Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 301–375

975 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQmedium

A developer is using the Cisco NX-OS REST API (NX-API) to configure a Cisco Nexus switch. The developer wants to send a JSON payload to create a new VLAN. Which HTTP method and headers are required to use the NX-API REST interface?

A.POST with Content-Type: application/xml and an XML body containing the VLAN configuration.
B.POST with Content-Type: application/json and a JSON body containing the VLAN configuration.
C.PUT with Content-Type: application/json and a JSON body containing the VLAN configuration.
D.GET with Content-Type: application/json and a JSON body containing the VLAN configuration.
AnswerB

NX-API REST uses HTTP POST to send configuration commands or JSON payloads. The Content-Type header must be application/json when sending JSON. The body contains the configuration in JSON format, such as the VLAN creation object. This is the standard way to configure via NX-API REST.

Why this answer

NX-API REST uses HTTP POST to send configuration payloads. When sending JSON, the Content-Type header must be application/json. The body contains the JSON representation of the configuration, such as the VLAN object.

Other methods or content types do not match the requirement to send a JSON payload for configuration.

Exam trap

The trap here is assuming PUT is used for creation in REST, but NX-API specifically uses POST for configuration changes, and the Content-Type must match the payload format.

302
MCQhard

In the OSI model, which layer is responsible for session management, including establishing, maintaining, and terminating connections between applications?

A.Layer 4 (Transport)
B.Layer 7 (Application)
C.Layer 5 (Session)
D.Layer 6 (Presentation)
AnswerC

Layer 5 (Session) governs dialogue control between applications, establishing, maintaining and terminating sessions — exactly the session management the stem requires. It sits above Transport (Layer 4), which handles end-to-end delivery, and below Presentation (Layer 6), which handles formatting, so connection lifecycle management belongs here.

Why this answer

The Session layer (Layer 5) manages sessions between applications. The Transport layer handles end-to-end communication.

303
MCQmedium

A developer's script calls a REST API and receives HTTP 429 Too Many Requests. The response includes a Retry-After header with a value of 30. What should the script do to behave correctly?

A.Immediately resend the identical request in a tight loop until it succeeds.
B.Change the HTTP method from GET to POST and resend.
C.Treat the response as a permanent failure and stop all further API calls.
D.Wait at least 30 seconds, then retry the request.
AnswerD

HTTP 429 means the client exceeded an allowed request rate. The Retry-After header communicates how many seconds to pause before trying again. Honoring that value lets the server's rate window reset and gives the retry a realistic chance of success, which is the behavior API providers expect from well-behaved clients.

Why this answer

A 429 response signals that the client has exceeded a rate limit, and the accompanying Retry-After header states how long to wait before retrying. Pausing for that interval respects the server's throttling policy and avoids worsening the condition. Immediate retries, method changes, or permanently aborting all fail to follow the server's explicit guidance.

Exam trap

The trap here is treating 429 like a permanent 4xx client error instead of a transient throttling response that should be retried after the indicated delay.

304
MCQmedium

A developer is building a Python script that calls the Cisco Webex Rooms API. The API returns a JSON error response with HTTP status code 429. The script currently retries immediately in a tight loop, but the errors persist. What should the developer implement to correctly handle this response?

A.Read the Retry-After response header and wait that many seconds before retrying the request.
B.Change the HTTP method from GET to POST and resend the request.
C.Set the Authorization header to a new access token and resend the request immediately.
D.Add a Content-Type: application/json header and resend the request.
AnswerA

HTTP 429 indicates the client has exceeded the rate limit. Cisco Webex APIs include a Retry-After header specifying how long to wait before retrying. Honoring this header prevents additional throttling and aligns with API rate-limiting best practices. Immediate retries in a tight loop would continue to fail and may extend the throttling period.

Why this answer

HTTP 429 signals that the client has exceeded the API rate limit. Cisco Webex APIs return a Retry-After header indicating how long to wait before the next request. Reading and honoring that value prevents further throttling and is the standard remediation.

Immediate retries, changing methods, or refreshing tokens do not address the underlying rate-limit condition.

Exam trap

The trap here is assuming that retrying immediately or refreshing credentials will resolve a 429, when the response specifically requires the client to pause for the interval given in the Retry-After header.

305
MCQmedium

A developer has created a Webex Teams bot that listens for messages in a specific room and responds with information from an external database. The bot uses the Webex API's 'messages.create' method to post replies. During testing, the bot sometimes fails to respond, but no errors are logged. The developer checks the Webex Developer Portal and sees that the bot's rate limit is set to 10 requests per second. The bot's average load is 5 requests per second, but occasionally spikes to 15 requests per second for a few seconds. The developer wants to ensure the bot functions reliably without exceeding rate limits. Which approach should the developer implement?

A.Implement a request queue that limits outgoing requests to 10 per second and uses exponential backoff on failure.
B.Request a higher rate limit from the Webex API support team.
C.Catch HTTP 429 (Too Many Requests) errors and immediately retry the request.
D.Reduce the bot's overall request rate to 5 per second to stay well within the limit.
AnswerA

A token-bucket queue caps outbound calls at the 10 requests per second ceiling, smoothing the 15 rps spikes that currently trigger silent HTTP 429 responses. Exponential backoff then retries throttled requests after the Retry-After interval, so bursts are absorbed rather than dropped, keeping the bot responsive within its Webex API quota.

Why this answer

Implementing a request queue that limits outgoing requests to 10 per second and uses exponential backoff on failure ensures the bot respects the Webex API rate limit of 10 requests per second. The queue smooths out spikes (e.g., 15 req/s) by buffering excess requests, while exponential backoff handles any HTTP 429 responses gracefully by retrying after increasing delays, preventing further rate limit violations. This approach directly addresses the bot's intermittent failure without relying on external support or sacrificing functionality.

Exam trap

Cisco often tests the misconception that simply catching HTTP 429 errors and retrying immediately is sufficient, when in fact exponential backoff is required to avoid compounding the rate limit violation.

How to eliminate wrong answers

Option B is wrong because requesting a higher rate limit from the Webex API support team is not a standard practice for Webex Teams bots; rate limits are fixed per application and cannot be arbitrarily increased, and the developer should first optimize their bot's behavior rather than seeking a limit change. Option C is wrong because catching HTTP 429 errors and immediately retrying the request would likely trigger another 429 response, as the rate limit is still exceeded; proper handling requires a delay (e.g., via exponential backoff) before retrying. Option D is wrong because reducing the bot's overall request rate to 5 per second is an overreaction that unnecessarily limits the bot's throughput and does not address the occasional spikes to 15 req/s, which could still cause failures if not managed with queuing or backoff.

306
MCQeasy

A developer needs to securely store API keys for use in a CI/CD pipeline. Which best practice should be followed?

A.Share the keys via email to the team.
B.Hardcode the keys in the source code.
C.Use built-in pipeline secrets or environment variables.
D.Store the keys in a JSON file committed to the repository.
AnswerC

Built-in pipeline secrets or environment variables keep API keys outside source control and build logs, injecting them only at runtime. This satisfies the constraint of secure storage, unlike committing credentials to a repository or baking them into images, where they persist and leak.

Why this answer

CI/CD platforms (e.g., Jenkins, GitLab CI, GitHub Actions) provide built-in mechanisms to store secrets as encrypted environment variables or pipeline secrets. These values are masked in logs and never exposed in source code, ensuring API keys remain confidential throughout the pipeline execution.

Exam trap

Cisco often tests the misconception that storing secrets in a separate configuration file (like a JSON or .env file) is acceptable as long as it is not committed, but the trap is that any file-based storage in the repository—even if ignored—risks accidental exposure, whereas pipeline secrets are designed specifically for secure injection without file persistence.

How to eliminate wrong answers

Option A is wrong because sharing keys via email exposes them in transit and at rest in mail servers, violating security best practices and potentially leading to unauthorized access. Option B is wrong because hardcoding keys in source code embeds them in version control history, making them accessible to anyone with repository access and violating the principle of not storing secrets in code. Option D is wrong because committing a JSON file with keys to the repository stores secrets in plaintext in version control, which can be easily read by anyone with access to the repository history.

307
MCQeasy

Which HTTP method is considered both safe and idempotent?

A.POST
B.PUT
C.PATCH
D.GET
E.DELETE
AnswerD

GET retrieves a representation without altering server state, making it safe, and repeating the same GET yields the same result, making it idempotent. POST, PATCH and DELETE change state or are non-idempotent, so GET uniquely satisfies both properties.

Why this answer

GET is both safe and idempotent according to HTTP semantics (RFC 7231). Safe means it must not cause side effects on the server, and idempotent means multiple identical requests produce the same result as a single request. GET is designed solely for retrieval of a resource, so it satisfies both properties.

Exam trap

Cisco often tests the distinction between 'safe' and 'idempotent' as separate properties, trapping candidates who assume that idempotent methods like PUT or DELETE are also safe, or that PATCH is idempotent because it modifies a resource.

How to eliminate wrong answers

Option A is wrong because POST is neither safe nor idempotent; it creates or modifies resources and repeated submissions can create multiple resources or different side effects. Option B is wrong because PUT is idempotent but not safe; it modifies or replaces a resource at a specific URI, which is a side effect. Option C is wrong because PATCH is neither safe nor idempotent; it applies partial modifications, and repeated requests can have different outcomes depending on the current state of the resource.

Option E is wrong because DELETE is idempotent but not safe; it removes a resource, which is a side effect.

308
MCQeasy

In a Postman collection, a developer stores the base URL of a Meraki API as a variable. Which Postman feature allows this?

A.Tests
B.Environments
C.Pre-request Scripts
D.Collections
AnswerB

Environments store variables as key-value pairs that Postman substitutes into requests, so the base URL can differ per deployment without editing the collection. This satisfies the requirement to hold the Meraki API base URL as a reusable variable rather than hard-coding it.

Why this answer

Environments in Postman allow developers to store variables, such as a base URL, that can be reused across requests and collections. By defining an environment with a variable for the base URL, the developer can easily switch between different environments (e.g., development, production) without modifying each request. This is the standard feature for managing variables like base URLs.

Exam trap

200-901 often tests the confusion between Environments and other Postman features like Collections or Pre-request Scripts, but Environments are specifically for managing variables across different contexts.

How to eliminate wrong answers

Option A is wrong because Tests are scripts that run after a request to validate responses, not for storing variables. Option C is wrong because Pre-request Scripts are scripts that run before a request to set up data or modify requests, but they are not the primary feature for storing reusable variables like a base URL. Option D is wrong because Collections are groups of saved requests, not a variable storage mechanism; while collections can have variables, the feature specifically designed for environment-specific variables is Environments.

309
MCQeasy

A developer is building a dashboard that displays the health status of network devices managed by Cisco ACI. The developer uses the ACI REST API to query the APIC (Application Policy Infrastructure Controller). The developer sends a GET request to https://apic-ip/api/class/fabricHealthInst.json returns a JSON object with health scores. The dashboard works for a small set of devices, but when scaled to 500 devices, the API responses become slower and sometimes time out. The developer needs to optimize the data retrieval to keep the dashboard responsive. Which approach should the developer use?

A.Break the request into multiple smaller requests, each fetching a subset of devices.
B.Add a query parameter to sort the results by health score to reduce processing time.
C.Switch from JavaScript to Python for the backend to handle larger responses more efficiently.
D.Use the ACI event subscription mechanism to receive health updates only when changes occur.
AnswerD

Event subscriptions push health updates only when state changes, eliminating repeated polling of 500 devices that saturates APIC and causes timeouts. Unlike GET queries returning full class objects each time, subscriptions use websockets or callbacks, so the dashboard stays responsive under scale while satisfying the requirement to optimise retrieval latency.

