns with the standard YANG data modeling approach where a leaf cannot hold multiple values or complex structures.

Exam trap

Cisco often tests the distinction between a 'leaf' (single value) and a 'leaf-list' (multiple values), so the trap here is that candidates may confuse a leaf with a list or container, especially when the leaf name 'bandwidth' might imply multiple possible values.

How to eliminate wrong answers

Option A is wrong because a 'leaf' in YANG cannot represent a set of unique values; sets are modeled using 'leaf-list' or 'list' nodes, not a single leaf. Option C is wrong because a grouping of related parameters is defined using a 'container' or 'grouping' statement in YANG, not a leaf. Option D is wrong because an ordered list of values is modeled with a 'leaf-list' (which can have ordered-by user or system), not a single leaf of type uint32.

191
MCQmedium

A network engineer is automating the deployment of VLANs across multiple switches using Ansible. The playbook fails with an error indicating that the VLAN ID already exists on one of the switches. Which approach should the engineer use to ensure the playbook completes without errors?

A.Modify the playbook to skip switches where the VLAN already exists.
B.Remove the VLAN from all switches before creating it again.
C.Use an idempotent Ansible module that checks for existing VLANs before creating them.
D.Add ignore_errors: yes to the VLAN creation task.
AnswerC

Idempotent modules such as ios_vlan query existing VLAN configuration before applying changes, so a pre-existing VLAN ID produces no error and no duplicate. This satisfies the requirement that the playbook complete successfully across switches with differing current state.

Why this answer

Ansible's idempotent modules, such as `ios_vlan` for Cisco IOS devices, are designed to check the current state of the device before making changes. If the VLAN already exists, the module will report 'ok' and not attempt to create it again, preventing the error and ensuring the playbook completes successfully. This aligns with Ansible's best practice of writing idempotent playbooks that produce the same result regardless of how many times they are run.

Exam trap

Cisco often tests the concept of idempotency in automation tools like Ansible, and the trap here is that candidates may think 'ignore_errors' is a valid workaround for configuration conflicts, when in fact it only hides failures without ensuring the desired state is achieved.

How to eliminate wrong answers

Option A is wrong because skipping switches where the VLAN already exists would require manual or dynamic inventory logic that is not built into a simple playbook; it would also defeat the purpose of automation by not ensuring consistent VLAN configuration across all switches. Option B is wrong because removing the VLAN from all switches before recreating it would cause unnecessary network disruption and downtime, violating the principle of minimal change in network automation. Option D is wrong because adding `ignore_errors: yes` would mask the error but not resolve the underlying issue; the VLAN creation task would still fail on the switch where the VLAN exists, and the playbook would continue without correcting the configuration, potentially leading to an inconsistent state.

192
MCQmedium

In version control with Git, which command creates a new branch and switches to it in one step?

A.git checkout -b <branch>
B.git checkout <branch>
C.git branch <branch>
D.git switch <branch>
AnswerA

git checkout -b <branch> creates the new branch at the current HEAD and immediately switches the working tree to it, combining creation and checkout. This single-step behaviour matches the stem's requirement, unlike git branch alone, which only creates.

Why this answer

git checkout -b <branch> creates and switches. git branch <branch> creates but does not switch. git switch -c is also valid but not listed.

193
MCQmedium

Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required, such as a backend service calling Cisco API?

A.Authorization code grant
B.Password grant
C.Device code grant
D.Client credentials grant
AnswerD

The client credentials grant exchanges the application's own client ID and secret directly for an access token, with no resource owner or browser redirect involved. This matches server-to-server backend calls where no user context exists, unlike authorisation code or implicit grants.

Why this answer

Client credentials grant is designed for server-to-server scenarios without user consent. Authorization code requires user interaction. Device code is for devices with limited UI.

194
MCQeasy

A developer wants to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint should they use?

A.GET /dna/intent/api/v1/topology/l2/{vlanID}
B.GET /dna/intent/api/v1/network-device
C.POST /dna/system/api/v1/auth/token
D.GET /dna/intent/api/v1/issues
AnswerB

The GET /dna/intent/api/v1/network-device endpoint targets Cisco DNA Center's Intent API, returning the full inventory of managed network devices. Its HTTP GET method and network-device resource path satisfy the requirement to retrieve, not modify, device listings.

Why this answer

The correct endpoint is GET /dna/intent/api/v1/network-device as per Cisco DNA Center API documentation.

195
MCQmedium

During an automation script run, a network device returns HTTP 429. What does this indicate?

A.Internal server error
B.Rate limiting
C.Authentication failure
D.Resource not found
AnswerB

HTTP 429 is the standard 'Too Many Requests' status code, returned when a client exceeds the server's permitted request rate within a given window. It directly signals rate limiting, satisfying the stem's scenario of an automation script being throttled by the network device.

Why this answer

HTTP 429 (Too Many Requests) indicates the client has sent too many requests in a given amount of time, triggering rate limiting on the server. In network automation, devices like routers or switches enforce rate limits to prevent resource exhaustion, often based on RFC 6585. This is common when automation scripts exceed API call thresholds, requiring retry logic with exponential backoff.

Exam trap

Cisco often tests HTTP 429 to distinguish it from HTTP 503 (Service Unavailable), which is a server overload but not specifically a client rate limit, and candidates may confuse the two due to both involving temporary unavailability.

