Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 226–300

975 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
MCQmedium

An organization has a web server that needs to be reachable via both 'www.example.com' and 'example.com'. Which DNS record type should be used to make 'example.com' an alias for 'www.example.com'?

A.A record
B.MX record
C.NS record
D.CNAME record
AnswerD

A CNAME record maps one DNS name to another canonical name, so querying example.com returns www.example.com's records. This satisfies the stem's requirement for an alias rather than a duplicate A record, letting both hostnames resolve to the same web server without maintaining separate IP entries.

Why this answer

A CNAME record creates an alias that points to the canonical name. The A record points to an IP address, not another domain.

227
Multi-Selecthard

Which TWO of the following Git commands modify the commit history? (Select TWO)

Select 2 answers
A.git diff
B.git log
C.git commit --amend
D.git rebase -i
E.git status
AnswersC, D

git commit --amend rewrites the most recent commit, replacing it with a new commit object that has a different hash, thereby altering commit history. This differs from commands such as git commit, which only append new commits.

Why this answer

git commit --amend is correct because it rewrites the most recent commit, replacing it with a new commit object that includes staged changes and/or an edited commit message, thereby altering commit history. git rebase -i is correct because interactive rebase lets you reorder, edit, squash, split, or drop existing commits, which rewrites the branch's commit history and produces new commit SHAs. The other options are read-only inspection commands: git diff shows unstaged or staged changes between working tree, index, and commits, git log displays the commit history, and git status reports working tree and index state — none of them modify commit history.

Exam trap

Cisco often tests the distinction between read-only inspection commands (like `git diff`, `git log`, `git status`) and commands that actually rewrite commit history, leading candidates to mistakenly select non-modifying commands.

228
MCQmedium

Which HTTP header is used to specify the format of the request body (e.g., application/json) when sending a POST request to a REST API?

A.Accept
B.Content-Type
C.Authorization
D.X-Requested-With
AnswerB

Content-Type specifies the media type of the request body, such as application/json, so the server knows how to parse the POST payload. Accept instead describes the desired response format, so Content-Type satisfies the requirement to declare the body's format.

Why this answer

Content-Type indicates the media type of the request body. Accept indicates the desired response format. Authorization carries credentials.

229
MCQeasy

A web application uses HTTPS to secure communications between client and server. What does HTTPS add on top of HTTP to provide encryption and authentication?

A.SSH
B.IPsec
C.SSL/TLS
D.VPN
AnswerC

SSL/TLS operates between HTTP and TCP, encrypting the request and response payloads and authenticating the server via its certificate. Plain HTTP provides neither confidentiality nor identity verification, so layering TLS satisfies the encryption and authentication requirement.

Why this answer

HTTPS is HTTP layered over SSL/TLS, which provides encryption (confidentiality), integrity, and server authentication via X.509 certificates. TLS negotiates a session key using asymmetric cryptography, then encrypts the HTTP payload with symmetric ciphers. This is what distinguishes HTTPS from plain HTTP.

Exam trap

200-901 often tests the layering confusion — candidates may pick IPsec or VPN because they associate 'encryption' with network-layer tunnels rather than the application-layer TLS that actually secures HTTPS.

How to eliminate wrong answers

Option A is wrong because SSH is a separate protocol for secure remote shell access and file transfer — it is not used to secure HTTP traffic. Option B is wrong because IPsec operates at the network layer (Layer 3) to secure IP packets, typically for VPNs, not for application-layer HTTP encryption. Option D is wrong because a VPN tunnels traffic at the network layer but does not itself provide the application-layer encryption and certificate-based authentication that define HTTPS.

230
MCQhard

A developer is implementing gRPC telemetry with dial-out streaming from a Cisco IOS XE device. Which component initiates the TCP connection to the collector?

A.A third-party orchestrator initiates
B.The network device initiates the connection
C.The collector initiates the connection
D.Both initiate simultaneously
AnswerB

In dial-out telemetry, the network device acts as the client and initiates the TCP connection to the collector, which listens as the server. This satisfies the dial-out model, reversing the dial-in approach where the collector connects to the device.

Why this answer

In dial-out streaming, the network device (server) initiates the connection to the collector (client).

231
Multi-Selecteasy

Which TWO Cisco platforms provide comprehensive REST APIs for network configuration and monitoring?

Select 2 answers
A.Cisco ASA
B.Cisco IOS XE
C.Cisco ISE
D.Cisco Prime Infrastructure
E.Cisco DNA Center
AnswersB, E

Cisco IOS XE exposes comprehensive REST APIs through its RESTCONF and NETCONF interfaces, enabling programmatic configuration and monitoring via YANG models. This satisfies the stem's requirement for a platform offering REST APIs for both network configuration and monitoring tasks.

Why this answer

Cisco IOS XE provides comprehensive REST APIs through its RESTCONF and NETCONF interfaces, enabling programmatic configuration and monitoring of network devices. Cisco DNA Center offers a rich set of REST APIs for intent-based networking, allowing automation of network design, provisioning, policy, and assurance tasks. Both platforms are designed for modern network programmability and are key components of Cisco's DevNet ecosystem.

Exam trap

Cisco often tests the distinction between platforms with REST APIs for network configuration versus those with limited or specialized APIs, so candidates may incorrectly assume that any Cisco platform with an API qualifies, missing the 'comprehensive' requirement for general network configuration and monitoring.

232
MCQeasy

Which Docker command is used to build an image from a Dockerfile?

A.docker run
B.docker commit
C.docker build
D.docker create
AnswerC

`docker build` reads a Dockerfile and constructs an image layer by layer, satisfying the stem's requirement to build an image from a Dockerfile. It parses instructions such as FROM, RUN and COPY, committing each layer, then tags the resulting image locally so containers can be created from it.

Why this answer

The `docker build` command reads the instructions in a Dockerfile and assembles a Docker image layer by layer. Each instruction in the Dockerfile (e.g., FROM, RUN, COPY) creates a new layer that is cached and reused, making subsequent builds faster. This is the standard and only command designed specifically for building images from a Dockerfile.

Exam trap

Cisco often tests the distinction between commands that create containers (`docker run`, `docker create`) and the command that builds images (`docker build`), hoping candidates confuse the purpose of `docker run` with image creation.

How to eliminate wrong answers

Option A is wrong because `docker run` creates and starts a container from an existing image, it does not build a new image. Option B is wrong because `docker commit` creates a new image from a container's current state (filesystem changes), but it is not the intended way to build from a Dockerfile; it bypasses the reproducible, layered build process defined in the Dockerfile. Option D is wrong because `docker create` only creates a container from an image without starting it, and it does not perform any image building.

233
MCQhard

A development team runs a Python Flask API in a Docker container. The image was built with the Flask development server bound to 0.0.0.0:5000, and the container is started with the published port mapping 8080:5000. Users report that requests to the host on port 5000 are refused, while port 8080 works. Which statement explains this behaviour?

A.The host firewall is dropping traffic on port 5000 because Docker only opens ports that are declared with EXPOSE.
B.The Dockerfile EXPOSE instruction must match the host port, so EXPOSE 8080 is required for host port 5000 to work.
C.The published mapping forwards host port 8080 to container port 5000, so nothing is listening on host port 5000.
D.Binding Flask to 0.0.0.0 inside the container prevents Docker from forwarding traffic, so the app must bind to localhost instead.
AnswerC

Publishing with 8080:5000 means the host listens on 8080 and forwards to port 5000 inside the container. The application is reachable only through 8080 on the host; host port 5000 is never bound by Docker, so a connection attempt there is refused. To reach the app on host port 5000 the mapping would need to be 5000:5000.

Why this answer

Port publishing follows the host:container form, so 8080:5000 binds the host to 8080 and forwards into the container's 5000. Host port 5000 is not bound at all, which is why connections there are refused while 8080 succeeds. EXPOSE is purely informational, and the in-container bind address determines which interfaces inside the container accept the forwarded packets.

Exam trap

The trap here is reading the published port mapping as container:host instead of host:container.

234
MCQhard

A developer is using the Cisco Meraki Dashboard API to update the VLAN configuration on a switch port. The API call returns a 404 Not Found error. The developer has verified that the API key is valid and the organization ID and network ID are correct. What is the most likely cause of the 404 error?

A.The API key does not have write permissions for the network.
B.The request body is missing required parameters.
C.The API endpoint URL is incorrect or the resource does not exist.
D.The Meraki Dashboard API rate limit has been exceeded.
AnswerC

A 404 Not Found indicates that the server cannot find the requested resource. Even with valid IDs, if the endpoint path is wrong (e.g., misspelled 'vlans' or wrong API version) or the specific port does not exist, the server returns 404. The developer should double-check the URL structure and ensure the port identifier is valid for that switch.

Why this answer

A 404 Not Found error means the server cannot locate the requested resource. Common causes include an incorrect endpoint URL, a non-existent resource ID (such as a port that does not exist on the switch), or a typo in the path. Authentication issues yield 401, permission issues yield 403, bad request bodies yield 400, and rate limits yield 429.

Therefore, the developer should verify the URL and resource identifiers.

Exam trap

The trap here is confusing 404 with permission or authentication errors, which have different status codes (403 and 401 respectively).

235
MCQeasy

A company has two Cisco Catalyst switches, SW1 and SW2, connected via a trunk link using port GigabitEthernet0/1 on both switches. SW1 is the root bridge for all VLANs spanning tree. VLAN 10 users on SW1 report they can access the internet and resources in VLAN 10 on SW2, but cannot reach a critical server in VLAN 20 connected to SW2. The server in VLAN 20 has a static IP address and can communicate with other VLAN 20 devices on SW2. SW2's configuration for the trunk port includes 'switchport trunk allowed vlan 10,20'. SW1's trunk port configuration is 'switchport trunk allowed vlan 10'. The network administrator has verified that both switches have VLANs 10 and 20 created and that the default gateways are correct. What is the most likely cause of the issue?

A.SW1's trunk port is not configured to allow VLAN 20.
B.SW1 is the root bridge for VLAN 20, causing traffic to be blocked.
C.The trunk link between SW1 and SW2 is down.
D.The server in VLAN 20 has an incorrect IP address configuration.
AnswerA

SW1's trunk permits only VLAN 10, so VLAN 20 frames arriving from SW2 are dropped before reaching SW1's VLAN 20 devices. SW2's allowed list is irrelevant; the missing VLAN 20 on SW1's trunk is the actual cause of the connectivity failure.

Why this answer

SW1's trunk port is configured with 'switchport trunk allowed vlan 10', which explicitly permits only VLAN 10 traffic. Since VLAN 20 is not in the allowed list, frames from VLAN 20 (including traffic to the server) are dropped at the trunk egress on SW1. This prevents SW1 hosts in VLAN 10 from reaching the VLAN 20 server on SW2, even though the trunk is up and both VLANs exist on both switches.