Why this answer

The ACI REST API supports an event subscription mechanism (e.g., WebSocket-based subscriptions) that pushes updates only when the health score of a device changes, rather than requiring the dashboard to poll the APIC repeatedly. This drastically reduces network overhead and server load, especially when scaling to 500 devices, as it eliminates the need for frequent full GET requests to /api/class/fabricHealthInst.json.

Exam trap

Cisco often tests the distinction between polling (synchronous GET requests) and event-driven subscriptions (asynchronous push) to evaluate understanding of API optimization patterns, and the trap here is that candidates mistakenly think breaking requests into smaller chunks or changing languages will solve scalability issues, when the real solution is to avoid unnecessary data retrieval altogether.

How to eliminate wrong answers

Option A is wrong because breaking a single request into multiple smaller requests increases the total number of HTTP transactions and overhead, which can exacerbate latency and timeout issues rather than solving them. Option B is wrong because sorting results by health score does not reduce the processing time for the APIC; the server still must fetch and process all records before sorting, and the bottleneck is typically in data retrieval and response size, not ordering. Option C is wrong because switching from JavaScript to Python does not address the root cause of slow API responses; the performance issue is due to polling frequency and response size, not the programming language used for the backend.

310
MCQhard

Refer to the exhibit. What is the most effective action to eliminate both vulnerabilities in the container image?

A.Rebuild the image using the same base image but update the OS packages.
B.Add a .dockerignore file to exclude vulnerable libraries.
C.Only run the container with read-only root filesystem.
D.Switch the base image to a distroless base image that does not include openssl and curl.
AnswerD

Distroless images contain only the application and its runtime dependencies, omitting package managers and shells. Removing openssl and curl eliminates the vulnerable libraries entirely, so both CVEs disappear rather than being patched or masked, satisfying the requirement to eliminate both vulnerabilities.

Why this answer

Switching to a distroless base image removes unnecessary packages like openssl and curl entirely, eliminating the vulnerabilities they introduce. Distroless images contain only the application and its runtime dependencies, reducing the attack surface by excluding OS package managers and shell utilities that are common sources of CVEs. This approach directly addresses both vulnerabilities by ensuring the vulnerable components are not present in the image at all.

Exam trap

Cisco often tests the misconception that updating packages (Option A) is sufficient, when the real goal is to eliminate the vulnerable components entirely, not just patch them.

How to eliminate wrong answers

Option A is wrong because rebuilding with the same base image and updating OS packages only patches known vulnerabilities but does not remove the packages themselves; future vulnerabilities in those packages would still require updates, and the attack surface remains. Option B is wrong because a .dockerignore file controls which files are sent to the Docker build context, not which packages are installed in the image; it cannot exclude pre-installed libraries like openssl or curl from the base image. Option C is wrong because running the container with a read-only root filesystem prevents writes at runtime but does not remove the vulnerable binaries from the image; an attacker could still exploit the vulnerable openssl or curl processes if they are executed.

311
MCQeasy

In the Ansible playbook snippet, what connection method is typically used for the ios_config module to communicate with the devices?

A.local
B.network_cli
C.netconf
D.httpapi
AnswerB

The ios_config module runs on the control node but targets Cisco IOS devices over SSH, so the playbook uses the network_cli connection plugin, which handles CLI prompt and privilege escalation rather than a local or API-based transport.

Why this answer

The ios_config module is designed for Cisco IOS devices and requires a persistent network connection to send configuration commands. The network_cli connection method establishes an SSH session that remains open for the duration of the playbook task, allowing the module to send multiple CLI commands and handle prompts. This is the recommended connection method for ios_config because it supports privilege escalation and command responses needed for configuration changes.

Exam trap

Cisco often tests the distinction between connection methods by making candidates think 'local' is correct because it runs on the control node, but the trap is that ios_config requires a persistent SSH session to the device, which only network_cli provides.

How to eliminate wrong answers

Option A is wrong because 'local' connection runs the module on the control node without opening a persistent SSH session to the device, which prevents ios_config from properly handling interactive prompts and privilege escalation. Option C is wrong because 'netconf' uses XML-based NETCONF protocol over SSH, which is not supported by the ios_config module (it is used with the ios_netconf module instead). Option D is wrong because 'httpapi' uses RESTCONF or other HTTP-based APIs, which are not applicable to the CLI-based ios_config module.

312
MCQhard

A developer is using the Cisco NX-OS API on a Nexus switch. The developer wants to retrieve the running configuration using a Python script that sends an HTTP POST request. Which command must be configured on the switch to enable this capability?

A.ip http server
B.feature nxapi
C.feature netconf
D.feature restconf
AnswerB

The 'feature nxapi' command enables the NX-API feature on a Cisco NX-OS device. This allows the switch to accept HTTP/HTTPS requests for CLI commands and retrieve configuration or operational data. Without this feature enabled, the switch will not respond to NX-API requests. It is the essential first step for using the NX-OS API.

Why this answer

To enable the NX-API on a Cisco NX-OS device, the 'feature nxapi' command must be configured. This allows the switch to accept HTTP/HTTPS requests for CLI commands. Other features like NETCONF or RESTCONF are separate protocols and do not enable NX-API.

Exam trap

The trap here is confusing NX-API with other management protocols like NETCONF or RESTCONF, or assuming that enabling the HTTP server is sufficient, when the specific 'feature nxapi' command is required.

313
MCQhard

A developer has a Docker container running a database. They need to inspect the database logs to debug a connection issue. Which command will show the logs in real-time?

A.docker exec my-db tail -f /var/log/mysql
B.docker logs --tail 100 my-db
C.docker logs my-db
D.docker logs -f my-db
AnswerD

docker logs -f streams the container's stdout and stderr continuously, following new output as it is written, which is what real-time debugging of the database connection issue requires. The -f flag distinguishes it from a one-off dump of existing log entries.

Why this answer

The `docker logs -f` command attaches to the container's stdout/stderr streams and follows new output in real-time, which is exactly what is needed to debug a live connection issue. The `-f` flag (short for `--follow`) continuously prints log lines as they are written, allowing the developer to observe database connection attempts and errors as they occur.

Exam trap

Cisco often tests the distinction between `docker exec` (for running commands inside a container) and `docker logs` (for retrieving container output streams), and the trap here is that candidates may mistakenly think they need to exec into the container and use a Linux command like `tail -f` instead of using the native Docker log-following feature.

How to eliminate wrong answers

Option A is wrong because `docker exec` runs a command inside the container, but it does not access the container's log stream; it would require the database to be configured to write logs to a file at that path, and it does not provide the real-time follow behavior of `docker logs -f`. Option B is wrong because `docker logs --tail 100 my-db` shows only the last 100 lines of the log and then exits; it does not follow new log entries in real-time. Option C is wrong because `docker logs my-db` dumps the entire current log buffer to stdout and exits, providing no real-time monitoring capability.

314
MCQeasy

A developer wants to receive real-time notifications when a new message is posted in a Webex room. Which Webex API resource should they use?

A.Webhooks
B.Memberships API
C.Rooms API
D.Messages API polling
AnswerA

Webhooks push event notifications to a supplied HTTPS endpoint the moment a message is created, satisfying the real-time constraint. Polling the messages resource would introduce latency and unnecessary API calls, so webhooks are the designed mechanism for immediate room activity alerts.

Why this answer

Webhooks provide real-time HTTP callbacks triggered by events in Webex, such as a new message being posted. By registering a webhook on the 'messages' resource with the 'created' event, the developer's server receives a POST request immediately when a message is sent, eliminating the need for polling.

Exam trap

Cisco often tests the distinction between synchronous polling (Messages API) and asynchronous event-driven notifications (Webhooks), trapping candidates who assume polling is acceptable for real-time requirements.

How to eliminate wrong answers

Option B (Memberships API) is wrong because it manages room membership (add/remove/list members) and does not expose message events. Option C (Rooms API) is wrong because it handles room creation, listing, and updates, not real-time message notifications. Option D (Messages API polling) is wrong because polling requires repeated GET requests to check for new messages, which is inefficient and not real-time; Webex explicitly recommends webhooks over polling for event-driven notifications.

315
MCQhard

A network engineer is configuring EtherChannel between two switches. The switches are connected via four links. The engineer wants to load balance traffic based on source and destination IP addresses. Which configuration command should be used on Cisco IOS?

A.port-channel load-balance src-ip
B.port-channel load-balance dst-ip
C.port-channel load-balance src-dst-mac
D.port-channel load-balance src-dst-ip
AnswerD

`port-channel load-balance src-dst-ip` hashes each frame on the source and destination IP address pair, distributing traffic across all four EtherChannel member links. This satisfies the stem's requirement to load balance on both IP addresses, unlike MAC-based methods such as src-dst-mac, which ignore Layer 3 information entirely.

Why this answer

The command 'port-channel load-balance src-dst-ip' configures EtherChannel to use both the source and destination IP addresses in the hash algorithm, which is exactly what the engineer needs for load balancing based on source and destination IP addresses. This ensures traffic distribution across the four links by computing a hash on the combination of source and destination IPs, providing a balanced distribution for IP traffic.

Exam trap

The trap here is that candidates often confuse the EtherChannel load-balance keywords, mistakenly selecting 'src-dst-mac' (Layer 2) when the question specifies IP addresses, or picking a single-address option like 'src-ip' or 'dst-ip' instead of the combined 'src-dst-ip' that matches the requirement for both source and destination.

How to eliminate wrong answers

Option A is wrong because 'port-channel load-balance src-ip' only uses the source IP address in the hash, ignoring the destination IP, which would not meet the requirement of load balancing based on both source and destination IP addresses. Option B is wrong because 'port-channel load-balance dst-ip' only uses the destination IP address, similarly failing to consider both source and destination IPs. Option C is wrong because 'port-channel load-balance src-dst-mac' uses source and destination MAC addresses instead of IP addresses, which is used for Layer 2 load balancing and does not satisfy the requirement for IP-based load balancing.

316
MCQmedium

A network engineer is using Cisco DNA Center's Intent API to retrieve a list of all devices in the inventory. The engineer wants to filter the results to only include devices that are reachable and managed. Which HTTP method and endpoint should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/network-device
C.PUT /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/device
AnswerB

The GET /dna/intent/api/v1/network-device endpoint returns the list of all network devices in the DNA Center inventory. It supports query parameters such as reachabilityStatus and managementState to filter results. This is the correct endpoint for retrieving device inventory information from the Intent API.

Why this answer

To retrieve the device inventory from Cisco DNA Center, the engineer must use the GET method on the /dna/intent/api/v1/network-device endpoint. This endpoint returns a JSON list of devices and supports query parameters like reachabilityStatus and managementState to filter results. The other methods either modify resources or target incorrect paths, making them unsuitable.

Exam trap

The trap here is confusing the HTTP method for listing resources with methods that create or update, or using an incorrect endpoint path that omits 'network-'.

317
MCQhard

A developer is using the Meraki Dashboard API to retrieve a list of clients for a network. The API returns a 429 error. What should the developer do to handle this correctly?

A.Ignore the error and continue, as 429 is a temporary issue.
B.Wait for the number of seconds specified in the Retry-After header before retrying.
C.Switch to a different base URL to bypass the limit.
D.Increase the request rate by using multiple API keys in parallel.
AnswerB

A 429 signals rate limiting, and the Meraki Dashboard API returns a Retry-After header giving the exact backoff interval. Honouring that value respects the documented rate-limit window, so the retry succeeds rather than being throttled again. Immediate retries or fixed delays ignore the server-supplied timing and risk further 429 responses.

