Courseiva

Cisco DevNet Associate 200-901 (200-901) — Questions 451–525

975 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQmedium

A Python script uses the `requests` library to fetch device details from Cisco DNA Center. The API returns a JSON response with nested objects. To extract the management IP address from the response stored in variable `data`, which code snippet is correct? The JSON structure is: { "response": [ { "managementIpAddress": "192.168.1.1", "hostname": "router1" } ] }

A.data.managementIpAddress
B.data['response']['managementIpAddress']
C.data.get('response')[0].get('managementIpAddress')
D.data['response'][0]['managementIpAddress']
AnswerD

Accessing `data['response']` yields the JSON array, and `[0]` selects its first element, the device object. Indexing that dictionary with `['managementIpAddress']` returns the nested string "192.168.1.1". This directly satisfies the stem's requirement to extract the management IP from the nested structure.

Why this answer

The response contains a list under key 'response'; correct access is via data['response'][0]['managementIpAddress'].

452
MCQeasy

Which HTTP method should be used to partially update an existing resource in a REST API?

A.PUT
B.DELETE
C.POST
D.PATCH
AnswerD

PATCH applies partial modifications to an existing resource, sending only the fields being changed. PUT would replace the entire resource representation, so PATCH uniquely satisfies the stem's requirement to partially update a resource without overwriting unspecified attributes.

Why this answer

PATCH is used for partial updates, while PUT replaces the entire resource.

453
MCQmedium

A developer is using the Meraki Dashboard API and notices that some requests return a 429 status code. What is the most likely cause?

A.The organization ID is incorrect.
B.The request payload is too large.
C.The API key is invalid.
D.The rate limit of 5 requests per second has been exceeded.
AnswerD

HTTP 429 Too Many Requests signals rate limiting. The Meraki Dashboard API enforces a limit of 5 calls per second per organisation; exceeding it returns 429 until the window resets. The Retry-After header indicates how long to wait, so the cause is request volume, not authentication or payload errors.

Why this answer

HTTP 429 means 'Too Many Requests.' The Meraki Dashboard API enforces a rate limit of 5 requests per second per organization, and exceeding it returns a 429 with a Retry-After header. The developer should implement exponential backoff and respect the Retry-After value.

Exam trap

200-901 often tests HTTP status code meanings — candidates confuse 429 (rate limit) with 401 (auth), 404 (not found), or 413 (payload too large).

How to eliminate wrong answers

Option A is wrong because an incorrect organization ID returns a 404 Not Found, not 429. Option B is wrong because an oversized payload returns 413 Payload Too Large or 400 Bad Request, not 429. Option C is wrong because an invalid API key returns 401 Unauthorized, not 429.

454
MCQmedium

A university IT department manages a Cisco Meraki network with 200 MR access points and 50 MS switches. They use the Meraki dashboard API to automate network provisioning. A new student dormitory was added, and the team needs to create a new network and claim devices. They have a Python script that uses the Meraki API to create the network and then claim devices by serial numbers. The script successfully creates the network but fails when claiming devices with a 400 error: 'Device serial number is not valid or already claimed'. The serial numbers are correct and unused. The API key has full organization access. The script uses the endpoint 'POST /networks/{networkId}/devices/claim' with the correct body. What is the most likely cause of the failure?

A.The API key does not have permission to claim devices.
B.The serial numbers contain a typo.
C.The devices have not been added to the organization's inventory first.
D.The devices are not Meraki MR or MS models.
AnswerC

Claiming into a network requires the serials to exist in the organisation's inventory; the dashboard rejects unknown serials with that 400 error. Meraki devices must first be added to inventory (via order, licence claim, or manual add) before `POST /networks/{networkId}/devices/claim` can bind them, so the script must add inventory first.

Why this answer

In the Meraki API workflow, devices must first be added to the organization's inventory via the 'POST /organizations/{organizationId}/inventory/devices' endpoint before they can be claimed into a specific network. The 400 error 'Device serial number is not valid or already claimed' occurs when the serial numbers are not present in the organization's inventory, even if they are correct and unused. The script successfully creates the network but fails at the claim step because the devices have not been inventoried at the organization level.

Exam trap

Cisco often tests the distinction between organization-level inventory and network-level claiming, trapping candidates who assume that claiming a device automatically adds it to the organization's inventory or that a valid serial number is sufficient without prior inventory registration.

How to eliminate wrong answers

Option A is wrong because the API key has full organization access, which includes permission to claim devices; a permission issue would typically result in a 403 Forbidden error, not a 400 error. Option B is wrong because the question explicitly states that the serial numbers are correct and unused, so a typo is not the cause. Option D is wrong because the devices are MR and MS models, which are supported by the Meraki dashboard API for claiming; the error message does not indicate an unsupported model.

455
Multi-Selectmedium

A developer is writing a Python script to interact with a REST API. The script must handle HTTP responses correctly. Which two HTTP status code ranges indicate a successful request and a client error, respectively? (Choose two.)

Select 2 answers
A.2xx
B.3xx
C.1xx
D.4xx
E.5xx
AnswersA, D

2xx status codes indicate success. The request was successfully received, understood, and accepted. For example, 200 OK means the request succeeded. This range is used when the client's request was valid and the server fulfilled it.

Why this answer

HTTP status codes are grouped into five classes. 2xx codes indicate successful request handling, such as 200 OK. 4xx codes indicate client errors, such as 404 Not Found or 400 Bad Request. 1xx, 3xx, and 5xx represent informational, redirection, and server error responses, respectively. Therefore, the correct ranges for success and client error are 2xx and 4xx.

Exam trap

The trap here is confusing 5xx (server error) with 4xx (client error), or thinking that 3xx indicates success.

456
MCQhard

A developer is writing a Python script that uses the requests library to call a REST API. The API occasionally returns a 429 status code. Which approach best handles this situation?

