Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 376–450

975 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
Multi-Selecthard

A developer is integrating with a REST API that returns JSON error responses. The team needs to handle failures robustly in code. Which TWO practices are appropriate when processing API responses? (Choose two.)

Select 2 answers
A.Retry every failed request immediately in a tight loop until it succeeds.
B.Ignore the status code and rely solely on whether the body parses as valid JSON.
C.Check the HTTP status code before attempting to parse the response body.
D.Assume any response containing the word "error" in the body indicates a failure and raise an exception.
E.Parse the response body as JSON only after confirming the content type and that the body is non-empty.
AnswersC, E

Status codes are the primary signal of success or failure in HTTP. Checking them first prevents the code from misinterpreting an error payload as valid data. For example, a 404 or 500 may return a different JSON shape than a 200, so branching on the status code avoids schema errors and lets the program route to error handling cleanly.

Why this answer

Robust API clients branch on the HTTP status code first, then guard JSON parsing by checking the content type and body presence. This ordering prevents schema mismatches when error payloads differ from success payloads and avoids parser exceptions on empty or non-JSON responses. These two practices together form a reliable foundation for error handling in any REST integration.

Exam trap

The trap here is assuming that a body which parses as JSON proves success, when error responses frequently return valid JSON with non-2xx status codes.

377
MCQhard

Which wireless security standard provides the strongest encryption and is recommended for enterprise networks as of 2023?

A.WEP
B.TKIP
C.WPA3
D.WPA2
AnswerC

WPA3 mandates SAE (Simultaneous Authentication of Equals), replacing WPA2's PSK handshake and providing forward secrecy plus 192-bit Enterprise mode. That stronger encryption and resistance to offline dictionary attacks make it the recommended enterprise standard, satisfying the 2023 requirement.

Why this answer

WPA3 is the latest standard with stronger encryption (SAE) and is recommended for modern networks.

378
Multi-Selectmedium

An administrator is configuring DNS records for a company's domain. Which three DNS record types are most commonly used to map hostnames to IP addresses or aliases? (Choose three.)

Select 3 answers
A.AAAA
B.CNAME
C.A
D.MX
E.PTR
AnswersA, B, C

AAAA records map a hostname to an IPv6 address, satisfying the requirement to resolve names to IP addresses. Where A records handle IPv4, AAAA provides the 128-bit equivalent, making it one of the standard hostname-to-address mappings alongside A and CNAME.

Why this answer

Option A (AAAA) is correct because an AAAA record maps a hostname to an IPv6 address, directly fulfilling the hostname-to-IP mapping purpose. Option B (CNAME) is correct because a Canonical Name record creates an alias from one hostname to another hostname, which is the alias-mapping function described in the question. Option C (A) is correct because an A record maps a hostname to an IPv4 address, the most fundamental hostname-to-IP mapping.

Option D (MX) is not correct here because MX records designate mail exchangers for email delivery, not hostname-to-IP or alias mapping. Option E (PTR) is not correct because PTR records provide reverse DNS lookups, mapping IP addresses back to hostnames rather than hostnames to IP addresses.

Exam trap

Cisco often tests the distinction between forward-mapping records (A, AAAA, CNAME) and service-specific or reverse records (MX, PTR), leading candidates to mistakenly include MX or PTR when the question explicitly asks for hostname-to-IP or alias mapping.

379
Multi-Selecthard

Which THREE of the following are common design patterns for microservices? (Choose three.)

Select 3 answers
A.Chain of Responsibility
B.Circuit Breaker
C.Singleton
D.Service Registry
E.API Gateway
AnswersB, D, E

Circuit Breaker isolates failing downstream dependencies by tripping to an open state after a threshold of errors, returning fallback responses instead of cascading timeouts. This satisfies the stem's requirement for a common microservices design pattern, preventing a single unavailable service from exhausting threads and degrading the entire distributed system.

Why this answer

The Circuit Breaker pattern (B) is a core microservices resilience pattern: it wraps calls to a remote service and, after a threshold of failures, 'trips' to fail fast instead of letting threads pile up on a slow or dead dependency, allowing recovery via half-open probing. Service Registry (D) is a standard microservices pattern for dynamic service discovery, where instances register their network locations (e.g., with Eureka or Consul) so consumers can locate healthy instances without hardcoded endpoints. API Gateway (E) is the canonical edge pattern: a single entry point that routes requests to backend microservices and centralizes cross-cutting concerns such as authentication, rate limiting, and response aggregation.

By contrast, Chain of Responsibility (A) is a general GoF behavioral pattern for passing a request along a handler chain, not specific to microservice architecture, and Singleton (C) is a GoF creational pattern that is actually discouraged in microservices because shared global state undermines independent deployability and horizontal scaling.

Exam trap

Cisco often tests the distinction between general software design patterns (like Singleton or Chain of Responsibility) and patterns specifically designed for microservices architecture, such as Circuit Breaker, Service Registry, and API Gateway.

380
MCQeasy

In a docker-compose.yaml file, which key is used to define the container image to be built from a Dockerfile in the current directory?

A.dockerfile
B.image
C.context
D.build
AnswerD

The build key names the directory containing the Dockerfile, so Compose builds the image from that context rather than pulling a prebuilt one. Specifying image alone would only tag or fetch an existing image, failing the requirement to build from the current directory.

Why this answer

The `build` key in a docker-compose.yaml file specifies the build context and optionally the Dockerfile location, instructing Docker Compose to build an image from a Dockerfile in the current directory. This is the correct key for building an image rather than using a pre-built one.

Exam trap

200-901 often tests the confusion between `build` and `image` keys, so candidates may choose `image` thinking it builds, but `image` only specifies a pre-built image.

How to eliminate wrong answers

Option A is wrong because `dockerfile` is not a top-level key; it is a sub-key under `build` to specify an alternative Dockerfile name. Option B is wrong because `image` specifies a pre-built image to pull from a registry, not to build from a Dockerfile. Option C is wrong because `context` is a sub-key under `build` that sets the build context path, but it is not the key that triggers a build.

381
MCQmedium

A developer is designing a microservices architecture for a network monitoring application. Which of the following is a key advantage of microservices over a monolithic architecture?

A.Lower latency due to in-process communication
B.Easier to maintain as a single codebase
C.Independent deployability and scalability of services
D.Simpler inter-service communication
AnswerC

Each microservice runs as a separate deployable unit, so teams can release and scale it independently without rebuilding the whole application. A monolith must be deployed and scaled as one artefact, which is the constraint this advantage directly addresses.

Why this answer

Microservices architecture enables each service to be deployed, updated, and scaled independently without affecting other services. This is a key advantage over monolithic architectures, where any change requires rebuilding and redeploying the entire application. For a network monitoring application, independent scalability allows resource-intensive services (e.g., packet capture) to scale separately from lightweight services (e.g., alerting).

Exam trap

Cisco often tests the misconception that microservices simplify communication or reduce latency, when in reality they introduce network overhead and complexity, making independent deployability and scalability the primary advantage.

How to eliminate wrong answers

Option A is wrong because microservices typically use inter-process communication (e.g., HTTP/REST, gRPC, or message queues), which introduces higher latency compared to in-process function calls in a monolithic application. Option B is wrong because microservices split the codebase into multiple smaller repositories, each maintained by separate teams, making the overall system more complex to manage than a single monolithic codebase. Option D is wrong because inter-service communication in microservices is inherently complex, requiring handling of network failures, serialization, and service discovery (e.g., via Consul or Kubernetes DNS), unlike monolithic architectures where components communicate via direct function calls.

382
MCQmedium

Refer to the exhibit. A network engineer runs a script that queries the Cisco DNA Center site health API. The response shows Branch1 with a healthScore of 10. What is the most likely action to improve Branch1's health?

A.Investigate the network devices and connectivity at Branch1.
B.Increase the number of clients at Branch1.
C.Check the API authentication token.
D.Use a different API version.
AnswerA

A healthScore of 10 is very low, indicating genuine degradation rather than a reporting quirk. The score aggregates device reachability, client onboarding and performance, so examining Branch1's devices and links is the appropriate first diagnostic step.

Why this answer

A healthScore of 10 on a scale of 0–100 indicates severe degradation, typically caused by network device failures, link flaps, or connectivity loss. Investigating the network devices and connectivity at Branch1 is the correct first step to identify and resolve the root cause, such as a down switch or a routing issue.

Exam trap

Cisco often tests the misconception that API response issues (like authentication or version) are the cause of low health scores, when in fact the API is correctly reporting a real network fault that must be investigated on the infrastructure side.

How to eliminate wrong answers

Option B is wrong because increasing the number of clients would likely worsen the health score by adding more load to an already failing network, and client count is not a direct lever for improving device or site health. Option C is wrong because the script successfully queried the API and received a valid response (healthScore of 10), so the authentication token is valid and not the issue. Option D is wrong because the API version is irrelevant to the health score value; using a different version would not change the underlying network condition that caused the low score.

383
MCQhard

A developer is designing a CI/CD pipeline that deploys to production. The team wants to ensure that a failed security scan blocks the deployment automatically. Which pipeline design element should be implemented?

A.Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit
B.Schedule the security scan as a nightly job separate from the pipeline
C.Run the security scan in parallel with deployment to save time
D.Configure the scan to only warn and continue on findings
AnswerA

Configuring the deploy stage to depend on a successful security scan, and having the scan return a non-zero exit code on findings, causes the pipeline to halt before deployment. This enforces the gate automatically without manual intervention. It is the standard way to make quality checks mandatory in CI/CD.

Why this answer

A security gate must be part of the pipeline flow and able to fail the build. Making the deploy stage depend on a successful scan, with the scanner exiting non-zero on violations, ensures vulnerable artifacts never reach production. Parallel or advisory scans cannot enforce this requirement.

Exam trap

The trap here is confusing visibility with enforcement, assuming that generating scan reports is enough when the pipeline must actually fail to block deployment.

384
Multi-Selectmedium

A developer is writing a Python script to interact with a Cisco IOS XE device using the NETCONF protocol. The script must retrieve the running configuration and then modify it. Which two actions must the script perform to establish a NETCONF session and retrieve the running configuration? (Choose two.)

Select 2 answers
A.Open an SSH session to the device on port 830 and exchange <hello> messages.
B.Send a <get> RPC with a filter of <config/> to retrieve the running configuration.
C.Send a <get-config> RPC with a <source> of <running/> to retrieve the running configuration.
D.Authenticate using the NETCONF username and password over HTTPS on port 443.
E.Use the <copy-config> RPC to copy the running datastore to a local file.
AnswersA, C

NETCONF uses SSH as its transport, and the default port is 830. After the SSH connection is established, the server and client exchange <hello> messages to advertise capabilities and session IDs. This handshake is mandatory before any RPCs can be sent, so opening the SSH session and exchanging hellos is a required step.

Why this answer

To establish a NETCONF session, the client opens an SSH connection to port 830 and exchanges <hello> messages with the server. Once the session is established, the client can send RPCs. To retrieve the running configuration, the client sends a <get-config> RPC with <source><running/></source>.

The other options either use the wrong RPC, the wrong transport, or an operation that does not read configuration into the session.

Exam trap

The trap here is confusing NETCONF with RESTCONF, leading to assumptions about HTTPS and port 443, or mixing up the <get> and <get-config> RPCs.

385
MCQmedium

In HTTP/2, which feature allows multiple concurrent requests and responses to be interleaved on a single connection, improving performance?