Why this answer

A 429 HTTP status code indicates 'Too Many Requests,' meaning the client has exceeded the rate limit imposed by the Meraki Dashboard API. The correct handling is to respect the Retry-After header, which specifies the number of seconds the client must wait before retrying the request, as per RFC 7231 Section 7.1.3. This ensures compliance with API rate limits and prevents further throttling or temporary blocking.

Exam trap

Cisco often tests the misconception that 429 is a transient error like a 503 Service Unavailable, leading candidates to think they can simply retry immediately or ignore it, rather than understanding that 429 specifically requires honoring the Retry-After header for rate-limit compliance.

How to eliminate wrong answers

Option A is wrong because ignoring a 429 error and continuing will likely result in continued failures or a temporary ban, as the API enforces rate limits to protect server resources. Option C is wrong because switching to a different base URL does not bypass rate limits; rate limits are applied per API key or client, not per URL endpoint. Option D is wrong because increasing the request rate with multiple API keys in parallel would exacerbate the rate-limit violation, and using multiple keys without coordination may still trigger per-key limits or violate the API's terms of service.

318
MCQmedium

A company uses a blue/green deployment strategy for their web application. The current live version is blue, and a new version green is ready. The load balancer currently routes all traffic to blue. What is the correct next step to switch traffic to green with minimal downtime?

A.Scale down blue pods and scale up green
B.Perform a rolling update from blue to green
C.Delete the blue deployment and create green
D.Update the load balancer to route all traffic to green
AnswerD

Updating the load balancer to route all traffic to green switches the live environment in a single atomic change, satisfying the minimal-downtime constraint. Because green is already deployed and healthy, no rebuild or restart is needed; the load balancer's routing rule is the only cutover point, so blue remains available for instant rollback.

Why this answer

In a blue/green deployment, the entire new version (green) is deployed alongside the current live version (blue). The correct next step to switch traffic with minimal downtime is to update the load balancer to route all traffic to green. This instant switch avoids the incremental risk of rolling updates and ensures a clean cutover that can be quickly reverted if issues arise.

Exam trap

Cisco often tests the distinction between deployment strategies, and the trap here is confusing a rolling update (which gradually replaces pods) with a blue/green deployment (which switches traffic at the load balancer level), leading candidates to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because scaling down blue and scaling up green is a manual, non-atomic process that does not leverage the load balancer's routing capability, potentially causing partial traffic loss or mixed-version serving. Option B is wrong because a rolling update gradually replaces blue pods with green pods, which contradicts the blue/green strategy's goal of maintaining two fully separate environments for instant rollback. Option C is wrong because deleting the blue deployment before creating green would cause downtime, as there is no live environment to serve traffic during the deletion and creation process.

319
MCQmedium

A developer pushes a container image to Docker Hub and then discovers that the image layers contain an .env file with production API keys. The team wants future builds to fail automatically in the CI pipeline when secrets are detected in the image before any push occurs. Which approach best addresses this requirement?

A.Enable Docker Content Trust so that only signed images can be pushed to Docker Hub.
B.Store the API keys in Docker Hub repository secrets and reference them from the Dockerfile at build time.
C.Run a container image scanning tool against the built image in the pipeline and fail the stage when secret findings are reported.
D.Add a .dockerignore entry for .env and rely on developers to never commit secrets.
AnswerC

Scanning the built image in the pipeline inspects the actual layers that would be pushed, detecting secrets wherever they were introduced, including base layers and hardcoded values. Configuring the scan stage to return a non-zero exit status on findings makes the pipeline fail before the push step executes, which is exactly the requested automatic gate.

Why this answer

The requirement is detection with an automatic pipeline failure before pushing. Scanning the built image examines the exact artifacts destined for the registry, so secrets leaked through any path are found. Wiring the scanner to exit non-zero on findings turns that detection into a hard gate.

Preventive measures like .dockerignore or signing policies reduce risk but cannot guarantee that no secret exists in the image.

Exam trap

The trap here is assuming that excluding a secrets file from the build context is equivalent to detecting secrets in the final image.

320
MCQhard

In Cisco DNA Center, which API category includes the ability to deploy a configuration template to devices?

A.Change your network
B.Run your network
C.Know your network
D.Platform
AnswerA

The "Change your network" category covers configuration and deployment operations, including template deployment to devices via the DNA Center template APIs. This satisfies the stem's requirement for the API category that deploys configuration templates, rather than monitoring or inventory categories.

Why this answer

The 'Change your network' category includes template deployment, plug and play, and other configuration changes.

321
MCQeasy

A developer is creating a Dockerfile for a Python Flask application. The application runs on port 5000. Which directive should be used to document that the container listens on this port?

A.EXPOSE 5000
B.PORT 5000
C.PUBLISH 5000
D.LISTEN 5000
AnswerA

EXPOSE 5000 documents that the container listens on port 5000 at runtime; it is metadata for image consumers and does not publish the port. This matches the requirement to document the Flask application's listening port.

Why this answer

The EXPOSE directive informs Docker that the container listens on specified ports at runtime. It does not actually publish the port but serves as documentation.

322
MCQhard

A network engineer wants to automate a configuration change on a Cisco IOS XE device when a specific syslog message appears. Which tool should they use?

A.RESTCONF with a Python script polling the device
B.SNMP trap receiver
C.EEM applet configured to match the syslog pattern and execute CLI commands
D.NETCONF with a YANG-based notification subscription
AnswerC

Embedded Event Manager applets run on the IOS XE device itself, matching syslog patterns via event statements and triggering CLI actions through action statements. This delivers the required local, event-driven automation without external orchestration tooling.

Why this answer

EEM (Embedded Event Manager) is a built-in Cisco IOS XE feature that allows the device to react to local events, including syslog messages. An EEM applet can be configured with an event syslog pattern to match a specific syslog message and an action to execute CLI commands, enabling automated configuration changes directly on the device. This is the most direct and native way to trigger a configuration change based on a syslog message without external dependencies.

Exam trap

The trap here is confusing EEM with external automation tools like RESTCONF or NETCONF, or assuming that SNMP traps can trigger CLI commands; candidates must remember that EEM is the native on-device automation engine for event-driven actions.

How to eliminate wrong answers

Option A is wrong because RESTCONF with polling is an external pull-based approach that introduces latency and requires a separate server; it does not natively react to syslog events. Option B is wrong because SNMP trap receivers are external systems that collect traps but do not automatically execute CLI commands on the device; they are for monitoring, not automation. Option D is wrong because NETCONF with YANG-based notification subscriptions is not supported on Cisco IOS XE for this purpose; while NETCONF supports notifications, IOS XE does not provide a native mechanism to subscribe to syslog events and trigger CLI commands via NETCONF.

323
MCQeasy

A Docker container needs to be started in detached mode with port mapping from host port 8080 to container port 80. Which command accomplishes this?

A.docker start -d -p 8080:80 myapp
B.docker run -d -p 8080:80 myapp
C.docker run -it -p 8080:80 myapp
D.docker run -d -p 80:8080 myapp
AnswerB

The `-d` flag detaches the container, running it in the background, while `-p 8080:80` maps host port 8080 to container port 80, satisfying both stem constraints. The syntax `host:container` is critical here; reversing it would publish the wrong port. This single command therefore meets the detached-mode and port-mapping requirements exactly.

Why this answer

The -d flag runs container in detached mode, -p maps host port to container port.

324
MCQmedium

A network engineer writes a Python script to handle exceptions when making REST API calls. Which exception type should be caught to handle network connectivity issues (e.g., DNS failure, refused connection)?

A.requests.exceptions.RequestException
B.requests.exceptions.ConnectionError
C.requests.exceptions.HTTPError
D.requests.exceptions.Timeout
AnswerB

requests.exceptions.ConnectionError is raised when the underlying connection cannot be established, covering DNS resolution failures and refused connections. Catching it satisfies the requirement to handle network connectivity issues, unlike HTTPError, which signals a received error response.

Why this answer

`requests.exceptions.ConnectionError` is specifically raised when the underlying TCP connection fails, which includes scenarios like DNS resolution failures, refused connections, or the remote host being unreachable. This exception is a subclass of `RequestException` and directly maps to network-level issues at the transport layer, making it the precise exception to catch for connectivity problems.

Exam trap

Cisco often tests the distinction between the broad `RequestException` and the specific `ConnectionError`, trapping candidates who choose the base class thinking it covers all errors, when the question explicitly asks for network connectivity issues.

How to eliminate wrong answers

Option A is wrong because `requests.exceptions.RequestException` is the base class for all exceptions in the `requests` library; catching it would be too broad and would also handle non-connectivity errors like HTTP errors or timeouts, which is not the specific requirement. Option C is wrong because `requests.exceptions.HTTPError` is raised only when the server returns an HTTP error status code (e.g., 4xx or 5xx), which indicates an application-level issue, not a network connectivity failure. Option D is wrong because `requests.exceptions.Timeout` is raised when a request exceeds the specified timeout period, which is a timing issue rather than a fundamental network connectivity failure like DNS failure or refused connection.

325
Multi-Selecthard

Which THREE options are valid methods to expose a Kubernetes service to external traffic?

Select 3 answers
A.ExternalName
B.NodePort
C.ClusterIP
D.Ingress
E.LoadBalancer
AnswersB, D, E

NodePort opens a static port on every cluster node, forwarding external traffic to the service's ClusterIP. This satisfies the requirement for exposing a service externally without a cloud load balancer, since kube-proxy listens on that port range (30000–32767) across all nodes.

Why this answer

NodePort (B) is correct because it allocates a static port in the 30000-32767 range on every node's IP, allowing external clients to reach the service via <NodeIP>:<NodePort>. Ingress (D) is correct because it provides HTTP/HTTPS routing from outside the cluster to internal services through an ingress controller acting as a reverse proxy. LoadBalancer (E) is correct because it provisions an external load balancer (e.g., via a cloud provider) with a public IP that forwards traffic to the service's NodePort.

ExternalName (A) is not a valid exposure method for external traffic; it merely creates a CNAME DNS alias to an external hostname without proxying traffic. ClusterIP (C) is incorrect because it only exposes the service on an internal cluster IP reachable solely from within the cluster.

Exam trap

The trap is including ExternalName or ClusterIP as external exposure methods — candidates confuse DNS aliasing and internal-only networking with actual external accessibility.

326
Multi-Selectmedium

A developer is writing a Dockerfile for a Node.js application. Which TWO instructions are commonly used to define the command that runs when the container starts?

Select 2 answers
A.CMD
B.RUN
C.START
D.ENTRYPOINT
E.EXPOSE
AnswersA, D

CMD sets the default executable and parameters for a container, but is overridden entirely when arguments are supplied at runtime. It satisfies the stem's requirement for a startup command instruction, and pairs with ENTRYPOINT, which fixes the executable while CMD supplies default arguments.

Why this answer

Option A (CMD) is correct because CMD specifies the default command (and/or arguments) executed when a container starts from the image, and it can be overridden at runtime by arguments passed to `docker run`. Option D (ENTRYPOINT) is correct because ENTRYPOINT configures the executable that always runs when the container starts, making it the primary way to define the container's startup process; CMD then typically supplies default arguments to it. Option B (RUN) is incorrect because RUN executes commands during image build time to create layers, not at container startup.

Option C (START) is incorrect because there is no Dockerfile START instruction; container startup is governed by CMD/ENTRYPOINT. Option E (EXPOSE) is incorrect because EXPOSE only documents the port the container listens on at runtime and does not define any startup command.