A.Implement exponential backoff and respect the Retry-After header if present.
B.Ignore the 429 and continue with the next request.
C.Retry the request immediately in a tight loop until it succeeds.
D.Switch to a different API endpoint that is not rate-limited.
AnswerA

Exponential backoff increases the delay between retries, reducing load on the API. Respecting the Retry-After header ensures compliance with the API's rate limit policy. This approach is standard for handling 429 errors and improves the chances of eventual success without causing further throttling. It is both polite and effective.

Why this answer

Exponential backoff with respect to Retry-After is the recommended way to handle 429 responses. It allows the client to recover from rate limiting without overwhelming the server. The other options either ignore the error, retry too aggressively, or avoid the endpoint, none of which are robust solutions.

This approach balances persistence with respect for API limits.

Exam trap

The trap here is thinking that immediate retries will eventually succeed, but they can worsen rate limiting; backoff is essential.

457
Multi-Selectmedium

Which TWO of the following are valid private IPv4 address ranges? (Select two.)

Select 2 answers
A.172.15.0.0/12
B.10.0.0.0/8
C.172.32.0.0/12
D.169.254.0.0/16
E.192.168.0.0/16
AnswersB, E

10.0.0.0/8 sits within the RFC 1918 private addressing space, spanning 10.0.0.0 to 10.255.255.255. It satisfies the stem's requirement for a valid private IPv4 range, unlike public or reserved blocks. Organisations use it for internal networks, with NAT handling external traffic.

Why this answer

Option B, 10.0.0.0/8, is correct because RFC 1918 designates the entire 10.0.0.0/8 block as a private IPv4 range, giving roughly 16.7 million addresses for internal use. Option E, 192.168.0.0/16, is also correct because RFC 1918 reserves 192.168.0.0/16 for private networks, commonly used in home and small-office LANs. The third RFC 1918 range, 172.16.0.0/12, covers 172.16.0.0 through 172.31.255.255, which is why option A (172.15.0.0/12) and option C (172.32.0.0/12) fall outside the private block and are invalid.

Option D, 169.254.0.0/16, is not a private range but the APIPA/link-local block (RFC 3927), automatically self-assigned when DHCP fails, so it does not qualify.

Exam trap

The trap here is confusing the 172.16.0.0/12 private range with adjacent public ranges like 172.15.0.0/12 or 172.32.0.0/12, or mistaking the link-local 169.254.0.0/16 for a private range.

458
MCQeasy

A developer needs to configure a Cisco IOS XE device using NETCONF and wants to ensure the session supports candidate configuration and confirmed commit. Which capability must the device advertise in its NETCONF hello message?

A.urn:ietf:params:netconf:capability:writable-running:1.0
B.urn:ietf:params:netconf:capability:candidate:1.0
C.urn:ietf:params:netconf:capability:startup:1.0
D.urn:ietf:params:netconf:capability:rollback-on-error:1.0
AnswerB

The candidate capability means the device supports a candidate configuration datastore that can be edited, validated, and then committed atomically. Combined with confirmed-commit, this allows the developer to stage changes and have them automatically rolled back if the commit is not confirmed, which is exactly the safe configuration workflow described.

Why this answer

NETCONF defines capabilities in the hello exchange, and candidate configuration is advertised via the candidate capability URN. When a device supports it, clients can edit the candidate datastore, validate it, and commit atomically. Confirmed commit builds on this by requiring an explicit confirmation within a timeout, otherwise the device reverts.

The candidate capability is therefore the prerequisite for the described workflow.

Exam trap

The trap here is assuming that writable-running is enough for transactional changes, when candidate configuration and confirmed commit require the candidate capability specifically.

459
MCQeasy

When using the Cisco Meraki Dashboard API to create an HTTP webhook for network alerts, which authentication method is required in the request header?

A.Authorization: Bearer <token>
B.Include the API key as a query parameter.
C.Authorization: Basic <base64>
D.X-Cisco-Meraki-API-Key: <your_api_key>
AnswerD

The Meraki Dashboard API authenticates every call with a custom header, X-Cisco-Meraki-API-Key, carrying the user-generated key. This satisfies the stem's requirement for the header-based credential, unlike OAuth bearer tokens or basic authentication, which the API does not accept.

Why this answer

The Cisco Meraki Dashboard API requires authentication via a custom HTTP header named `X-Cisco-Meraki-API-Key`, where the value is your API key. This is the only supported method for authenticating requests to the Meraki API, as documented in the official API reference. Option D correctly specifies this header, making it the required authentication method for creating an HTTP webhook for network alerts.

Exam trap

Cisco often tests the distinction between standard authentication methods (Bearer tokens, Basic Auth) and vendor-specific custom headers, so the trap here is that candidates may assume a common standard like OAuth 2.0 or Basic Auth applies, when the Meraki API explicitly requires its own proprietary header.

How to eliminate wrong answers

Option A is wrong because the Meraki API does not use OAuth 2.0 Bearer tokens; it uses a custom API key header instead. Option B is wrong because passing the API key as a query parameter is insecure and not supported by the Meraki API; the key must be sent in a header. Option C is wrong because HTTP Basic Authentication (Base64-encoded credentials) is not used by the Meraki API; it relies solely on the `X-Cisco-Meraki-API-Key` header.

460
MCQeasy

Which design principle suggests that a module should be responsible for a single part of the functionality?

A.Separation of Concerns
B.YAGNI (You Aren't Gonna Need It)
C.DRY (Don't Repeat Yourself)
D.KISS (Keep It Simple, Stupid)
AnswerA

Separation of Concerns assigns each module one distinct responsibility, directly satisfying the stem's requirement for a single part of the functionality. Unlike cohesion, which measures how strongly related a module's internals are, this principle prescribes the boundary itself, keeping unrelated functionality isolated so changes in one area do not ripple across others.