How to eliminate wrong answers

Option A is wrong because HTTP 500 (Internal Server Error) indicates a server-side failure, not a client-side request limit. Option C is wrong because authentication failures return HTTP 401 (Unauthorized) or 403 (Forbidden), not 429. Option D is wrong because resource not found returns HTTP 404, which is unrelated to request throttling.

196
MCQmedium

A network administrator is configuring subnetting for a new branch office that requires 50 usable host addresses per subnet. The available network is 192.168.10.0/24. What subnet mask should be used to meet the requirement with minimal waste?

A.255.255.255.128 (/25)
B.255.255.255.224 (/27)
C.255.255.255.192 (/26)
D.255.255.255.240 (/28)
AnswerC

A /26 mask yields 64 addresses, giving 62 usable hosts, which satisfies the 50-host requirement with minimal waste. Smaller masks like /25 waste over 70 addresses; larger masks like /27 provide only 30 usable hosts, falling short.

Why this answer

A /26 mask provides 62 usable hosts (2^(32-26)-2=62), which is the smallest subnet that supports 50 hosts.

197
MCQmedium

A Python script sends a PUT request to update a resource. The API returns a response with status code 204. What does this indicate?

A.The request was malformed.
B.The update was successful and no content is returned.
C.The resource was not found.
D.The update failed due to a server error.
AnswerB

HTTP 204 No Content confirms the server processed the PUT successfully but returns no body, matching the stem's update scenario. It differs from 200, which carries a response body, and from 404, which signals the resource was not found.

Why this answer

HTTP 204 No Content means the server successfully processed the request and is not returning any body content. For a PUT request, this indicates the resource was updated successfully but the server chose not to return the updated representation. It is a 2xx success status, distinct from 200 OK which would include a response body.

Exam trap

200-901 often tests the meaning of specific HTTP status codes — candidates confuse 204 (success, no content) with 200 (success, with content) or with 202 (accepted, processing not complete), and may incorrectly associate 204 with an error condition.

How to eliminate wrong answers

Option A is wrong because a malformed request returns 400 Bad Request, not 204. Option C is wrong because a missing resource returns 404 Not Found. Option D is wrong because a server-side failure returns 5xx codes such as 500 Internal Server Error or 503 Service Unavailable. 204 is unambiguously a success code in the 2xx class.

198
MCQhard

An application sends a packet with destination IP 10.0.0.10. The sending host's routing table has a default gateway of 10.0.0.1. The host's ARP cache is empty. What is the next step after the host determines the packet should go to the default gateway?

A.Sends an ARP request for 10.0.0.1
B.Sends the packet to the DNS server
C.Sends the packet directly to 10.0.0.10
D.Sends an ARP request for 10.0.0.10
AnswerA

With the destination off-subnet, the host must forward the frame to 10.0.0.1, but its ARP cache holds no MAC mapping for that gateway. ARP resolves the gateway's link-layer address, so the host broadcasts a request for 10.0.0.1 before it can encapsulate and transmit the packet.

Why this answer

When the host determines that the destination IP (10.0.0.10) is not on the same subnet and must be sent to the default gateway (10.0.0.1), it needs the gateway's MAC address to encapsulate the packet in a Layer 2 frame. Since the ARP cache is empty, the host must send an ARP request for the IP address of the default gateway (10.0.0.1) to obtain its MAC address before the packet can be forwarded.

Exam trap

Cisco often tests the misconception that ARP is always used for the final destination IP, but the trap here is that when routing through a gateway, ARP is only performed for the next-hop router's IP, not the remote destination.

How to eliminate wrong answers

Option B is wrong because DNS resolution is used to resolve hostnames to IP addresses, not to determine the next-hop MAC address; the destination IP is already known. Option C is wrong because the host cannot send the packet directly to 10.0.0.10 if it is on a different subnet; the packet must be sent to the default gateway for routing. Option D is wrong because the host does not need the MAC address of the final destination (10.0.0.10) when routing through a gateway; it only needs the MAC address of the next-hop router (10.0.0.1).

199
Multi-Selecthard

Which THREE of the following are characteristics of NETCONF? (Select THREE)

Select 3 answers
A.Uses SSH as the transport protocol
B.Uses HTTP as the transport protocol
C.Supports JSON encoding for data
D.Encodes operations as XML RPCs
E.Supports operations like <edit-config> and <get-config>
AnswersA, D, E

NETCONF runs over a secure, connection-oriented SSH session on port 830, giving encrypted transport and authenticated access to network devices. This satisfies the characteristic of using SSH as its transport protocol, distinguishing it from SNMP or RESTCONF over HTTPS.

Why this answer

NETCONF is defined in RFC 6241 and uses SSH as its mandatory transport protocol (port 830), so option A is correct because SSH provides the secure, connection-oriented session over which NETCONF messages are exchanged. Option D is correct because NETCONF encodes its protocol operations as XML-based RPC elements (for example, <rpc> and <rpc-reply>), making XML the required encoding for the protocol's messages. Option E is correct because NETCONF defines standard operations such as <get-config> to retrieve configuration data and <edit-config> to modify it, which are core to its configuration-management capabilities.

Option B is incorrect because HTTP is the transport used by RESTCONF, not NETCONF. Option C is incorrect because NETCONF uses XML encoding, whereas JSON encoding is a feature of RESTCONF (and other YANG-based interfaces), not of NETCONF itself.