Exam trap

Cisco often tests the distinction between build-time instructions (RUN) and runtime instructions (CMD/ENTRYPOINT), and the trap here is that candidates confuse RUN (which executes during `docker build`) with CMD (which executes during `docker run`).

327
MCQeasy

A network engineer is troubleshooting connectivity issues and wants to verify the path that packets take from a source to a destination IP address. Which OSI layer is primarily responsible for packet forwarding and routing?

A.Layer 4 - Transport
B.Layer 3 - Network
C.Layer 1 - Physical
D.Layer 2 - Data Link
AnswerB

Layer 3 handles logical addressing and routing, with routers forwarding packets hop-by-hop using IP addresses and routing tables. This satisfies the engineer's need to verify the packet path, since traceroute relies on Layer 3 forwarding decisions rather than Layer 2 switching.

Why this answer

The Network layer (Layer 3) is responsible for packet forwarding and routing, using logical IP addresses to determine the best path from source to destination. Protocols like IP (IPv4/IPv6) and routing protocols (e.g., OSPF, BGP) operate at this layer to make forwarding decisions. The traceroute command is a common tool that leverages Layer 3 TTL (Time-to-Live) fields to map the path packets take.

Exam trap

Cisco often tests the distinction between Layer 2 switching (MAC-based forwarding within a LAN) and Layer 3 routing (IP-based forwarding between networks), and the trap here is that candidates confuse the Data Link layer's local forwarding with the Network layer's path determination.

How to eliminate wrong answers

Option A is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), not packet forwarding or routing. Option C is wrong because Layer 1 (Physical) deals with the physical transmission of raw bits over a medium (e.g., cables, signals) and has no awareness of paths or addresses. Option D is wrong because Layer 2 (Data Link) is responsible for node-to-node delivery within a single network segment using MAC addresses, not for routing across multiple networks.

328
MCQmedium

An organization uses Cisco DNA Center and wants to programmatically deploy a configuration template to multiple devices. Which API category should be used?

A.Platform
B.Change your network
C.Run your network
D.Know your network
AnswerB

The Intent API's "Change your network" category covers configuration operations, including deploying templates to devices. It satisfies the stem's requirement for programmatic template deployment across multiple devices, unlike monitoring or integration categories that only read data or connect platforms.

Why this answer

The 'Change your network' API category in Cisco DNA Center is specifically designed for making configuration changes, including deploying templates to devices. It provides endpoints for template deployment, configuration management, and other write operations. This aligns with the goal of programmatically deploying a configuration template to multiple devices.

Exam trap

The trap here is confusing the API categories based on their names; candidates might think 'Run your network' is for deploying configurations because it sounds operational, but it's actually for monitoring and troubleshooting.

How to eliminate wrong answers

Option A is wrong because the Platform API category provides foundational services like authentication, not configuration deployment. Option C is wrong because 'Run your network' APIs are for operational tasks such as monitoring and troubleshooting, not for deploying configurations. Option D is wrong because 'Know your network' APIs are for discovery and inventory, not for making changes.

329
MCQeasy

A network automation team is adopting Git for managing Python scripts and YAML device templates. They want a branching model where each new feature is developed in isolation and merged back into a shared integration branch before release. Which Git branching strategy best matches this requirement?

A.Trunk-Based Development
B.GitHub Flow
C.Git Flow
D.Forking Workflow
AnswerC

Git Flow uses a long-lived develop branch as the integration branch where feature branches are merged, and a main branch that holds released code. This directly matches the requirement that features be isolated and then merged into a shared integration branch before release, making it the correct branching strategy here.

Why this answer

Git Flow defines a develop branch that acts as the integration point for completed feature branches and a main branch that stores release-ready code. Because the team wants features isolated and then merged into a shared integration branch before release, Git Flow is the model that matches those constraints.

Exam trap

The trap here is assuming any modern branching model uses a separate integration branch, when GitHub Flow and trunk-based development integrate directly into main.

330
MCQeasy

A developer needs to send a message to a Webex room using the API. Which HTTP method and endpoint should they use?

A.GET /v1/messages
B.PUT /v1/messages
C.DELETE /v1/messages
D.POST /v1/messages
AnswerD

Creating a message is a resource-creating operation, so the Webex messaging API expects POST against the /v1/messages collection endpoint, with the roomId and text in the JSON body. GET on that path would only list messages.

Why this answer

To send a message, use POST to /v1/messages with the room ID and message body.

331
Multi-Selectmedium

Which THREE of the following are valid JSON data types? (Choose three.)

Select 3 answers
A.String
B.Number
C.Function
D.Array
E.Date
AnswersA, B, D

Strings are enclosed in double quotes.

Why this answer

JSON (JavaScript Object Notation) is a lightweight data-interchange format that supports only a fixed set of data types as defined by RFC 7159. String is a valid JSON type because it must be enclosed in double quotes and can contain Unicode characters. Number is valid as it includes integers and floating-point values without quotes, following the numeric grammar in the JSON specification.

Exam trap

Cisco often tests the misconception that JSON supports JavaScript-specific types like Function or Date, but JSON is a language-independent format with only six defined types per RFC 7159.

332
MCQeasy

An application developer is using a protocol that does not require a connection setup and has minimal header overhead. Which transport protocol is being used?

A.TCP
B.UDP
C.HTTP
D.ICMP
AnswerB

UDP is connectionless, requiring no handshake before transmission, and its header carries only source port, destination port, length and checksum — eight bytes versus TCP's larger header. This satisfies both constraints: no connection setup and minimal header overhead.

Why this answer

UDP (User Datagram Protocol) is a connectionless transport-layer protocol that does not require a handshake (no SYN/SYN-ACK/ACK) and has minimal header overhead (only 8 bytes, compared to TCP's 20 bytes). This makes it ideal for applications like DNS queries, streaming media, or real-time communications where low latency is more critical than guaranteed delivery.

Exam trap

Cisco often tests the distinction between transport-layer and application-layer protocols, so candidates mistakenly choose HTTP (an application protocol) instead of recognizing that the question explicitly asks for the transport protocol.

How to eliminate wrong answers

Option A is wrong because TCP requires a three-way handshake to establish a connection and has a larger header (20–60 bytes) with fields for sequence numbers, acknowledgments, and flow control, contradicting the 'no connection setup' and 'minimal header overhead' criteria. Option C is wrong because HTTP is an application-layer protocol, not a transport-layer protocol; it relies on TCP (or rarely UDP via HTTP/3) for transport, so it does not itself define connection setup or header overhead at the transport level. Option D is wrong because ICMP (Internet Control Message Protocol) is a network-layer protocol used for error reporting and diagnostics (e.g., ping), not a transport-layer protocol; it has no concept of port numbers or connection setup, but it is not a transport protocol.

333
MCQmedium

A DevOps team is using Cisco AppDynamics to monitor a microservices application. They notice that a specific service's response time spikes under load. Which AppDynamics feature should be used to drill down into the transaction trace?

A.Health Rules
B.Transaction Snapshots
C.Business Transactions
D.Service Endpoints
AnswerB

Transaction Snapshots capture full call-graph detail, including slow and stalled downstream calls, for individual slow or erroring transactions. Drilling into a snapshot isolates which tier or remote call causes the response-time spike under load, which is exactly what the stem asks for.

Why this answer

Transaction Snapshots in AppDynamics capture detailed traces of individual requests, including call chains, method timings, and database queries. When a response time spike occurs, drilling into Transaction Snapshots provides the precise data needed for root-cause analysis. Business Transactions are logical groupings of similar transactions; while they can be used to locate the problematic transaction, the direct drill-down feature for detailed traces is the Transaction Snapshot.

Exam trap

Cisco often tests the distinction between the logical grouping (Business Transactions) and the raw trace data (Transaction Snapshots), trapping candidates who confuse the container with the content.

How to eliminate wrong answers

Option A is wrong because Health Rules are used to define thresholds and trigger alerts or actions (e.g., email, remediation) when metrics deviate, not to drill into transaction traces. Option B is wrong because Transaction Snapshots are the detailed trace data itself, not the feature used to initiate the drill-down; you must first select a Business Transaction to access its snapshots. Option D is wrong because Service Endpoints represent the specific HTTP or API endpoints (e.g., /api/orders) and are a subset of a Business Transaction; they provide endpoint-level metrics but not the full transaction trace across services.

334
MCQhard

A Kubernetes Service must expose a pod running a database to other pods in the same cluster, but not externally. Which Service type should be used?

A.ClusterIP
B.LoadBalancer
C.ExternalName
D.NodePort
AnswerA

ClusterIP assigns the Service a virtual IP reachable only from within the cluster, satisfying the requirement that the database be accessible to other pods but never exposed externally. NodePort and LoadBalancer would publish it beyond the cluster, and headless Services suit direct pod addressing rather than stable internal load balancing.

Why this answer

ClusterIP exposes the service on a cluster-internal IP, making it accessible only within the cluster.

335
MCQmedium

A developer is building a Python script that calls the Cisco Webex API. The API returns JSON with a top-level key "items" containing a list of records, and a "link" object with a "next" URL when more records exist. The developer needs to iterate through all pages until every record is retrieved. Which approach correctly handles this pagination style?

A.Read the "X-Total-Count" response header and loop exactly that many times using an offset parameter.
B.Request the same endpoint repeatedly and deduplicate results until the returned item count stabilizes.
C.Increment a "page" query parameter starting at 1 and stop when the response body is empty.
D.Parse the top-level "items" array, then check the "link" object for a "next" URL and request that URL until no "next" key is present.
AnswerD

This is correct because the Webex API returns records in an "items" array and provides the next page location inside a "link" object with a "next" field. The script must follow that URL iteratively, stopping when the "link" object no longer contains a "next" key, which signals the final page has been reached.

Why this answer

The Webex API paginates by returning an "items" array plus a "link" object whose "next" field holds the URL of the following page. A correct client parses each page, then follows the "next" URL until that field disappears, indicating the last page. This link-driven approach avoids guessing page sizes or totals and adapts if the server changes page boundaries.

Exam trap

The trap here is assuming every paginated API uses a numeric page or offset query parameter, when this collection instead supplies an explicit next-page URL in the response body.

336
MCQmedium

A company uses a /24 subnet for its office LAN. The network must accommodate 30 hosts per VLAN. Which subnet mask would be most efficient for each VLAN while minimizing wasted IP addresses?

A.255.255.255.224
B.255.255.255.240
C.255.255.255.0
D.255.255.255.128
E.255.255.255.192
AnswerA

This is /27, provides 30 usable hosts, exactly meeting the requirement.

Why this answer

A /27 subnet mask (255.255.255.224) provides 32 total addresses per subnet, with 30 usable host addresses (2^5 - 2 = 30). This exactly meets the requirement of 30 hosts per VLAN without wasting IP addresses, as any larger subnet would leave unused addresses.

Exam trap

Cisco often tests the misconception that the subnet mask must match the exact number of hosts without accounting for the network and broadcast addresses, leading candidates to choose a mask that provides exactly 30 total addresses (like /27) but forget that 2 addresses are reserved.

How to eliminate wrong answers

Option B (255.255.255.240) is wrong because it provides only 14 usable hosts per subnet (2^4 - 2 = 14), which is insufficient for 30 hosts. Option C (255.255.255.0) is wrong because it provides 254 usable hosts, which is far more than needed and wastes IP addresses. Option D (255.255.255.128) is wrong because it provides 126 usable hosts, also wasteful for 30 hosts.

Option E (255.255.255.192) is wrong because it provides 62 usable hosts, which is more than required and inefficient.