Why this answer

Separation of Concerns (SoC) is the design principle that dictates each module or component should focus on a single, well-defined part of the functionality. In software development, this reduces coupling and increases cohesion, making code easier to maintain, test, and refactor. For example, in a Python Flask web application, separating route handling, business logic, and database access into distinct modules follows SoC.

Exam trap

Cisco often tests the distinction between Separation of Concerns and DRY, as candidates may confuse 'not repeating code' with 'assigning single responsibility' — the trap is that DRY is about code reuse, not module focus.

How to eliminate wrong answers

Option B (YAGNI) is wrong because it advises against adding functionality until it is actually needed, focusing on avoiding over-engineering rather than assigning single responsibilities to modules. Option C (DRY) is wrong because it aims to reduce duplication of code by abstracting repeated logic, not to ensure each module handles one part of functionality. Option D (KISS) is wrong because it advocates for simplicity in design and implementation, but does not specifically address the granularity of module responsibility.

461
MCQmedium

A DNS AAAA record is used to resolve a hostname to what type of address?

A.Mail exchange server
B.IPv4 address
C.Canonical name alias
D.IPv6 address
AnswerD

An AAAA record maps a hostname to a 128-bit IPv6 address, satisfying the stem's requirement for the address family returned by this record type. It mirrors the A record's role for IPv4 but uses four times the bits, which is why the mnemonic quadruples the letter.

Why this answer

A DNS AAAA record maps a hostname to an IPv6 address, analogous to how an A record maps to an IPv4 address. The four A's in 'AAAA' correspond to the 128-bit IPv6 address being four times the 32-bit IPv4 size, making it the standard record type for IPv6 resolution.

Exam trap

The trap is confusing AAAA with A records or with CNAME — candidates must remember AAAA is exclusively for IPv6, while A is for IPv4 and CNAME is an alias.

How to eliminate wrong answers

Option A is wrong because mail exchange servers are specified by MX records, which direct email delivery to mail servers. Option B is wrong because IPv4 addresses are resolved via A records, not AAAA records. Option C is wrong because canonical name aliases are defined by CNAME records, which point one hostname to another hostname rather than to an IP address.

462
MCQeasy

A network engineer is using the Cisco DNA Center Intent API to retrieve a list of all sites. Which HTTP method and endpoint should be used?

A.GET /dna/intent/api/v1/site
B.GET /dna/system/api/v1/site
C.GET /dna/intent/api/v1/sites
D.POST /dna/intent/api/v1/site
AnswerA

The Cisco DNA Center Intent API provides a GET endpoint at /dna/intent/api/v1/site to retrieve all sites. This endpoint returns a list of sites defined in the network hierarchy. It is a read-only operation that requires authentication via an X-Auth-Token header obtained from the authentication API. This is the correct way to list sites.

Why this answer

To retrieve a list of sites in Cisco DNA Center, the correct API call is a GET request to /dna/intent/api/v1/site. This endpoint is part of the Intent API and returns all sites. Authentication is required using a token from the authentication API.

Other methods or paths do not perform this function.

Exam trap

The trap here is confusing the singular and plural forms of the endpoint or using the wrong base path for the Intent API.

463
MCQeasy

Using the Cisco DNA Center API, which endpoint should be queried to retrieve the Layer 2 topology for a specific VLAN?

A.GET /dna/intent/api/v1/issues
B.GET /dna/intent/api/v1/topology/l2/{vlanID}
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/physical-topology
AnswerB

The DNA Center intent API exposes Layer 2 topology through the topology/l2 path, and appending the VLAN identifier scopes results to that broadcast domain. Querying this endpoint with GET returns nodes and links for the specified VLAN, matching the requirement.

Why this answer

Cisco DNA Center provides /dna/intent/api/v1/topology/l2/{vlanID} to retrieve Layer 2 topology information for a given VLAN.

464
MCQmedium

A developer needs to update an existing resource via a REST API. The update should be partial, meaning only the fields provided in the request body should be changed. Which HTTP method should be used?

A.PATCH
B.DELETE
C.PUT
D.POST
AnswerA

PATCH applies a partial modification, changing only the fields included in the request body while leaving all other resource properties untouched. This directly satisfies the stem's requirement for a partial update, unlike PUT, which replaces the entire resource representation and would overwrite unspecified fields with defaults or nulls.

Why this answer

PATCH is used for partial updates to a resource, while PUT replaces the entire resource.

465
MCQmedium

A developer wants to retrieve the current user's Webex profile information. Which API endpoint should be called?

A.GET /v1/people
B.GET /v1/people/me
C.GET /v1/memberships/me
D.GET /v1/rooms/me
AnswerB

GET /v1/people/me returns the authenticated user's own profile, resolving the caller's identity from the OAuth token rather than requiring an explicit person ID. This satisfies the stem's requirement to retrieve the current user's Webex profile information without knowing or supplying their identifier in advance.

Why this answer

The /v1/people/me endpoint returns details about the authenticated user.

466
Multi-Selectmedium

Which THREE of the following are key principles of Infrastructure as Code (IaC) as applied to network automation?

Select 3 answers
A.Manual configuration is preferred for critical devices.
B.Configuration should be idempotent.
C.Configuration should be validated through automated testing.
D.Temporary scripts should be used for one-time changes.
E.All configuration code should be stored in version control.
AnswersB, C, E

Idempotency ensures consistent state.

Why this answer

Idempotency ensures that applying the same configuration multiple times results in the same final state, preventing unintended changes. In network automation, tools like Ansible or Terraform use idempotent modules (e.g., `ios_config`) to verify the current device state before applying changes, avoiding configuration drift or repeated command failures.