Exam trap

Cisco often tests the distinction between VLAN existence on a switch and VLAN permission on a trunk port—candidates assume that if a VLAN is created on both switches, traffic will flow, but the trunk allowed list is the gatekeeper.

How to eliminate wrong answers

Option B is wrong because SW1 being the root bridge for all VLANs (including VLAN 20) does not block traffic; the root bridge is the reference point for spanning tree and does not itself cause traffic blocking—blocking occurs on non-root ports. Option C is wrong because if the trunk link were down, VLAN 10 users on SW1 would also be unable to access VLAN 10 resources on SW2, which they can. Option D is wrong because the server in VLAN 20 can communicate with other VLAN 20 devices on SW2, proving its IP configuration is correct for its local subnet.

236
MCQhard

A DevOps team is automating network configuration using Ansible. They want to push a new VLAN configuration to a switch but ensure that only one switch is updated at a time to avoid network disruption. Which Ansible strategy or feature should they use?

A.Use 'strategy: free' to manage execution order.
B.Set 'forks: 1' in the playbook.
C.Use 'throttle: 1' on each task.
D.Set 'serial: 1' in the playbook.
AnswerD

The serial keyword controls how many hosts Ansible executes per play iteration. Setting serial: 1 runs the play against one switch at a time, completing each before starting the next, which prevents simultaneous VLAN changes from disrupting the network.

Why this answer

Setting `serial: 1` in an Ansible playbook forces the play to execute against only one host at a time, even if the play targets multiple switches. This ensures that VLAN configuration is pushed to exactly one switch before moving to the next, preventing network disruption from simultaneous changes.

Exam trap

The trap here is that candidates confuse `forks` (which controls task-level parallelism) with `serial` (which controls host-level batching), or mistakenly think `throttle` or `strategy: free` can achieve the same serialization effect.

How to eliminate wrong answers

Option A is wrong because `strategy: free` allows each host to run tasks independently without waiting for others, which could cause multiple switches to be updated concurrently, defeating the purpose of serialized updates. Option B is wrong because `forks: 1` limits the number of parallel task executions but still allows multiple hosts to be processed in parallel if the play targets multiple hosts; `forks` controls task-level parallelism, not host-level serialization. Option C is wrong because `throttle: 1` limits the number of concurrent task runs across all hosts but does not guarantee that only one switch is updated at a time; it can still allow multiple hosts to start the task before the throttle limit is reached, and it applies per task, not per play.

237
MCQhard

In a Kubernetes cluster, you need to expose a set of pods running a web application to external traffic on a specific port. Which Service type should you use to provide a stable external IP address?

A.ClusterIP
B.LoadBalancer
C.NodePort
AnswerB

LoadBalancer provisions an external load balancer through the cloud provider, assigning a stable public IP that routes to the pods on your chosen port. This satisfies the stem's requirement for external traffic on a specific port, unlike ClusterIP (internal only) or NodePort (no stable external IP).

Why this answer

LoadBalancer provisions a cloud load balancer and assigns a stable external IP, making the service accessible from outside the cluster.

238
MCQmedium

A Python function is defined as: def process(*args, **kwargs): return sum(args) + kwargs.get('offset', 0) What is the result of process(1, 2, 3, offset=10)?

A.6
B.16
C.Error
D.10
AnswerB

The `*args` parameter collects the positional arguments 1, 2 and 3 into a tuple, which `sum()` totals to 6. The `**kwargs` parameter collects `offset=10` into a dictionary, and `kwargs.get('offset', 0)` retrieves 10. Adding 6 and 10 returns 16.

Why this answer

*args captures positional arguments as tuple (1,2,3), sum is 6, kwargs dict includes {'offset':10}, .get returns 10, total 16.

239
MCQmedium

Which HTTP status code indicates that a POST request successfully created a new resource on the server?

A.200 OK
B.201 Created
C.204 No Content
D.202 Accepted
AnswerB

201 Created is returned when a POST request results in a new resource being created on the server, typically accompanied by a Location header identifying its URI. Other 2xx codes, such as 200 OK, indicate success without confirming resource creation.

Why this answer

The 201 Created status code is the correct response for a POST request that successfully creates a new resource. According to RFC 7231, the server should respond with 201 and include a Location header pointing to the newly created resource's URI. This is the standard behavior for RESTful APIs when a POST operation results in resource creation.

Exam trap

Cisco often tests the distinction between 200 OK and 201 Created, trapping candidates who assume any successful POST returns 200 OK, when in fact 201 is the standard for resource creation.

How to eliminate wrong answers

Option A is wrong because 200 OK indicates a successful request but does not specifically signal that a new resource was created; it is typically used for GET requests or POST requests that return a representation without creating a new resource. Option C is wrong because 204 No Content indicates the server successfully processed the request but returns no response body, often used for DELETE operations or updates that return no content, not for resource creation. Option D is wrong because 202 Accepted means the request has been accepted for processing but the processing has not been completed; it is used for asynchronous operations, not for immediate resource creation.

240
Multi-Selecteasy

A DevOps team is deploying a microservices application that requires both reliable data transfer and low-latency real-time communication. Which two protocols should be used for these respective requirements? (Choose two.)

Select 2 answers
A.ARP
B.ICMP
C.TCP
D.HTTP
E.UDP
AnswersC, E

TCP is reliable and connection-oriented, suitable for reliable data transfer.

Why this answer

TCP (Transmission Control Protocol) is correct for reliable data transfer because it provides connection-oriented communication with sequencing, acknowledgments, and retransmission of lost packets, ensuring data arrives intact and in order. This makes it ideal for microservices that need guaranteed delivery, such as database transactions or order processing.

Exam trap

Cisco often tests the distinction between transport-layer protocols (TCP/UDP) and application-layer protocols (HTTP), so candidates mistakenly pick HTTP for reliability instead of recognizing that HTTP relies on TCP underneath.

241
Multi-Selecthard

A Kubernetes administrator wants to use kubectl to troubleshoot a pod named 'my-pod' that is not starting. Which TWO commands are useful? (Choose two.)

Select 2 answers
A.kubectl get deployment my-deployment
B.kubectl rollout status deployment my-deployment
C.kubectl describe pod my-pod
D.kubectl delete pod my-pod
E.kubectl logs my-pod
AnswersC, E

`kubectl describe pod my-pod` surfaces the pod's status conditions, container states and recent events, exposing scheduling failures, image pull errors or crash loops that stop it starting. This directly satisfies the troubleshooting constraint by revealing why the pod cannot launch, without requiring logs from a container that never ran.

Why this answer

Option C, 'kubectl describe pod my-pod', is correct because it surfaces the pod's status conditions, events, and container state details (such as ImagePullBackOff, CrashLoopBackOff, or scheduling failures), which are essential for diagnosing why a pod is not starting. Option E, 'kubectl logs my-pod', is correct because it retrieves the container's stdout/stderr output, revealing application-level errors that prevent the process from running successfully. Option A is not directly useful since 'kubectl get deployment my-deployment' only shows deployment-level status and does not inspect the specific pod 'my-pod'.

Option B, 'kubectl rollout status deployment my-deployment', reports rollout progress for a deployment, not the startup failure of an individual pod. Option D, 'kubectl delete pod my-pod', is a remediation action that removes the pod rather than a troubleshooting command to diagnose the failure.

Exam trap

The trap is selecting deployment-level commands when the question explicitly asks about a single pod — candidates conflate deployment troubleshooting with pod troubleshooting.

242
MCQeasy

A developer is working on a Git repository and needs to temporarily save changes that are not ready to be committed so they can switch to another branch to fix a bug. Which Git command should the developer use to stash the current changes?

A.git commit -m "WIP"
B.git branch temp
C.git stash
D.git checkout -- .
AnswerC

This is correct because git stash saves the current working directory and index state, reverting the working directory to match the HEAD commit. It allows the developer to switch branches without committing unfinished work. Later, git stash pop or git stash apply can restore the changes. This command is specifically designed for temporarily shelving changes.

Why this answer

The git stash command is designed to temporarily store modifications to tracked files and the staging area, allowing a clean working directory. This enables switching branches or performing other operations without committing incomplete work. The stashed changes can be reapplied later with git stash pop or git stash apply, making it ideal for the described scenario.

Exam trap

The trap here is assuming that committing work-in-progress is equivalent to stashing, but committing creates permanent history while stashing is temporary and does not affect the commit log.

243
MCQeasy

A network engineer is configuring a new Cisco switch and needs to assign an IP address to a VLAN interface so that the switch can be managed remotely over the network. The engineer enters the commands: interface vlan 10, then ip address 192.168.10.2 255.255.255.0, then no shutdown. However, the interface remains down. What is the most likely cause?

A.The switch does not have any physical ports assigned to VLAN 10, so the VLAN interface is down.
B.The no shutdown command must be issued from global configuration mode, not interface configuration mode.
C.The IP address is incorrectly configured because the subnet mask should be in CIDR notation.
D.VLAN 10 has not been created on the switch.
AnswerA

A VLAN interface (SVI) remains in a down state until the VLAN is active, which requires at least one physical port to be up and assigned to that VLAN, or the VLAN to be manually activated. Without an active port in VLAN 10, the SVI cannot come up. The engineer must assign an access port to VLAN 10 and ensure it is connected and up.

Why this answer

A VLAN interface (SVI) on a Cisco switch remains down until the VLAN is active, which requires at least one physical port to be up and assigned to that VLAN. Simply creating the SVI and assigning an IP address is not enough. The engineer must assign an access port to VLAN 10 and ensure it is operational to bring the SVI up.

Exam trap

The trap here is assuming that configuring an SVI is sufficient for it to come up, ignoring the dependency on active physical ports in the VLAN.

244
MCQeasy

A developer is writing a Python script to iterate over a list of server hostnames. Which loop structure is most appropriate to process each hostname in the list?

A.for i, hostname in enumerate(hostnames): print(hostname)
B.while len(hostnames) > 0: print(hostnames.pop())
C.for i in range(len(hostnames)): print(hostnames[i])
D.for hostname in hostnames: print(hostname)
AnswerD

A for loop iterates directly over the hostnames list, binding each element to the loop variable in turn, which is the idiomatic structure for processing every item in a sequence. It satisfies the requirement to process each hostname without manual index management.

Why this answer

The 'for item in list' loop iterates directly over each element, making it the simplest and most readable for processing each hostname.

245
Multi-Selecthard

Which THREE are benefits of using YANG as a data modeling language for network automation? (Select exactly 3.)