337
MCQeasy

A network engineer is configuring a new switch and needs to ensure that frames from VLAN 10 and VLAN 20 are isolated on the same trunk link to another switch. Which IEEE standard should be configured on the trunk interfaces?

A.802.3
B.802.11
C.802.1Q
D.802.1X
AnswerC

802.1Q defines VLAN tagging on trunk links, inserting a tag into each frame to identify its VLAN. This lets VLAN 10 and VLAN 20 traffic traverse the same trunk while remaining logically isolated, exactly as the scenario requires.

Why this answer

C is correct because 802.1Q is the IEEE standard that defines VLAN tagging, allowing multiple VLANs (such as VLAN 10 and VLAN 20) to be carried over a single trunk link while maintaining isolation between them. By inserting a 4-byte VLAN tag into the Ethernet frame, 802.1Q enables the receiving switch to identify which VLAN a frame belongs to, ensuring traffic from different VLANs remains separate.

Exam trap

Cisco often tests the distinction between 802.1Q (VLAN tagging) and 802.1X (authentication), so the trap here is confusing a trunking protocol with a security protocol, leading candidates to pick 802.1X when the question is about VLAN isolation on a trunk.

How to eliminate wrong answers

Option A is wrong because 802.3 is the IEEE standard for Ethernet (CSMA/CD) and defines physical layer and MAC sublayer specifications, not VLAN tagging or trunking. Option B is wrong because 802.11 is the IEEE standard for wireless LAN (Wi-Fi) and is unrelated to wired switch trunk links or VLAN isolation. Option D is wrong because 802.1X is the IEEE standard for port-based network access control (authentication), not for VLAN tagging or trunking.

338
MCQhard

Refer to the exhibit. Based on the YANG model snippet, what is the data type of the 'mask' leaf?

A.inet:ipv4-address
B.inet:ipv4-prefix-length
C.uint8
D.string
AnswerB

The `mask` leaf is typed as `inet:ipv4-prefix-length`, a YANG built-in derived type restricting values to 0–32. This satisfies the exhibit's requirement for a subnet mask length rather than a dotted-decimal address, since the type enforces an integer prefix length consistent with the model's IPv4 addressing constraint.

Why this answer

The 'mask' leaf is defined with the type 'inet:ipv4-prefix-length', which represents a decimal integer from 0 to 32 indicating the number of leading 1 bits in the subnet mask (e.g., 24 for /24). This is the correct data type for a prefix length in YANG models, not an IPv4 address or a generic string.

Exam trap

Cisco often tests the distinction between 'inet:ipv4-address' (a full address) and 'inet:ipv4-prefix-length' (the /N notation), tricking candidates who confuse the subnet mask value with its prefix length representation.

How to eliminate wrong answers

Option A is wrong because 'inet:ipv4-address' is a dotted-decimal IPv4 address (e.g., 192.168.1.1), not a prefix length. Option C is wrong because 'uint8' is a generic 8-bit unsigned integer (0-255) but lacks the semantic constraint of 0-32 that 'inet:ipv4-prefix-length' enforces. Option D is wrong because 'string' would allow arbitrary text, which is not appropriate for a numeric prefix length that must be validated as an integer between 0 and 32.

339
MCQhard

In Cisco DNA Center, which API endpoint is used to retrieve the site hierarchy?

A.POST /dna/intent/api/v1/site
B.GET /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/site
D.GET /dna/intent/api/v1/topology
AnswerC

The site hierarchy is exposed through the intent API's site resource, so a GET to /dna/intent/api/v1/site returns the full site topology. This satisfies the stem's requirement to retrieve, not modify, the hierarchy, and the v1 intent path matches DNA Center's controller-level northbound interface.

Why this answer

Cisco DNA Center exposes the site hierarchy through the Intent API at GET /dna/intent/api/v1/site, which returns the list of sites with their hierarchy, parent-child relationships, and site IDs. This is the documented endpoint for retrieving site topology information.

Exam trap

200-901 often tests HTTP method semantics — candidates see a familiar path like /site and pick POST or confuse /site with /topology or /network-device.

How to eliminate wrong answers

Option A is wrong because POST to /site creates a new site rather than retrieving the hierarchy — the HTTP method is incorrect for a read operation. Option B is wrong because /network-device returns the list of managed network devices (switches, routers, WLCs), not the site hierarchy. Option D is wrong because /topology returns physical or logical topology data (links and nodes), which is related but not the site hierarchy endpoint.

340
MCQhard

An HTTP/2 connection uses multiple concurrent streams over a single TCP connection. Which feature of HTTP/2 enables this?

A.Binary framing layer
B.Multiplexing
C.Server push
D.Header compression (HPACK)
AnswerB

Multiplexing allows multiple request/response streams to be interleaved concurrently over one TCP connection, each identified by a stream ID. This removes HTTP/1.1's head-of-line blocking at the connection level and is the specific HTTP/2 feature enabling concurrent streams.

Why this answer

Multiplexing is the HTTP/2 feature that allows multiple concurrent streams to share a single TCP connection. This eliminates head-of-line blocking at the application layer by enabling the interleaving of frames from different streams, so a slow response on one stream does not block others.

Exam trap

Cisco often tests the distinction between the enabling mechanism (binary framing) and the resulting capability (multiplexing), so candidates mistakenly choose 'binary framing layer' because it sounds technical, but it is the foundation, not the feature that directly enables concurrency.

How to eliminate wrong answers

Option A is wrong because the binary framing layer is the mechanism that encodes frames into binary format, but it does not itself enable concurrency; multiplexing uses the framing layer to interleave streams. Option C is wrong because server push is a feature that allows the server to proactively send resources to the client, but it does not enable multiple concurrent streams. Option D is wrong because header compression (HPACK) reduces overhead by compressing HTTP headers, but it has no role in enabling concurrent streams.

341
MCQmedium

A developer is writing a script that uses a REST API to configure network devices via NETCONF. Which layer of the SDN architecture does NETCONF belong to?

A.Northbound interface
B.Southbound interface
C.Application layer
D.Control layer
AnswerB

NETCONF carries configuration and state data between the SDN controller and managed network devices, sitting below the controller. This places it in the southbound interface layer, distinct from northbound APIs that expose controller capabilities to applications.

Why this answer

NETCONF is a network management protocol used to install, manipulate, and delete the configuration of network devices. In the SDN architecture, the southbound interface is the layer that connects the control plane to the data plane, and NETCONF operates as a southbound protocol by carrying configuration data from a controller or management system down to network devices.

Exam trap

Cisco often tests the distinction between the protocol itself (NETCONF) and the architectural layer it belongs to, leading candidates to mistakenly select 'Control layer' because they associate NETCONF with the controller, rather than recognizing it as a southbound interface protocol.

How to eliminate wrong answers

Option A is wrong because the northbound interface is the API layer that connects the SDN controller to applications and business logic, not to network devices; NETCONF does not operate at this level. Option C is wrong because the application layer contains the business applications and services that consume northbound APIs, not the protocols that directly configure devices. Option D is wrong because the control layer is the SDN controller itself, which uses southbound protocols like NETCONF to communicate with devices, but NETCONF is not the control layer; it is a protocol used by that layer.

342
MCQmedium

A developer is building a Python script that calls the Cisco Webex API to retrieve a list of rooms. The API returns a maximum of 100 items per page and includes a 'Link' response header with a rel="next" URL. The script must automatically fetch all pages until no 'next' link remains. Which approach should the developer implement?

A.Set the 'max' query parameter to 1000 and make a single GET request to retrieve all rooms at once.
B.Use the 'offset' query parameter, increasing it by 100 on each request until the response body is empty.
C.Increment a 'page' query parameter starting at 0 and continue until an empty JSON array is returned.
D.Parse the Link header, extract the URL with rel="next", and issue a GET request to that URL in a loop until the header is absent.
AnswerD

The Webex API uses RFC 5988 Link headers for pagination. The rel="next" URL contains the appropriate cursor or page parameters. By following this URL iteratively, the script retrieves all pages without manually constructing query strings. This is the documented and most reliable method for traversing paginated Webex API results.

Why this answer

The Webex API provides pagination through Link headers containing a rel="next" URL. Following that URL in a loop ensures all pages are retrieved. Other methods like page numbers, large max values, or offset parameters are not supported by this API and would fail to return the complete dataset.

Exam trap

The trap here is assuming that a simple page number or offset parameter can be used for pagination, when the API actually requires following the Link header.

343
MCQmedium

A developer is writing a Python script that calls the Cisco Webex Teams API. The script must handle the case where the access token has expired. Which HTTP status code should the script check for to detect an expired or invalid token?

A.403 Forbidden
B.401 Unauthorized
C.429 Too Many Requests
D.404 Not Found
AnswerB

HTTP 401 Unauthorized indicates that the request lacks valid authentication credentials. For Cisco Webex APIs, an expired or invalid access token produces a 401 response. The client should then refresh the token or re-authenticate. Checking for 401 allows the script to handle token expiration gracefully.

Why this answer

Cisco Webex APIs return HTTP 401 Unauthorized when the access token is expired, revoked, or invalid. The client should detect this status and trigger a token refresh or re-authentication flow. Other status codes such as 403, 404, or 429 represent different conditions and would not correctly identify an expired token.

Exam trap

The trap here is confusing 401 Unauthorized with 403 Forbidden, when only 401 specifically signals that the token is missing, expired, or invalid.

344
MCQeasy

Which OSI layer is responsible for routing packets across different networks?

A.Layer 1 (Physical)
B.Layer 3 (Network)
C.Layer 4 (Transport)
D.Layer 2 (Data Link)
AnswerB

Layer 3 handles logical addressing and path selection between distinct networks, so routers forward packets hop by hop using IP addresses. Layer 2 switches only forward within one broadcast domain, which is why routing across different networks is a Network layer function.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing packets between different networks. Protocols like IP (IPv4/IPv6) use routing tables and algorithms (e.g., OSPF, BGP) to determine the best path for forwarding packets across multiple hops. Without Layer 3, traffic could not leave a local broadcast domain.

Exam trap

Cisco often tests the distinction between Layer 2 switching (MAC-based, same network) and Layer 3 routing (IP-based, between networks), and the trap here is confusing the Data Link layer's local forwarding with the Network layer's internetwork routing.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) handles raw bit transmission over physical media (e.g., voltages, frequencies, cables) and has no concept of addressing or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), but does not perform network-level routing between different subnets. Option D is wrong because Layer 2 (Data Link) uses MAC addresses to forward frames within a single network segment or VLAN, and relies on Layer 3 to route across different networks.

345
MCQmedium

An application uses the Meraki Dashboard API and receives a 429 Too Many Requests error. What is the most likely cause, and how should the application adjust?

A.The request body is malformed; check JSON syntax.
B.The API key is invalid; regenerate the key.
C.The network is down; check connectivity.
D.The application exceeded the rate limit of 5 calls per second; implement exponential backoff.
AnswerD

The Meraki Dashboard API enforces a per-organisation limit of five calls per second, so sustained bursts trigger 429 responses. Exponential backoff retries with progressively longer delays, letting the application recover without hammering the endpoint, directly satisfying the stem's requirement to identify the cause and adjust accordingly.

Why this answer

A 429 Too Many Requests error from the Meraki Dashboard API indicates that the application has exceeded the rate limit, which is 5 calls per second per organization. The correct adjustment is to implement exponential backoff to retry requests after increasing delays, respecting the Retry-After header if provided.

Exam trap

200-901 often tests HTTP status codes and their meanings, and candidates may confuse 429 with 400 or 401, or fail to recognize that rate limiting requires backoff rather than immediate retry.