Exam trap

Cisco often tests the misconception that IaC allows manual overrides for critical devices or that one-time scripts are acceptable, but the exam expects you to recognize that all changes must be code-driven, version-controlled, and idempotent to ensure consistency and auditability.

467
Multi-Selectmedium

A developer is designing a Python script that interacts with multiple Cisco APIs, including Cisco Webex and Cisco DNA Center. The script must authenticate to each API and handle tokens securely. Which TWO of the following practices are recommended for securely managing API credentials and tokens? (Choose two.)

Select 2 answers
A.Store API keys and tokens in environment variables or a secure vault, and retrieve them at runtime.
B.Share API tokens with team members via email to facilitate collaboration.
C.Implement token refresh logic to automatically obtain a new access token when the current one expires, using a refresh token.
D.Log the full API request and response, including Authorization headers, to aid in debugging.
E.Hard-code API keys directly in the Python script for simplicity and ease of deployment.
AnswersA, C

Using environment variables or a secure vault keeps credentials out of source code, reducing the risk of accidental exposure. It allows for different configurations across environments and facilitates rotation. This is a widely recommended practice for managing secrets in applications.

Why this answer

The recommended practices are to store credentials securely (e.g., environment variables or vault) and to implement token refresh logic. These reduce the risk of credential leakage and ensure uninterrupted API access. Hard-coding, logging tokens, and sharing via email are insecure and should be avoided.

Exam trap

The trap here is underestimating the risk of hard-coding or logging credentials, which are common but dangerous shortcuts.

468
MCQhard

A security team requires that a web application's API calls to an internal service use mutual TLS. The application runs in a Kubernetes pod and the team wants the certificate and private key mounted as files without embedding them in the container image. Which Kubernetes resource should be used to provide the certificate and key to the pod?

A.A ConfigMap containing the certificate and key in data fields
B.An environment variable defined in the pod spec referencing a Secret
C.A Secret of type kubernetes.io/tls mounted as a volume
D.A PersistentVolumeClaim bound to a network file share
AnswerC

A Secret of type kubernetes.io/tls stores a TLS certificate and private key and can be mounted as files into a pod via a volume. This keeps sensitive material out of the image and allows the application to read the files at a known path for mutual TLS. Other resources either store non-sensitive data or do not provide file-based injection.

Why this answer

Kubernetes Secrets are designed for sensitive data and the kubernetes.io/tls type specifically holds a certificate and key. Mounting the Secret as a volume projects the data into files inside the pod, allowing the application to load them for mutual TLS without baking credentials into the image. This satisfies both the security and file-mount requirements.

Exam trap

The trap here is treating ConfigMaps and Secrets as interchangeable because both can be mounted as files, when only Secrets are intended for confidential key material.

469
MCQmedium

A developer is testing a REST API using curl. The API returns a JSON response with a status code of 201. What does this status code indicate about the request?

A.The request was successful and the response contains a representation of the modified resource.
B.The request was successful and a new resource was created.
C.The request was accepted for processing but has not been completed.
D.The request was successful but the response body is empty.
AnswerB

HTTP 201 Created indicates that the request has succeeded and has led to the creation of a new resource. The response typically includes a Location header with the URI of the new resource. This is the correct interpretation for a POST request that creates a resource. It is a success status code in the 2xx range.

Why this answer

The 201 Created status code indicates that the request was successful and a new resource was created. It is commonly returned after a POST request to a collection endpoint. The response may include a Location header and a body with the new resource.

Other status codes like 200, 202, and 204 have different meanings. Understanding these distinctions is essential for API testing and development.

Exam trap

The trap here is confusing 201 Created with 200 OK or 202 Accepted, which have different implications for resource creation and processing.

470
MCQmedium

A developer's application opens a TCP connection to a REST API, sends a request, and receives a response. The developer then wants to reuse the same connection for several subsequent requests to the same host instead of opening a new socket each time. Which HTTP behavior makes this reuse possible?

A.Persistent connections keep the TCP socket open for multiple request/response exchanges.
B.The server sends a 101 Switching Protocols response to upgrade the socket.
C.The client multiplexes requests by interleaving them in a single HTTP/1.0 stream.
D.HTTP cookies are exchanged so the server can correlate successive sockets.
AnswerA

HTTP keep-alive, the default in HTTP/1.1, allows a single TCP connection to carry multiple sequential request/response pairs. Reusing the established socket avoids repeating the three-way handshake and TCP slow start for each call, which lowers latency and resource consumption when a client makes several requests to the same server.

Why this answer

Persistent connections, the default in HTTP/1.1, let a client send multiple requests over one TCP socket. This avoids re-establishing the connection and re-entering TCP slow start for every call, which is the reuse the developer wants. Cookies, protocol upgrades, and HTTP/1.0 behavior do not provide this transport-level efficiency.

Exam trap

The trap here is confusing application-layer session state, such as cookies, with transport-layer connection reuse, when only persistent connections keep the TCP socket open across requests.

471
MCQmedium

A developer is writing a script to interact with a REST API. The API documentation states that the base URL is https://api.example.com/v1/ and that the resource for users is /users. The developer needs to retrieve a list of all users. Which HTTP request should the developer send to the correct endpoint?

A.PUT https://api.example.com/v1/users
B.GET https://api.example.com/v1/users
C.GET https://api.example.com/v1/user
D.POST https://api.example.com/v1/users
AnswerB

The correct endpoint is formed by combining the base URL and the resource path. A GET request to /v1/users retrieves the collection of users. This follows RESTful conventions where GET is used to retrieve data without side effects. The full URL includes the base and the resource, resulting in the correct endpoint.

Why this answer

RESTful APIs use HTTP methods semantically: GET for retrieval, POST for creation, PUT for update, DELETE for removal. To list users, a GET request to the users collection endpoint is correct. The base URL and resource path must be concatenated properly, and the plural form /users indicates the collection.