A.Header compression (HPACK)
B.Server push
C.Multiplexing
D.Binary framing
AnswerC

HTTP/2 multiplexing lets many request/response streams share one TCP connection, interleaving frames so no stream blocks another. This removes HTTP/1.1's head-of-line queuing per connection, directly satisfying the stem's requirement for concurrent, interleaved exchanges on a single connection.

Why this answer

HTTP/2 multiplexing allows multiple streams to be sent concurrently over a single TCP connection, reducing head-of-line blocking.

386
Multi-Selecteasy

Which TWO of the following are essential steps in a typical Git workflow when collaborating on a feature branch? (Choose two.)

Select 2 answers
A.Rebase onto master
B.Merge the branch into master
C.Delete the remote repository
D.Stash changes before switching branches
E.Create a branch
AnswersB, E

Merging the feature branch into master integrates completed work into the mainline, satisfying the collaboration requirement that changes reach the shared repository. In a typical Git workflow, the branch's commits are combined via merge, making the feature available to all collaborators before the branch is deleted.

Why this answer

Option E (Create a branch) is essential because a feature branch isolates new work from the mainline, allowing commits to be made without affecting master until the work is ready. Option B (Merge the branch into master) is essential because the completed feature must be integrated back into the mainline so other collaborators can build on it. Option A (Rebase onto master) is a valid but optional technique for updating or linearizing history, not a required step in every workflow.

Option C (Delete the remote repository) is destructive and unrelated to normal collaboration. Option D (Stash changes before switching branches) is only a convenience when the working tree is dirty, not an essential step of the workflow.

387
MCQmedium

A developer is designing an API that needs to support rate limiting per API key. The application is deployed on multiple instances. Which approach ensures consistent rate limiting across all instances?

A.Use a local in-memory counter
B.Use a file-based lock
C.Use environment variables
D.Use a distributed cache like Redis
AnswerD

Redis provides a shared, centralised counter store that every application instance reads and writes atomically, so per-API-key request counts remain consistent regardless of which instance handles a request. This satisfies the stem's multi-instance constraint, unlike in-memory limiting, which fragments state across instances and permits exceeding the intended quota.

Why this answer

A distributed cache like Redis provides a shared, atomic counter that all application instances can read and increment, ensuring consistent rate limiting across a multi-instance deployment. Redis supports atomic operations like INCR and EXPIRE, which are essential for implementing sliding window or token bucket algorithms without race conditions.

Exam trap

Cisco often tests the misconception that local counters or environment variables can be used for distributed state, when in fact they lack the shared, atomic, and persistent storage required for multi-instance rate limiting.

How to eliminate wrong answers

Option A is wrong because a local in-memory counter is per-instance and cannot synchronize across multiple instances, leading to inconsistent rate limits. Option B is wrong because a file-based lock introduces severe performance bottlenecks and is not designed for high-throughput distributed systems; it also fails to provide atomic counters. Option C is wrong because environment variables are static configuration values and cannot be dynamically updated or shared across instances to track real-time request counts.

388
MCQmedium

A Cisco Webex bot needs to receive real-time notifications when new messages are posted in a space. Which API feature should the bot use?

A.Server-Sent Events (SSE)
B.Polling the /messages endpoint every second
C.Webhooks via the /webhooks API
D.Long polling with a keep-alive connection
AnswerC

Webhooks let the bot register a target URL with the /webhooks API; Webex then pushes HTTP POST notifications when messages are posted in the space. This satisfies the real-time requirement without polling, unlike continuously querying the messages endpoint.

Why this answer

Webex Webhooks allow real-time event notifications; the bot registers a webhook with a target URL that receives POST requests when events occur.

389
MCQeasy

A developer needs to partially update a Meraki network's configuration, changing only the time zone. Which HTTP method should be used on the network resource?

A.PUT
B.PATCH
C.DELETE
D.POST
AnswerB

PATCH sends only the changed attribute, here the time zone, leaving all other network settings untouched. PUT would require submitting the complete network configuration, risking unintended overwrites, so PATCH satisfies the partial-update constraint in the stem.

Why this answer

PATCH is used for partial updates in REST APIs.

390
MCQhard

An organization uses a private Docker registry with TLS. A developer attempts to pull an image and receives the error: "x509: certificate signed by unknown authority". What is the most likely cause and solution?

A.Add the CA certificate to the client's trust store
B.Use the registry's IP address instead of hostname
C.Disable TLS verification on the client
D.Use HTTP instead of HTTPS
AnswerA

The x509 error means the registry's certificate chains to a CA absent from the client's trust store. Installing that CA certificate into the Docker daemon's trusted certificates directory lets the client validate the registry's TLS chain, resolving the pull failure described in the stem.

Why this answer

The error 'x509: certificate signed by unknown authority' occurs because the Docker client does not recognize the certificate authority (CA) that signed the registry's TLS certificate. The correct solution is to add the CA certificate to the client's trust store, typically by placing it in /etc/docker/certs.d/<registry_hostname>:<port>/ca.crt on Linux or the equivalent Docker certs directory on other platforms. This allows the Docker daemon to validate the registry's certificate during the TLS handshake.

Exam trap

The trap here is that candidates may confuse a certificate trust issue with a hostname mismatch or think disabling TLS is an acceptable workaround, but Cisco specifically tests the understanding that the correct enterprise-grade fix is to trust the CA, not to weaken security.

How to eliminate wrong answers

Option B is wrong because using the registry's IP address instead of hostname does not resolve a certificate trust issue; it may cause a hostname mismatch error if the certificate is issued to a specific hostname, but the root cause is the untrusted CA, not the address format. Option C is wrong because disabling TLS verification (e.g., setting 'insecure-registries' in Docker daemon config) bypasses security entirely and is not a best practice; it exposes the connection to man-in-the-middle attacks and is not the intended fix for a missing CA certificate. Option D is wrong because using HTTP instead of HTTPS would eliminate TLS entirely, but the registry is configured with TLS and likely rejects plain HTTP connections; this also compromises security and does not address the trust issue.

391
MCQeasy

A team uses GitHub for version control and wants Jenkins to automatically run tests when changes are pushed to the main branch. Which trigger should be configured in the Jenkins job?

A.Cron job on the Jenkins server
B.Poll SCM every minute
C.Manual build trigger
D.GitHub webhook
AnswerD

A GitHub webhook pushes an event to Jenkins the moment code is pushed to main, triggering the job automatically. This satisfies the requirement for tests to run on push, unlike polling, which introduces delay and unnecessary load.

Why this answer

D is correct because a GitHub webhook sends an HTTP POST payload to Jenkins whenever a push event occurs on the main branch, triggering the Jenkins job in real time. This is the most efficient and immediate way to automate CI/CD pipelines in response to code changes, avoiding the need for polling or manual intervention.

Exam trap

Cisco often tests the distinction between event-driven triggers (webhooks) and polling-based triggers (Poll SCM), where candidates mistakenly choose Poll SCM because it is a familiar Jenkins feature, but the question explicitly asks for automatic triggering on push, which webhooks handle without delay.

How to eliminate wrong answers

Option A is wrong because a cron job on the Jenkins server would run builds on a fixed schedule, not in response to a specific Git push event, leading to unnecessary builds or delays. Option B is wrong because Poll SCM every minute checks the repository periodically, which introduces latency and wastes resources compared to an event-driven webhook; it also does not guarantee immediate triggering. Option C is wrong because a manual build trigger requires a user to click 'Build Now' in Jenkins, which defeats the purpose of automated CI when changes are pushed.

392
MCQmedium

An engineer is writing a script that calls the Cisco DNA Center API to create a new site. The API requires the request body to be encoded as JSON. Which HTTP request header should the script set so the server interprets the payload correctly?

A.Authorization: Bearer <token>
B.Content-Type: application/json
C.Accept: application/json
D.Content-Length: application/json
AnswerB

The Content-Type header declares the media type of the entity body in the request, so setting it to application/json tells Cisco DNA Center to parse the create-site payload as JSON rather than form-encoded or plain text. Without it, the server may reject the request with 415 Unsupported Media Type or misinterpret the body, making this the correct header for the scenario.

Why this answer

Content-Type describes the media type of the request body, which is exactly what a server needs in order to parse a JSON payload. Cisco DNA Center's create-site operation expects application/json, so the client must send that header or risk a 415 error. Accept negotiates the response format, Authorization supplies credentials, and Content-Length must be a byte count, so none of those substitutes for declaring the request body encoding.

Exam trap

The trap here is confusing Accept, which describes what the client wants back, with Content-Type, which describes what the client is sending.

393
MCQeasy

A network automation engineer wants to retrieve a list of all network devices from Cisco DNA Center. Which HTTP method and URL path should be used with the DNAC intent API?

A.PUT /dna/intent/api/v1/network-device
B.POST /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/network-device
D.DELETE /dna/intent/api/v1/network-device
AnswerC

Retrieving devices is a read operation, so GET is correct; the intent API path /dna/intent/api/v1/network-device returns the device inventory collection. POST would create resources and PUT would replace them, so GET against that exact path satisfies the stem's requirement.

Why this answer

The intent API uses GET to retrieve data, and /dna/intent/api/v1/network-device is the correct path for listing network devices.

394
MCQeasy

A DevOps engineer wants to automate the configuration of network devices using Ansible. Which file format is commonly used for Ansible playbooks?

A.INI
B.YAML
C.XML
D.JSON
AnswerB

Ansible playbooks are written in YAML, a human-readable data-serialisation format using indentation-based structure. This satisfies the stem's requirement for the file format commonly used to define Ansible automation tasks, since YAML's declarative syntax maps directly onto Ansible's task, play and inventory constructs.

Why this answer

Ansible playbooks are written in YAML (YAML Ain't Markup Language) because YAML is human-readable, supports complex data structures like lists and dictionaries, and is designed for configuration files. YAML's indentation-based syntax aligns with Ansible's declarative automation model, making it the default and recommended format for defining tasks, variables, and handlers in playbooks.

Exam trap

Cisco often tests the distinction between Ansible inventory files (which can use INI or YAML) and playbook files (which exclusively use YAML), causing candidates to incorrectly associate INI with playbooks.

How to eliminate wrong answers

Option A is wrong because INI files are used for Ansible inventory definitions (e.g., listing hosts and groups), not for playbooks; playbooks require a structured format that supports sequences and mappings, which INI lacks. Option C is wrong because XML is verbose, less human-readable, and not natively supported by Ansible for playbooks; Ansible uses YAML for its simplicity and readability. Option D is wrong because JSON, while valid for some Ansible configurations (e.g., dynamic inventory scripts), is not the standard format for playbooks; YAML is preferred for its cleaner syntax and reduced boilerplate.

395
MCQhard

A team is designing a CI/CD pipeline that uses the Cisco ACI REST API to deploy tenant policies. Which best practice should be followed for secure credential management?

A.Store credentials in plain text in the pipeline configuration
B.Use a secrets management service and reference it in the pipeline
C.Hardcode credentials in the source code
D.Use a shared user account with no MFA
AnswerB

Hard-coded credentials in pipeline scripts or repositories leak through logs and version control. A dedicated secrets management service stores the ACI credentials externally and injects them at runtime, so the pipeline references the secret rather than embedding it, satisfying the secure credential management requirement.

Why this answer

Using a secrets management service (such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault) and referencing it from the pipeline is the recommended best practice for securing credentials used by the Cisco ACI REST API. This centralizes secret storage, enables rotation, enforces access controls, and keeps credentials out of code and configuration files. It aligns with zero-trust and least-privilege principles.

Exam trap

200-901 often tests secure credential handling — candidates may pick a convenient but insecure option like plain-text config or hardcoding, missing that secrets management with runtime injection is the expected best practice.