How to eliminate wrong answers

Option A is wrong because a malformed request body would typically return a 400 Bad Request error, not 429. Option B is wrong because an invalid API key would return a 401 Unauthorized error. Option C is wrong because network connectivity issues would result in timeouts or connection errors, not a 429 status code.

346
MCQmedium

A company uses a centralized automation server that runs Ansible playbooks. What is the best security practice for storing SSH credentials?

A.Store credentials in a public repository
B.Use Ansible Vault
C.Hardcode credentials in playbooks
D.Use plain text inventory files
AnswerB

Ansible Vault encrypts sensitive variables and files at rest using AES-256, so SSH credentials are never stored as plaintext on the centralised automation server. This satisfies the stem's requirement for secure credential storage within playbook workflows.

Why this answer

Ansible Vault is the recommended security practice for encrypting sensitive data like SSH credentials. It allows you to store encrypted variables and files within your playbooks or inventory, protecting secrets at rest while enabling decryption at runtime via a password or key file. This avoids exposing credentials in plain text, which is critical for centralized automation servers that may be accessed by multiple users or integrated into CI/CD pipelines.

Exam trap

Cisco often tests the misconception that 'inventory files are safe if stored locally' or that 'hardcoding is acceptable for small teams,' but the exam expects candidates to recognize that any plain text storage of credentials violates security best practices, and Ansible Vault is the standard built-in solution for encryption.

How to eliminate wrong answers

Option A is wrong because storing credentials in a public repository exposes them to unauthorized access, violating the principle of least privilege and potentially leading to security breaches. Option C is wrong because hardcoding credentials in playbooks embeds secrets in plain text within version control, making them visible to anyone with repository access and preventing easy rotation. Option D is wrong because using plain text inventory files stores SSH credentials unencrypted, which is insecure and defeats the purpose of a centralized automation server that should enforce encryption at rest.

347
Multi-Selecteasy

A software developer is using the Cisco Webex REST API and wants to filter messages by date range. Which two query parameters should be included? (Choose two.)

Select 2 answers
A.since
B.before
C.after
D.end
E.start
AnswersB, C

The before parameter filters Webex messages to those sent prior to a specified ISO 8601 timestamp, forming the upper bound of the date range. Combined with after, it satisfies the stem's date-range filtering requirement on the messages endpoint.

Why this answer

The Cisco Webex REST API uses the 'before' and 'after' query parameters to filter messages by date range. 'before' returns messages sent before a specified date/time, and 'after' returns messages sent after a specified date/time, allowing precise range-based filtering.

Exam trap

Cisco often tests the specific parameter names used in the Webex API (before/after) versus generic terms like start/end or since/until, catching candidates who assume common naming conventions from other platforms.

348
MCQmedium

A developer is writing a script that uses the Cisco SD-WAN vManage REST API to retrieve a list of devices. The script uses the GET method to https://vmanage.example.com/dataservice/device. The API returns a 401 Unauthorized status code. Which of the following should the developer do to resolve the issue?

A.Ensure the request URL includes the correct query parameters for device filtering.
B.Include a valid authentication token in the request header.
C.Verify that the vManage server's TLS certificate is trusted by the client.
D.Change the HTTP method to POST.
AnswerB

A 401 Unauthorized response means the request lacks valid authentication credentials. The vManage API requires a session token or basic authentication. The developer should obtain a token by authenticating to the /j_security_check endpoint or using basic auth, then include it in the request header, typically as a cookie (JSESSIONID) or an Authorization header. This will allow the request to succeed.

Why this answer

The 401 Unauthorized status code indicates that the request lacks valid authentication credentials. For the Cisco SD-WAN vManage API, developers must authenticate first, usually by obtaining a session token, and then include that token in subsequent requests. Without it, the API rejects the request.

The other options address different issues such as method, TLS, or query parameters, which would produce different error codes.

Exam trap

The trap here is assuming that a 401 error is related to the request format or URL, when it specifically indicates missing or invalid authentication credentials.

349
MCQmedium

Which authentication method is used by the Cisco Meraki Dashboard API?

A.JWT token in the Authorization header
B.OAuth 2.0 token in the Authorization header
C.HTTP Basic authentication with username and password
D.API key in the X-Cisco-Meraki-API-Key header
AnswerD

The Meraki Dashboard API authenticates every call with a static API key passed in the X-Cisco-Meraki-API-Key request header, satisfying the stem's requirement for the dashboard's native authentication method. Unlike OAuth 2.0 bearer tokens, which Meraki does not issue for dashboard API access, this header-based key is the sole supported credential.

Why this answer

Meraki Dashboard API uses an API key passed in the X-Cisco-Meraki-API-Key header.

350
MCQhard

A developer is writing a unit test for a Python function that calls the Cisco DNA Center API to fetch device health. The test must not perform real network calls and should verify that the function parses a sample JSON response correctly. Which approach best satisfies these requirements?

A.Increase the requests timeout value and retry on failure so the test tolerates slow DNA Center responses.
B.Run the test against a live Cisco DNA Center sandbox and assert that the returned health values are non-empty.
C.Point the function at a recorded HTTP proxy that replays previously captured DNA Center responses.
D.Use the unittest.mock library to patch the function's requests call so it returns a mock response object whose json method yields the sample data.
AnswerD

Patching the HTTP call with unittest.mock prevents real network traffic and lets the test supply a controlled response object. The function under test then exercises its parsing logic against known JSON, producing deterministic results. This isolates the unit under test and satisfies both the no-network and parsing-verification requirements.

Why this answer

Unit tests should isolate the code under test from external systems. Patching the HTTP call with unittest.mock replaces the real request with a mock response containing sample JSON, so the parsing logic is exercised deterministically without any network traffic. Proxies, live sandboxes, and retry tuning all leave real calls in place.

Exam trap

The trap here is equating 'no live production system' with 'no network calls', when even a replay proxy or sandbox still makes real HTTP requests that break unit-test isolation.

351
MCQeasy

An engineer needs to identify which hosts are reachable in a 10.0.0.0/24 network using an automated script that does not require any credentials on the target devices. Which protocol is best suited for this task?

A.ICMP
B.CDP
C.SNMP
D.ARP
AnswerA

ICMP echo requests require no credentials on target hosts, satisfying the script's credential-free constraint. Scanning the 10.0.0.0/24 range with pings identifies which hosts respond, confirming reachability at the network layer. Unlike SNMP or WMI, ICMP needs no authentication, making it ideal for automated discovery across the subnet.

Why this answer

ICMP (Internet Control Message Protocol) is the correct choice because it provides the Echo Request and Echo Reply messages (commonly used by the 'ping' command) that can determine host reachability without requiring any authentication or credentials on the target devices. This makes ICMP ideal for an automated script that needs to probe a 10.0.0.0/24 network for live hosts, as it operates at the network layer and only requires IP connectivity.

Exam trap

Cisco often tests the distinction between protocols that require credentials (SNMP) and those that do not (ICMP), and the trap here is that candidates may choose ARP thinking it can discover hosts without credentials, but ARP only works on the local subnet and does not confirm IP-level reachability across a routed network.

How to eliminate wrong answers

Option B (CDP) is wrong because Cisco Discovery Protocol is a proprietary Layer 2 protocol used to discover directly connected Cisco devices and their capabilities; it requires the target devices to be Cisco devices with CDP enabled and does not test reachability via IP, nor does it work across routers or subnets. Option C (SNMP) is wrong because Simple Network Management Protocol requires credentials (community strings or SNMPv3 authentication) to query managed devices, and the question explicitly states no credentials are allowed. Option D (ARP) is wrong because Address Resolution Protocol resolves IP addresses to MAC addresses on a local broadcast domain; it can only detect hosts on the same subnet and requires an ARP request to be sent, but it does not confirm end-to-end reachability beyond Layer 2 and is not suitable for a /24 network that may span multiple Layer 2 segments.

352
Multi-Selectmedium

A network automation solution uses YANG data models to describe network configurations. Which THREE statements about YANG are true? (Select THREE)

Select 3 answers
A.YANG can be used in conjunction with NETCONF and RESTCONF.
B.YANG models are always written in XML syntax.
C.YANG is used to define both configuration and state data.
D.YANG is a data modeling language used to define the structure of data.
E.YANG is a replacement for SNMP.
AnswersA, C, D

Both protocols use YANG models.

Why this answer

YANG is a data modeling language that defines the structure and constraints of configuration and state data, and it is designed to be used with NETCONF (RFC 6241) and RESTCONF (RFC 8040) as the transport protocols. This makes option A correct because YANG models are encoded in XML or JSON and exchanged via these protocols.

Exam trap

Cisco often tests the misconception that YANG is tied to a specific encoding (like XML) or that it replaces SNMP entirely, when in fact YANG is encoding-agnostic and complements SNMP by providing structured, transactional configuration management.

353
MCQeasy

A network engineer needs to allow HTTPS traffic from the internet to an internal web server. Which type of firewall rule should be applied on the perimeter firewall?

A.Routing protocol configuration
B.Outbound ACL on the inside interface
C.Inbound ACL on the outside interface
D.Static NAT configuration
AnswerC

An inbound ACL on the outside interface filters traffic arriving from the internet, permitting TCP 443 to the internal web server's translated address while denying other inbound flows. This satisfies the requirement to expose HTTPS only, applied at the perimeter where untrusted traffic first enters.

Why this answer

To allow HTTPS traffic from the internet to an internal web server, you need an inbound ACL on the outside interface of the perimeter firewall. This ACL will permit TCP port 443 (HTTPS) from any external source to the public IP address of the web server (often via static NAT). Inbound ACLs filter traffic entering the firewall from the untrusted network, which is exactly where the internet traffic arrives.

Exam trap

The trap is confusing inbound and outbound ACLs; candidates may think an outbound ACL on the inside interface is needed to allow return traffic, but the initial request from the internet must be permitted by an inbound ACL on the outside interface.

How to eliminate wrong answers

Option A is wrong because routing protocol configuration is about dynamic route exchange (e.g., OSPF, BGP) and does not filter traffic. Option B is wrong because an outbound ACL on the inside interface would filter traffic leaving the internal network, not traffic coming from the internet. Option C is correct because an inbound ACL on the outside interface controls traffic entering from the internet.

Option D is wrong because static NAT configuration translates addresses but does not itself permit or deny traffic; an ACL is still required to allow the traffic.

354
MCQeasy

A developer runs the command: docker run -d -p 8080:80 --name web nginx. Which of the following best describes what happens?

A.The container runs in interactive mode, and port 8080 is exposed but not published.
B.The container is removed after stopping, and port mapping is automatic.
C.The container runs in the foreground, and port 80 on the host is mapped to port 8080 in the container.
D.The container runs in detached mode, and host port 8080 is mapped to container port 80.
AnswerD

The -d flag detaches the container, returning the terminal immediately. The -p 8080:80 flag publishes host port 8080 and forwards it to container port 80, where nginx listens. Traffic to the host's 8080 reaches nginx inside the container.

Why this answer

The `-d` flag runs the container in detached mode (in the background), and the `-p 8080:80` flag publishes host port 8080 to container port 80. The syntax for `-p` is always `hostPort:containerPort`, so traffic hitting the host on 8080 is forwarded to port 80 inside the nginx container. The `--name web` simply assigns a friendly name to the container.

Exam trap

The trap here is confusing the order of the port mapping — candidates often assume `-p 8080:80` means container 8080 to host 80, but Docker always uses host:container order.

How to eliminate wrong answers

Option A is wrong because `-d` means detached, not interactive (that would be `-it`), and `-p` actually publishes the port rather than merely exposing it. Option B is wrong because `docker run` without `--rm` does not remove the container after stopping, and port mapping is never automatic — it must be specified with `-p` or `-P`. Option C is wrong because it reverses the port mapping order; the host port comes first (8080) and the container port second (80), and `-d` runs the container in the background, not the foreground.