The other methods would cause unintended actions or target the wrong resource.

Exam trap

The trap here is using POST or PUT for retrieval; these methods alter state or create resources, whereas GET is safe and idempotent for fetching data.

472
MCQmedium

A developer is building a Python script that must resolve a hostname to an IPv4 address and then connect to a specific TCP port. The script uses `socket.getaddrinfo(host, port, family=socket.AF_INET, type=socket.SOCK_STREAM)`. What does the returned list contain?

A.A dictionary mapping address families to lists of IPv4 addresses.
B.A single string containing the IPv4 address in dotted-decimal notation.
C.Tuples of (family, type, proto, canonname, sockaddr) for each address that matches the criteria.
D.A list of `ipaddress.IPv4Address` objects representing resolved addresses.
AnswerC

`socket.getaddrinfo` returns a list of 5-tuples: address family, socket type, protocol, canonical name, and a socket address tuple. With `family=socket.AF_INET` and `type=socket.SOCK_STREAM`, it filters for IPv4 TCP endpoints. Each sockaddr is a (host, port) pair for IPv4. This structure lets a client iterate over candidates and attempt connections without manually parsing DNS responses or constructing sockaddr structures.

Why this answer

`socket.getaddrinfo` resolves a host and service into a list of 5-tuples containing family, type, protocol, canonical name, and socket address. When filtered with `AF_INET` and `SOCK_STREAM`, the results are IPv4 TCP endpoints ready for socket creation. This design supports multiple addresses and protocol independence, which is why developers use it instead of the simpler but less flexible `gethostbyname`.

Exam trap

The trap here is assuming that hostname resolution returns just an IP string or a custom object, when `getaddrinfo` actually returns structured tuples designed for direct socket creation.

473
Multi-Selecthard

Which THREE of the following are benefits of using an SDN (Software-Defined Networking) architecture compared to traditional networking? (Choose three.)

Select 3 answers
A.Reduced need for network engineers.
B.Automation of network configuration changes.
C.Faster deployment of new network services.
D.Centralized control and visibility of the network.
E.Built-in encryption for all network traffic.
AnswersB, C, D

SDN separates the control plane from the data plane, letting a controller push configuration programmatically via APIs. This replaces per-device CLI changes, so network configuration changes are automated across the fabric rather than performed manually, satisfying the benefit of reduced manual effort and human error.

Why this answer

Option B is correct because SDN's centralized controller exposes northbound APIs (e.g., REST) that let orchestration tools push configuration programmatically, enabling automation of network configuration changes instead of manual CLI work on each device. Option C is correct because that same programmable control plane allows new services and policies to be provisioned in software via the controller rather than waiting on per-device hardware configuration, so new network services deploy faster. Option D is correct because SDN logically centralizes the control plane in a controller, giving a single, network-wide view and centralized control and visibility over all data-plane devices.

Option A is not a benefit—SDN changes the skill set required but does not inherently reduce the need for network engineers. Option E is not a benefit—SDN does not provide built-in encryption for all traffic; encryption is handled by separate mechanisms such as IPsec, TLS, or MACsec.

Exam trap

Cisco often tests the misconception that SDN eliminates the need for network engineers entirely, but the correct understanding is that SDN automates tasks and centralizes control, not that it removes the human role in network design and troubleshooting.

474
Multi-Selecthard

A developer is building a Python application that integrates with Cisco DNA Center. The application needs to authenticate and then retrieve a list of network devices. The developer decides to use the DNA Center Intent API. Which two steps are required to successfully authenticate and make an API call? (Choose two.)

Select 2 answers
A.Generate a JWT token using the DNA Center certificate and sign each request with it.
B.Send a POST request to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.
C.Use OAuth 2.0 with the client credentials grant to obtain an access token from the /token endpoint.
D.Include the obtained token in the 'X-Auth-Token' header for subsequent API requests.
E.Pass the username and password as query parameters in each API request.
AnswersB, D

The DNA Center Intent API requires obtaining an authentication token by sending a POST request to the /dna/system/api/v1/auth/token endpoint. The request must include Basic Auth headers with the username and password. The response contains a token that must be used in subsequent API calls. This step is essential for authentication and is documented in the Cisco DNA Center Platform API guide.

Why this answer

To authenticate with the DNA Center Intent API, the developer must first obtain a token by sending a POST request with Basic Auth credentials to the token endpoint. Then, that token must be included in the 'X-Auth-Token' header for all subsequent API calls. This two-step process ensures secure authentication and authorization.

The other options describe incorrect or insecure methods that are not supported by DNA Center.

Exam trap

The trap here is assuming DNA Center uses OAuth 2.0 or JWT, when it actually uses a simple token-based system with Basic Auth.

475
Multi-Selectmedium

A developer is writing a Python script that uses the requests library to interact with a REST API. The script must handle common HTTP status codes appropriately. Which two actions should the developer take to ensure robust error handling? (Choose two.)

Select 2 answers
A.Always assume the response is JSON and parse it without checking the Content-Type header.
B.Disable SSL verification to avoid certificate errors.
C.Check the response.status_code attribute and branch logic based on the code.
D.Set the timeout parameter to a very high value to avoid connection errors.
E.Use response.raise_for_status() to automatically raise an exception for 4xx and 5xx responses.
AnswersC, E

Checking the status_code allows the script to handle different HTTP responses explicitly. For example, a 200 indicates success, while 404 means the resource was not found, and 500 indicates a server error. By branching logic, the developer can implement retries for 5xx errors or display user-friendly messages for 4xx errors. This is a fundamental practice for robust API interaction.