How to eliminate wrong answers

Option A is wrong because storing credentials in plain text in the pipeline configuration exposes them to anyone with repository or pipeline access and violates basic secret management hygiene. Option C is wrong because hardcoding credentials in source code embeds secrets in version control history, making them extremely difficult to rotate and highly vulnerable to leakage. Option D is wrong because a shared user account with no MFA eliminates accountability, prevents least-privilege enforcement, and removes a critical authentication control, increasing the blast radius of any compromise.

396
MCQhard

A developer maintains a Python library that is published to a package index and consumed by other teams. The build pipeline should ensure that a compromised maintainer account cannot publish a malicious version under the project's name. Which control should be configured on the pipeline?

A.Pin dependency versions in requirements.txt so downstream installs are reproducible.
B.Enable two-factor authentication on the publishing account and use API tokens scoped to the project.
C.Sign release artifacts with a key held in the CI system's trusted identity and have consumers verify the signature.
D.Run a linter and static analysis over the source before each publish step.
AnswerC

Digital signatures bind the released artifact to a private key that only the trusted pipeline can use, so a stolen account credential alone cannot forge a valid release. Consumers who verify the signature reject artifacts not signed by the expected key. This provides the cryptographic guarantee that a compromised account cannot publish malicious code that passes verification.

Why this answer

Preventing a compromised account from publishing malicious code requires a control that does not depend solely on that account's credentials. Artifact signing with a key controlled by the trusted pipeline ties each release to a verifiable identity, and consumers who check the signature will reject anything not signed by that key. Account hardening, dependency pinning, and source analysis improve security elsewhere but cannot stop an authorized-but-malicious publish.

Exam trap

The trap here is assuming that stronger login controls prevent malicious publishing, when a stolen credential can still produce a validly uploaded artifact unless releases are cryptographically signed.

397
Multi-Selecthard

A developer is preparing a Python script that will be shared with a team and run in multiple environments. The script relies on several third-party libraries. Which TWO practices should be followed to ensure reproducible dependency management? (Choose two.)

Select 2 answers
A.Install packages globally with pip install --user to avoid permission issues.
B.Commit the entire virtual environment directory to the Git repository.
C.Pin exact versions of dependencies in a requirements.txt file using the == operator.
D.Rely on the latest versions of dependencies by omitting version specifiers in requirements.txt.
E.Use a virtual environment to isolate project dependencies from the system Python installation.
AnswersC, E

Pinning exact versions with == ensures that every environment installs the same package versions, preventing unexpected behavior from newer releases. This is a cornerstone of reproducible builds. When combined with a virtual environment, it guarantees that the dependencies resolved during development match those in testing and production, which is essential for collaborative projects and consistent API interactions.

Why this answer

Reproducible dependency management requires isolating project packages and recording exact versions. A virtual environment prevents interference from system-wide packages, while pinning versions in requirements.txt ensures that every installation uses the same releases. Together they allow any team member or CI system to recreate the exact environment.

Global installs, unpinned versions, and committing the virtual environment all introduce variability and are not recommended.

Exam trap

The trap here is thinking that installing packages globally or omitting version pins is acceptable for shared projects, when both practices lead to inconsistent environments.

398
MCQeasy

A developer is integrating a Python script with the Cisco Webex API. The script needs to read the value of the HTTP status code returned by the API to decide whether to retry a request. Using the requests library, which attribute of the response object should the developer inspect?

A.response.headers['Status']
B.response.reason
C.response.status_code
D.response.ok
AnswerC

The requests library exposes the numeric HTTP status code of the server's reply through the status_code attribute, so a script can compare it against values such as 200, 401, or 429 and branch its retry logic accordingly. This is the standard, documented way to read the code without parsing the raw message, making it the right choice for a Webex integration that must react to rate limiting or authentication failures.

Why this answer

The requests library parses the HTTP status line of the server response and stores the numeric code in the status_code attribute. A client integrating with the Webex API reads that integer to detect conditions such as 401 for bad tokens or 429 for rate limiting, then decides whether to retry, refresh credentials, or fail. The boolean ok, the reason phrase, and header lookups do not provide the exact numeric value needed.

Exam trap

The trap here is assuming that a boolean success indicator such as ok carries the same information as the numeric status code, when it collapses every failure into a single False.

399
MCQmedium

A developer writes a web application that accepts user input and displays it on a page. To prevent cross-site scripting (XSS), what is the most effective defense?

A.Implement output encoding when rendering user input in HTML.
B.Use parameterized queries for all database access.
C.Store user input in a secure cookie.
D.Disable JavaScript in the browser.
AnswerA

Output encoding converts user-supplied characters into safe HTML entities before rendering, so injected script tags are displayed as text rather than executed. This directly neutralises the stored or reflected XSS vector described in the stem.

Why this answer

Output encoding converts special characters (e.g., < >) to HTML entities, so the browser does not interpret them as code. Input validation alone is insufficient for XSS.

400
MCQmedium

A developer is designing a Python script that uses the NSO (Network Services Orchestrator) northbound API. Which data format is natively supported by NSO's RESTCONF API?

A.YAML only
B.JSON only
C.XML only
D.JSON and XML
AnswerD

NSO's RESTCONF northbound API natively supports both JSON and XML payloads, satisfying the requirement for formats the interface accepts without conversion. YAML is used for service models but is not a native RESTCONF media type.

Why this answer

NSO's RESTCONF API natively supports both JSON and XML data formats, as defined by RFC 8040. RESTCONF uses HTTP methods to manipulate YANG-defined data, and the API can serialize data in either JSON (application/yang-data+json) or XML (application/yang-data+xml) based on the Accept header or Content-Type in the request. This dual-format support allows developers to choose the format that best fits their application's ecosystem.

Exam trap

Cisco often tests the misconception that RESTCONF only supports one format (typically JSON) because of its popularity in modern APIs, but the standard explicitly mandates support for both JSON and XML.

How to eliminate wrong answers

Option A is wrong because YAML is not a natively supported data format for NSO's RESTCONF API; RESTCONF specifically uses JSON and XML as per RFC 8040, and YAML is not defined in the standard. Option B is wrong because while JSON is supported, it is not the only format; RESTCONF also supports XML, so stating 'JSON only' is incorrect. Option C is wrong because XML is supported, but it is not the exclusive format; RESTCONF equally supports JSON, making 'XML only' a false limitation.

401
MCQmedium

A network application requires reliable, ordered delivery of data and uses a three-way handshake to establish a connection. Which transport protocol is being used?

A.UDP
B.ICMP
C.TCP
D.IP
AnswerC

TCP guarantees reliable, ordered delivery through sequence numbers, acknowledgements and retransmission, and establishes connections via the three-way SYN, SYN-ACK, ACK handshake. This satisfies the stem's explicit requirements for both ordered reliable delivery and handshake-based connection establishment, which connectionless UDP cannot provide.

Why this answer

TCP is a connection-oriented protocol that provides reliable, ordered delivery and uses a three-way handshake (SYN, SYN-ACK, ACK) to establish a connection.

402
MCQhard

A developer is using the Meraki Dashboard API and receives an HTTP 429 status code with a Retry-After header. What is the correct interpretation?

A.The API key is invalid and the request should be re-authenticated.
B.The rate limit has been exceeded; the client should wait the number of seconds specified in Retry-After before retrying.
C.The server is temporarily unavailable; the client should retry immediately.
D.The request was successful but the response is too large.
AnswerB

HTTP 429 signals the Meraki Dashboard API rate limit has been exceeded. The Retry-After header specifies the number of seconds the client must wait before issuing another request; retrying earlier risks further throttling. This is a throttling response, not an authentication or server error.

Why this answer

HTTP 429 status code indicates 'Too Many Requests', meaning the client has exceeded the rate limit imposed by the Meraki Dashboard API. The Retry-After header specifies the number of seconds the client must wait before sending a new request to avoid further throttling. This is a standard rate-limiting mechanism defined in RFC 6585.

Exam trap

Cisco often tests the distinction between HTTP 429 (rate limiting) and 503 (server unavailable), and candidates may confuse Retry-After with a suggestion rather than a mandatory wait period.

How to eliminate wrong answers

Option A is wrong because an invalid API key would result in a 401 Unauthorized or 403 Forbidden status, not 429. Option C is wrong because a 429 status specifically indicates rate limiting, not server unavailability (which would be 503 Service Unavailable), and retrying immediately would continue to exceed the limit. Option D is wrong because a successful request returns a 2xx status code, and a response that is too large would typically result in a 413 Payload Too Large or be handled via pagination, not a 429.

403
Multi-Selecthard

Which TWO of the following are features of the DNA Center 'Platform' API category?

Select 2 answers
A.Template deployment
B.Path trace
C.Task management
D.Event notifications
E.Device inventory
AnswersC, D

Task management belongs to the Platform API category, exposing asynchronous job operations such as checking task status and results. It lets callers track long-running operations initiated through other DNA Center APIs, distinct from Intent or Know Your Network categories.

Why this answer

The Platform category includes event notifications and task management.

404
MCQhard

A network administrator is troubleshooting BGP path selection for a route received from two different ISPs. The routes have the same local preference and AS-path length, but one route has a shorter MED value. Which route will be preferred?

A.The route with the most specific prefix length
B.The route from the ISP with the higher bandwidth
C.The route with the lower MED
D.The route with the higher local preference
AnswerC

Multi-Exit Discriminator is evaluated after local preference and AS-path length in BGP best-path selection, and a lower MED is preferred. Since both routes tie on the earlier attributes, the shorter MED wins, satisfying the stem's stated tie-breaking condition.

Why this answer

In BGP path selection, when routes have the same local preference and AS-path length, the next tiebreaker is the Multi-Exit Discriminator (MED) value. A lower MED value is preferred because it indicates a more desirable entry point into the neighboring AS. Therefore, the route with the shorter MED will be selected.

Exam trap

Cisco often tests the order of BGP path selection steps, and the trap here is that candidates may confuse MED with local preference or AS-path length, or incorrectly think that prefix length or bandwidth plays a role in BGP best-path selection.

How to eliminate wrong answers

Option A is wrong because prefix length (most specific route) is not a BGP path selection attribute; it is used in the routing table for longest-prefix match, not for BGP best-path decision. Option B is wrong because bandwidth is not a standard BGP attribute and is not considered in the BGP path selection algorithm; BGP relies on configured metrics like MED, not physical link speed. Option D is wrong because the question states both routes have the same local preference, so this attribute cannot differentiate them; higher local preference would only matter if they were different.

405
MCQeasy

A network automation team wants to run a Python script that uses the ncclient library to retrieve configuration from a Cisco IOS XE device over NETCONF. The device is reachable on TCP port 830. Which transport and port combination must the script use?

A.HTTP transport on TCP port 80
B.SSH transport on TCP port 22
C.SSH transport on TCP port 830
D.TLS transport on TCP port 6513
AnswerC

NETCONF runs over an SSH subsystem and Cisco IOS XE listens on TCP port 830 for NETCONF sessions. The ncclient library's connect method uses the SSH transport by default, so specifying port 830 with SSH is the correct combination for retrieving configuration from the device.

Why this answer

NETCONF on Cisco IOS XE is exposed as an SSH subsystem on TCP port 830. The ncclient library negotiates the SSH transport and then exchanges XML capabilities and RPCs. Using SSH on the NETCONF port is the documented combination, so the script must target TCP 830 rather than the standard CLI port or a TLS-based alternative.

Exam trap

The trap here is confusing the standard SSH CLI port 22 with the dedicated NETCONF-over-SSH port 830, which serve different services on the same device.