200
MCQhard

A network administrator is configuring a switch and needs to segment traffic into multiple broadcast domains while also allowing communication between them. Which device or feature should be used to achieve this?

A.Port mirroring on a switch
B.STP on a switch
C.EtherChannel on a switch
D.VLANs on a switch
AnswerD

VLANs (Virtual LANs) logically segment a switch into multiple broadcast domains. Each VLAN is a separate broadcast domain. To allow communication between VLANs, a Layer 3 device (like a router or a Layer 3 switch) is required. The scenario asks for segmentation into broadcast domains, which VLANs provide.

Why this answer

VLANs are used to logically segment a switch into multiple broadcast domains. Each VLAN represents a separate broadcast domain, and devices within a VLAN can communicate at Layer 2. To enable communication between VLANs, inter-VLAN routing is needed.

STP, EtherChannel, and port mirroring do not create broadcast domains; they serve other purposes.

Exam trap

The trap here is assuming that any switch feature can segment broadcast domains, but only VLANs (and routers) can do that; features like STP or EtherChannel do not.

201
MCQmedium

A developer writes a Python script that calls the Cisco DNA Center Intent API. The script must authenticate once and reuse the returned token on subsequent requests instead of sending credentials with every call. Which HTTP header should the script include on each API request to present the token?

A.Content-Type: application/json
B.Authorization: Basic <base64-credentials>
C.X-Auth-Token: <token>
D.Cookie: session=<token>
AnswerC

Cisco DNA Center's authentication endpoint returns a token that clients must present in the X-Auth-Token request header on subsequent API calls. This avoids re-sending credentials and lets the controller validate the session quickly. The header name is case-insensitive per HTTP, but the exact spelling matters for clarity and for tools that generate requests from documentation examples.

Why this answer

After authenticating to the DNA Center Intent API, clients receive a token that must be sent in the X-Auth-Token header on every subsequent request. Basic credentials, cookies, and content type headers serve different purposes and do not carry the issued token. Reusing the token reduces credential exposure and matches how the controller expects stateless API calls to be authorized.

Exam trap

The trap here is assuming the token behaves like an OAuth bearer token placed in the Authorization header, when DNA Center uses its own X-Auth-Token header.

202
MCQhard

A network engineer is analyzing a packet capture and observes that a host sends a TCP segment with the SYN flag set, then receives a segment with both SYN and ACK flags set, and finally sends a segment with only the ACK flag set. Which TCP mechanism is being demonstrated?

A.TCP window scaling negotiation
B.TCP connection termination
C.TCP selective acknowledgment
D.TCP three-way handshake
AnswerD

The sequence of SYN, SYN-ACK, and ACK is the standard TCP three-way handshake used to establish a connection. The first host sends a SYN to initiate, the second host responds with SYN-ACK to acknowledge and synchronize, and the first host completes with an ACK. This ensures both sides are ready to communicate and agree on initial sequence numbers. The capture clearly shows this exact exchange.

Why this answer

The three segments with SYN, SYN-ACK, and ACK flags are the definitive signature of the TCP three-way handshake. This process synchronizes sequence numbers and establishes a reliable connection before data transfer begins. Other TCP mechanisms such as termination, window scaling, or selective acknowledgment involve different flags or options and occur at different stages.

Exam trap

The trap here is confusing the SYN-ACK segment as part of connection termination or as a separate mechanism, when it is actually the second step of the three-way handshake.

203
MCQeasy

A developer is making a GET request to a REST API and needs to specify that the response should be in JSON format. Which HTTP header should be set?

A.Content-Type
B.User-Agent
C.Authorization
D.Accept
AnswerD

The Accept request header tells the server which media types the client can handle, so setting Accept: application/json requests a JSON response. This satisfies the stem's requirement to specify JSON as the desired response format.

Why this answer

The Accept header is used by the client to tell the server which media types (e.g., application/json) it can understand and prefers for the response. In a GET request, the client does not send a body, so Content-Type is irrelevant for specifying the response format. Setting Accept: application/json ensures the server returns JSON if it supports that format.

Exam trap

Cisco often tests the distinction between Content-Type (for request body) and Accept (for response body), leading candidates to mistakenly choose Content-Type because they confuse 'sending' data with 'receiving' data.

How to eliminate wrong answers

Option A is wrong because Content-Type indicates the media type of the request body, not the desired response format; for a GET request with no body, Content-Type has no effect on the response. Option B is wrong because User-Agent identifies the client software (e.g., browser or tool) and has no role in content negotiation. Option C is wrong because Authorization carries credentials (e.g., Bearer token) for access control, not a preference for response format.

204
Multi-Selectmedium

Which THREE of the following are common steps in a CI/CD pipeline for a Python application that manages Cisco devices?

Select 3 answers
A.Build a Docker container
B.Manually review code before merge
C.Perform static code analysis (linting)
D.Run unit tests on each commit
E.Deploy to production on every commit
AnswersA, C, D

Building a Docker container packages the Python application with its dependencies into an immutable image, satisfying the pipeline's need for consistent, reproducible artefacts across environments. This step typically follows unit testing and precedes registry push and deployment, ensuring the Cisco device management code runs identically regardless of the underlying host configuration.