Why this answer

To robustly handle HTTP errors, the developer should check the status code and branch logic accordingly, and use raise_for_status() to raise exceptions for 4xx and 5xx responses. These practices allow the script to respond appropriately to different error conditions, such as retrying or logging. Other options either introduce risks or do not address error handling effectively.

Exam trap

The trap here is thinking that increasing timeout or disabling SSL verification makes the script more robust, when they actually introduce fragility or security risks.

476
MCQeasy

A network engineer is using the Cisco DNA Center API to retrieve a list of all sites. The API response is a JSON object with a 'response' array containing site objects. The engineer wants to extract the name of each site. Which Python code snippet correctly parses the JSON response and prints each site name?

A.for site in response.json(): print(site['name'])
B.print(response.json()['name'])
C.for site in response.json()['sites']: print(site['name'])
D.for site in response.json()['response']: print(site['name'])
AnswerD

This snippet correctly accesses the 'response' key from the parsed JSON and iterates over the list of site objects, printing the 'name' field of each. The Cisco DNA Center API returns a JSON object with a top-level 'response' key containing an array of site details, so this approach accurately extracts the required information.

Why this answer

The Cisco DNA Center API returns site data within a top-level 'response' array. To print each site name, the code must parse the JSON, access the 'response' list, iterate over each site dictionary, and print the 'name' value. The correct snippet does exactly that, while the others either misidentify the key or attempt to iterate over the wrong structure.

Exam trap

The trap here is assuming that the API response directly contains a list of sites or that the top-level object has a 'name' field, rather than nesting the data under 'response'.

477
Multi-Selectmedium

A developer is reviewing a CI/CD pipeline that builds and deploys a containerized application. The team wants to protect sensitive values such as API keys and registry passwords used during the pipeline. Which TWO practices should be used? (Choose two.)

Select 2 answers
A.Commit the secrets to a private repository branch so only team members can read them.
B.Store secrets in the CI/CD platform's encrypted secret store and reference them as masked variables in pipeline steps.
C.Reuse the same secret value across all environments and rotate it only when a team member leaves.
D.Inject secrets at runtime from a dedicated secrets manager rather than baking them into the image or pipeline configuration.
E.Print the decrypted secrets to the build log so the team can verify they are correct.
AnswersB, D

Encrypted secret stores keep values out of the repository and mask them in logs, so pipeline output does not reveal them. Referencing them as variables allows jobs to consume secrets without hardcoding. This directly protects API keys and registry passwords during builds and deployments.

Why this answer

Protecting pipeline secrets requires both keeping them out of source and pipeline definitions and retrieving them from controlled stores at the moment they are needed. Encrypted secret stores with masking prevent accidental disclosure in logs, while runtime retrieval from a secrets manager limits exposure and supports rotation. Practices that persist secrets in repositories or logs defeat these protections.

Exam trap

The trap here is treating repository privacy or log verification as equivalent to secret protection, when both still expose the values.

478
MCQeasy

Which HTTP method is idempotent and safe?

A.GET
B.DELETE
C.POST
D.PUT
AnswerA

GET retrieves a representation without altering server state, satisfying both safety (no side effects) and idempotence (repeated identical requests yield the same result). Unlike POST, which creates or modifies resources, GET is defined by RFC 9110 as both safe and idempotent, making it the only listed method meeting both constraints.

Why this answer

GET is both idempotent and safe because it is designed to retrieve a resource without causing any side effects on the server. According to RFC 7231, a safe method does not modify the resource state, and an idempotent method guarantees that multiple identical requests produce the same result as a single request. GET satisfies both conditions, as it never alters server state and repeating the same GET request returns the same representation.

Exam trap

Cisco often tests the distinction between idempotent and safe by pairing DELETE (idempotent but not safe) or PUT (idempotent but not safe) as distractors, leading candidates to assume that any method that can be repeated safely is also safe, when in fact safety requires no server-side state change.

How to eliminate wrong answers

Option B (DELETE) is wrong because while DELETE is idempotent (repeated calls have the same effect as one call, typically returning 404 after the first deletion), it is not safe because it modifies server state by removing a resource. Option C (POST) is wrong because POST is neither safe nor idempotent; it creates or updates a resource, and multiple identical POST requests can result in multiple resource creations or side effects. Option D (PUT) is wrong because although PUT is idempotent (replacing a resource with the same representation yields the same state), it is not safe because it modifies server state by updating or creating a resource.

479
MCQeasy

What HTTP method should be used to update only the description field of a network device resource via a REST API?

A.DELETE
B.PUT
C.POST
D.PATCH
AnswerD

PATCH applies a partial modification, sending only the description field in the request body while leaving all other device attributes untouched. PUT would replace the entire resource representation, risking unintended overwrites of unmentioned fields. This satisfies the stem's constraint of updating solely the description.

Why this answer

PATCH is used for partial updates, whereas PUT replaces the entire resource. GET retrieves, POST creates, DELETE removes.

480
Multi-Selecthard

A company is implementing a secure CI/CD pipeline. Which THREE practices are essential for securing the pipeline?

Select 3 answers
A.Sign and verify all build artifacts.
B.Allow all container images to be pulled from any public registry.
C.Store secrets (API keys, passwords) in version control.
D.Implement role-based access control (RBAC) on the CI/CD system.
E.Use static application security testing (SAST) tools in the build stage.
AnswersA, D, E

Signing build artifacts with a private key and verifying signatures before deployment ensures tampering between build and release is detected. This satisfies the pipeline's integrity requirement, preventing an attacker who compromises an intermediate repository from injecting altered binaries into production.

Why this answer

Option A is correct because signing build artifacts (e.g., with Sigstore/cosign or GPG) and verifying those signatures before deployment ensures integrity and provenance, preventing tampered or unauthorized artifacts from reaching production. Option D is correct because implementing role-based access control (RBAC) on the CI/CD system enforces least privilege, restricting who can modify pipelines, trigger builds, or access secrets and deployment targets. Option E is correct because integrating SAST tools into the build stage catches code-level vulnerabilities (e.g., injection flaws, insecure deserialization) early, before artifacts are promoted through the pipeline.