406
MCQeasy

A company is designing a new branch network. They want to segment traffic into separate broadcast domains to improve security and reduce broadcast traffic. Which technology should be used to achieve this?

A.Spanning Tree Protocol
B.Subnetting
C.EtherChannel
D.VLANs
AnswerD

VLANs logically partition a single physical switch into isolated Layer 2 segments, each forming its own broadcast domain. This directly satisfies the requirement to separate broadcast domains, cutting broadcast traffic and enforcing segmentation between groups without additional hardware.

Why this answer

VLANs (Virtual Local Area Networks) segment a physical network into multiple logical broadcast domains at Layer 2. By assigning different VLANs to different groups of devices, broadcast traffic is confined to the VLAN, reducing unnecessary propagation and improving security by isolating traffic between segments.

Exam trap

Cisco often tests the misconception that subnetting alone can create broadcast domains, but subnetting is a Layer 3 concept while VLANs are the Layer 2 technology that actually isolates broadcast traffic at the data link layer.

How to eliminate wrong answers

Option A is wrong because Spanning Tree Protocol (STP) prevents loops in redundant Layer 2 topologies by blocking specific ports; it does not create broadcast domains. Option B is wrong because subnetting operates at Layer 3 (IP addressing) to create separate IP networks, but it does not inherently segment broadcast domains at Layer 2; VLANs are the Layer 2 mechanism for broadcast domain separation. Option C is wrong because EtherChannel aggregates multiple physical links into a single logical link for increased bandwidth and redundancy; it does not affect broadcast domain segmentation.

407
MCQmedium

A team is using Git for version control. A developer accidentally committed a sensitive file. Which Git command should be used to remove the file from the repository history while keeping it locally?

A.git rebase -i
B.git reset --soft
C.git rm --cached
D.git filter-branch
AnswerD

git filter-branch rewrites commits across the entire repository history, stripping the sensitive file from every past commit while leaving the working copy untouched. Simpler commands such as git rm only affect future commits, so the file would persist in earlier history.

Why this answer

Git filter-branch, because it rewrites the entire repository history to remove a file from all commits, effectively purging it from the version history while leaving the local working copy untouched. This is the standard Git approach for permanently deleting sensitive data (e.g., passwords, API keys) from the repository's history.

Exam trap

Cisco often tests the distinction between removing a file from future commits (git rm --cached) versus purging it from all history (git filter-branch), trapping candidates who confuse 'keeping locally' with 'removing from history'.

How to eliminate wrong answers

Option A is wrong because git rebase -i (interactive rebase) can only rewrite a linear range of commits, not the entire history, and it does not provide a built-in mechanism to remove a file from all commits without manual, error-prone editing. Option B is wrong because git reset --soft moves the HEAD pointer and leaves changes staged, but it does not remove a file from the repository history; it only affects the current branch's commit pointer and index. Option C is wrong because git rm --cached removes a file from the index (staging area) and future commits, but it does not remove the file from existing commit history, so the sensitive file remains accessible in previous commits.

408
MCQeasy

A developer is working on a Python script that must read a JSON configuration file containing device credentials. The script needs to parse the file and access the value of the key 'username'. Which Python standard library module and function should be used?

A.configparser.ConfigParser().read()
B.json.loads()
C.json.load()
D.yaml.safe_load()
AnswerC

The json module's load() function reads a file object and deserializes JSON data into a Python dictionary. This directly allows access to the 'username' key. It is the standard, correct approach for parsing a JSON file in Python, handling the conversion from JSON text to native Python objects seamlessly.

Why this answer

The json.load() function is the correct choice because it reads a file object and returns a Python dictionary, allowing immediate access to the 'username' key. The other options either parse strings, handle different formats, or are not part of the standard library for JSON parsing.

Exam trap

The trap here is confusing json.load() with json.loads(), where the former reads from a file and the latter from a string.

409
MCQmedium

A developer is using Git for source control. They have made changes to a file and want to temporarily save the changes without committing, then work on a different branch. Which Git command should they use?

A.git checkout other-branch
B.git commit -m 'temp'
C.git reset --hard
D.git stash
AnswerD

git stash saves uncommitted working-tree and index changes onto a stack and reverts the working directory to HEAD, letting the developer switch branches cleanly. The changes are reapplied later with git stash pop, satisfying the temporary-save requirement.

Why this answer

`git stash` temporarily saves uncommitted changes (both staged and unstaged) to a stack, reverting the working directory to the last commit. This allows the developer to switch branches without losing work, then later reapply the changes with `git stash pop` or `git stash apply`.

Exam trap

Cisco often tests the distinction between temporarily saving work (`git stash`) versus permanently committing or discarding changes, and the trap here is that candidates may think `git checkout` can switch branches regardless of dirty state, ignoring the conflict risk.

How to eliminate wrong answers

Option A is wrong because `git checkout other-branch` will fail if there are uncommitted changes that conflict with the target branch, or it may carry the changes to the other branch unintentionally. Option B is wrong because `git commit -m 'temp'` creates a permanent commit in the commit history, which is not a temporary save and would require later cleanup (e.g., rebase or reset). Option C is wrong because `git reset --hard` discards all uncommitted changes permanently, which is destructive and does not save the work for later use.

410
Multi-Selectmedium

A company is implementing an API gateway for its microservices. Which TWO security features should be enabled at the gateway to protect backend services?

Select 2 answers
A.In-depth packet inspection.
B.Database connection pooling.
C.JWT validation.
D.CORS configuration.
E.Rate limiting.
AnswersC, E

JWT validation at the gateway verifies token signature, issuer, audience and expiry before forwarding requests, so unauthenticated or tampered calls never reach backend microservices. This satisfies the stem's requirement to enable security features at the gateway that protect backend services.

Why this answer

JWT validation (C) is correct because the API gateway should authenticate and authorize requests by verifying the signature, issuer, audience, and expiry of JSON Web Tokens before forwarding traffic to backend microservices, offloading this concern from each service. Rate limiting (E) is correct because throttling requests per client, API key, or IP at the gateway mitigates abuse, brute-force attempts, and denial-of-service traffic before it reaches backend services. In-depth packet inspection (A) is a network-layer/IDS-IPS function, not a typical API gateway security feature, and is unnecessary here.

Database connection pooling (B) is a performance/scalability concern, not a security control, and gateways do not manage backend database connections. CORS configuration (D) is a browser-origin policy mechanism for controlling cross-origin requests; while often configured at a gateway, it is not primarily a backend-protection security feature for microservice APIs.

Exam trap

Cisco often tests the distinction between security features that protect the API layer (JWT validation, rate limiting) versus network-level or backend-specific features (DPI, connection pooling), leading candidates to confuse operational optimizations with security controls.

411
MCQeasy

A developer needs to retrieve a secret stored in HashiCorp Vault from a CI job. The Vault administrator has enabled the AppRole auth method. Which sequence correctly authenticates and reads the secret using the Vault HTTP API?

A.Use the `secret_id` as the value of the `X-Vault-Token` header and GET the secret path.
B.POST to `/v1/auth/approle/login` with `role_id` and `secret_id` to obtain a client token, then GET the secret path with the `X-Vault-Token` header set to that token.
C.GET the secret path directly with a `role_id` query parameter and no token header.
D.POST the `secret_id` to the secret path to unwrap it, then read the response body for the secret value.
AnswerB

AppRole authentication requires exchanging a `role_id` and `secret_id` at the login endpoint for a Vault client token. That token is then presented in the `X-Vault-Token` header on subsequent requests. This is the documented flow and correctly separates authentication from secret retrieval, making it the right sequence for the CI job.

Why this answer

AppRole is a machine-oriented auth method that exchanges a `role_id` and `secret_id` for a short-lived Vault token. That token must then be supplied on the secret read. The other options either skip authentication, misuse the `secret_id` as a token, or misunderstand how Vault secret reads work, so only the login-then-read sequence succeeds.

Exam trap

The trap here is confusing the AppRole `secret_id`, which is an authentication credential, with a Vault client token used to authorize secret reads.

412
Multi-Selectmedium

Which TWO of the following are characteristics of Model-Driven Programmability with YANG models?

Select 2 answers
A.YANG models define a hierarchical data tree.
B.YANG models are only used with the Python library ncclient.
C.NETCONF and RESTCONF use YANG models to manipulate device configurations.
D.The controller directly pushes configurations to network devices without validation.
E.NETCONF requires JSON encoding for configuration data.
AnswersA, C

YANG models represent data as a tree structure.

Why this answer

YANG models define a hierarchical data tree structure that organizes configuration and state data in a parent-child relationship, mirroring the structure of the device's operational and configuration data. This hierarchical representation allows for precise, path-based access to individual data nodes, which is fundamental to model-driven programmability.

Exam trap

Cisco often tests the misconception that YANG models are tied to a single protocol or encoding format, leading candidates to incorrectly associate YANG exclusively with NETCONF or JSON.

413
MCQmedium

An engineer is tasked with automating the backup of running configurations from 50 routers. Which approach is most scalable?

A.SSH manually to each router and copy config
B.Schedule a cron job on each router to SCP config
C.Use SNMP to capture config
D.Use an Ansible playbook with ios_config backup
AnswerD

Ansible's ios_config module with the backup parameter retrieves running configurations from each device and stores them locally, using SSH rather than screen-scraping. Executing one playbook against a 50-router inventory satisfies the scalability constraint, since parallel host execution replaces 50 manual sessions, and Microsoft Entra ID integration is unnecessary for device-level CLI automation.

Why this answer

An Ansible playbook with the ios_config module's backup option is the most scalable approach because it uses a push-based automation model that can manage all 50 routers from a single control node, leveraging SSH for secure transport and idempotent configuration management without requiring any agent on the routers.

Exam trap

Cisco often tests the misconception that SNMP can be used for configuration backup, but SNMP is designed for read-only monitoring of OIDs, not for retrieving or storing entire configuration files, which requires a file transfer or CLI-based method.

How to eliminate wrong answers

Option A is wrong because manually SSHing to each router is not scalable for 50 devices, introduces human error, and defeats the purpose of automation. Option B is wrong because scheduling a cron job on each router to SCP the config requires individual configuration on every device, does not centralize management, and still relies on per-router setup, which is not scalable. Option C is wrong because SNMP is designed for monitoring and retrieving MIB data, not for capturing full running configurations; it lacks the ability to reliably back up the entire configuration file and is not a standard method for configuration backup.

414
MCQeasy

A developer needs to enforce HTTPS for a web application. Which security measure should be implemented in the application or reverse proxy?

A.SSL/TLS termination and HTTP redirect
B.Parameterized queries
C.CORS configuration
D.Input validation
AnswerA

Terminating SSL/TLS at the reverse proxy decrypts incoming traffic there, then a redirect rule rewrites any HTTP request to HTTPS, so every client connection is forced onto TLS. This directly satisfies the requirement to enforce HTTPS across the web application.

Why this answer

Enforcing HTTPS requires the reverse proxy or application to terminate incoming SSL/TLS connections (decrypting traffic at the proxy) and then redirect any HTTP requests to HTTPS using a 301 or 302 redirect. This ensures all client traffic is encrypted in transit, meeting security best practices and compliance requirements like PCI DSS.

Exam trap

Cisco often tests the distinction between security measures that protect data in transit (HTTPS/SSL termination) versus those that protect data at rest or during processing (input validation, parameterized queries), leading candidates to confuse application-layer defenses with transport-layer encryption.

How to eliminate wrong answers

Option B is wrong because parameterized queries prevent SQL injection attacks, not enforce HTTPS encryption. Option C is wrong because CORS (Cross-Origin Resource Sharing) configuration controls which domains can access resources via browser cross-origin requests, not transport-layer encryption. Option D is wrong because input validation sanitizes user-supplied data to prevent injection or malformed input, but does not enforce encrypted communication between client and server.