355
MCQeasy

Which header is used in an HTTP request to tell the server the format of the request body?

A.Authorization
B.Content-Type
C.Accept
D.Host
AnswerB

Content-Type declares the media type of the request body, letting the server parse it correctly. Without it, the server may reject the payload or misinterpret JSON as form data, so it satisfies the requirement to state the body's format.

Why this answer

Content-Type header specifies the media type of the request body, e.g., application/json.

356
MCQmedium

A developer is testing a REST API with curl and receives a response body containing JSON. They want to confirm that the payload is JSON before parsing it in code. Which HTTP response header should they check?

A.User-Agent
B.Content-Type
C.Accept
D.Content-Length
AnswerB

Content-Type is a representation header that the server sets to describe the media type of the response body, for example application/json. Checking it confirms the payload format before parsing, and a value like application/json; charset=utf-8 also indicates the character encoding, which matters when decoding the bytes.

Why this answer

The Content-Type response header is the server's declaration of the media type of the returned body. When it is application/json, the developer can safely hand the body to a JSON parser; when it is something else, such as text/html for an error page, parsing as JSON would fail. Checking this header is a standard defensive step before decoding API responses.

Exam trap

The trap here is confusing the request header Accept, which expresses what the client wants, with the response header Content-Type, which states what the server actually sent.

357
MCQmedium

A developer is writing a Python script that authenticates to a Cisco IOS XE device using NETCONF over SSH on port 830. The script must send a candidate configuration and commit it atomically. Which NETCONF capability must the device advertise for the script to use the candidate datastore?

A.urn:ietf:params:netconf:capability:writable-running:1.0
B.urn:ietf:params:netconf:capability:candidate:1.0
C.urn:ietf:params:netconf:capability:rollback-on-error:1.0
D.urn:ietf:params:netconf:capability:validate:1.1
AnswerB

The candidate capability URI is exactly what signals the device supports a separate candidate datastore that can be edited, validated, and committed atomically. Without this capability in the hello message, the client cannot legally target <candidate/> in edit-config or issue a commit, so the script would fail. Advertising this capability is a prerequisite for the transactional workflow the developer requires.

Why this answer

The candidate datastore capability is the only one that introduces a separate staging area plus a commit operation, enabling atomic configuration changes. Writable-running, rollback-on-error, and validate are separate capabilities that do not create a candidate store. When a NETCONF client must edit offline and commit transactionally, the hello message must include the candidate capability URI before the client can target candidate in edit-config.

Exam trap

The trap here is assuming that rollback-on-error or validate implies a candidate datastore, when in fact candidate is its own distinct capability URI that must be advertised independently.

358
Multi-Selectmedium

Which TWO of the following are characteristics of TLS (Transport Layer Security) used in HTTPS? (Choose two.)

Select 2 answers
A.It supports multiplexing of multiple streams.
B.It uses asymmetric encryption to exchange a symmetric session key.
C.It is an application layer protocol like HTTP.
D.It uses port 443 by default.
E.It provides server (and optionally client) certificate verification.
AnswersB, E

TLS performs an asymmetric handshake (for example, ECDHE with RSA or ECDSA signatures) to authenticate the server and negotiate a shared symmetric session key, which then encrypts bulk traffic. This hybrid approach satisfies HTTPS's need for both secure key exchange and efficient confidentiality.

Why this answer

Option B is correct because the TLS handshake uses asymmetric cryptography (e.g., RSA key transport or ECDHE for key agreement) to securely establish a shared symmetric session key, which is then used for bulk data encryption with algorithms like AES-GCM. Option E is correct because TLS authenticates the server via an X.509 certificate signed by a trusted CA, and can optionally authenticate the client through client certificates during mutual TLS. Option A is incorrect because stream multiplexing is a feature of HTTP/2 and QUIC, not TLS itself.

Option C is incorrect because TLS is a session/presentation-layer security protocol that runs between TCP and application protocols like HTTP, not an application-layer protocol. Option D is incorrect because port 443 is the default port for HTTPS, not an inherent characteristic of TLS, which can run over any port.

359
MCQmedium

A CI/CD pipeline for a microservice application includes stages: code commit, build Docker image, push to registry, deploy to staging, run integration tests, and deploy to production. The team wants to ensure that if integration tests fail, the pipeline stops and does not proceed to production. Which CI/CD concept is used to enforce this behavior?

A.Stage gates
B.Rolling update
C.Container orchestration
D.Artifact management
AnswerA

Stage gates are approval or quality checkpoints between pipeline stages that halt progression when a condition fails. Placing a gate after integration tests prevents deployment to production on test failure, directly enforcing the required stop behaviour.

Why this answer

Stage gates are conditional checkpoints in a CI/CD pipeline that evaluate predefined criteria before allowing the pipeline to proceed to the next stage. In this scenario, the integration test stage acts as a gate: if the tests fail, the gate blocks the pipeline from advancing to the production deployment stage, ensuring only validated code reaches production.

Exam trap

Cisco often tests the distinction between pipeline control mechanisms (stage gates) and deployment strategies (rolling updates), so candidates mistakenly choose a deployment method when the question is about conditional pipeline flow.

How to eliminate wrong answers

Option B (Rolling update) is wrong because it is a deployment strategy that gradually replaces instances of an application with a new version, not a mechanism to halt a pipeline based on test results. Option C (Container orchestration) is wrong because it refers to managing container lifecycles (e.g., scaling, scheduling) using tools like Kubernetes, not to pipeline conditional logic. Option D (Artifact management) is wrong because it involves storing and versioning build outputs (e.g., Docker images) in a registry like Docker Hub or Nexus, not enforcing pipeline flow control.

360
MCQmedium

A Kubernetes pod needs to read configuration data such as database hostname, which is non-sensitive and may change across environments. Which resource should be used to store this data and inject it into the pod?

A.Deployment
B.Secret
C.Service
D.ConfigMap
AnswerD

ConfigMaps hold non-sensitive configuration as key-value pairs, decoupled from pod images, so database hostnames can vary per environment without rebuilding containers. Secrets are reserved for sensitive data, making ConfigMap the appropriate resource for injection via environment variables or volumes.

Why this answer

ConfigMap stores non-sensitive configuration data. Secret stores sensitive data. Deployment and Service are for workload and networking.

361
MCQhard

A network administrator wants to use EEM on an IOS XE device to send a syslog message whenever a specific CLI command is entered. Which event detector should be used?

A.event syslog pattern
B.event interface
C.event cli match
D.event timer
AnswerC

The event cli detector triggers an EEM applet when CLI input matches a specified regular expression, which is exactly the requirement to react to a particular command being entered. Other detectors watch syslog, SNMP, timers or interface counters, none of which fire on command entry.

Why this answer

The 'event cli match' detector in EEM triggers when the CLI input on the device matches a specified regular expression pattern. This is exactly what the administrator needs: to detect when a specific CLI command is entered and then take action (send a syslog message). The 'match' keyword uses a regex to compare against the command string typed by the user.

Exam trap

The trap here is confusing event detectors: candidates might think 'event syslog pattern' can detect CLI commands because CLI commands often generate syslog messages, but the detector specifically watches syslog output, not CLI input.

How to eliminate wrong answers

Option A is wrong because 'event syslog pattern' triggers on syslog messages generated by the device, not on CLI command entry. Option B is wrong because 'event interface' triggers on interface state changes (up/down), not CLI commands. Option D is wrong because 'event timer' triggers based on a time schedule (absolute or periodic), not on CLI input.

362
MCQmedium

A developer is building a Python application that manages Cisco IOS XE devices through the Python library ncclient. The application must apply a configuration change atomically, validate it before committing, and avoid persisting the change if validation fails. Which approach should the developer take?

A.Issue a discard-changes operation against running after each edit-config to confirm the edit was accepted
B.Lock the candidate datastore, edit the candidate, validate it with the validate operation, then commit and unlock
C.Send an edit-config directly to the running datastore with the default merge operation
D.Use the copy-config operation to copy running into startup, then edit startup directly
AnswerB

The candidate datastore exists specifically to stage changes before they take effect. Locking prevents concurrent edits, the validate operation checks the staged configuration, and commit applies it only when validation succeeds. This sequence meets the atomic, validated, non-persistent-on-failure requirement and is the standard ncclient workflow for transactional configuration.

Why this answer

Transactional configuration over NETCONF depends on a staging datastore and an explicit validation step. Locking the candidate, editing it, running the validate operation, and then committing ensures the change is checked before it becomes active. If validation fails, the candidate can be discarded and running is never touched, satisfying the atomic and non-persistent requirements.

Exam trap

The trap here is treating the running datastore as if it were staged, when only the candidate datastore supports validate-then-commit semantics.

363
MCQmedium

In a Docker Compose file, you want to ensure that the 'web' service starts only after the 'db' service is healthy. Which key should you use under the 'web' service?

A.networks
B.links
C.depends_on
AnswerC

The depends_on key establishes startup ordering, but adding the condition: service_healthy form makes Compose wait until the db service's healthcheck reports healthy before starting web. This satisfies the stem's requirement that web starts only after db is genuinely healthy, not merely launched.

Why this answer

In Docker Compose, the `depends_on` key with the `condition: service_healthy` option ensures that the `web` service starts only after the `db` service has passed its health check. This is defined in the `db` service using a `healthcheck` directive, and Compose waits for the healthy state before starting dependent services.

Exam trap

The trap here is that candidates often assume `depends_on` alone (without `condition: service_healthy`) guarantees the dependent service is ready, but it only waits for the container to start, not for it to be healthy.

How to eliminate wrong answers

Option A is wrong because `networks` defines which Docker networks a service connects to, not startup ordering or dependency health. Option B is wrong because `links` is a legacy feature for network connectivity between containers (like an alias) and does not control startup order or health status; it has been superseded by user-defined networks.

364
Multi-Selecteasy

An engineer is automating the configuration of SNMP on Cisco routers using Ansible. Which two modules are commonly used for this purpose? (Select TWO)

Select 2 answers
A.cisco.ios.ios_interface
B.cisco.ios.ios_config
C.cisco.ios.ios_snmp_server
D.cisco.ios.ios_command
E.cisco.ios.ios_banner
AnswersB, C

The cisco.ios.ios_config module pushes arbitrary configuration lines, including SNMP commands such as snmp-server community and snmp-server host, to Cisco IOS devices. It satisfies the automation constraint by applying raw CLI snippets idempotently over SSH, letting Ansible configure SNMP without a dedicated SNMP-specific module.

Why this answer

The cisco.ios.ios_config module is correct because it allows you to push raw CLI configuration lines to Cisco IOS devices, including SNMP-related commands like 'snmp-server community' or 'snmp-server host'. The cisco.ios.ios_snmp_server module is correct because it is a dedicated Ansible module that provides structured, idempotent management of SNMP server settings (e.g., communities, hosts, traps) without requiring raw CLI lines.

Exam trap

Cisco often tests the distinction between general-purpose modules like ios_config and purpose-built modules like ios_snmp_server, expecting candidates to recognize that both can configure SNMP but the dedicated module is more appropriate for structured automation.

365
MCQhard

A developer is writing a Python script to interact with a Cisco Meraki Dashboard API. The script retrieves a list of organizations and then, using the organization ID, retrieves the networks for that organization. The API returns a 200 OK with a JSON body and a Link header containing a URL for the next page. The developer wants to ensure all networks are retrieved. Which approach should the developer take?