Select 3 answers
A.Enables validation of data constraints before applying changes
B.Allows direct execution of CLI commands on any device
C.Provides a standard way to define configuration and state data
D.Supports multiple serialization formats like JSON and XML
E.Promotes interoperability between different vendor devices
AnswersA, C, E

Why this answer

YANG (RFC 6020/7950) allows you to define data constraints such as ranges, mandatory elements, and type restrictions directly in the model. When you attempt to apply configuration via NETCONF or RESTCONF, the server validates the data against these constraints before committing, preventing invalid changes from being applied.

Exam trap

Cisco often tests the distinction between the data modeling language (YANG) and the transport protocols (NETCONF/RESTCONF) or serialization formats (JSON/XML), so the trap here is confusing the benefits of the model itself with the features of the protocols that use it.

246
MCQeasy

When using the Meraki Dashboard API, what HTTP header is used to pass the API key?

A.API-Key: <key>
B.X-Cisco-Meraki-API-Key: <key>
C.Authorization: Bearer <key>
D.Meraki-API-Key: <key>
AnswerB

The Meraki Dashboard API authenticates each request by placing the API key in the X-Cisco-Meraki-API-Key request header. This satisfies the stem's requirement, since the key is passed as a custom HTTP header rather than a query string or bearer token.

Why this answer

Meraki requires the API key in the X-Cisco-Meraki-API-Key header.

247
MCQmedium

A developer wants to use the Cisco Webex API to send a message to a specific person by email. Which parameter should be used in the POST /v1/messages request?

A.personId
B.toPersonEmail
C.recipientEmail
D.roomId
AnswerB

The Webex messages endpoint accepts toPersonEmail to address a recipient directly by their email address. This satisfies the stem's requirement to send a message to a specific person identified by email, rather than by person ID or room ID.

Why this answer

To send a message to a person, use the toPersonEmail parameter instead of roomId.

248
MCQeasy

Which of the following is a private IPv4 address range as defined by RFC 1918?

A.192.167.0.0/16
B.169.254.0.0/16
C.10.0.0.0/8
D.172.32.0.0/12
AnswerC

10.0.0.0/8 falls within the RFC 1918 private address space, alongside 172.16.0.0/12 and 192.168.0.0/16. These ranges are non-routable on the public internet, satisfying the stem's requirement for a private IPv4 range. The /8 prefix covers 10.0.0.0 through 10.255.255.255.

Why this answer

The private IPv4 ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. 169.254.0.0/16 is link-local (APIPA).

249
Multi-Selectmedium

Which TWO methods are commonly used to discover network devices in an automation environment? (Select exactly 2.)

Select 2 answers
A.Manually entering device details into a spreadsheet
B.Using SNMP to bulk-configure devices
C.Monitoring DHCP logs to lease IP addresses to new devices
D.Using LLDP or CDP to retrieve directly connected neighbor information
E.Using a centralized controller like Cisco DNA Center to query device inventory
AnswersD, E

Why this answer

LLDP (IEEE 802.1AB) and CDP (Cisco Discovery Protocol) are Layer 2 protocols that allow network devices to advertise their identity, capabilities, and directly connected neighbors. In automation environments, these protocols enable dynamic discovery of the network topology without manual intervention, making them essential for automated inventory and mapping.

Exam trap

Cisco often tests the distinction between discovery protocols (LLDP/CDP) and management protocols (SNMP), so candidates may mistakenly think SNMP is used for discovery when it is actually used for reading MIBs after discovery is complete.

250
MCQeasy

A network engineer is writing a Python script to interact with Cisco DNA Center. After successfully authenticating and receiving a token, what header must be included in subsequent API requests?

A.In a custom header
B.In the URL query string
C.In the request body
D.In the Authorization header as Bearer
AnswerD

DNA Center issues a token after authentication, and subsequent calls must present it as a Bearer credential in the Authorization header. This OAuth-style scheme lets the controller validate the caller's identity per request, satisfying the stem's requirement for the header included after successful token retrieval.

Why this answer

Cisco DNA Center uses token-based authentication following the OAuth 2.0 framework. After obtaining a token via the /dna/system/api/v1/auth/token endpoint, the token must be included in the Authorization header using the Bearer scheme (e.g., 'Authorization: Bearer <token>') for all subsequent API requests to prove the client's identity and authorization.

Exam trap

Cisco often tests the distinction between authentication (getting the token) and authorization (using the token), and the trap here is that candidates might think the token is sent in the request body or a custom header because they confuse it with API keys or session cookies, but the correct standard is the Authorization header with Bearer.

How to eliminate wrong answers

Option A is wrong because while you can technically place the token in a custom header, Cisco DNA Center's API specification explicitly requires the token in the Authorization header; using a custom header would result in a 401 Unauthorized error. Option B is wrong because passing the token in the URL query string is insecure (it can be logged, cached, or exposed in browser history) and is not supported by Cisco DNA Center's REST API design. Option C is wrong because the token is not sent in the request body; the body is reserved for payload data (e.g., JSON parameters for creating a site or device), and placing the token there would violate the standard HTTP authentication mechanism.

251
Multi-Selectmedium

A developer is designing a Python script that interacts with a REST API. The script must handle common HTTP methods appropriately. Which TWO of the following statements correctly describe the use of HTTP methods in RESTful APIs? (Choose two.)

Select 2 answers
A.GET requests should be idempotent and safe, meaning they do not modify server state.
B.POST requests are idempotent, so sending the same POST request multiple times has the same effect as sending it once.
C.PATCH requests must always be idempotent and safe.
D.PUT requests are idempotent and are used to update or replace a resource entirely.
E.DELETE requests are not idempotent because deleting a resource twice will cause an error the second time.
AnswersA, D

In REST, GET is defined as a safe and idempotent method. Safe means it does not alter server state, and idempotent means multiple identical requests have the same effect as a single one. This is why GET is used for retrieving data without side effects, and clients can cache or retry GET requests without concern for unintended changes.

Why this answer

In REST, GET is safe and idempotent, and PUT is idempotent and used for full updates or replacements. POST is neither safe nor idempotent, DELETE is idempotent despite possible error responses, and PATCH is not guaranteed to be idempotent or safe. Understanding these properties helps developers choose the correct method and handle retries appropriately.

Exam trap

The trap here is assuming that all methods that modify state are non-idempotent, or that DELETE is not idempotent because it might return an error on subsequent calls.

252
MCQmedium

A Kubernetes pod runs two containers that need to share a filesystem. Which volume type should be used to enable file sharing between the containers within the same pod?

A.configMap
B.hostPath
C.persistentVolumeClaim
D.emptyDir
AnswerD

emptyDir volumes are created when a pod is assigned to a node and exist for that pod's lifetime, shared by all containers within it. Because both containers mount the same emptyDir, they read and write the same filesystem, satisfying the requirement for intra-pod file sharing.

Why this answer

An `emptyDir` volume is created when a pod is assigned to a node and exists for the lifetime of that pod. All containers in the pod can mount the same emptyDir at different paths and read/write the same files, making it the canonical choice for intra-pod file sharing. It is deleted when the pod is removed.

Exam trap

The trap is selecting persistentVolumeClaim because it sounds more robust — candidates overlook that the question specifies containers within the same pod, where emptyDir is the idiomatic and lifecycle-appropriate choice.

How to eliminate wrong answers

Option A is wrong because a configMap volume is read-only and designed to inject configuration data (key-value pairs or files) into containers — it cannot serve as a shared writable filesystem. Option B is wrong because hostPath mounts a directory from the node's filesystem, which ties the pod to a specific node and is not scoped to the pod's lifecycle; it is also a security risk and not intended for inter-container sharing. Option C is wrong because a persistentVolumeClaim provides durable storage that outlives the pod and is typically used for stateful workloads — it works for sharing but is overkill and not the intended answer when the question specifies containers within the same pod needing a shared filesystem.

253
MCQmedium

A network administrator is tasked with automating the deployment of a new VLAN configuration across a fabric of Cisco ACI switches. Which automation tool is best suited for interacting with the APIC REST API?

A.Bash scripting with curl
B.Chef
C.Puppet
D.Ansible
AnswerD

Ansible provides a native Cisco ACI module that interacts directly with the APIC REST API, letting the administrator declaratively push VLAN configuration across the fabric. It satisfies the automation requirement without bespoke scripting, unlike manual CLI or generic tools lacking ACI-aware modules.

Why this answer

Ansible is the best-suited tool because it provides a dedicated module (cisco.aci.aci_rest) that directly interacts with the APIC REST API, allowing declarative automation of VLAN and other ACI configurations. Unlike generic scripting, Ansible abstracts the HTTP requests and handles idempotency, authentication, and error handling natively for the ACI fabric.

Exam trap

Cisco often tests the misconception that any scripting tool (like Bash with curl) is sufficient for automation, but the key is choosing a tool with native, purpose-built modules for the specific API, not just the ability to make HTTP requests.

How to eliminate wrong answers

Option A is wrong because Bash scripting with curl is a low-level, manual approach that requires writing custom code for every API call, lacks idempotency, and does not provide the structured, reusable automation framework needed for consistent ACI deployments. Option B is wrong because Chef is a configuration management tool designed for node-based infrastructure (e.g., servers) and does not have native modules or resources for interacting with the Cisco APIC REST API; it would require extensive custom scripting. Option C is wrong because Puppet, like Chef, is primarily a configuration management tool for server nodes and lacks built-in support for the ACI APIC REST API, making it inefficient for automating network fabric configurations.

254
Multi-Selecthard

Which TWO statements about REST API design best practices are correct?

Select 2 answers
A.API versioning should be implemented using query parameters only
B.HTTP PUT method should be used for partial updates to a resource
C.Resources should be represented using nouns in the URI
D.Responses should return only HTTP status codes without a body
E.HTTP verbs should describe the action performed on the resource
AnswersC, E

REST treats everything as a resource, so URIs should name those resources with nouns (for example, /orders/42) rather than verbs or actions. The HTTP method then conveys the operation, keeping the interface uniform and predictable.

Why this answer

Option C is correct because REST best practice dictates that URIs identify resources, not actions, so they should use nouns (e.g., /users/123) rather than verbs like /getUser. Option E is correct because in REST the HTTP method itself conveys the action on the resource — GET retrieves, POST creates, PUT replaces, PATCH partially updates, and DELETE removes — keeping the URI action-free. Option A is wrong because versioning is commonly done via URI path (e.g., /v1/users), custom media types, or headers, not query parameters only.

Option B is wrong because PUT is meant for full resource replacement, while PATCH is the correct method for partial updates. Option D is wrong because REST responses typically include a representation (JSON/XML) in the body along with the status code, not just a bare status code.

Exam trap

Cisco often tests the distinction between PUT (full replacement) and PATCH (partial update), and the trap here is that candidates mistakenly think PUT can be used for partial updates because they overlook the idempotent, full-replacement semantics defined in RFC 7231.

255
MCQeasy

Which Cisco DNA Center API is used to retrieve a list of network devices?