415
MCQhard

A developer maintains a Python library that calls a REST API and currently stores the API token in a module-level constant. The team wants to follow twelve-factor app principles so the same build artifact can be deployed to lab and production without code changes. Which change should the developer make?

A.Move the token into a config.ini file that is committed to the repository and read at import time.
B.Encrypt the token with a symmetric key and store both the ciphertext and key in the repository for decryption at runtime.
C.Read the token from an environment variable, such as os.environ['API_TOKEN'], at runtime.
D.Detect the deployment environment by hostname and select a hardcoded token for each environment.
AnswerC

Twelve-factor apps store configuration in the environment, so reading the token from an environment variable lets the same artifact run in lab and production with different values. This removes secrets from source code and enables per-environment configuration without rebuilding or editing files, satisfying the stated requirement.

Why this answer

Twelve-factor configuration is stored in the environment, not in code or committed files. Reading the API token from an environment variable allows the identical build artifact to run in lab and production with different credentials, keeps secrets out of source control, and requires no code edits between deployments.

Exam trap

The trap here is thinking encryption at rest in the repository solves secret management, when the decryption key must also be externalized.

416
MCQeasy

A network engineer is using curl to test a REST API endpoint on a Cisco IOS XE device that supports RESTCONF. The engineer wants to retrieve the configuration of the GigabitEthernet1 interface. Which curl command correctly sends a GET request to the RESTCONF API with the appropriate headers to retrieve the interface configuration in JSON format?

A.curl -X POST -H 'Accept: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
B.curl -X GET -H 'Accept: application/json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
C.curl -X GET -H 'Accept: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
D.curl -X GET -H 'Content-Type: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
AnswerC

This command uses the correct HTTP method (GET) and sets the Accept header to 'application/yang-data+json', which tells the RESTCONF server to return the data in JSON format according to the YANG data model. The URL path correctly targets the specific interface using the ietf-interfaces module.

Why this answer

To retrieve data via RESTCONF, a GET request must be sent with the Accept header set to 'application/yang-data+json' to request JSON-formatted YANG data. The URL must correctly reference the data node using the module name and interface name. The other options use incorrect headers or HTTP methods.

Exam trap

The trap here is confusing the Accept header with Content-Type, or using the wrong HTTP method for retrieval.

417
Multi-Selectmedium

A CI/CD pipeline includes stages for security scanning. Which TWO tools or services are specifically designed for dependency vulnerability scanning?

Select 2 answers
A.Snyk
B.Kubernetes
C.Jenkins
D.Dependabot
E.Docker
AnswersA, D

Snyk scans manifest and lock files against vulnerability databases, flagging known CVEs in third-party packages and their transitive dependencies. This directly satisfies the pipeline's dependency vulnerability scanning stage, unlike SAST or container image scanning tools.

Why this answer

Snyk (A) is a security platform whose core capability is scanning open-source dependencies and container images for known vulnerabilities, making it a purpose-built dependency vulnerability scanner for CI/CD pipelines. Dependabot (D) is GitHub's native service that monitors a project's dependency manifests (e.g., package.json, requirements.txt, pom.xml) and raises alerts or pull requests when vulnerable or outdated packages are detected, so it is also specifically designed for dependency vulnerability scanning. Kubernetes (B) is a container orchestration platform, not a vulnerability scanner, so it does not belong.

Jenkins (C) is a CI/CD automation server that can invoke scanners but does not itself perform dependency vulnerability scanning. Docker (E) is a containerization platform for building and running images, not a dependency vulnerability scanning tool.

Exam trap

Cisco often tests the distinction between tools that perform a specific security function (like dependency scanning) versus general-purpose CI/CD or container tools that can only facilitate security scanning through external integrations.

418
MCQmedium

A developer is creating a REST API client that needs to authenticate using credentials passed in the HTTP header. Which header should be used?

A.Authorization
B.Host
C.Content-Type
D.Cookie
AnswerA

The Authorization header carries credentials, typically as a Bearer token or Basic scheme, in the HTTP request. It satisfies the stem's requirement for passing credentials in the header, unlike Content-Type or Accept, which describe payload format and response preferences.

Why this answer

The Authorization header is the standard HTTP header used to transmit credentials (such as Basic, Bearer, or Digest tokens) to authenticate a REST API client. RFC 7235 defines this header as the mechanism for carrying authentication information from the client to the server, making it the correct choice for passing credentials in the HTTP header.

Exam trap

The trap here is that candidates often confuse the Cookie header with the Authorization header because both can carry tokens, but Cisco tests the specific RFC-defined purpose of the Authorization header for direct credential transmission in REST APIs.

How to eliminate wrong answers

Option B (Host) is wrong because the Host header specifies the target domain and port of the request, as defined in RFC 7230, and has no role in authentication. Option C (Content-Type) is wrong because it indicates the media type of the request body (e.g., application/json) and is used for content negotiation, not for passing credentials. Option D (Cookie) is wrong because while cookies can carry session tokens, they are designed for state management and are not the standard header for direct credential transmission in REST API authentication; the Authorization header is the explicit and preferred method.

419
MCQmedium

A developer wants to use Cisco NX-API on a Nexus switch to execute a CLI command via JSON. What must be enabled on the switch first?

A.feature nxapi
B.ip http server
C.netconf-yang
D.restconf
AnswerA

NX-API is disabled by default on Nexus switches and must be activated with the command 'feature nxapi' in configuration mode. Enabling this feature starts the HTTP/HTTPS listener that accepts JSON-formatted CLI requests, satisfying the stem's prerequisite.

Why this answer

The 'feature nxapi' command enables NX-API on NX-OS.

420
MCQeasy

A junior developer is writing a Python script to gather interface statistics from a Cisco IOS-XE device using NETCONF. They use the 'ncclient' library and successfully connect. They want to retrieve the operational status of all interfaces. Which YANG model and XPATH expression should they use to get the operational data?

A.Model: ietf-interfaces, XPATH: /interfaces-state/interface
B.Model: cisco-native, XPATH: /native/interface
C.Model: ietf-interfaces, XPATH: /interfaces/interface
D.Model: ietf-interfaces, XPATH: /interfaces-state
AnswerA

Interfaces-state contains operational data per IETF standard.

Why this answer

The 'ietf-interfaces' YANG model defines the '/interfaces-state' container specifically for operational state data (e.g., status, counters), as per RFC 7223. The XPATH '/interfaces-state/interface' retrieves the list of all interfaces with their operational status, which is exactly what the developer needs. The 'ncclient' library can filter using this XPATH to get read-only operational data from a NETCONF-enabled Cisco IOS-XE device.

Exam trap

Cisco often tests the distinction between configuration and operational data in YANG models, and the trap here is that candidates confuse '/interfaces/interface' (configuration) with '/interfaces-state/interface' (operational state), or they pick a too-broad XPATH like '/interfaces-state' instead of the specific list node.

How to eliminate wrong answers

Option B is wrong because 'cisco-native' is a proprietary Cisco model for configuration data, not operational state, and '/native/interface' would return configured interfaces, not their operational status. Option C is wrong because '/interfaces/interface' under 'ietf-interfaces' targets the configuration container, which holds intended settings, not operational state (status, counters). Option D is wrong because '/interfaces-state' is the correct container, but the XPATH is too broad—it returns the entire container rather than the list of interfaces; the developer needs '/interfaces-state/interface' to get each interface's operational data.

421
MCQmedium

A developer is writing a Python script that calls the Cisco Webex API. The script must handle the case where the API returns a 429 Too Many Requests response. Which HTTP response header should the script inspect to determine how long to wait before retrying the request?

A.X-RateLimit-Limit
B.Cache-Control
C.Retry-After
D.Link
AnswerC

The Retry-After header is the standard HTTP mechanism for a server to tell a client how many seconds to wait before making another request. Cisco Webex APIs return this header on 429 responses, so the script should read its value and sleep for that duration before retrying, avoiding further throttling and potential temporary blocking.

Why this answer

When a REST API throttles a client with 429 Too Many Requests, the standard way to communicate the required backoff is the Retry-After response header, which contains either a number of seconds or an HTTP date. Cisco Webex returns this header, so a well-behaved client reads it and delays the next attempt accordingly, rather than retrying immediately and remaining throttled.

Exam trap

The trap here is assuming any rate-limit-related header such as X-RateLimit-Limit or X-RateLimit-Remaining tells you how long to wait, when only Retry-After conveys the backoff duration.

422
MCQeasy

A developer is writing a script that must resolve a hostname to an IPv4 address before making an HTTP request. The script uses a DNS resolver library and needs to query for the appropriate record type. Which DNS record type should the script query to obtain the IPv4 address?

A.A
B.CNAME
C.MX
D.AAAA
AnswerA

An A record maps a hostname to an IPv4 address. Querying for an A record returns the IPv4 address needed to establish the HTTP connection. This is the standard record type for IPv4 resolution and directly answers the scenario's requirement.

Why this answer

The A record is the DNS record type that maps a hostname to an IPv4 address. When a script needs to resolve a hostname to an IPv4 address for an HTTP request, it should query for an A record. Other record types serve different purposes, such as AAAA for IPv6, CNAME for aliases, and MX for mail routing.

Exam trap

The trap here is mixing up A and AAAA records, or assuming that a CNAME directly returns an IP address, when only the A record provides IPv4 resolution.

423
MCQmedium

A developer is writing a Python script that uses the ncclient library to configure a Cisco IOS XE device over NETCONF. The script must push a candidate configuration, validate it, and then commit it atomically. Which sequence of NETCONF operations should the script use to guarantee the configuration is only applied if it passes validation?

A.get-config, edit-config with the candidate datastore, then discard-changes
B.edit-config with the running datastore, validate, then commit
C.lock the running datastore, edit-config with the running datastore, then unlock
D.edit-config with the candidate datastore, validate, then commit
AnswerD

The candidate datastore allows a configuration to be staged without affecting the running configuration. After edit-config loads the candidate, the validate operation checks syntax and constraints, and commit applies it atomically. This sequence ensures the change is applied only if validation succeeds, which matches the requirement for validated, atomic deployment.

Why this answer

NETCONF separates staging from activation through the candidate datastore and the commit operation. Loading the candidate with edit-config, validating it, and then committing ensures the configuration is syntactically and semantically correct before it becomes active, and the commit is atomic. This is the standard approach for safe, transactional configuration changes on devices that support the candidate capability.

Exam trap

The trap here is assuming that validate must be called after commit, or that the running datastore supports transactional commit like the candidate datastore does.

424
MCQmedium

An application requires reliable, ordered delivery of data. Which transport protocol should be used?

A.UDP
B.HTTP
C.TCP
D.IP
AnswerC

TCP establishes a connection, sequences segments, acknowledges receipt and retransmits lost data, guaranteeing ordered, reliable delivery. UDP offers neither ordering nor delivery guarantees. The stem's requirement for reliable, ordered delivery therefore maps directly to TCP's transport-layer mechanisms.

Why this answer

TCP is the correct choice because it is a connection-oriented transport-layer protocol that guarantees reliable, ordered delivery of data through mechanisms such as sequence numbers, acknowledgments, and retransmissions. UDP does not provide reliability or ordering, HTTP is an application-layer protocol that itself relies on TCP for reliability, and IP is a network-layer protocol that offers best-effort delivery with no guarantees.

Exam trap

The trap here is confusing protocol layers — candidates may pick HTTP thinking it guarantees delivery, or IP thinking it routes data reliably, when only TCP provides transport-layer reliability and ordering.