Why this answer

Option A (Build a Docker container) is correct because packaging the Python application and its dependencies into a Docker image is a standard CI/CD build step that ensures consistent, portable deployment artifacts across environments. Option C (Perform static code analysis/linting) is correct because tools like flake8, pylint, or black are typically run in the pipeline to catch syntax errors, style violations, and potential bugs before code is merged or deployed. Option D (Run unit tests on each commit) is correct because executing automated tests (e.g., pytest or unittest) on every commit provides fast feedback and verifies that the Python code managing Cisco devices behaves as expected.

Option B (Manually review code before merge) is not a pipeline step—it is a human code-review activity typically handled via pull requests, not automated CI/CD execution. Option E (Deploy to production on every commit) is not a common practice; production deployments usually require passing tests and approvals, and continuous deployment to production on every commit is risky and not a standard CI/CD step for network automation.

Exam trap

Cisco often tests the distinction between version control practices (like manual code review) and actual CI/CD pipeline stages (automated build, test, deploy), leading candidates to incorrectly select manual review as a pipeline step.

205
MCQmedium

A CI/CD pipeline for a Python project should run unit tests and check for known vulnerabilities in dependencies. Which tool can be integrated into the pipeline to perform dependency scanning?

A.Docker
B.Kubernetes
C.Jenkins
D.Snyk
AnswerD

Snyk scans third-party dependencies for known vulnerabilities, matching packages against a vulnerability database, which directly satisfies the pipeline's dependency-checking requirement. It integrates into CI/CD workflows and supports Python manifests such as requirements.txt and Pipfile, complementing the unit tests rather than replacing them.

Why this answer

Snyk is a popular dependency scanning tool that integrates with CI/CD pipelines. pip audit and npm audit are similar but for specific ecosystems. Snyk supports multiple languages.

206
MCQmedium

A network administrator uses the Cisco IOS XE CLI to configure a router. They want to use a Python script to automate this configuration via the guest shell. Which library should they use to interact with the CLI from within the guest shell?

A.cli
B.requests
C.ncclient
D.paramiko
AnswerA

The cli Python module is bundled inside the IOS XE guest shell, exposing functions such as cli.execute and cli.configurep to run CLI commands programmatically. It satisfies the constraint of interacting with the router's CLI from within the guest shell itself.

Why this answer

The `cli` library is a built-in Python module available within the Cisco Guest Shell that allows scripts to execute IOS XE CLI commands directly on the host device. This library provides functions like `cli.execute()` and `cli.configure()` to send commands and retrieve output, making it the correct choice for automating configuration via the Guest Shell without external dependencies.

Exam trap

Cisco often tests the distinction between on-box automation (using the `cli` library) and off-box automation (using libraries like paramiko, ncclient, or requests), and the trap here is that candidates may assume any SSH library (paramiko) works for local Guest Shell interaction, not realizing the `cli` library is purpose-built for direct host communication.

How to eliminate wrong answers

Option B (requests) is wrong because it is an HTTP client library used for REST API calls, not for interacting with the native IOS XE CLI within the Guest Shell. Option C (ncclient) is wrong because it is a Python library for NETCONF, which uses XML-based YANG models over SSH, not the direct CLI interface. Option D (paramiko) is wrong because it is an SSH implementation for remote connections, but within the Guest Shell, the script runs locally on the device and does not need to SSH back into itself; the `cli` library provides direct, privileged access without additional authentication.

207
Multi-Selecthard

A developer is using the Cisco DNA Center API to manage devices. The developer needs to perform operations that are part of the 'Site Management' API category. (Choose two.)

Select 2 answers
A.Retrieve device health
B.Assign a device to a site
C.Configure SNMP settings on a device
D.Create a new network profile
E.Create a new site
AnswersB, E

Assigning a device to a site is another key operation in Site Management. This is done via endpoints such as POST /dna/intent/api/v1/site/{siteId}/device. It associates a network device with a specific site, enabling site-based monitoring and policy enforcement. This operation is fundamental for site-based management.

Why this answer

The Site Management API category in Cisco DNA Center includes operations for creating, updating, and deleting sites, as well as associating devices with sites. Creating a new site and assigning a device to a site are both part of this category. Other operations like retrieving device health or configuring SNMP belong to different API categories.

Exam trap

The trap here is confusing Site Management with other DNA Center API categories such as Device Monitoring or Network Settings.

208
Multi-Selecthard

Which THREE of the following are best practices when using Git for a collaborative project? (Choose three.)

Select 3 answers
A.Use feature branches for new work.
B.Rebase or merge regularly to incorporate upstream changes.
C.Commit directly to the main branch.
D.Write descriptive commit messages.
E.Avoid pulling from remote to prevent conflicts.
AnswersA, B, D

Feature branches isolate new work from the mainline, so unfinished or experimental changes never destabilise shared code. This satisfies the stem's collaborative best-practice requirement by enabling independent development and clean pull requests before merging into the shared branch.

Why this answer

Option A is correct because feature branches isolate new work from the main branch, allowing changes to be developed, reviewed, and tested before integration, which reduces the risk of breaking shared code. Option B is correct because regularly rebasing or merging upstream changes keeps a feature branch current, minimizes large and painful merge conflicts, and ensures the work is built against the latest codebase. Option D is correct because descriptive commit messages document the intent and context of changes, making history easier to review, debug, and audit for collaborators.

Option C is not a best practice in a collaborative project because committing directly to the main branch bypasses review and can destabilize the shared branch. Option E is not a best practice because avoiding pulls prevents developers from incorporating others' changes, leading to stale local work and more severe conflicts later.