A.GET /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/topology
C.GET /dna/intent/api/v1/issue
D.GET /dna/intent/api/v1/site
AnswerA

The GET method against /dna/intent/api/v1/network-device queries Cisco DNA Center's Intent API inventory collection, returning the full device list as JSON. This satisfies the stem's requirement to retrieve, rather than modify, network devices, since GET is the read-only HTTP verb mapped to that resource.

Why this answer

The Cisco DNA Center Intent API endpoint GET /dna/intent/api/v1/network-device is specifically designed to return a list of all network devices managed by DNA Center. It provides details such as device ID, hostname, management IP, platform, software version, and reachability status. This is the canonical endpoint for device inventory retrieval, making it the correct choice.

Exam trap

The trap here is confusing the network-device endpoint with other intent APIs like topology or site, which also return network-related data but not a simple device list. Candidates might assume any endpoint under /dna/intent/api/v1/ returns devices, but each has a specific purpose.

How to eliminate wrong answers

Option B is wrong because GET /dna/intent/api/v1/topology returns network topology information (nodes and links), not a device list. Option C is wrong because GET /dna/intent/api/v1/issue retrieves issues or alarms, not device inventory. Option D is wrong because GET /dna/intent/api/v1/site returns site hierarchy information, not a list of devices.

256
MCQeasy

Which layer of the OSI model uses MAC addresses to deliver frames within the same network segment?

A.Layer 2 (Data Link)
B.Layer 1 (Physical)
C.Layer 3 (Network)
D.Layer 4 (Transport)
AnswerA

MAC addressing and frame delivery occur at the Data Link layer, which encapsulates packets into frames and uses hardware addresses to forward them between nodes on the same segment. Layer 2 therefore satisfies the stem's requirement for intra-segment delivery, unlike Layer 3's logical IP routing.

Why this answer

Layer 2 (Data Link) uses MAC addresses for local delivery.

257
MCQeasy

What is the default transport protocol for NETCONF sessions?

A.HTTP
B.SSH
C.TLS
D.SNMP
AnswerB

NETCONF uses SSH as its default transport, running over TCP port 830 to provide an encrypted, authenticated channel for configuration and state retrieval. TLS is optional rather than default, so SSH satisfies the stem's requirement.

Why this answer

NETCONF (Network Configuration Protocol) uses SSH as its default transport protocol, as specified in RFC 6242. SSH provides the required secure, authenticated, and encrypted channel for NETCONF sessions, ensuring confidentiality and integrity of configuration data exchanged between the client and server.

Exam trap

Cisco often tests the distinction between 'default' and 'optional' transports, so the trap here is that candidates may confuse TLS (which is supported but not default) with the mandatory SSH transport, or assume HTTP is used because NETCONF is XML-based and HTTP is commonly associated with XML APIs.

How to eliminate wrong answers

Option A is wrong because HTTP is not a transport protocol for NETCONF; NETCONF over HTTP is not defined in any standard, and HTTP lacks the built-in encryption and authentication required for secure network device configuration. Option C is wrong because TLS is an optional transport for NETCONF (as per RFC 7589), not the default; the default remains SSH, and TLS is used only when explicitly configured. Option D is wrong because SNMP is a separate protocol for network management and monitoring, not a transport for NETCONF; SNMP uses UDP or TCP, but it does not carry NETCONF messages.

258
MCQmedium

A developer is writing a web application and needs to prevent SQL injection attacks. Which coding practice is most effective?

A.Validate input with regex to allow only alphanumeric characters
B.Use parameterized queries with prepared statements
C.Use stored procedures exclusively
D.Escape all user input with htmlspecialchars
AnswerB

Parameterised queries send SQL code and user-supplied values separately, so input is bound as data rather than parsed as executable SQL. This structurally prevents injection, unlike escaping or validation, which can be bypassed by crafted payloads.

Why this answer

Parameterized queries with prepared statements separate SQL code from user-supplied data, so the database treats input as data rather than executable SQL. This prevents attackers from injecting SQL syntax regardless of the input's content. It is the most robust and recommended defense against SQL injection.

Exam trap

200-901 often tests the difference between input validation and parameterization — candidates pick regex validation or escaping because they sound secure, but only parameterized queries eliminate the code/data mixing that enables SQL injection.

How to eliminate wrong answers

Option A is wrong because regex whitelisting is brittle and context-dependent; it can break legitimate input and may still allow injection through numeric fields or encoded characters, and it does not address the root cause of mixing code and data. Option C is wrong because stored procedures can still be vulnerable if they build dynamic SQL using string concatenation with user input; they are not inherently safe. Option D is wrong because htmlspecialchars is a PHP function for escaping HTML output to prevent XSS, not SQL injection; it does not escape SQL metacharacters and is irrelevant to database queries.

259
Multi-Selectmedium

Which THREE of the following are key characteristics of a RESTful API? (Choose three.)

Select 3 answers
A.Resource-based URLs
B.Stateless communication
C.Uses SOAP protocol
D.Relies on session cookies for state
E.Uses standard HTTP methods (GET, POST, PUT, DELETE)
AnswersA, B, E

Resource-based URLs expose each entity as a distinct addressable endpoint, so clients manipulate state through standard HTTP verbs rather than bespoke method names. This satisfies REST's uniform-interface constraint, letting the API scale statelessly and cache predictably across distributed callers.

Why this answer

Option A (Resource-based URLs) is correct because REST models everything as a resource identified by a URI, such as /users/123, so each endpoint represents a distinct resource rather than an action. Option B (Stateless communication) is correct because each REST request must contain all information needed to process it, and the server does not retain client session state between requests. Option E (Uses standard HTTP methods (GET, POST, PUT, DELETE)) is correct because REST leverages HTTP verbs to perform CRUD operations on resources, with GET for retrieval, POST for creation, PUT for update/replace, and DELETE for removal.

Option C (Uses SOAP protocol) is incorrect because SOAP is a separate XML-based messaging protocol, whereas REST is an architectural style that typically uses HTTP and can return JSON or XML. Option D (Relies on session cookies for state) is incorrect because REST is stateless and does not depend on server-side sessions or cookies to maintain client state.

Exam trap

Cisco often tests the distinction between REST and SOAP, and the trap here is that candidates may confuse REST's statelessness with the need for session cookies (stateful behavior) or incorrectly associate REST with SOAP due to both being web service technologies.

260
MCQeasy

A developer is writing a Python script that interacts with a REST API. The API requires authentication using a token. Which HTTP header should the developer include in the request to pass the token?

A.Cookie: session=<token>
B.X-API-Key: <token>
C.Authorization: Bearer <token>
D.Authentication: Token <token>
AnswerC

The Authorization header with the Bearer scheme is the standard way to transmit a token for OAuth 2.0 and many REST APIs. It clearly indicates the token type and is widely supported. Using this header ensures the API can validate the token and grant access to the requested resource.

Why this answer

For REST API authentication using a token, the standard method is to include the token in the Authorization header with the Bearer scheme. This is defined in RFC 6750 for OAuth 2.0 Bearer Tokens. Other headers like X-API-Key or custom headers may be used for API keys, but when the requirement is a token, Bearer is the correct choice.

Cookies are for browser sessions.

Exam trap

The trap here is confusing API key authentication with token-based authentication, leading to the use of X-API-Key instead of the standard Authorization header.

261
MCQmedium

A developer is building a container image for a Python application using Docker. The Dockerfile contains several instructions, including a RUN pip install command that downloads dependencies. The developer wants to reduce the final image size and improve build cache efficiency. Which Dockerfile instruction should be used to combine multiple commands and avoid leaving unnecessary files in the image layer?

A.Use a single RUN instruction with commands chained using && and clean up temporary files in the same RUN.
B.Use the COPY instruction to copy a pre-built virtual environment into the image.
C.Use multiple RUN instructions, one for each command, to make the Dockerfile more readable.
D.Use the ADD instruction to download and extract dependencies automatically.
AnswerA

Chaining commands with && in a single RUN creates one layer and allows cleanup of temporary files in that same layer, reducing image size. Each RUN creates a new layer, so separate commands leave intermediate files. This is a best practice for minimizing layers and cache efficiency.

Why this answer

Combining commands into a single RUN instruction with && and cleaning up temporary files in the same layer minimizes the number of layers and prevents leftover files from persisting in the image. This approach directly reduces image size and improves build cache utilization by keeping related operations together.

Exam trap

The trap here is assuming that more RUN instructions improve readability without considering the layer size penalty.

262
MCQeasy

A developer is using Git to contribute to a shared repository. After making several commits on a local feature branch, the developer wants to integrate the latest changes from the remote main branch into the feature branch while keeping a linear history. Which Git command should be used?

A.git rebase main
B.git merge main
C.git pull origin main
D.git cherry-pick main
AnswerA

git rebase main replays the commits from the current feature branch on top of the latest main, resulting in a linear history without a merge commit. This is the standard way to incorporate upstream changes while keeping a clean, linear commit sequence. It rewrites the feature branch commits, which is acceptable for local branches that have not been shared.

Why this answer

To integrate upstream changes while keeping a linear history, the feature branch commits must be replayed on top of the updated main. git rebase main performs exactly this operation, moving the branch pointer and rewriting commits so that the history appears as if the feature was developed after the latest main. Merging or pulling would create a merge commit, and cherry-pick does not apply the full set of changes.

Exam trap

The trap here is confusing merge and rebase: merge preserves branch topology but adds a merge commit, while rebase rewrites commits to achieve a linear sequence.

263
Multi-Selectmedium

A security review of a CI/CD pipeline finds that build jobs run with credentials that have far more privilege than needed, and that the same long-lived token is reused across repositories. Which TWO changes reduce the blast radius if a pipeline credential is compromised? (Choose two.)

Select 2 answers
A.Run all pipeline jobs on self-hosted runners located inside the corporate network.
B.Store the shared token in the CI platform's encrypted secret store instead of in the repository.
C.Grant the pipeline identity the minimum permissions required for its deployment tasks.
D.Enable verbose debug logging for all pipeline jobs so credential usage can be audited after an incident.
E.Replace the shared long-lived token with short-lived credentials issued per job by the CI platform's identity integration.
AnswersC, E

Least privilege limits what an attacker can do with a stolen credential, even inside its validity window. If the identity can only push to one registry namespace or update one service, compromise does not yield broad access to other repositories or cloud resources, which is the core of reducing blast radius in this scenario.

Why this answer

Blast radius is governed by how much a credential can do and how long it remains valid. Issuing short-lived, per-job credentials and constraining the pipeline identity to least privilege both directly reduce the impact of theft. Encryption at rest, verbose logging, and runner placement improve hygiene or visibility but leave the credential's power and lifetime intact, so they do not shrink the damage an attacker can inflict.

Exam trap

The trap here is equating safer secret storage with reduced privilege, when storage location does not change what a stolen credential can access.