How to eliminate wrong answers

Option A is wrong because UDP is a connectionless transport protocol that provides no reliability, ordering, or retransmission — it is used for speed-sensitive traffic like DNS or streaming. Option B is wrong because HTTP is an application-layer protocol, not a transport protocol, and it depends on TCP underneath for reliable delivery. Option D is wrong because IP operates at the network layer and provides best-effort, connectionless delivery with no ordering or reliability guarantees.

425
MCQmedium

In the OAuth 2.0 authorization code flow, what does the client receive after the user grants authorization?

A.An authorization code
B.A client secret
C.A refresh token
D.An access token
AnswerA

The client receives a short-lived authorization code, which it then exchanges at the token endpoint for access and ID tokens. This satisfies the flow's security constraint: tokens are never exposed to the user agent via the front channel, only the single-use code, which is bound to the client and redirect URI.

Why this answer

In the OAuth 2.0 authorization code flow, after the user grants authorization, the authorization server redirects the client with an authorization code in the query string. This code is a temporary credential that the client must exchange for an access token by sending it along with its client credentials to the token endpoint. The authorization code itself is not the final token; it is a one-time-use intermediary that prevents the access token from being exposed to the user agent.

Exam trap

Cisco often tests the distinction between what is received immediately after user authorization (the authorization code) versus what is obtained after the subsequent token exchange (access token and optionally a refresh token), causing candidates to mistakenly select the access token.

How to eliminate wrong answers

Option B is wrong because a client secret is a static credential pre-shared between the client and authorization server, not something received after user authorization. Option C is wrong because a refresh token is issued only after the client exchanges the authorization code for an access token at the token endpoint, not immediately upon user grant. Option D is wrong because the access token is not directly returned to the client after user authorization; the client must first exchange the authorization code for it via a back-channel request to the token endpoint.

426
Multi-Selecthard

Which THREE practices help ensure idempotent network automation? (Select three)

Select 3 answers
A.Using the 'state' parameter in Ansible modules to define desired state
B.Using a transactional approach (e.g., configure candidate and commit)
C.Running commands multiple times to ensure they are applied
D.Checking the current state before applying changes
E.Always appending new configuration commands to the running config
AnswersA, B, D

This ensures the module only takes action if the current state does not match the desired state.

Why this answer

Using the 'state' parameter in Ansible modules (e.g., 'state: present' or 'state: absent') explicitly declares the desired end state of a resource. This allows the module to compare the current state against the desired state and only make changes if necessary, ensuring that running the playbook multiple times produces the same result without unintended side effects.

Exam trap

Cisco often tests the misconception that simply running a command multiple times or appending configuration ensures idempotency, when in fact true idempotency requires state checking and declarative desired-state definitions.

427
MCQmedium

An application requires reliable, ordered delivery of data with flow control and retransmission of lost segments. Which transport layer protocol should the developer choose and what is a key characteristic of this protocol?

A.TCP; it uses a three-way handshake for connection establishment
B.UDP; it provides ordered delivery through sequence numbers
C.TCP; it has lower overhead than UDP
D.UDP; it uses a three-way handshake for connection establishment
AnswerA

TCP's sequence numbers and acknowledgements guarantee ordered delivery, while windowing provides flow control and unacknowledged segments are retransmitted — exactly the reliability the application demands. The three-way handshake establishes the connection state these mechanisms depend on before any data flows.

Why this answer

TCP is the correct transport protocol because it provides reliable, ordered delivery with flow control and retransmission of lost segments, and a defining characteristic is that it establishes connections via the three-way handshake (SYN, SYN-ACK, ACK). UDP provides none of these guarantees, and TCP actually has higher overhead than UDP, not lower.

Exam trap

The trap is the false pairing of UDP with TCP-like features (sequence numbers, handshakes) or the misconception that TCP has lower overhead — candidates must remember TCP trades overhead for reliability.

How to eliminate wrong answers

Option B is wrong because UDP does not provide ordered delivery or sequence numbers — it is connectionless and best-effort, leaving ordering and reliability to the application. Option C is wrong because TCP has higher overhead than UDP due to its handshake, headers (20+ bytes vs 8), acknowledgments, and state management, not lower. Option D is wrong because UDP does not perform a three-way handshake — that is a TCP-specific connection establishment mechanism.

428
Multi-Selectmedium

A developer is writing a Python script that consumes a REST API which returns JSON error bodies. The script must distinguish client mistakes from server-side problems and react accordingly. Which TWO HTTP status code ranges or codes indicate conditions the client should handle as errors caused by the request or by the server rather than success? (Choose two.)

Select 2 answers
A.3xx redirection status codes
B.200 OK
C.4xx client error status codes
D.101 Switching Protocols
E.5xx server error status codes
AnswersC, E

Codes in the 4xx class indicate the request itself was flawed, such as 400 for malformed syntax, 401 for missing credentials, 403 for insufficient permission, or 404 for an unknown resource. The script should inspect these codes and avoid blind retries, since resending the same request typically reproduces the same failure until the request is corrected.

Why this answer

The 4xx class identifies requests the client got wrong, and the 5xx class identifies server-side failures. Together they form the error conditions a consuming script must branch on: 4xx usually requires fixing the request, while 5xx usually warrants retries with backoff. Success codes, redirections, and informational responses belong to different handling paths.

Exam trap

The trap here is lumping all non-200 responses into one error bucket, ignoring that 3xx and 1xx responses are not failures at all.

429
MCQmedium

A network engineer wants to use NETCONF to change the hostname of a Cisco device. Which operation should be used?

A.<lock>
B.<copy-config>
C.<edit-config>
D.<get-config>
AnswerC

The `<edit-config>` operation writes configuration changes into the running datastore, which is exactly what altering a hostname requires. It targets the specified configuration node and applies the new value, satisfying NETCONF's requirement for modifying device configuration rather than merely retrieving state with `<get-config>`.

Why this answer

The <edit-config> operation is used to modify configuration data in NETCONF.

430
MCQeasy

A network engineer is analyzing a packet capture of a TCP session establishment between a client and a server. The engineer observes a packet with the SYN flag set and another with both the SYN and ACK flags set. Which flag will be set in the next packet sent by the client to complete the three-way handshake?

A.RST
B.PSH
C.FIN
D.ACK
AnswerD

The three-way handshake consists of SYN, SYN-ACK, and ACK. The client initiates with SYN, the server responds with SYN-ACK, and the client completes the handshake by sending an ACK. This ACK acknowledges the server's SYN and establishes the connection, allowing data transfer to begin.

Why this answer

The three-way handshake is a fundamental TCP connection establishment process. The client sends a SYN packet, the server responds with a SYN-ACK packet, and the client completes the handshake by sending an ACK packet. This final ACK acknowledges the server's SYN and confirms that both sides are ready to exchange data.

Exam trap

The trap here is confusing the final ACK of the three-way handshake with other TCP control flags like FIN or RST, which serve entirely different purposes in connection management.

431
Multi-Selecthard

Which TWO are components of a REST API request? (Choose two.)

Select 2 answers
A.URI
B.Status code
C.Payload
D.HTTP method
E.Query string
AnswersA, D

Identifies the resource.

Why this answer

A REST API request is defined by the combination of a URI (Uniform Resource Identifier) and an HTTP method. The URI identifies the specific resource (e.g., /api/users/123) on the server, while the HTTP method (GET, POST, PUT, DELETE, etc.) specifies the desired action to be performed on that resource. Together, they form the fundamental components that the client sends to the server to initiate a request.

Exam trap

Cisco often tests the distinction between request components and response components, and the trap here is that candidates mistakenly include status codes or payloads as request components, when in fact status codes are only in responses and payloads are optional in requests.

432
MCQmedium

A developer is writing a Python script that uses the Meraki Dashboard API to page through a very large organization's list of network devices. The developer wants to iterate through all pages of results without manually constructing page URLs. Which approach should be used?

A.Send a POST request to the devices endpoint with a body containing a startingIndex field that the API uses to return the next slice.
B.Send a single GET request and read the HTTP Link response header to follow the next page URL until no Link header is returned.
C.Send a single GET request with the query parameter perPage set to the organization's total device count so all devices return in one response.
D.Rely on the X-RateLimit-Remaining response header; when it reaches zero, the API automatically returns the next page of devices.
AnswerB

The Meraki Dashboard API returns pagination metadata in the HTTP Link response header, using rel="next" to point at the following page. A client that reads this header and keeps following the next URL will traverse every page without hand-building offsets or page numbers, which is exactly what the scenario requires.

Why this answer

Meraki paginates large collections and advertises the subsequent page through the HTTP Link response header with rel="next". A client that inspects headers and follows that URL iterates the entire collection robustly, which is the documented pattern for traversing large result sets. Approaches that assume a single oversized page, misuse POST, or repurpose rate-limit headers all fail to advance through the data.

Exam trap

The trap here is assuming pagination is controlled by a query parameter or rate-limit header rather than by the Link response header that Meraki actually returns.

433
MCQeasy

An automation engineer is using the Cisco DNA Center REST API to retrieve a list of network devices. The API call returns HTTP status code 200. What does this indicate?

A.The request succeeded but no content is returned.
B.The request was created successfully.
C.The request was successful and data is returned.
D.The request failed due to a client error.
AnswerC

HTTP 200 means the request succeeded and the response body carries the requested device list, satisfying the engineer's goal of retrieving devices via the Cisco DNA Center REST API. Other 2xx codes also signal success, but 200 specifically confirms data is returned.

Why this answer

HTTP status code 200 indicates a successful GET request where the server has processed the request and is returning the requested data in the response body. In the context of the Cisco DNA Center REST API, a 200 response to a GET /network-device call means the list of network devices was successfully retrieved and is included in the response payload.

Exam trap

Cisco often tests the distinction between 200 OK and 204 No Content, expecting candidates to know that 200 always includes a response body while 204 explicitly does not, even though both are successful.

How to eliminate wrong answers

Option A is wrong because HTTP 200 does not mean 'no content' — that is indicated by status code 204 (No Content), which is used for successful requests that intentionally return no body. Option B is wrong because a 201 (Created) status code indicates successful creation of a resource, not a retrieval; 200 is used for successful GET, PUT, or DELETE operations that return data. Option D is wrong because client errors are represented by 4xx status codes (e.g., 400 Bad Request, 401 Unauthorized), not 2xx success codes.

434
MCQeasy

A developer needs to retrieve the list of devices from a Meraki network using the Meraki Dashboard API. Which HTTP method and endpoint should be used?

A.POST /networks/{networkId}/devices
B.GET /devices
C.GET /organizations/{organizationId}/networks
D.GET /networks/{networkId}/devices
AnswerD

GET requests retrieve data without modifying server state, satisfying the read-only requirement for listing devices. The endpoint `/networks/{networkId}/devices` correctly scopes the query to a specific network via the `networkId` path parameter, returning its device collection as JSON. POST, PUT, or DELETE would alter resources, and omitting the network scope would target the wrong resource hierarchy.

Why this answer

The Meraki Dashboard API uses RESTful conventions: to retrieve a list of devices within a specific network, you send a GET request to the endpoint `/networks/{networkId}/devices`. This follows the standard pattern of using GET for read operations and scoping the resource under the network identifier.

Exam trap

Cisco often tests the distinction between GET and POST for read vs. create operations, and the trap here is that candidates may confuse the endpoint for listing networks (`/organizations/{organizationId}/networks`) with the endpoint for listing devices, or assume a top-level `/devices` path exists without understanding the hierarchical resource model.