Exam trap

Cisco often tests the misconception that committing directly to main is acceptable for small changes, but the exam emphasizes that all changes should go through feature branches to maintain a clean, reviewable history.

209
Multi-Selectmedium

A developer is working with the Meraki Dashboard API to manage SSIDs. Which TWO statements about pagination are correct? (Choose two.)

Select 2 answers
A.Pagination is handled automatically by the client library; no action required
B.The 'page' query parameter is used to specify page number
C.The 'endingBefore' parameter is used to go to the previous page
D.The 'startingAfter' parameter can be used to fetch the next page of results
E.The Link header contains a 'last' URL for the final page
AnswersC, D

endingBefore retrieves items before a given ID, effectively moving backward.

Why this answer

Meraki uses the Link header with 'prev' and 'next' URLs for pagination. Additionally, the startingAfter and endingBefore query parameters allow manual pagination.

210
MCQhard

A developer is writing a Python script using the Cisco Webex Teams API to send a message to a specific room. The script works for some rooms but fails for others with a 404 error. What is the most likely reason?

A.The API rate limit has been exceeded for those rooms.
B.The access token is invalid for those rooms.
C.The bot does not have permission to send messages in those rooms.
D.The bot is not a member of those rooms.
AnswerD

A 404 on the Webex Teams messages endpoint occurs when the bot lacks membership in the target room, since the API scopes room access to authenticated participants. The stem's constraint is that some rooms succeed while others fail, which rules out token or syntax faults and points to per-room authorisation.

Why this answer

The 404 error indicates that the resource (the room) was not found by the API. In the Cisco Webex Teams API, a bot can only interact with rooms it has been added to as a member. If the bot is not a member of a room, the API cannot locate the room from the bot's perspective, resulting in a 404 error.

This is the most common cause of intermittent 404 errors when the script works for some rooms but not others.

Exam trap

Cisco often tests the distinction between HTTP status codes (404 vs 403 vs 401) and their specific meanings in the context of API authorization and resource existence, leading candidates to confuse permission issues (403) with membership/visibility issues (404).

How to eliminate wrong answers

Option A is wrong because exceeding the API rate limit would return a 429 (Too Many Requests) error, not a 404. Option B is wrong because an invalid access token would cause a 401 (Unauthorized) error for all API calls, not just for specific rooms. Option C is wrong because permission issues (e.g., not having the 'send messages' scope) would typically result in a 403 (Forbidden) error, not a 404; the bot must be a member of the room to even be considered for permission checks.

211
MCQeasy

A network engineer is configuring a switch and needs to assign an IP address to a VLAN interface for management purposes. The engineer wants to ensure that devices on different VLANs can communicate through the switch. Which feature must be enabled on the switch to allow inter-VLAN routing?

A.Link Aggregation Control Protocol (LACP)
B.Spanning Tree Protocol (STP)
C.Port mirroring
D.IP routing
AnswerD

Enabling IP routing on a Layer 3 switch allows it to route packets between VLANs. Each VLAN interface (SVI) acts as a default gateway for hosts in that VLAN, and the switch uses its routing table to forward traffic between subnets. This is the standard method for inter-VLAN routing on modern switches.

Why this answer

Inter-VLAN routing requires a Layer 3 device to forward packets between subnets. On a Layer 3 switch, enabling IP routing allows the switch to route between VLAN interfaces (SVIs). Each SVI is configured with an IP address and acts as the gateway for hosts in that VLAN.

Without IP routing, the switch would only forward frames within the same VLAN.

Exam trap

The trap here is assuming that any switch feature that involves multiple VLANs, like trunking or STP, can enable inter-VLAN communication; only Layer 3 routing accomplishes that.

212
MCQmedium

Given the JSON string: '{"name": "Alice", "scores": [90, 85, 92]}', which Python code correctly extracts the second score (85)?

A.json.loads(json_str)['scores'][1]
B.json.dumps(json_str)['scores'][1]
C.json_str['scores'][1]
D.json.loads(json_str)['scores'][2]
AnswerA

json.loads parses the string into a dictionary, then ['scores'] retrieves the list and [1] indexes its second element, which is 85. Python lists are zero-indexed, so index 1 satisfies the stem's requirement of extracting the second score rather than the first.

Why this answer

json.loads converts to dict, then access scores list index 1.

213
MCQeasy

An application exposes a REST API. To ensure that only authorized clients can access the API, the developer implements token-based authentication. Which HTTP header is typically used to transmit the bearer token?

A.Cookie
B.X-API-Key
C.Authorization: Basic
D.Authorization: Bearer
AnswerD

The Authorization header carries credentials for HTTP authentication, and the Bearer scheme conveys an OAuth 2.0 access token, so 'Authorization: Bearer <token>' transmits the bearer token. This satisfies the token-based authentication requirement, since servers read that header to validate client authorisation.

Why this answer

The Authorization header with the Bearer scheme (RFC 6750) is the standard method for transmitting bearer tokens in HTTP requests. When a client authenticates and receives a token, it includes the token in the Authorization header as 'Bearer <token>', allowing the server to validate the token and authorize the request without requiring session state.

Exam trap

Cisco often tests the distinction between Authorization: Basic and Authorization: Bearer, where candidates confuse the two because both use the Authorization header, but Basic transmits credentials while Bearer transmits a token.