Option B is incorrect because pulling container images from any public registry exposes the pipeline to untrusted or malicious images; images should come from vetted, trusted registries with scanning and signature verification. Option C is incorrect because storing secrets such as API keys and passwords in version control exposes them to anyone with repository access and to history leaks; secrets should be kept in a dedicated secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager) and injected at runtime.

Exam trap

Cisco often tests the misconception that 'allowing any public registry' is acceptable for speed or convenience, but the correct practice is to restrict registries to trusted, scanned sources to prevent supply chain attacks.

481
MCQmedium

During a network outage, a technician notices that hosts in VLAN 10 cannot reach the default gateway at 192.168.10.1, but hosts in VLAN 20 can. The switch interfaces are up, and the router is configured with subinterfaces. What is the most likely cause?

A.The trunk link is administratively down.
B.The switchport trunk native VLAN is mismatched.
C.The router subinterface for VLAN 10 is down or misconfigured.
D.The router does not have an IP address configured.
AnswerC

VLAN 20 succeeding proves the router's trunk and subinterface configuration works generally, isolating the fault to VLAN 10's subinterface being down or misconfigured. This satisfies the stem's constraint by explaining why only VLAN 10 hosts cannot reach their gateway.

Why this answer

The router subinterface for VLAN 10 is down or misconfigured. Since hosts in VLAN 10 cannot reach the default gateway but hosts in VLAN 20 can, the issue is isolated to VLAN 10. The router uses subinterfaces to route between VLANs via a trunk link; if the subinterface for VLAN 10 is down (e.g., no 'no shutdown' command) or misconfigured (e.g., wrong VLAN ID or encapsulation), it will not process traffic for that VLAN, while other subinterfaces remain functional.

Exam trap

Cisco often tests the misconception that a trunk link issue or native VLAN mismatch would affect all VLANs equally, when in fact a subinterface-specific problem (like being administratively down or misconfigured) can isolate a single VLAN.

How to eliminate wrong answers

Option A is wrong because if the trunk link were administratively down, all VLANs (including VLAN 20) would be affected, not just VLAN 10. Option B is wrong because a native VLAN mismatch on a trunk would cause issues for untagged traffic (typically VLAN 1) or potential spanning-tree problems, but it would not selectively break only VLAN 10 while VLAN 20 works. Option D is wrong because the router does have IP addresses configured (as implied by the default gateway 192.168.10.1 for VLAN 10 and presumably another for VLAN 20), and the problem is specific to VLAN 10, not a global lack of IP configuration.

482
MCQmedium

A developer is building a Python script that calls a REST API which returns a JSON payload containing a list of interfaces. The script must parse the response and extract the 'name' field from each interface object. Which approach correctly uses the requests library to parse the JSON and iterate over the interfaces?

A.response = requests.get(url); interfaces = json.loads(response); for intf in interfaces['interfaces']: print(intf['name'])
B.response = requests.get(url); interfaces = response.json; for intf in interfaces['interfaces']: print(intf['name'])
C.response = requests.get(url); interfaces = response.json(); for intf in interfaces['interfaces']: print(intf['name'])
D.response = requests.get(url); interfaces = response.text; for intf in interfaces['interfaces']: print(intf['name'])
AnswerC

This is correct because requests.get() returns a Response object, and calling .json() on it parses the JSON body into Python data structures. If the payload has a top-level key 'interfaces' containing a list of dictionaries, indexing with ['interfaces'] and iterating yields each interface dict, from which ['name'] extracts the desired field.

Why this answer

The requests library's Response object provides a .json() method that deserializes the JSON response body into Python objects. After calling .json(), the result is typically a dictionary or list that can be indexed and iterated. Using response.json() is the idiomatic way to parse JSON in requests, and the subsequent iteration extracts the 'name' field from each interface dictionary.

Exam trap

The trap here is confusing the Response object with its JSON content, or forgetting to call .json() as a method, leading to type errors when trying to index the response.

483
MCQhard

Refer to the exhibit. A service engineer runs a 'check-sync' action on the NSO service 'vpn1'. The result shows 'out-of-sync' for device 'pe1'. What does this indicate?

A.The device pe1 is unreachable via NETCONF.
B.The service model in NSO does not have a configuration for pe1.
C.The device pe1 has a hardware failure.
D.The configuration on pe1 differs from the service model defined in NSO.
AnswerD

NSO's check-sync compares the device's running configuration against the service instance's intended configuration. An out-of-sync result means pe1's actual config has drifted from what the vpn1 service model specifies, so a re-deploy or reconcile action is needed to restore alignment.

Why this answer

The 'check-sync' action in NSO compares the actual device configuration (retrieved via NETCONF or CLI) against the configuration that NSO's service model expects. An 'out-of-sync' result for device 'pe1' means the running configuration on pe1 does not match the configuration defined by the NSO service model for that device. This is a standard NSO feature to detect configuration drift.

Exam trap

The trap here is confusing 'out-of-sync' with connectivity or hardware issues; Cisco tests whether you understand that NSO's check-sync is a configuration comparison mechanism, not a reachability or health check.

How to eliminate wrong answers

Option A is wrong because 'out-of-sync' does not indicate reachability; if pe1 were unreachable via NETCONF, the check-sync action would fail with a connection error, not return 'out-of-sync'. Option B is wrong because if the service model had no configuration for pe1, NSO would not attempt a check-sync on that device, or the result would indicate 'no configuration' rather than 'out-of-sync'. Option C is wrong because hardware failures are not detected by NSO's configuration synchronization mechanism; NSO operates at the configuration management layer, not the hardware monitoring layer.