264
Multi-Selecthard

Which THREE of the following are valid NETCONF operations? (Choose three.)

Select 3 answers
A.<edit-config>
B.<rpc>
C.<get-config>
D.<commit>
E.<close-session>
AnswersA, C, E

`<edit-config>` is a standard NETCONF operation, defined in RFC 6241, that loads configuration data into a target datastore such as running or candidate. It satisfies the stem's requirement for valid NETCONF operations, unlike RESTCONF-specific verbs or SNMP primitives, making it one of the three correct choices.

Why this answer

<edit-config> (A) is a valid NETCONF operation defined in RFC 6241; it loads all or part of a configuration into the specified target datastore (running, candidate, or startup) and is one of the core base protocol operations. <get-config> (C) is also a base NETCONF operation from RFC 6241; it retrieves all or part of a specified configuration datastore and is distinct from <get>, which returns both state and configuration data. <close-session> (E) is a valid NETCONF session-level operation from RFC 6241 that gracefully terminates the NETCONF session and releases any locks and resources held by the client. <rpc> (B) is not an operation but the transport-framing wrapper element that carries every NETCONF operation, and <commit> (D) is not a standalone NETCONF operation; committing the candidate datastore is performed via the <commit> element inside an <rpc> as part of the candidate capability, not as a base operation itself.

265
MCQeasy

A Python script using the Cisco Meraki SDK fails with 'APIError: 429 Too Many Requests'. What action should the developer take?

A.Increase the timeout value
B.Change the HTTP method to POST
C.Use a different API key
D.Add a retry mechanism with exponential backoff
AnswerD

Standard best practice to handle rate limiting.

Why this answer

The HTTP 429 status code indicates rate limiting has been exceeded. The Meraki API enforces rate limits to protect its infrastructure, and the SDK's built-in retry mechanism with exponential backoff is the correct way to handle this, as it automatically waits increasing intervals between retries, respecting the Retry-After header if present.

Exam trap

Cisco often tests the distinction between handling rate limiting (429) versus handling request timeouts (408/504), so candidates mistakenly choose to increase the timeout value instead of implementing retry logic with backoff.

How to eliminate wrong answers

Option A is wrong because increasing the timeout value only extends how long the script waits for a single request to complete; it does not address the rate limit being exceeded. Option B is wrong because changing the HTTP method to POST does not affect rate limiting; the 429 error is about request frequency, not the method used. Option C is wrong because using a different API key does not resolve the rate limit issue; the new key would also be subject to the same rate limits, and the problem is the request rate, not authentication.

266
MCQmedium

Which IP address is a valid host address in the 192.168.1.0/24 network?

A.192.168.1.128
B.192.168.2.1
C.192.168.1.255
D.192.168.1.0
AnswerA

192.168.1.128 falls within the 192.168.1.0/24 subnet range, satisfying the network constraint. Unlike the network address (192.168.1.0) or broadcast address (192.168.1.255), it is assignable to a host device. The /24 mask leaves 254 usable host addresses, and .128 sits comfortably inside that pool.

Why this answer

In 192.168.1.0/24, usable host addresses range from 192.168.1.1 through 192.168.1.254. The address 192.168.1.128 falls within this range and is not the network or broadcast address, so it is a valid host address. It is a normal unicast address that can be assigned to a device.

Exam trap

The trap is forgetting that the first and last addresses in any subnet are reserved — candidates often pick the broadcast (.255) or network (.0) address as a valid host.

How to eliminate wrong answers

Option B is wrong because 192.168.2.1 belongs to a different subnet (192.168.2.0/24) and is outside the 192.168.1.0/24 range entirely. Option C is wrong because 192.168.1.255 is the directed broadcast address for the /24 network and cannot be assigned to a host. Option D is wrong because 192.168.1.0 is the network address that identifies the subnet itself and is reserved, not assignable to a host.

267
MCQmedium

A developer runs a Python script that calls a REST API on a remote server. The script hangs indefinitely with no response. The developer opens a terminal and runs `curl -v https://api.example.com/status`. The output shows that the TCP three-way handshake completes, but the TLS handshake never starts. Which of the following is the most likely cause?

A.The server is not listening on port 443, so the TCP handshake should have failed.
B.A network device is intercepting the connection and terminating it before TLS negotiation.
C.A firewall is blocking outbound TCP port 80.
D.The client is using an outdated version of TLS that the server does not support.
AnswerB

When the TCP handshake completes but the TLS handshake never begins, an inline device such as a firewall, proxy, or intrusion prevention system may be accepting the TCP connection on behalf of the server and then dropping or resetting it before TLS negotiation. This behavior is typical of a device performing TCP proxy or deep packet inspection without proper TLS passthrough.

Why this answer

The key symptom is that the TCP three-way handshake succeeds but the TLS handshake never initiates. This indicates that something between the client and server is completing the TCP connection and then preventing the TLS negotiation from starting. A transparent proxy or firewall that terminates TCP connections without forwarding them can cause this exact behavior.

The other options either contradict the observed TCP success or describe failures that would occur after TLS begins.

Exam trap

The trap here is assuming that a successful TCP handshake guarantees the application-layer protocol will proceed, when an inline device can intercept and terminate the connection after TCP establishment.

268
Multi-Selecthard

Which three statements are true about the Cisco Catalyst Center (formerly DNA Center) intent API? (Choose three.)

Select 3 answers
A.The base URL for the API includes the Catalyst Center hostname and port.
B.Authentication is done by sending a POST request to /dna/system/api/v1/auth/token with credentials.
C.The API uses only GET and POST methods.
D.It uses RESTful principles and returns JSON responses.
E.It requires an API key passed in the X-Cisco-Meraki-API-Key header.
AnswersA, B, D

Catalyst Center’s intent API is reached over HTTPS at a host-specific endpoint, so the base URL must combine the appliance’s hostname with its port, satisfying the stem’s requirement for a true statement about API structure. Requests target that address directly, making hostname and port integral rather than optional.

Why this answer

Option A is correct because every Catalyst Center intent API call is built on a base URL of the form https://<Catalyst-Center-hostname>:<port>, typically port 443 for HTTPS, followed by the service path such as /dna/intent/api/v1. Option B is correct because authentication is performed by sending a POST request with the username and password in a JSON body to /dna/system/api/v1/auth/token, which returns a JWT token used as a Bearer token in the X-Auth-Token header for subsequent calls. Option D is correct because the intent API follows RESTful principles, using resource-oriented URIs and standard HTTP verbs, and returns responses formatted as JSON.

Option C is incorrect because the API also uses PUT and DELETE methods (for example, to update or remove resources), not only GET and POST. Option E is incorrect because the X-Cisco-Meraki-API-Key header belongs to the Cisco Meraki Dashboard API, not to Catalyst Center, which relies on token-based authentication.

Exam trap

Cisco often tests the distinction between Catalyst Center and Meraki APIs, so the trap here is confusing the authentication method (token-based vs. API key) and assuming only GET/POST are used, when in fact RESTful APIs support full CRUD operations.

269
MCQeasy

A developer is working on a Python script that performs CRUD operations on devices via a REST API. Which HTTP method should be used to update an existing device's configuration partially?

A.PATCH
B.POST
C.DELETE
D.PUT
AnswerA

PATCH applies a partial modification to an existing resource, sending only the changed fields. It satisfies the constraint of updating a device's configuration partially, whereas PUT would replace the entire representation and require the full payload.

Why this answer

PATCH is the correct HTTP method for partial updates to an existing resource. Unlike PUT, which replaces the entire resource, PATCH applies a set of changes (a patch document) to the resource, modifying only the specified fields. In the context of a REST API for device configuration, using PATCH allows the developer to update a subset of configuration parameters without affecting others.

Exam trap

The trap here is confusing PUT with PATCH: candidates often think PUT can be used for any update, but PUT replaces the entire resource, while PATCH is for partial modifications.

How to eliminate wrong answers

Option B is wrong because POST is used to create new resources or submit data to be processed, not for partial updates to an existing resource. Option C is wrong because DELETE is used to remove a resource, not to update it. Option D is wrong because PUT is used to replace the entire resource with the provided representation; using PUT for a partial update would overwrite unspecified fields, potentially causing data loss.

270
MCQeasy

An administrator wants to retrieve a list of all network devices from Cisco DNA Center using the REST API. Which authentication method must be used first to obtain a token?

A.Basic Authentication to /dna/system/api/v1/auth/token
B.API key in the X-Cisco-Meraki-API-Key header
C.Bearer token passed directly in the first request
D.OAuth 2.0 with client credentials grant
AnswerA

Basic Authentication encodes the administrator's credentials and posts them to /dna/system/api/v1/auth/token, which returns a time-limited token. Cisco DNA Center requires this token exchange before any other API call, satisfying the stem's constraint that a token must be obtained first.

Why this answer

Cisco DNA Center uses Basic Authentication to authenticate to the /dna/system/api/v1/auth/token endpoint, which returns a token for subsequent API calls.

271
Multi-Selectmedium

A developer is writing a Python script that will authenticate to a Cisco DNA Center controller and then call multiple REST API endpoints. The script must handle authentication securely and manage the token lifecycle. Which two practices should the developer follow? (Choose two.)

Select 2 answers
A.Store the username and password in environment variables or a secrets manager rather than in the script.
B.Disable TLS certificate verification to simplify HTTPS calls to the controller.
C.Reuse the authentication token for all subsequent API calls until it expires, then obtain a new one.
D.Call the authentication endpoint before every API request to guarantee a fresh token.
E.Hardcode the token in the script to avoid repeated authentication calls during development.
AnswersA, C

Credentials embedded in source code can leak through version control, logs, or shared repositories. Reading them from environment variables or a secrets manager keeps them out of the codebase and supports rotation. This is a foundational secure coding practice for API automation.

Why this answer

Secure automation requires protecting credentials and managing tokens efficiently. Storing secrets outside the code prevents leaks, and reusing a valid token until expiration avoids unnecessary authentication calls. The other options either weaken security or add avoidable overhead that can trigger rate limits.

Exam trap

The trap here is treating authentication as something to repeat for every call, when tokens are meant to be cached and reused until they expire.

272
MCQhard

Refer to the exhibit. A developer sends a PUT request to the RESTCONF endpoint with the above JSON payload. The device already has interface GigabitEthernet1/0/1 configured with IP address 10.10.10.1/24. What is the expected outcome?

A.The request fails because the interface already exists.
B.The request creates a new interface with the same configuration.
C.The request fails because the JSON is malformed.
D.The request succeeds and the interface configuration remains unchanged.
AnswerD

The PUT replaces the target resource with the supplied payload, so the interface's existing IP address is overwritten by whatever the JSON body specifies. If the payload omits the address or matches the current 10.10.10.1/24 value, the configuration is effectively unchanged and the request returns a success status.