How to eliminate wrong answers

Option A is wrong because the Cookie header is used for session-based authentication (e.g., JSESSIONID) and is not the standard for bearer token transmission; cookies are vulnerable to CSRF and require additional security measures. Option B is wrong because X-API-Key is a custom header typically used for API key authentication, not for bearer tokens; it lacks the standardized Bearer scheme defined in RFC 6750. Option C is wrong because Authorization: Basic uses Base64-encoded credentials (username:password) for HTTP Basic Authentication, not a token; it transmits credentials directly rather than a bearer token.

214
MCQeasy

At which layer of the OSI model do switches operate when forwarding frames based on MAC addresses?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 2 (Data Link)
D.Layer 4 (Transport)
AnswerC

Switches forward frames using MAC addresses contained in Ethernet headers, which reside at Layer 2, the Data Link layer. This satisfies the scenario's forwarding basis, distinguishing switches from Layer 3 routers that forward on IP addresses.

Why this answer

Switches operate at Layer 2 (Data Link layer) because they use MAC addresses to forward frames.

215
MCQmedium

Which TCP flag is set in the second step of the three-way handshake?

A.ACK
B.SYN and ACK
C.SYN
D.FIN
AnswerB

The second handshake step has the server responding to the client's initial SYN with its own sequence number while acknowledging the client's, so both SYN and ACK flags are set. This synchronises sequence numbers in both directions.

Why this answer

The TCP three-way handshake begins with the client sending a SYN segment to initiate a connection. In the second step, the server responds with a SYN-ACK segment, which both acknowledges the client's SYN (using the ACK flag) and synchronizes its own sequence number (using the SYN flag). This combined flag is essential for establishing a reliable, bidirectional connection.

Exam trap

Cisco often tests the misconception that the second step uses only an ACK flag, confusing it with the third step where the client sends an ACK to complete the handshake.

How to eliminate wrong answers

Option A is wrong because the ACK flag alone is used in later stages of the handshake (e.g., the third step) or in subsequent data transfers, not in the second step where both synchronization and acknowledgment are required. Option C is wrong because a pure SYN flag is only sent in the first step by the client to initiate the connection; the server must also acknowledge that SYN, so a standalone SYN in the second step would leave the client's initial sequence number unacknowledged. Option D is wrong because the FIN flag is used to gracefully terminate a connection, not to establish one; it appears in the four-way teardown process.

216
MCQmedium

A developer is building a chatbot that retrieves interface status from a Cisco Catalyst 9000 switch using RESTCONF. Which authentication method is most appropriate for programmatic access?

A.HTTP Basic Authentication over HTTPS.
B.API key passed in the HTTP header.
C.OAuth 2.0 with client credentials grant.
D.Client certificate authentication.
AnswerA

HTTP Basic Authentication over HTTPS supplies credentials in the request header, which RESTCONF accepts for programmatic access, satisfying the stem's chatbot requirement. HTTPS encrypts the base64-encoded credentials in transit, preventing interception, and the method needs no browser-based interactive login flow.

Why this answer

RESTCONF on Cisco Catalyst 9000 switches supports HTTP Basic Authentication over HTTPS as a straightforward, standards-based method for programmatic access. Basic authentication sends the username and password in the HTTP Authorization header, and when combined with HTTPS, the credentials are encrypted in transit, providing adequate security for device management without requiring additional infrastructure like an OAuth provider or certificate authority.

Exam trap

Cisco often tests the misconception that RESTCONF requires OAuth or API keys because it is a RESTful API, but in reality, IOS XE devices rely on traditional AAA and HTTP Basic Auth over HTTPS for programmatic access.

How to eliminate wrong answers

Option B is wrong because RESTCONF does not natively support API key authentication; API keys are typically used with REST APIs that have a dedicated key management system, not with NETCONF/RESTCONF on Cisco IOS XE. Option C is wrong because OAuth 2.0 with client credentials grant is not a standard authentication mechanism for RESTCONF on Catalyst 9000 switches; these devices use local or AAA-based authentication, not token-based OAuth flows. Option D is wrong while client certificate authentication is supported for HTTPS, it is not the most appropriate for simple programmatic access because it requires a PKI infrastructure and certificate management, adding complexity that is unnecessary for basic interface status retrieval.

217
MCQeasy

A developer is working with a REST API that uses HTTP Basic Authentication. The developer needs to send a request with the username 'admin' and password 'secret'. Which HTTP header should be set?

A.Authorization: Basic admin:secret
B.Authorization: YWRtaW46c2VjcmV0
C.Authorization: Basic YWRtaW46c2VjcmV0
D.Authorization: Bearer YWRtaW46c2VjcmV0
AnswerC

HTTP Basic Authentication transmits credentials as base64-encoded `username:password` in the `Authorization` header. Encoding `admin:secret` yields `YWRtaW46c2VjcmV0`, satisfying the stem's requirement to send those exact credentials. The `Basic` scheme prefix must precede the encoded value, which this header does correctly.

Why this answer

HTTP Basic Authentication requires the credentials to be formatted as 'username:password', then Base64-encoded, and sent in the Authorization header with the 'Basic' scheme. Option C correctly includes the 'Basic' scheme followed by the Base64-encoded string 'YWRtaW46c2VjcmV0' (which decodes to 'admin:secret').

Exam trap

Cisco often tests whether candidates know that the credentials must be Base64-encoded and prefixed with the 'Basic' scheme, not sent in plaintext or with the wrong scheme like 'Bearer'.