A.Parse the Link header and follow the URL for the next page until no Link header is present.
B.Parse the response for an 'offset' field and use it in subsequent requests until the offset equals the total count.
C.Use the 'perPage' query parameter set to 1000 to retrieve all networks in a single request.
D.Send the same GET request with an increased 'page' query parameter until an empty array is returned.
AnswerA

The Meraki Dashboard API uses pagination via the Link header. When more results exist, the Link header includes a rel="next" URL. By following that URL until no next link is provided, the developer can retrieve all networks. This is the correct method to handle pagination in the Meraki API.

Why this answer

The Meraki Dashboard API implements pagination using the Link header, which contains a URL for the next page of results. To retrieve all networks, the developer must follow the 'next' link until it is absent. Other methods like using a 'page' parameter, increasing 'perPage', or looking for an 'offset' field do not align with the API's design and will not work.

Exam trap

The trap here is assuming that pagination is done with simple page numbers or offsets, rather than the cursor-based Link header used by Meraki.

366
Multi-Selectmedium

Which THREE are characteristics of OSPF? (Choose three.)

Select 3 answers
A.It is a distance-vector routing protocol
B.It uses cost as the metric
C.It uses hop count as the metric
D.It is a link-state routing protocol
E.It supports Variable-Length Subnet Mask (VLSM)
AnswersB, D, E

Cost is derived from bandwidth.

Why this answer

OSPF uses cost as its metric, which is derived from the bandwidth of the interface (calculated as 10^8 / bandwidth in bps by default). This allows OSPF to select the most efficient path based on link speed rather than a simple hop count, making it suitable for larger, more complex networks.

Exam trap

Cisco often tests the distinction between OSPF (link-state, cost metric) and RIP (distance-vector, hop count metric), so the trap here is confusing OSPF's cost with RIP's hop count or assuming OSPF is distance-vector due to its routing behavior.

367
Multi-Selectmedium

Which TWO commands are used to view information about Docker containers? (Select two.)

Select 2 answers
A.docker build
B.docker logs -f
C.docker images
D.docker volume ls
E.docker ps -a
AnswersB, E

docker logs -f streams a container's stdout and stderr, following output continuously. It retrieves runtime information about a container's processes, satisfying the requirement to view container information, though it requires a container name or ID.

Why this answer

Option B, `docker logs -f`, is correct because it retrieves and follows the stdout/stderr log output of a running (or stopped) container, which is information about that container's runtime behavior. Option E, `docker ps -a`, is correct because it lists all containers, including stopped ones, showing container IDs, images, status, ports, and names. Option A, `docker build`, is wrong because it builds a new image from a Dockerfile rather than viewing container information.

Option C, `docker images`, is wrong because it lists locally stored images, not containers. Option D, `docker volume ls`, is wrong because it lists Docker volumes, which are separate storage resources, not containers.

368
MCQhard

Refer to the exhibit. A developer receives this response when making a POST request to the Cisco DNA Center API to create a new device. What is the most likely issue?

A.The request body is missing the required field 'ipAddress'.
B.The API endpoint is incorrect.
C.The device IP address is already in use.
D.The API token has expired.
AnswerA

Cisco DNA Center validates the JSON payload against its schema, and a missing mandatory attribute such as ipAddress triggers a 400 error naming that field. The response therefore indicates the body omitted a required property rather than an authentication or endpoint fault.

Why this answer

The error response includes a field 'missingParameters' with the value 'ipAddress', which explicitly indicates that the request body did not include the required 'ipAddress' field. Cisco DNA Center's API for device creation requires this field to identify the device on the network. Without it, the API cannot proceed with adding the device, resulting in a 400 Bad Request.

Exam trap

Cisco often tests the ability to read API error responses carefully, where candidates might overlook the 'missingParameters' field and incorrectly assume a token or endpoint issue instead of a missing required field.

How to eliminate wrong answers

Option B is wrong because the API endpoint is likely correct; a wrong endpoint would typically return a 404 Not Found or a different error message, not a 'missingParameters' error. Option C is wrong because if the IP address were already in use, the API would return a conflict error (e.g., 409 Conflict) with a message like 'Device already exists', not a missing field error. Option D is wrong because an expired token would result in a 401 Unauthorized or 403 Forbidden response, not a 400 Bad Request with parameter validation details.

369
MCQeasy

Refer to the exhibit. A developer is parsing the output of 'show ip route' using Python. Which regular expression would extract the prefix '10.0.1.0/24'?

A.r'^S\s+(\d+\/\d+)'
B.r'^S.*(\d+\.\d+\.\d+\.\d+)'
C.r'S\s+(\S+)'
D.r'^S\s+(\d+\.\d+\.\d+\.\d+/\d+)'
AnswerD

The pattern anchors at line start, matches the code 'S', consumes whitespace, then captures the dotted-quad prefix with its CIDR suffix via a group. Anchoring prevents matching similar addresses embedded elsewhere in the routing table output.

Why this answer

The regex `^S\s+(\d+\.\d+\.\d+\.\d+/\d+)` matches lines starting with 'S' (static route) followed by whitespace, then captures the entire prefix including both the IP address and subnet mask in CIDR notation (e.g., 10.0.1.0/24). This ensures the extracted string is exactly the prefix as it appears in the 'show ip route' output.

Exam trap

Cisco often tests the distinction between capturing only the IP address versus the full CIDR prefix, leading candidates to pick options that omit the subnet mask (like Option B) or use overly broad patterns (like Option C) that match unintended fields.

How to eliminate wrong answers

Option A is wrong because `\d+/\d+` matches only digits separated by a slash (e.g., 10/24), which does not match the dotted-decimal IP address format. Option B is wrong because `.*` is greedy and `(\d+\.\d+\.\d+\.\d+)` captures only the IP address without the subnet mask (/24), so the prefix is incomplete. Option C is wrong because `\S+` captures any non-whitespace characters after 'S', which could include the next field (e.g., the next-hop IP) rather than the prefix, and it does not anchor to the start of the line, risking false matches.

370
MCQeasy

Which HTTP method is used to partially update a resource in a RESTful API?

A.POST
B.PUT
C.UPDATE
D.PATCH
AnswerD

PATCH applies partial modifications to a resource, sending only the fields being changed rather than a complete replacement. This satisfies the stem's requirement for a partial update, unlike PUT, which overwrites the entire resource representation. PATCH therefore matches the scenario precisely.

Why this answer

The HTTP PATCH method is used to apply partial modifications to a resource. Unlike PUT, which replaces the entire resource, PATCH only updates the specified fields, making it ideal for partial updates.

Exam trap

The trap is confusing PUT with PATCH; PUT replaces the entire resource, while PATCH performs a partial update.

How to eliminate wrong answers

Option A is wrong because POST is used to create a new resource or submit data to be processed, not for partial updates. Option B is wrong because PUT replaces the entire resource with the provided representation, not a partial update. Option C is wrong because UPDATE is not a standard HTTP method; it is a common misconception.

371
Matchingmedium

Match each YAML structure to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Scalar mapping

List item

Comment line

Nested mapping

Block scalar (literal)

Why these pairings

In YAML, a mapping (dictionary) uses key: value pairs; a sequence (list) uses '- ' items; a scalar is a single value. The distractors swap definitions or apply collection concepts to scalars.

372
MCQmedium

A developer is writing a Python script that calls the Cisco Webex Teams API to create a new space. The API returns the new space object, including a Location header pointing to the newly created resource. Which HTTP status code should the developer expect from a successful space creation?

A.204 No Content
B.200 OK
C.201 Created
D.202 Accepted
AnswerC

201 Created is the correct status for a POST that successfully creates a new resource. The Webex API returns 201 along with the new space object and a Location header containing the URI of the created space. The developer can use this Location header to subsequently retrieve or modify the space. This status confirms that the resource was created and provides its canonical URL.

Why this answer

The correct status code for a successful resource creation via POST in the Webex API is 201 Created. This status indicates that the request has been fulfilled and has resulted in one or more new resources being created. The response typically includes a Location header with the URI of the new resource and a body containing the representation of the created space.

Understanding this helps developers correctly handle API responses and extract necessary identifiers.

Exam trap

The trap here is confusing 201 Created with 200 OK, assuming any successful response must be 200.

373
MCQhard

A developer is using NETCONF to retrieve the running configuration of a network device. Which operation should be used?

A.<get>
B.<copy-config>
C.<get-config>
D.<edit-config>
AnswerC

NETCONF's <get-config> operation retrieves configuration data from a specified datastore, such as <running/>, which is exactly the stem's requirement. It differs from <get>, which returns state and operational data, and from <edit-config>, which modifies configuration.

Why this answer

The <get-config> operation retrieves configuration from a datastore (e.g., running).

374
MCQhard

A team uses Git for source control. They want to ensure that all code committed to the main branch passes unit tests and linting. Which Git workflow practice best ensures this?

A.Using pre-commit hooks and CI pipeline to block failing commits
B.Trunk-based development with feature toggles
C.Feature branching with manual merge
D.GitFlow with hotfix branches
AnswerA

Pre-commit hooks catch lint and test failures locally before the commit is created, while the CI pipeline re-runs the same checks server-side and blocks merges into main. Together they enforce the constraint that no failing code reaches the main branch.

Why this answer

Pre-commit hooks run unit tests and linting locally before a commit is created, preventing failing code from entering the repository. A CI pipeline then verifies the same checks on the remote branch before allowing a merge to main, ensuring only passing code is integrated. This combination enforces quality gates at both the developer workstation and the server side, directly addressing the requirement to block failing commits.

Exam trap

Cisco often tests the distinction between a workflow that merely organizes branches (like GitFlow or trunk-based development) and one that actively enforces quality gates (like pre-commit hooks combined with CI), leading candidates to confuse branching strategies with automated validation mechanisms.

How to eliminate wrong answers

Option B is wrong because trunk-based development with feature toggles focuses on short-lived branches and hiding incomplete features behind flags, but it does not inherently enforce unit tests or linting before merging to main. Option C is wrong because feature branching with manual merge relies on human review and does not automatically run or block commits based on test or lint results, leaving the main branch vulnerable to failing code. Option D is wrong because GitFlow with hotfix branches is a branching model that structures releases and patches but provides no built-in mechanism to enforce unit tests or linting before commits reach main.

375
MCQhard

In a CI/CD pipeline for network changes, which practice best ensures that a configuration push does not disrupt production traffic?

A.Disable rollback
B.Canary deployment
C.Push all changes at once
D.Skip validation
AnswerB

Canary deployment pushes the configuration to a small subset of devices first, allowing traffic impact to be observed before fleet-wide rollout. This limits blast radius, satisfying the requirement that a configuration push does not disrupt production traffic.

Why this answer

Canary deployment is the correct practice because it gradually introduces the configuration change to a small subset of devices or traffic before full rollout. This allows monitoring for adverse effects and automatic rollback if issues arise, minimizing the risk of production disruption. In a CI/CD pipeline for network changes, this approach aligns with incremental validation and risk mitigation.

Exam trap

Cisco often tests the misconception that 'push all changes at once' is efficient and safe, but the trap here is that it ignores the principle of incremental risk reduction, which is fundamental to CI/CD best practices for network automation.

How to eliminate wrong answers

Option A is wrong because disabling rollback removes the safety net to revert a failed configuration push, increasing the risk of prolonged disruption. Option C is wrong because pushing all changes at once maximizes the blast radius and makes it difficult to isolate the cause of any failure. Option D is wrong because skipping validation bypasses critical checks (e.g., syntax, reachability, or policy compliance), which can directly cause misconfigurations that disrupt traffic.

Page 4

Page 5 of 13

Page 6