Why this answer

D is correct because the PUT request to the RESTCONF endpoint with the provided JSON payload is an idempotent operation. Since the interface GigabitEthernet1/0/1 already exists with the exact same configuration (IP address 10.10.10.1/24), the PUT request effectively replaces the resource with the same data, resulting in no change. RESTCONF uses the HTTP PUT method to create or replace a resource, and if the resource already exists and the payload matches, the operation succeeds without modification.

Exam trap

Cisco often tests the misconception that PUT will fail or create a duplicate resource when the target already exists, but the correct behavior is that PUT replaces the resource idempotently, and if the data is identical, the configuration remains unchanged.

How to eliminate wrong answers

Option A is wrong because RESTCONF PUT is idempotent and does not fail when the resource already exists; it replaces the resource with the provided data, and if the data is identical, the configuration remains unchanged. Option B is wrong because PUT does not create a new interface when the resource already exists; it replaces the existing resource, and since the payload matches the current configuration, no new interface is created. Option C is wrong because the JSON payload is syntactically valid and correctly structured for a RESTCONF PUT request to modify an interface; there is no malformation.

273
MCQeasy

A network automation engineer needs to ensure that a Python script can securely store and retrieve API credentials for Cisco DNA Center without hardcoding them in the script. Which method is the most appropriate?

A.Embed the credentials directly in the Python script as constants.
B.Use environment variables to hold the credentials and access them via os.environ in the script.
C.Store the credentials in a YAML file that is committed to the same Git repository as the script.
D.Store the credentials in a plain text file on the local filesystem and read them at runtime.
AnswerB

Environment variables are a common and secure way to inject secrets into applications at runtime. They are not stored in the codebase and can be managed by the operating system or container orchestration. This approach keeps credentials out of source control and allows different environments to use different values.

Why this answer

Using environment variables keeps credentials out of source code and allows them to be managed securely by the deployment environment. This is a widely accepted practice for handling secrets in automation scripts. It avoids the risks of hardcoding or storing secrets in version control, and it supports different credentials per environment.

Exam trap

The trap here is assuming that storing credentials in a file within the repository is acceptable as long as it is not the main script, but version control exposure remains a critical risk.

274
Multi-Selecteasy

Which TWO are valid capabilities advertised during a NETCONF session?

Select 2 answers
A.urn:ietf:params:netconf:capability:url:1.0
B.urn:ietf:params:netconf:capability:writable-running:2.0
C.urn:ietf:params:netconf:capability:validate:2.0
D.urn:ietf:params:netconf:base:1.0
E.urn:ietf:params:netconf:capability:interleave:1.0
AnswersA, D

This is the URL capability for NETCONF.

Why this answer

The URL capability (urn:ietf:params:netconf:capability:url:1.0) is a standard NETCONF capability that allows a client to specify a URL as the source or target of operations like <copy-config> or <edit-config>. Option D is correct because urn:ietf:params:netconf:base:1.0 is the mandatory base capability that every NETCONF session must advertise, as defined in RFC 6241, indicating support for the core NETCONF protocol operations.

Exam trap

Cisco often tests the exact version numbers of NETCONF capabilities, and the trap here is that candidates assume all capabilities use version 2.0 (confusing them with YANG module revisions or other protocols), but in reality, the standard NETCONF capabilities defined in RFC 6241 are all version 1.0.

275
MCQhard

A CI/CD pipeline is configured to build a Docker image, run unit tests, and push the image to a registry. To ensure that only successfully tested images are pushed, which stage order is correct?

A.Run tests -> Build image -> Push image
B.Build image -> Push image -> Run tests
C.Push image -> Build image -> Run tests
D.Build image -> Run tests -> Push image
AnswerD

Running tests before the push gate ensures only validated artefacts reach the registry. Building first produces the image under test; executing unit tests against it then permits the push stage to publish solely on success, preventing untested images from being distributed.

Why this answer

The correct order is: build the image, run tests, then push only if tests pass. Pushing before tests could push a broken image.

276
MCQmedium

A developer needs to parse a JSON string received from a REST API into a Python dictionary. Which function should they use?

A.json.dumps()
B.json.loads()
C.json.load()
D.json.dump()
AnswerB

json.loads() deserialises a JSON-formatted string into a Python dictionary, satisfying the stem's requirement to parse an incoming REST API string. Its counterpart json.load() reads from a file object instead, so it would not work on the raw string the developer receives.

Why this answer

json.loads() converts a JSON string into a Python object (dict, list, etc.).

277
MCQhard

A developer is troubleshooting an API call to Cisco SD-WAN vManage. The request fails with HTTP 400 status and the response body: '{"error": "Bad Request", "details": "Invalid JSON: unexpected token at position 42"}'. Which tool or technique should the developer use to quickly identify the syntax error?

A.Use a JSON validator to check the request body.
B.Increase the timeout value for the HTTP request.
C.Check the API key validity in the header.
D.Review the API documentation for required fields.
AnswerA

The response pinpoints a malformed JSON token at position 42, so the request body itself is invalid. A JSON validator parses the payload and reports the exact syntax fault, letting the developer correct it before resending the vManage call.

Why this answer

The HTTP 400 status code indicates a client-side error, and the response body explicitly states 'Invalid JSON: unexpected token at position 42'. This means the request body contains malformed JSON. A JSON validator (e.g., jsonlint.com, jq, or a library like `json.loads()` in Python) will parse the JSON and pinpoint the exact syntax error (e.g., a missing comma, extra brace, or unescaped quote) at the specified position, allowing the developer to fix the request body quickly.

Exam trap

Cisco often tests the ability to map specific HTTP status codes and error messages to the correct troubleshooting tool, and the trap here is that candidates may confuse a JSON syntax error (400) with an authentication error (401/403) or a missing-field error (422), leading them to choose options like checking the API key or reviewing documentation instead of using a JSON validator.

How to eliminate wrong answers

Option B is wrong because increasing the timeout value addresses network latency or server delays, not a syntax error in the request body that causes an immediate 400 response. Option C is wrong because checking the API key validity would be relevant for a 401 Unauthorized or 403 Forbidden error, not a 400 Bad Request with a JSON parsing error. Option D is wrong because reviewing API documentation for required fields would help if the error were about missing or invalid fields (e.g., 422 Unprocessable Entity), but the error message explicitly points to a JSON syntax error, not a schema validation issue.

278
MCQmedium

A developer is writing a Python function that accepts a list of interface names and returns a dictionary mapping each interface name to the number of characters in that name. The function should also verify that the input is a list and raise a TypeError otherwise. Which approach correctly implements the described behavior?

A.def map_lengths(names): if type(names) != list: raise ValueError('names must be a list') return {n: n.__len__() for n in names}
B.def map_lengths(names): assert isinstance(names, list) return dict(zip(names, map(len, names)))
C.def map_lengths(names): return {n: len(n) for n in names}
D.def map_lengths(names): if not isinstance(names, list): raise TypeError('names must be a list') return {n: len(n) for n in names}
AnswerD

This implementation checks the input with isinstance against list and raises TypeError when the check fails, then builds the required dictionary with a comprehension. It satisfies both stated requirements: type validation that raises TypeError and a mapping of each interface name to its character length.

Why this answer

The requirement is twofold: validate that the argument is a list and raise TypeError when it is not, then return a dictionary of name to length. Only the implementation using isinstance with a TypeError raise and a dictionary comprehension satisfies both constraints in a single, correct function.

Exam trap

The trap here is treating assert or ValueError as equivalent to raising TypeError, when the exception type and runtime behavior differ.

279
MCQeasy

A developer wants to get the current user's information from the Webex API. Which endpoint should they use?

A.GET /v1/people/me
B.POST /v1/messages
C.GET /v1/webhooks
D.GET /v1/rooms
AnswerA

GET /v1/people/me returns the authenticated user's own profile, identified by the access token, so no user ID is needed. Other people endpoints require an explicit personId, making them unsuitable for retrieving the current user's information.

Why this answer

The Webex API endpoint GET /v1/people/me returns the profile information of the authenticated user, which is exactly what the developer needs. It uses the OAuth token of the current user to identify 'me'. Other endpoints serve different resources like messages, webhooks, or rooms.

Exam trap

The trap is confusing resource endpoints (messages, rooms, webhooks) with the identity endpoint; candidates might pick a familiar resource but forget that 'me' is the canonical way to get the current user.

How to eliminate wrong answers

Option B is wrong because POST /v1/messages is used to send a message to a room, not to retrieve user information. Option C is wrong because GET /v1/webhooks lists webhooks configured by the user, not the user's own profile. Option D is wrong because GET /v1/rooms lists rooms the user belongs to, not the user's identity details.

280
MCQeasy

A developer needs to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint and HTTP method should be used?

A.POST /dna/intent/api/v1/issues
B.POST /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/l2/{vlanID}
AnswerC

The `GET /dna/intent/api/v1/network-device` endpoint retrieves all network devices from Cisco DNA Center, satisfying the stem’s requirement to “retrieve a list” by using the HTTP GET method, which is idempotent and safe for read-only operations. This contrasts with POST, which would create a new resource, and DELETE, which would remove devices. The path’s `/network-device` resource collection directly maps to the requested data set.

Why this answer

The correct API to get the device list is GET /dna/intent/api/v1/network-device. Authentication is handled separately via POST /dna/system/api/v1/auth/token.

281
MCQeasy

When designing a RESTful API for a network automation tool, which status code indicates that a resource has been created successfully?

A.204 No Content
B.200 OK
C.201 Created
D.202 Accepted
AnswerC

201 Created confirms a new resource now exists at the URI returned in the Location header, satisfying the stem's requirement for successful creation. Unlike 200 OK, which merely reports general success, 201 explicitly signals that the POST persisted a new entity — the precise semantic REST expects after resource creation.

Why this answer

(201 Created). According to HTTP semantics and RESTful API best practices, a successful POST request that creates a new resource should return the 201 Created status code. This indicates that the request has been fulfilled and a new resource has been created, often with a Location header pointing to the resource's URI. 204 No Content (option A) is used for successful requests that have no response body, such as DELETE or when an update returns no content, but not for creation.

Exam trap

Cisco often tests the distinction between 201 Created and 204 No Content. A common trap is to think that 204 No Content is appropriate for creation if the API returns no body, but the standard HTTP semantics require 201 for successful resource creation. 204 should be used for operations like DELETE that do not return a body.

How to eliminate wrong answers

Option B (200 OK) is wrong because it indicates a successful request with a response body, but it is not the standard status code for resource creation; it is typically used for read operations like GET. Option C (201 Created) is wrong because, while it is the standard HTTP status code for resource creation, the question specifies that the resource has been created successfully and the correct answer is 204 No Content, which implies the response intentionally omits a body (e.g., when the API returns no representation). Option D (202 Accepted) is wrong because it indicates the request has been accepted for processing but the processing has not been completed, which is used for asynchronous operations, not for immediate successful creation.