How to eliminate wrong answers

Option A is wrong because it sends the credentials in plaintext 'admin:secret' without Base64 encoding and omits the required 'Basic' scheme prefix. Option B is wrong because it sends the Base64-encoded string 'YWRtaW46c2VjcmV0' but lacks the 'Basic' scheme identifier, making the header invalid per RFC 7617. Option D is wrong because it uses the 'Bearer' scheme, which is used for OAuth 2.0 token authentication, not HTTP Basic Authentication.

218
MCQmedium

A developer is writing a Python script to interact with a Cisco IOS XE device using the NETCONF protocol. The script uses the ncclient library to establish a connection and retrieve the running configuration. Which method should the developer use to retrieve the configuration?

A.manager.edit_config(target='running')
B.manager.get(filter=('subtree', 'running'))
C.manager.dispatch(rpc='get-config')
D.manager.get_config(source='running')
AnswerD

In ncclient, the get_config method retrieves configuration data from a specified datastore. Using source='running' fetches the running configuration. This is the correct method for retrieving configuration via NETCONF. The method returns a response object containing the configuration in XML format, which can then be parsed.

Why this answer

The ncclient library provides the get_config method to retrieve configuration from a NETCONF server. The source parameter specifies the datastore, such as 'running' for the running configuration. The get method is for state data, edit_config is for modifying configuration, and dispatch is for custom RPCs.

Therefore, the correct method is manager.get_config(source='running').

Exam trap

The trap here is confusing get_config with get; the former retrieves configuration, while the latter retrieves state data.

219
Multi-Selectmedium

A developer is building a CI/CD pipeline that must securely manage secrets such as API keys and database passwords. Which two practices should be implemented to protect these secrets throughout the pipeline? (Choose two.)

Select 2 answers
A.Store secrets in a dedicated secrets manager and inject them at runtime.
B.Encrypt secrets and commit them to the repository for versioning.
C.Disable logging for all pipeline stages to prevent secret leakage.
D.Hardcode secrets in the pipeline configuration file for simplicity.
E.Use environment variables to pass secrets to build steps without logging them.
AnswersA, E

Using a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) centralizes secret storage with encryption, access controls, and audit logging. Injecting secrets at runtime avoids embedding them in code or configuration files, reducing exposure. This is a best practice for secure secret management in CI/CD pipelines.

Why this answer

To protect secrets in a CI/CD pipeline, they should be stored in a dedicated secrets manager and injected at runtime, avoiding persistent storage in code or configuration. Additionally, using environment variables with masking ensures secrets are not exposed in logs. These practices minimize the attack surface and align with the principle of least privilege.

Encrypting and committing secrets or hardcoding them are insecure, and disabling all logging is impractical.

Exam trap

The trap here is believing that encrypting secrets before committing them to a repository is sufficient, when in fact any storage in version control remains risky and violates best practices.

220
MCQeasy

A developer is writing a unit test for a Python function that calls the Cisco Meraki Dashboard API to retrieve a list of organizations. The test must run without making real HTTP requests to the Meraki cloud. Which technique should be used to isolate the function under test?

A.Run the test only on a developer workstation that has a valid Meraki API key configured.
B.Use the unittest.mock library to patch the requests.get call and return a canned JSON response.
C.Replace the API call with a print statement that outputs the expected organization list.
D.Increase the test timeout to 60 seconds so the real Meraki API call has time to complete.
AnswerB

Patching requests.get with unittest.mock replaces the real network call with a controlled return value, so the test exercises the function's parsing and error handling without contacting the Meraki Dashboard API. This makes the test fast, deterministic, and safe to run in CI. It is the standard Python approach for isolating external HTTP dependencies in unit tests.

Why this answer

Unit tests for API clients should isolate the code under test from external services. Patching the HTTP call with unittest.mock lets the test supply a fixed JSON payload and verify how the function handles it, including success and error paths. This keeps the test fast, repeatable, and independent of the Meraki Dashboard API's availability or rate limits.

Exam trap

The trap here is confusing a longer timeout or a real API key with true isolation, when the goal is to eliminate the network call rather than wait longer for it.

221
MCQmedium

A developer is using gRPC/gNMI for model-driven telemetry from a Cisco device. Which of the following best describes the difference between dial-in and dial-out streaming?

A.Dial-in uses gNMI; dial-out uses NETCONF.
B.Dial-in uses TCP; dial-out uses UDP.
C.Dial-in is initiated by the network device; dial-out is initiated by the collector.
D.Dial-in is initiated by the collector; dial-out is initiated by the device.
AnswerD

In dial-in telemetry the collector opens the gRPC session to the device and subscribes; in dial-out the device initiates the connection to the collector and pushes data. This direction of session initiation is the defining difference between the two modes.

Why this answer

In dial-in telemetry, the collector (management station) initiates the connection to the network device and subscribes to telemetry data — the collector 'dials in' to the device. In dial-out telemetry, the network device initiates the connection to the collector and pushes data, which is useful when the device is behind NAT or a firewall.

Exam trap

200-901 often tests the initiator direction in telemetry modes, tricking candidates who assume the collector always initiates (as in traditional SNMP polling).

How to eliminate wrong answers

Option A is wrong because both dial-in and dial-out can use gNMI; the distinction is about who initiates the connection, not the protocol used. Option B is wrong because both modes typically use TCP (gRPC runs over HTTP/2 over TCP), not UDP. Option C is wrong because it reverses the roles — dial-in is initiated by the collector, not the device.