How to eliminate wrong answers

Option A is wrong because POST is used to create resources, not retrieve them; sending a POST to `/networks/{networkId}/devices` would attempt to add a new device, not list existing ones. Option B is wrong because `/devices` is not a valid top-level endpoint in the Meraki API; device resources are always nested under a network or organization context. Option C is wrong because `/organizations/{organizationId}/networks` returns a list of networks, not devices; it retrieves the networks within an organization, which is a different resource entirely.

435
MCQeasy

A developer is designing a REST API that will be used by multiple client applications. The API must support versioning to ensure backward compatibility. Which approach should the developer use to implement API versioning?

A.Embed the version in the URI, e.g., /v1/resource
B.Use different HTTP methods for different versions
C.Pass the version as a query parameter, e.g., ?version=1
D.Use a custom HTTP header to specify the version
AnswerA

Placing the version in the URI path creates a distinct endpoint per version, so clients calling /v1/resource remain unaffected when /v2 is introduced. This satisfies the backward-compatibility constraint by letting old and new contracts coexist without breaking existing consumers.

Why this answer

Embedding the version in the URI (e.g., /v1/resource) is the most common and straightforward approach for REST API versioning. It makes the version explicit in the URL, allowing clients to directly target a specific version without requiring special header handling or query parameter parsing. This method is widely adopted in industry APIs (e.g., GitHub, Twilio) and ensures backward compatibility by keeping older endpoints accessible under their original URI path.

Exam trap

Cisco often tests the misconception that query parameters or custom headers are more 'RESTful' or flexible, but the exam expects URI-based versioning as the simplest and most compatible approach for backward compatibility.

How to eliminate wrong answers

Option B is wrong because HTTP methods (GET, POST, PUT, DELETE) define the action on a resource, not the version; using different methods for different versions violates REST principles and confuses clients. Option C is wrong because passing the version as a query parameter (e.g., ?version=1) can be cached incorrectly by proxies and CDNs, and it clutters the URL without providing a clean, hierarchical resource structure. Option D is wrong because using a custom HTTP header (e.g., Accept-Version) requires clients to implement additional header logic, reduces discoverability, and is not as transparent or testable as URI-based versioning.

436
MCQhard

A developer is using the ncclient library in Python to connect to a network device via NETCONF. Which operation should be used to modify the running configuration and commit the changes?

A.validate() followed by get_config()
B.get_config() followed by copy_config()
C.edit_config() followed by commit()
D.discard_changes() followed by edit_config()
AnswerC

The NETCONF edit_config() operation writes changes into the candidate datastore, satisfying the requirement to modify configuration without immediately affecting the running state. commit() then promotes the candidate to running, which the stem explicitly demands. This two-step sequence matches the candidate-to-running workflow that NETCONF's distinct datastores enforce.

Why this answer

In NETCONF, the `edit-config()` operation is used to modify the running configuration, and the `commit()` operation is required to make those changes permanent when the device operates in candidate configuration mode. The ncclient library provides these methods to align with the NETCONF protocol's standard operations.

Exam trap

Cisco often tests the distinction between candidate and running datastores, and the trap here is that candidates assume `edit_config()` alone commits changes, forgetting that a separate `commit()` is required when the device uses a candidate configuration model.

How to eliminate wrong answers

Option A is wrong because `validate()` checks the syntactic correctness of a configuration but does not modify it, and `get_config()` retrieves configuration data without making changes. Option B is wrong because `get_config()` retrieves configuration, and `copy_config()` copies a configuration from one datastore to another (e.g., running to startup), but neither directly modifies the running configuration with a commit step. Option D is wrong because `discard_changes()` reverts uncommitted changes in a candidate datastore, and `edit_config()` modifies the configuration; performing `discard_changes()` before `edit_config()` would discard any pending changes but does not achieve a commit of new modifications.

437
MCQmedium

A network automation engineer is writing a Python script to configure multiple devices. Which library is most appropriate for SSH-based interactions?

A.requests
B.socket
C.Netmiko
D.paramiko
AnswerC

Netmiko abstracts SSH transport for multi-vendor network devices, handling prompt detection and enable-mode escalation that raw Paramiko requires manually. It satisfies the stem's SSH-based interaction constraint across multiple device types, unlike RESTCONF or SNMP libraries.

Why this answer

Netmiko is a Python library built on top of Paramiko that simplifies SSH connections to network devices. It provides high-level methods for sending commands, handling prompts, and managing device interactions, making it the most appropriate choice for automating configuration tasks across multiple devices.

Exam trap

Cisco often tests the distinction between Paramiko (a general SSH library) and Netmiko (a network-device-specific library built on Paramiko), leading candidates to choose Paramiko because they recognize it as an SSH library without considering the higher-level abstractions Netmiko provides for network automation.

How to eliminate wrong answers

Option A is wrong because the requests library is designed for HTTP/HTTPS API calls, not for SSH-based interactions. Option B is wrong because the socket library provides low-level network communication primitives and lacks the SSH protocol handling needed for device configuration. Option D is wrong because while Paramiko is a valid SSH library, it requires manual handling of authentication, channel management, and command output parsing, making it less suitable than Netmiko for multi-device automation scenarios.

438
Multi-Selecthard

A security team is reviewing a Python application that integrates with Cisco DNA Center. The application authenticates with a username and password and stores them in a configuration file that is deployed to multiple servers. The team wants to reduce the risk of credential exposure while keeping the application functional. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Disable TLS verification for Cisco DNA Center API calls to simplify certificate management.
B.Embed the credentials in the Python source code so the configuration file can be deleted.
C.Log the credentials at startup so operators can confirm the configuration is correct.
D.Store the configuration file with restrictive file permissions and exclude it from version control.
E.Replace static credentials with short-lived tokens obtained from the Cisco DNA Center authentication API.
AnswersD, E

Restricting file permissions limits which local users can read the credentials, and excluding the file from version control prevents accidental commits that would expose secrets to anyone with repository access. Together these controls reduce the attack surface for a deployed configuration file. They complement, rather than replace, token-based authentication.

Why this answer

Reducing credential exposure involves both limiting how long secrets live and limiting who can read them. Short-lived tokens from the Cisco DNA Center authentication API shrink the useful lifetime of a stolen secret, while restrictive file permissions and exclusion from version control protect the configuration file itself. Together these controls address the risk without breaking the integration.

Exam trap

The trap here is treating file permissions as sufficient on their own, or assuming that hiding credentials in source code is safer than a protected configuration file.

439
MCQeasy

A developer runs `curl -I http://api.example.com/health` and receives `HTTP/1.1 301 Moved Permanently` with a `Location: https://api.example.com/health` header. They want to follow the redirect automatically and print the final response body. Which curl option should they add?

A.`-v`
B.`-L`
C.`-X GET`
D.`-k`
AnswerB

The `-L` flag instructs curl to follow HTTP 3xx redirects by reissuing the request to the URL in the Location header. Because the original request used `-I` (HEAD), curl will still issue HEAD requests on the redirect chain, so it will not print a body; to see the final body, the developer should also drop `-I` or use `-o`/`-O` with `-L`. In this scenario, adding `-L` is the correct mechanism to resolve the 301 automatically.

Why this answer

Following an HTTP redirect requires curl to recognize the 3xx status and reissue the request to the URL in the Location header. The `-L` flag enables exactly that behavior. Other flags alter TLS verification, verbosity, or the request method, but none of them cause curl to traverse the redirect chain.

Combining `-L` with a method that returns a body is what produces the final content.

Exam trap

The trap here is assuming that any curl flag that changes request behavior, such as forcing a method or disabling certificate checks, will also resolve a 301 redirect, when only the redirect-following flag does that.

440
MCQmedium

Based on the exhibit, which interface is in a state that prevents it from sending or receiving IP traffic?

A.GigabitEthernet0/2
B.GigabitEthernet0/0
C.GigabitEthernet0/1
D.None of the interfaces are down
AnswerC

It is administratively down, so no traffic can pass.

Why this answer

Interface GigabitEthernet0/1 is in the 'administratively down' state, as indicated by the 'down' status in the 'Status' column and the 'down' in the 'Protocol' column. This means the interface has been manually disabled with the 'shutdown' command, preventing it from sending or receiving any IP traffic. In contrast, interfaces that are 'up/up' can forward traffic, while 'up/down' indicates a Layer 1 issue but still allows Layer 2 control plane traffic.

Exam trap

Cisco often tests the distinction between 'administratively down' (Status: down) and 'up/down' (Status: up, Protocol: down), where candidates mistakenly assume any 'down' protocol means no IP traffic is possible, but only the administratively down state explicitly prevents all traffic due to manual shutdown.

How to eliminate wrong answers

Option A is wrong because GigabitEthernet0/2 shows 'up' in both Status and Protocol columns, meaning it is fully operational and can send/receive IP traffic. Option B is wrong because GigabitEthernet0/0 shows 'up' in Status and 'down' in Protocol, indicating a Layer 1 connectivity issue (e.g., no cable or faulty transceiver) but the interface is not administratively disabled; it still attempts to send/receive Layer 2 frames, though IP traffic may fail due to the protocol being down. Option D is wrong because GigabitEthernet0/1 is indeed in a state that prevents IP traffic (administratively down), so not all interfaces are operational.

441
MCQmedium

A developer is building a Python script that calls the Cisco Webex Rooms API. The script must handle rate limiting gracefully by reading the response headers when the API returns HTTP 429. Which response header should the script inspect to determine how long to wait before retrying?

A.X-RateLimit-Reset
B.Retry-After
C.Location
D.WWW-Authenticate
AnswerB

The Retry-After header is a standard HTTP response header that indicates how many seconds the client should wait before making a follow-up request. When the Webex API returns 429 Too Many Requests, it includes Retry-After so the client can pause accordingly, avoiding further throttling and ensuring the script respects the service's rate limits.

Why this answer

When the Webex API throttles a client with HTTP 429, it includes the Retry-After header to specify the number of seconds to wait. Reading this header allows the script to implement an appropriate backoff, respecting the service's limits and avoiding further penalties. The other headers serve different purposes and do not provide rate-limit timing information.

Exam trap

The trap here is assuming that a custom header like X-RateLimit-Reset is always used for rate limiting, when the Webex API specifically relies on the standard Retry-After header.

442
Multi-Selectmedium

Which TWO of the following are characteristics of a declarative automation model? (Select exactly 2.)

Select 2 answers
A.It requires procedural scripts
B.You specify the desired end state
C.Idempotency is not a concern
D.The tool handles ordering and dependencies
E.You specify the exact steps to achieve the state
AnswersB, D

Declarative models require the operator to define the intended end state, such as interfaces up with specific VLANs, leaving the tool to reconcile actual against desired. This contrasts with imperative models that list sequential commands.

Why this answer

Option B is correct because a declarative automation model is defined by describing the desired end state (for example, a Terraform HCL resource block or an Ansible task declaring 'state: present'), and the tool then works out how to reach that state. Option D is correct because in declarative tools the engine itself determines execution order and resolves dependencies, such as Terraform building a dependency graph from resource references or Ansible handling task ordering and handlers. Option A is incorrect because procedural scripts are the hallmark of imperative, not declarative, automation.

Option C is incorrect because idempotency is a core concern and benefit of declarative models, ensuring repeated runs converge to the same state without unwanted changes. Option E is incorrect because specifying exact steps is the defining trait of an imperative model, whereas declarative models specify the outcome, not the steps.

Exam trap

Cisco often tests the distinction between declarative and imperative models by presenting options that sound plausible but reverse the roles, such as confusing 'specify the end state' with 'specify the exact steps', or assuming idempotency is irrelevant in declarative models.