282
MCQhard

A developer is building a Python application that consumes the Cisco Meraki Dashboard API. The application must handle rate limiting gracefully when it performs many calls in a short period. Which response should the application check to determine that it has exceeded the rate limit and must wait before retrying?

A.HTTP 403 Forbidden
B.HTTP 401 Unauthorized
C.HTTP 429 Too Many Requests
D.HTTP 503 Service Unavailable
AnswerC

The Meraki Dashboard API returns HTTP 429 when a client exceeds the allowed call rate. A well-behaved client should inspect this status, read the Retry-After header when present, and pause before retrying. Handling 429 explicitly prevents the application from hammering the API and being throttled further.

Why this answer

Meraki enforces per-organization call limits and communicates throttling with the 429 Too Many Requests status. The application should catch that status, honor any Retry-After header, and back off before retrying. Authentication and permission errors use different codes, and server outages use 503, so only 429 correctly identifies rate limiting.

Exam trap

The trap here is confusing throttling with authorization or availability failures and retrying on the wrong status code.

283
MCQmedium

A developer is writing a Python unit test for a function that makes an HTTP request to an external API. To avoid network calls during testing, the developer wants to mock the requests.get function. Which Python library is specifically designed for mocking in unit tests and is part of the standard library?

A.requests-mock
B.mock
C.pytest-mock
D.unittest.mock
AnswerD

unittest.mock is part of the Python standard library and provides a flexible framework for mocking objects and functions in unit tests. It allows patching requests.get with a mock object that returns a predefined response, eliminating network calls. The patch decorator or context manager can temporarily replace the function during the test. This is the standard approach for mocking in Python.

Why this answer

The unittest.mock module, part of the Python standard library, provides the patch function and Mock class to replace objects during tests. It can mock requests.get to return a controlled response, preventing actual network calls. This is the standard way to isolate unit tests from external dependencies without third-party libraries.

Exam trap

The trap here is confusing the third-party mock library or pytest-mock with the standard library module, but unittest.mock is the built-in solution since Python 3.3.

284
MCQmedium

A web application is vulnerable to SQL injection. Which secure coding practice should the developer implement in the code to prevent this?

A.Use parameterised queries for database access.
B.Escape all user input with htmlspecialchars.
C.Use a CAPTCHA on the login form.
AnswerA

Parameterised queries send SQL code and user-supplied values to the database as separate constructs, so input is bound as data rather than parsed as executable SQL. This neutralises injection payloads by removing the mechanism attackers rely on, directly satisfying the requirement to prevent SQL injection within the application code.

Why this answer

Using parameterised queries (prepared statements) ensures that user input is treated as data, not executable SQL code, preventing SQL injection.

285
MCQhard

A network engineer is subnetting the network 192.168.1.0/24 into subnets that each support at least 50 hosts. What subnet mask should be used?

A.255.255.255.192 (/26)
B.255.255.255.224 (/27)
C.255.255.255.240 (/28)
D.255.255.255.128 (/25)
AnswerA

A /26 mask leaves six host bits, giving 62 usable addresses, which satisfies the minimum of 50 hosts per subnet. A /27 would provide only 30 usable addresses, so 255.255.255.192 is the smallest mask that meets the requirement.

Why this answer

To support at least 50 hosts, you need 6 host bits (2^6 - 2 = 62 usable addresses). A /26 subnet mask (255.255.255.192) provides exactly 6 host bits, meeting the requirement. The original /24 network is borrowed with 2 subnet bits, yielding 4 subnets of 64 addresses each.

Exam trap

Cisco often tests the distinction between the number of host bits needed versus the number of subnet bits, and the trap here is that candidates may choose /25 because it supports more hosts, overlooking that /26 is the minimum mask that meets the 50-host requirement and is the correct answer per the question's wording.

How to eliminate wrong answers

Option B (255.255.255.224, /27) is wrong because it provides only 5 host bits (2^5 - 2 = 30 usable addresses), which is insufficient for 50 hosts. Option C (255.255.255.240, /28) is wrong because it provides only 4 host bits (2^4 - 2 = 14 usable addresses), far below the requirement. Option D (255.255.255.128, /25) is wrong because although it provides 7 host bits (126 usable addresses), it uses only 1 subnet bit, creating only 2 subnets; the question asks for subnets that each support at least 50 hosts, and while /25 meets the host count, it is not the most efficient choice and the correct answer is the smallest mask that satisfies the host requirement, which is /26.

286
MCQeasy

A developer is building a Python application that consumes the Cisco Meraki Dashboard API. The application must store the API key securely and include it on every request. Which HTTP request header should the application set to authenticate each call?

A.Authorization: Bearer <API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.Authorization: Basic <base64(API_KEY:)>
D.X-Auth-Token: <API_KEY>
AnswerB

The Meraki Dashboard API authenticates requests with a custom header named X-Cisco-Meraki-API-Key whose value is the API key generated in the dashboard. Setting this header on every call is the documented method, and it works alongside the required Content-Type and Accept headers for JSON payloads.

Why this answer

Cisco Meraki Dashboard API authentication uses a proprietary request header, X-Cisco-Meraki-API-Key, populated with a key created under the organization's dashboard profile. Unlike OAuth-based Cisco APIs that expect an Authorization Bearer token, Meraki requires this specific header on each call, and the application must also send appropriate Content-Type and Accept headers for JSON.

Exam trap

The trap here is assuming every Cisco API uses Authorization: Bearer, when Meraki specifically requires its own X-Cisco-Meraki-API-Key header instead.

287
MCQmedium

An engineer is troubleshooting an application running in a Docker container. The container is running but the application is not responding. The Dockerfile EXPOSE instruction lists port 8080, and the container was started with the command: docker run -d -p 8080:80 myapp. Which command should the engineer use to verify the application's actual listening port inside the container?

A.docker inspect <container_id>
B.docker port <container_id>
C.docker logs <container_id>
D.docker exec <container_id> netstat -tuln
AnswerD

This command executes netstat inside the running container and lists all TCP/UDP listening ports. Since the application may not be listening on the port declared in EXPOSE, checking the actual listening socket is the most direct way to identify a mismatch. It provides the ground truth needed to correct the port mapping or application configuration.

Why this answer

The application's actual listening port can differ from the EXPOSE instruction in the Dockerfile. EXPOSE is metadata and does not publish the port or dictate where the app listens. To see the real listening ports inside the container, one must execute a network inspection command inside the container's namespace, such as netstat or ss.

This reveals whether the app is bound to the expected port, helping diagnose connectivity issues.

Exam trap

The trap here is assuming that the EXPOSE instruction or the published port mapping guarantees the application is listening on that port inside the container.

288
MCQmedium

A REST API uses offset and limit parameters for pagination. If the first request returns items 0-49 with limit=50 and offset=0, how should the next request be constructed to get the next page?

A.offset=1, limit=50
B.offset=50, limit=50
C.offset=50, limit=100
D.offset=0, limit=100
AnswerB

Offset pagination advances by the page size, so the next page begins after the 50 items already retrieved. Keeping limit=50 and setting offset=50 returns items 50-99, satisfying the stem's requirement to fetch the subsequent page without overlap or gaps.

Why this answer

Pagination with offset and limit works by advancing the offset by the limit value to fetch the next set of items. The first request returned items 0-49 (offset=0, limit=50), so the next request should start at offset=50 with the same limit=50 to retrieve items 50-99. This ensures no overlap and no gaps in the data.

Exam trap

The trap here is that candidates mistakenly think offset should be incremented by 1 (like a page number) rather than by the limit value, leading them to choose offset=1 instead of offset=50.

How to eliminate wrong answers

Option A is wrong because offset=1 would skip item 0 and start at item 1, causing a gap and missing item 0 from the second page. Option C is wrong because offset=50 with limit=100 would retrieve items 50-149, which is not the correct next page size (should be 50 items) and could exceed the intended page size. Option D is wrong because offset=0 with limit=100 would retrieve items 0-99, which includes the already-fetched first page and changes the page size, leading to duplicate data.

289
MCQhard

A development team is using Docker Compose to run a multi-container application. They need to ensure that the web service can resolve the hostname 'db' to the database container's IP address. Which network configuration in the docker-compose.yml file achieves this?

A.Use the 'links' directive to link the web service to the db service.
B.Publish the database port on the host and use 'host.docker.internal' as the hostname.
C.Define both services under the same custom network.
D.Set the 'network_mode' of the web service to 'service:db'.
AnswerC

When services are attached to the same user-defined bridge network in Docker Compose, Docker's embedded DNS server automatically resolves service names to their container IPs. This allows the web service to connect to 'db' by hostname without manual linking or IP management. It is the recommended and simplest approach for service discovery in Compose.

Why this answer

Docker Compose automatically creates a default network for the application, and all services join it unless configured otherwise. On a user-defined bridge network, Docker provides automatic DNS resolution so that service names become valid hostnames. Therefore, ensuring both the web and db services are on the same custom network allows the web service to connect to 'db' by its service name, which is the cleanest and most reliable method.

Exam trap

The trap here is thinking that the legacy 'links' directive is required for service name resolution, when modern Docker Compose uses shared networks and embedded DNS instead.

290
MCQeasy

Which Docker networking mode provides the most isolation by not connecting the container to any network?

A.overlay
B.bridge
C.none
D.host
AnswerC

The none network mode attaches no network interface beyond loopback, so the container cannot reach other containers or external hosts. This delivers the strongest isolation, satisfying the requirement of connecting to no network at all.

Why this answer

The `none` networking mode in Docker creates a container with no network interfaces except the loopback device, providing the highest level of network isolation. This means the container cannot send or receive any external traffic, making it ideal for security-sensitive workloads that require complete network disconnection.

Exam trap

Cisco often tests the misconception that 'none' means no network at all (including loopback), but the container still has a loopback interface; the trap is that candidates confuse 'none' with 'host' or assume bridge provides stronger isolation than it actually does.

How to eliminate wrong answers

Option A is wrong because the overlay network mode creates a distributed network across multiple Docker hosts, enabling container-to-container communication across nodes, which does not provide isolation from external networks. Option B is wrong because the bridge network mode (default) connects containers to a private internal network and provides NAT-based outbound connectivity, allowing external traffic through port mapping. Option D is wrong because the host network mode removes network isolation entirely by sharing the host's network stack, giving the container direct access to all host network interfaces.

291
MCQeasy

A developer is configuring a new application server and needs to allow HTTP traffic from web clients. Which port should be opened on the firewall to permit standard unencrypted HTTP traffic?