222
Multi-Selecthard

A developer is building a Cisco Webex bot that needs to automatically respond to messages. Which THREE resources/endpoints are essential for this functionality? (Choose three.)

Select 3 answers
A.Rooms API
B.People API
C.Licenses API
D.Webhooks API
E.Messages API
AnswersA, D, E

The Rooms API lets the bot enumerate and inspect Webex spaces, supplying the roomId that every message response must target. Without it, the bot cannot determine which conversation to post into, so it satisfies the requirement to respond automatically to messages received across multiple rooms.

Why this answer

Essential endpoints are Messages (to send/receive), Webhooks (to get notified of events), and Rooms (to interact with rooms). People is useful but not essential for bot functionality.

223
MCQmedium

A developer is building a Python script to configure a Cisco IOS XE device using NETCONF. The script must send an <edit-config> RPC that places the target datastore in candidate mode, changes the description of GigabitEthernet0/0, and commits the change. Which NETCONF capability must the device advertise for the script to use the candidate datastore?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:rollback-on-error:1.0
C.urn:ietf:params:netconf:capability:writable-running:1.0
D.urn:ietf:params:netconf:capability:validate:1.0
AnswerA

The candidate capability allows a client to edit a candidate datastore and then commit those changes to the running datastore. Because the script edits the candidate and commits, the device must advertise this capability. Without it, the client cannot use <edit-config> with a candidate target or issue <commit>, so this is the required capability for the described workflow.

Why this answer

The candidate capability is required because the script edits a candidate datastore and then commits the change to running. NETCONF capabilities are advertised in the server's <hello> message; a client must check for the candidate capability before using <edit-config> with a candidate target and <commit>. Rollback-on-error, validate, and writable-running serve different purposes and do not enable the candidate datastore workflow.

Exam trap

The trap here is assuming that any edit-config operation requires the candidate capability, when in fact only workflows that explicitly target the candidate datastore and commit need it.

224
MCQmedium

In a Cisco DNA Center environment, an application needs to retrieve the network device list using REST API. Which authentication method is required?

A.OAuth 2.0 client credentials grant with client ID and secret
B.Obtain an API token by POSTing credentials to /dna/system/api/v1/auth/token, then use the token in subsequent requests
C.Basic authentication with username and password in the header
D.API key passed in a query parameter
AnswerB

Cisco DNA Center requires token-based authentication: credentials are Base64-encoded and POSTed to /dna/system/api/v1/auth/token, which returns a time-limited token. Subsequent REST calls must include this token in the X-Auth-Token header, satisfying the stem's requirement to retrieve the device list securely without resending credentials per request.

Why this answer

Cisco DNA Center uses token-based authentication. The correct flow is to first send a POST request to the /dna/system/api/v1/auth/token endpoint with a valid username and password (typically using Basic Authentication over HTTPS). The response contains a JSON Web Token (JWT) that must be included in the X-Auth-Token header of all subsequent API requests.

This token has a configurable expiry (default 60 minutes) and must be refreshed before it expires.

Exam trap

Cisco often tests the distinction between the authentication method used to obtain a token (Basic Auth) versus the method used to authorize subsequent API calls (Bearer token), leading candidates to mistakenly select Basic Authentication for all requests.

How to eliminate wrong answers

Option A is wrong because OAuth 2.0 client credentials grant is not the authentication method used by Cisco DNA Center; DNA Center uses a custom token-based system, not the OAuth 2.0 framework. Option C is wrong because Basic authentication with username and password in the header is only used for the initial token acquisition step, not for subsequent API calls; sending credentials with every request is insecure and not supported by the API. Option D is wrong because API keys passed in query parameters are not used by Cisco DNA Center; the token must be sent in the Authorization header as a Bearer token, not as a query parameter.

225
MCQeasy

Which Cisco platform provides a cloud-managed dashboard with a REST API that uses an API key in the header and has a rate limit of 5 requests per second?

A.Cisco Webex
B.Cisco Meraki
C.Cisco DNA Center
D.Cisco IOS XE
AnswerB

Cisco Meraki's cloud-managed dashboard exposes a REST API authenticated with an API key in the request header and enforces a documented rate limit of 5 requests per second per organisation, matching all three stated constraints.

Why this answer

Cisco Meraki is a cloud-managed networking platform whose Dashboard API is RESTful, uses an API key passed in the X-Cisco-Meraki-API-Key header, and enforces a rate limit of 5 requests per second per organization. This matches the question's description exactly.

Exam trap

The trap is that candidates confuse Cisco DNA Center's token-based API with Meraki's API-key-based API, or assume Webex because it is also cloud-based, missing the specific rate limit and header details.

How to eliminate wrong answers

Option A is wrong because Cisco Webex is a collaboration platform (meetings, messaging) with its own REST API, but it is not a cloud-managed network dashboard and does not use the Meraki API key header or 5 req/s limit. Option C is wrong because Cisco DNA Center is an on-premises (or private cloud) controller for enterprise networks; its API uses token-based authentication (X-Auth-Token) and different rate limits, not a simple API key in the header. Option D is wrong because Cisco IOS XE is a network operating system, not a cloud-managed dashboard; it exposes RESTCONF/NETCONF but not a Meraki-style API key header.

Page 2

Page 3 of 13

Page 4