443
Multi-Selectmedium

Which TWO of the following are benefits of using NETCONF over SNMP for network automation? (Select exactly 2.)

Select 2 answers
A.Structured data models (YANG)
B.Lower CPU usage on devices
C.Binary data encoding
D.Transactional configuration changes
E.Simple polling mechanism
AnswersA, D

YANG provides standardised, hierarchical data models that NETCONF encodes in XML, giving automation tools machine-readable schema and validation. SNMP's flat MIB structure and opaque OIDs cannot express configuration intent this precisely, satisfying the structured-model benefit.

Why this answer

Option A is correct because NETCONF uses YANG data models to define configuration and state data in a structured, hierarchical, vendor-neutral way, which is far more suitable for programmatic automation than SNMP's flat MIB/OID model. Option D is correct because NETCONF supports transactional configuration changes via candidate datastores, commit, confirmed-commit, and rollback-on-error, so a set of edits either fully applies or is rolled back, unlike SNMP SET operations which are not transactionally grouped. Option B is not a defining benefit of NETCONF over SNMP; NETCONF over SSH can actually be more resource-intensive than lightweight SNMP polling, and CPU usage depends on implementation.

Option C is wrong because NETCONF typically uses XML (text) encoding, not binary encoding, while SNMP can use BER binary encoding. Option E is wrong because simple polling is characteristic of SNMP monitoring, whereas NETCONF is designed for configuration management and uses RPC-based sessions, not simple polling.

Exam trap

Cisco often tests the misconception that NETCONF is 'lighter' than SNMP, but the trap here is that NETCONF's XML and SSH overhead actually increase CPU usage, while SNMP's binary encoding and UDP make it more efficient for simple monitoring tasks.

444
Multi-Selectmedium

A developer is building a Python script that consumes a REST API exposed by a Cisco controller. The script must authenticate using a token obtained from a login endpoint and then call protected resources. Which TWO practices are appropriate for handling authentication and session state in this script? (Choose two.)

Select 2 answers
A.Disable TLS certificate verification so the login request succeeds against the controller's self-signed certificate.
B.Send the username and password with every API request instead of obtaining a token.
C.Handle token expiry by detecting an authentication failure response and re-authenticating to obtain a fresh token before retrying the request.
D.Hard-code the token value in the script so it never needs to be fetched at runtime.
E.Store the token returned by the login endpoint and include it in an Authorization or X-Auth-Token header on subsequent requests.
AnswersC, E

Tokens expire after a defined lifetime, and protected calls then return an authentication error. Detecting that response and logging in again to refresh the token keeps the script running unattended, which is essential for long-lived automation that cannot rely on a single token lasting forever.

Why this answer

Token-based controller APIs require the client to obtain a token at login, present it on subsequent protected calls, and refresh it when it expires. Storing and attaching the token in a request header satisfies the session requirement, and detecting an authentication failure to re-login keeps unattended scripts working. Replaying credentials, hard-coding tokens, and disabling TLS verification are insecure or nonfunctional alternatives.

Exam trap

The trap here is treating the token as a one-time artifact or bypassing TLS, when the real requirements are header-based reuse and expiry refresh.

445
MCQmedium

An engineer needs to transfer a router configuration file to a server in the same network using a simple protocol that does not require authentication. Which protocol is best?

A.SCP
B.TFTP
C.FTP
D.HTTP
AnswerB

TFTP runs over UDP port 69 with no authentication or encryption, making it the simplest option for copying a configuration file across the same network. FTP and SCP require credentials, violating the stem's no-authentication constraint.

Why this answer

TFTP (Trivial File Transfer Protocol) is the best choice because it is a lightweight, connectionless protocol that operates over UDP (port 69) and does not require any authentication or user credentials. It is commonly used for transferring router configuration files and IOS images in local network environments where simplicity and speed are prioritized over security.

Exam trap

Cisco often tests the distinction between TFTP and SCP, where candidates mistakenly choose SCP because it is secure, overlooking the explicit requirement for a protocol that does not require authentication.

How to eliminate wrong answers

Option A (SCP) is wrong because it relies on SSH for authentication and encryption, requiring credentials and adding overhead that is unnecessary for a simple, unauthenticated transfer. Option C (FTP) is wrong because it typically requires username/password authentication and uses TCP, making it more complex and less suitable for a no-authentication requirement. Option D (HTTP) is wrong because while it can be used without authentication, it is designed for web content transfer and often involves more overhead (TCP-based) and is not the standard protocol for router configuration file transfers in a local network.

446
MCQmedium

A Kubernetes environment has multiple teams sharing the same cluster. One team wants to deploy applications without interfering with other teams' resources. Which Kubernetes resource should be used to isolate the team's resources?

A.ServiceAccount
B.NodePort
C.ConfigMap
D.Namespace
AnswerD

Namespaces partition a single cluster into logically isolated virtual clusters, so each team's objects, quotas and RBAC bindings stay scoped to their own boundary. This directly satisfies the stem's requirement that one team deploy applications without interfering with other teams sharing the same cluster.

Why this answer

A Kubernetes Namespace provides a logical isolation boundary within a cluster, allowing multiple teams to share the same cluster while keeping their resources (pods, services, etc.) separate. It is the standard resource for multi-tenancy isolation. The other options serve different purposes.

Exam trap

200-901 often tests the confusion between namespaces and other Kubernetes resources, so candidates may choose ServiceAccount or ConfigMap thinking they provide isolation, but only Namespace is designed for logical separation.

How to eliminate wrong answers

Option A is wrong because a ServiceAccount provides an identity for processes running in pods, not resource isolation. Option B is wrong because a NodePort is a type of service that exposes a port on each node, not an isolation mechanism. Option C is wrong because a ConfigMap stores configuration data, not isolation.

447
MCQhard

When using NETCONF to edit the configuration of a Cisco IOS XE device, an engineer receives an <rpc-error> with error-tag 'in-use' and error-app-tag 'data-exists'. What does this error indicate?

A.The NETCONF session was closed due to a timeout.
B.The RPC message was malformed.
C.The configuration being added already exists on the device.
D.The device does not have the required user permissions.
AnswerC

NETCONF maps YANG data-exists violations to the in-use error-tag, meaning the target datastore already holds the node being created. The edit is rejected because the configuration being added already exists, so the engineer must merge or replace rather than create it.

Why this answer

The error-tag 'in-use' combined with the error-app-tag 'data-exists' in NETCONF indicates that the configuration operation (e.g., <edit-config> with operation 'create') attempted to add a configuration element that already exists in the running datastore. NETCONF uses these standardized error tags per RFC 6241 to signal that the requested operation cannot be completed because the target data node is already present, preventing duplicate configuration entries.

Exam trap

Cisco often tests the distinction between NETCONF <edit-config> operations (create vs. merge vs. replace) and their corresponding error tags, leading candidates to confuse 'in-use' with permission or syntax errors.

How to eliminate wrong answers

Option A is wrong because a session timeout would generate an <rpc-error> with error-tag 'session-timeout' or 'transport-error', not 'in-use'. Option B is wrong because a malformed RPC message would produce error-tag 'malformed-message' or 'operation-failed', not 'in-use'. Option D is wrong because insufficient permissions would result in error-tag 'access-denied' or 'authorization-error', not 'in-use'.

448
MCQmedium

In software architecture, which pattern separates an application into three interconnected components: Model (data), View (UI), and Controller (input logic)?

A.MVC (Model-View-Controller)
B.Microservices
C.Event-driven
D.REST
AnswerA

MVC directly satisfies the stem's three-component split: the Model handles data and business rules, the View renders the UI, and the Controller processes input and mediates between them. This separation of concerns is precisely the interconnected Model-View-Controller architecture the question describes.

Why this answer

The MVC pattern explicitly separates an application into three interconnected components: Model (data and business logic), View (user interface), and Controller (handles user input and updates the Model/View). This is the foundational architectural pattern for many web frameworks like Django, Ruby on Rails, and Spring MVC, where the Controller receives HTTP requests, interacts with the Model, and selects the appropriate View for rendering.

Exam trap

Cisco often tests that candidates confuse MVC with REST or Microservices because both involve separation of concerns, but MVC is specifically about internal component separation within a single application, not about service decomposition or API design.

How to eliminate wrong answers

Option B (Microservices) is wrong because it decomposes an application into independently deployable services, each with its own data and logic, rather than separating a single application into Model, View, and Controller components. Option C (Event-driven) is wrong because it relies on event producers and consumers communicating asynchronously via an event bus, not on a three-component separation of data, UI, and input logic. Option D (REST) is wrong because it is an architectural style for designing networked APIs using HTTP methods and stateless communication, not a pattern for structuring internal application components.

449
MCQhard

A developer uses the requests library to call an API. The API returns 429 Too Many Requests. What is the best practice to handle this?

A.Ignore the status code and proceed
B.Immediately retry the request
C.Use exponential backoff and retry
D.Wait a fixed amount of time and retry
AnswerC

HTTP 429 signals rate limiting, so retrying immediately would worsen the condition. Exponential backoff progressively increases the delay between retries, satisfying the stem's best-practice requirement by giving the server time to recover while respecting its rate limits.

Why this answer

HTTP 429 Too Many Requests indicates the client has exceeded the server's rate limit. The correct handling is to retry after a delay, and exponential backoff (with jitter) is the industry best practice because it progressively increases wait times between retries, reducing load on the server and avoiding thundering-herd effects. Many APIs also return a Retry-After header that should be honored.

Exam trap

The trap is choosing 'immediately retry' or 'fixed wait' as simpler alternatives — candidates underestimate how retry storms amplify server load and overlook exponential backoff as the standard resilience pattern.

How to eliminate wrong answers

Option A is wrong because ignoring the 429 and proceeding will continue to violate the rate limit, likely resulting in further 429s or a temporary ban. Option B is wrong because immediately retrying without delay will hammer the server, worsen the rate-limit condition, and may trigger stricter throttling or IP blocking. Option D is wrong because a fixed wait time is less effective than exponential backoff — it doesn't adapt to sustained overload and can still cause synchronized retry storms when many clients retry simultaneously.

450
MCQhard

A developer is building a chat application that requires low-latency communication, and occasional packet loss is acceptable. Which transport protocol should the developer choose?

A.UDP
B.RTP
C.QUIC
D.TCP
AnswerA

UDP is connectionless and low-latency; packet loss is acceptable in this scenario.

Why this answer

UDP is the correct choice because it provides low-latency, connectionless communication without retransmission or congestion control, making it ideal for real-time chat applications where occasional packet loss is acceptable. Unlike TCP, UDP does not require a handshake or acknowledgment, minimizing delay and overhead.

Exam trap

Cisco often tests the distinction between transport protocols and application-layer protocols, so candidates may confuse RTP (which is not a transport protocol) with UDP, or assume QUIC is a transport protocol when it is actually an application-layer protocol built on UDP.

How to eliminate wrong answers

Option B (RTP) is wrong because RTP is an application-layer protocol that typically runs over UDP to deliver real-time media, but it is not a transport protocol itself; the question asks for a transport protocol. Option C (QUIC) is wrong because QUIC, while offering lower latency than TCP, is built on top of UDP and includes reliability and congestion control features that are unnecessary when packet loss is acceptable, and it is not a pure transport protocol in the OSI model. Option D (TCP) is wrong because TCP's reliability mechanisms (retransmission, flow control, congestion avoidance) introduce latency and overhead that conflict with the requirement for low-latency communication, and its connection-oriented nature is unsuitable when occasional packet loss is acceptable.

Page 5

Page 6 of 13

Page 7