A.Port 80
B.Port 22
C.Port 53
D.Port 443
AnswerA

Port 80 is the default port for HTTP (Hypertext Transfer Protocol) used for unencrypted web traffic. Web servers listen on port 80 for standard HTTP requests. Opening this port on the firewall allows clients to access web content over HTTP, matching the requirement.

Why this answer

HTTP by default uses TCP port 80 for unencrypted communication. When a client makes an HTTP request to a web server, it connects to port 80 unless another port is specified. Therefore, to allow standard HTTP traffic, the firewall must permit inbound connections on port 80.

Exam trap

The trap here is mixing up port 80 (HTTP) with port 443 (HTTPS) or other common ports like 22 (SSH) and 53 (DNS).

292
MCQmedium

A developer clones a shared repository and creates a feature branch, but a teammate pushes a commit to the main branch that conflicts with local edits. The developer wants to bring those upstream changes into the feature branch and resolve conflicts before opening a pull request. Which Git operation should be used?

A.git stash pop after fetching main
B.git merge main while the feature branch is checked out
C.git revert main while the feature branch is checked out
D.git reset --hard main while the feature branch is checked out
AnswerB

Running merge with the feature branch checked out integrates the commits from main into the current branch and leaves the feature branch history intact. Conflicts are surfaced in the working tree for the developer to resolve and commit, and the pull request then reflects the merged state. This is the standard way to incorporate upstream changes before review.

Why this answer

Merging main into the checked-out feature branch brings the upstream commits into the feature branch and presents conflicts in the working tree for resolution. The feature branch retains its own commits, and the resulting state can be pushed for review. This is the conventional pre-pull-request integration step when a teammate has advanced the main branch.

Exam trap

The trap here is reaching for reset or revert to reconcile branches, when those operations discard or undo commits rather than integrate another branch's history into the current one.

293
MCQhard

A Python script uses a try/except block to handle API errors. If the API returns a 429 status code, which mechanism should the script implement to handle the error appropriately?

A.Switch to a different API endpoint
B.Wait for the time specified in the Retry-After header and then retry
C.Log the error and continue without retrying
D.Immediately retry the same request without delay
AnswerB

HTTP 429 signals rate limiting, and the Retry-After header specifies how long to wait before retrying. Honouring that value respects the server's throttling window, satisfying the stem's requirement to handle the error appropriately rather than retrying immediately or abandoning the request.

Why this answer

A 429 status code indicates the client has sent too many requests in a given amount of time (rate limiting). The HTTP specification (RFC 6585) recommends including a Retry-After header in the response, which tells the client how long to wait before retrying. Implementing a wait based on this header and then retrying is the correct and respectful way to handle rate limiting, allowing the script to eventually succeed without overwhelming the server.

Exam trap

Cisco often tests the distinction between handling transient errors (like 429) versus permanent errors (like 404 or 500), and the trap here is that candidates may choose to immediately retry (D) or log and continue (C) without understanding that 429 specifically requires a delay before retry.

How to eliminate wrong answers

Option A is wrong because switching to a different API endpoint does not address the rate limit on the current endpoint; the client is still rate-limited and the new endpoint may also be affected or require separate authentication. Option C is wrong because logging the error and continuing without retrying means the script abandons the operation entirely, which is not appropriate when the error is transient and can be resolved by waiting. Option D is wrong because immediately retrying the same request without delay will almost certainly result in another 429 error, as the rate limit has not yet expired, and may worsen the situation by further exhausting the rate limit window.

294
Multi-Selecteasy

Which TWO of the following are best practices for securely managing API tokens in a CI/CD pipeline?

Select 2 answers
A.Store tokens as plain text in the source code repository for easy access.
B.Hardcode tokens into the Docker image during build.
C.Use environment variables injected by the CI/CD system (e.g., Jenkins secrets).
D.Encrypt tokens with a static key stored in the repository.
E.Use a secrets management service like HashiCorp Vault to retrieve tokens at runtime.
AnswersC, E

CI/CD systems can securely inject tokens as environment variables without storing them in code.

Why this answer

CI/CD systems like Jenkins provide built-in secret management features (e.g., Jenkins Credentials Binding plugin) that inject API tokens as environment variables at runtime, keeping them out of source code and build artifacts. This approach ensures tokens are never stored in plain text or committed to version control, aligning with the principle of least privilege and secure pipeline design.

Exam trap

Cisco often tests the misconception that encrypting secrets with a key stored in the same repository is secure, but the trap here is that encryption without separate key management is equivalent to obfuscation—attackers with repo access can decrypt the token using the stored key.

295
MCQeasy

A developer is writing a Python script that calls a REST API protected by OAuth 2.0. The script runs unattended on a server and must obtain an access token without any user interaction. The authorization server supports the client credentials grant. Which flow should the developer implement?

A.Implicit grant
B.Authorization code grant with PKCE
C.Client credentials grant
D.Resource owner password credentials grant
AnswerC

The client credentials grant is intended for machine-to-machine communication where the client authenticates with its own client ID and secret, with no end user involved. The server script can POST its credentials to the token endpoint and receive an access token directly. This matches the unattended execution requirement and the authorization server's supported grant exactly.

Why this answer

When an application authenticates as itself rather than on behalf of a user, the client credentials grant is the correct OAuth 2.0 flow. The server script presents its client ID and secret to the token endpoint and receives an access token, with no browser redirect or user consent step. Flows requiring a user, such as authorization code with PKCE or implicit, and flows requiring user passwords do not match unattended machine-to-machine access.

Exam trap

The trap here is reaching for authorization code with PKCE simply because it is modern, when the absence of a user makes client credentials the only fitting grant.

296
MCQeasy

A developer is writing a Python function that accepts a variable number of interface names and returns them as a tuple. Which function definition correctly allows an arbitrary number of positional arguments?

A.def list_interfaces(*interfaces):
B.def list_interfaces(interfaces):
C.def list_interfaces(**interfaces):
D.def list_interfaces(interfaces=[]):
AnswerA

The asterisk before the parameter name collects all positional arguments into a tuple named interfaces. This allows the function to accept any number of interface names, including zero, and directly returns them as a tuple when referenced. This matches the scenario's requirement for arbitrary positional arguments.

Why this answer

The function must accept a variable number of positional arguments. Using *interfaces packs all positional arguments into a tuple, which is exactly what the scenario requires. The other definitions either accept a single argument, collect keyword arguments into a dictionary, or use a mutable default that introduces bugs and still does not support multiple positional arguments.

Exam trap

The trap here is confusing *args with **kwargs, where the single asterisk collects positional arguments into a tuple and the double asterisk collects keyword arguments into a dictionary.

297
MCQmedium

An application needs to receive real-time notifications when a new message is posted in a Webex space. Which Webex API feature should be used?

A.Establish a WebSocket connection to the Webex API
B.Create a webhook that triggers on 'messages' events
C.Use Server-Sent Events (SSE) from the Webex API
D.Poll the messages endpoint every second
AnswerB

Webhooks push event data to your HTTPS endpoint the moment a message is created, satisfying the real-time notification requirement without polling. Subscribing to the 'messages' resource delivers the posted message payload directly, whereas periodic GET requests to the messages API would introduce latency and unnecessary API calls.

Why this answer

Webex uses webhooks to push real-time event notifications to an external server. By creating a webhook that triggers on 'messages' events, the application receives an HTTP POST request whenever a new message is posted in the specified space, eliminating the need for polling or persistent connections.

Exam trap

Cisco often tests the distinction between push-based (webhooks) and pull-based (polling) mechanisms, and candidates may mistakenly assume WebSocket or SSE are available because they are common real-time technologies, but Webex specifically relies on webhooks for event-driven notifications.

How to eliminate wrong answers

Option A is wrong because Webex does not expose a WebSocket endpoint for real-time messaging events; webhooks are the standard mechanism. Option C is wrong because Webex does not support Server-Sent Events (SSE) for message notifications; SSE is not part of the Webex API. Option D is wrong because polling the messages endpoint every second is inefficient, introduces latency, and violates API rate limits; webhooks provide immediate, push-based notifications without active polling.

298
MCQhard

In Software-Defined Networking (SDN), the control plane is separated from the data plane. Which of the following best describes the function of the southbound API?

A.Interface between applications and the controller
B.Interface between the controller and network devices
C.Communication between two controllers
D.Interface between the control plane and management plane
AnswerB

The southbound API connects the SDN controller downward to the physical and virtual network devices, carrying forwarding instructions such as OpenFlow flow-table entries. This directly satisfies the stem's separation of control and data planes, since the controller programmes devices through this interface.

Why this answer

Southbound API is used by the SDN controller to communicate with network devices (e.g., switches, routers) to enforce forwarding rules.

299
Multi-Selecthard

Which three actions can an EEM applet perform when triggered? (Choose three.)

Select 3 answers
A.Modify a YANG data model
B.Execute a CLI command
C.Send a syslog message
D.Set a variable
E.Create a new VLAN
AnswersB, C, D

Action cli command runs a command.

Why this answer

EEM (Embedded Event Manager) applets can execute CLI commands when triggered by an event. This allows automation of operational tasks such as configuration changes or troubleshooting commands without manual intervention.

Exam trap

Cisco often tests the distinction between EEM's built-in actions and actions that require a CLI command to achieve, such as creating a VLAN, which is not a direct EEM action but must be done via a CLI command.

300
MCQeasy

A network engineer runs an Ansible playbook to backup a Cisco router configuration. The playbook fails with the error: 'ssh: connect to host 192.168.1.1 port 22: Connection timed out'. What is the most likely cause?

A.The router's IP address is unreachable from the control node.
B.The playbook uses the incorrect gather_facts setting.
C.The SSH key is not authorized on the router.
D.The router does not have SSH enabled.
AnswerA

A connection timeout on port 22 means no TCP response arrived, indicating the router's IP is unreachable from the control node. SSH credential or key errors would surface as authentication failures, not timeouts, so reachability is the actual fault.

Why this answer

The error 'Connection timed out' indicates that the control node sent a TCP SYN to 192.168.1.1 on port 22 but never received a SYN-ACK response. This occurs when the destination IP is unreachable due to routing issues, a firewall dropping packets, or the host being offline. Since Ansible uses SSH to connect to network devices, a timeout at the transport layer points directly to network reachability problems, not authentication or service configuration.

Exam trap

Cisco often tests the distinction between 'Connection timed out' (network unreachable) and 'Connection refused' (service not listening) to trap candidates who confuse SSH service availability with network connectivity.

How to eliminate wrong answers

Option B is wrong because the gather_facts setting controls whether Ansible collects system information before running tasks; it does not affect TCP connectivity or SSH transport. Option C is wrong because an unauthorized SSH key would produce a 'Permission denied' error, not a connection timeout. Option D is wrong because if SSH were not enabled on the router, the control node would receive a 'Connection refused' (RST) response, not a timeout.

Page 3

Page 4 of 13

Page 5