484
Multi-Selectmedium

A developer receives HTTP 409 Conflict when updating a network configuration via Cisco NX-OS API. Which two scenarios could cause this error?

Select 2 answers
A.The resource was recently modified by another client.
B.The update conflicts with a lock held by another transaction.
C.The request body contains malformed JSON.
D.The request includes unsupported parameters.
E.The API key used is invalid.
AnswersA, B

A concurrent write by another client triggers HTTP 409 Conflict because NX-OS detects a stale configuration revision, rejecting the update to prevent overwriting newer changes. This satisfies the stem's requirement for a scenario causing the conflict, since the resource's version no longer matches the client's submitted payload.

Why this answer

Option A is correct because HTTP 409 Conflict is returned when the target resource's state has changed since the client last read it, typically due to a concurrent modification by another client, so the update cannot be applied against the stale representation. Option B is correct because NX-OS API transactions can hold locks on configuration resources, and attempting to update a resource locked by another transaction produces a 409 Conflict indicating the request conflicts with the current state of the resource. Option C is not correct because malformed JSON causes a 400 Bad Request, as the server cannot parse the payload.

Option D is not correct because unsupported parameters typically yield a 400 Bad Request or 422 Unprocessable Entity, not a 409. Option E is not correct because an invalid API key results in 401 Unauthorized (or 403 Forbidden), which is an authentication/authorization failure rather than a resource-state conflict.

Exam trap

Cisco often tests the distinction between client-side errors (400, 401) and server-side state conflicts (409), so the trap here is confusing a malformed request or authentication failure with a resource state conflict.

485
MCQeasy

Based on the exhibit, which interface is in a down/down state (both Status and Protocol are down)?

A.None
B.GigabitEthernet0/2
C.GigabitEthernet0/0
D.GigabitEthernet0/1
AnswerD

Gig0/1 shows Status down and Protocol down.

Why this answer

The exhibit shows that GigabitEthernet0/1 has both Status and Protocol listed as 'down'. In Cisco IOS, the 'Status' column indicates the line protocol state (Layer 1), and the 'Protocol' column indicates the data link layer state (Layer 2). When both are 'down', the interface is administratively down or has a physical layer issue, such as a disconnected cable or a shutdown command.

Exam trap

Cisco often tests the ability to read the 'show interfaces' output correctly, where candidates may confuse the 'Status' and 'Protocol' columns or misinterpret an 'up/up' state as a problem, leading them to select a wrong interface like GigabitEthernet0/0 or GigabitEthernet0/2.

How to eliminate wrong answers

Option A is wrong because the exhibit clearly shows at least one interface (GigabitEthernet0/1) with both Status and Protocol down, so 'None' is incorrect. Option B is wrong because GigabitEthernet0/2 shows Status as 'up' and Protocol as 'up', indicating a fully operational interface. Option C is wrong because GigabitEthernet0/0 shows Status as 'up' and Protocol as 'up', meaning it is also fully functional.

486
MCQmedium

What is the correct Content-Type header value for a RESTCONF request using JSON encoding?

A.application/yang-data+json
B.application/json
C.text/json
D.application/xml
AnswerA

`application/yang-data+json` is the media type RESTCONF mandates for JSON-encoded YANG data, as defined in RFC 8040. It satisfies the stem's JSON encoding constraint by pairing the `+json` structured suffix with the `yang-data` subtype, letting the server parse the payload against the YANG schema rather than treating it as generic JSON.

Why this answer

RESTCONF uses application/yang-data+json for JSON and application/yang-data+xml for XML. application/json is not specific to YANG data.

487
Multi-Selectmedium

A network engineer is preparing an Ansible playbook that will configure VLANs on a fleet of Cisco IOS XE switches. The playbook must authenticate to each device securely and must be able to reference the device-specific variables that the playbook expects. (Choose two.)

Select 2 answers
A.Hard-code the enable password directly inside each task's ios_config module arguments.
B.Define host and group variables for each switch in the inventory so tasks can reference the expected variable names.
C.Pass the credentials as extra variables on the ansible-playbook command line and rely on shell history being cleared.
D.Create a separate playbook for every switch and store the credentials only in that switch's playbook.
E.Store device credentials in an Ansible Vault-encrypted variable file and reference those variables in the playbook.
AnswersB, E

Ansible resolves variables from inventory host_vars and group_vars, making device-specific values available to tasks. Defining them there ensures the playbook references resolve correctly for each switch. This is the standard mechanism for supplying per-device data such as management addresses and platform-specific settings.

Why this answer

Secure authentication in Ansible is achieved by encrypting secrets with Ansible Vault and letting the playbook load them at runtime, while per-device values are supplied through inventory host_vars and group_vars. Together these satisfy both requirements: credentials stay protected, and the playbook can reference the variables it expects for each switch.

Exam trap

The trap here is treating any working method of supplying credentials as acceptable, when only encrypted storage plus proper variable resolution meets the stated security and reference requirements.

488
Multi-Selectmedium

Which TWO of the following are recommended practices for securing a CI/CD pipeline in a DevOps environment? (Choose two.)

Select 2 answers
A.Store secrets and credentials in a secure vault and inject them at runtime
B.Grant all developers write access to the production environment to enable faster fixes
C.Deploy code to production first, then run security tests to check for issues
D.Scan container images for known vulnerabilities as part of the build pipeline
E.Use the same API token for all pipeline stages to simplify authentication
AnswersA, D

Hard-coded credentials in pipeline definitions, scripts or repositories leak through logs and version history. A vault keeps secrets encrypted and access-controlled, injecting them only into the running job, so the pipeline never persists plaintext credentials in build artefacts or source control.

Why this answer

Option A is correct because storing secrets and credentials in a dedicated secure vault (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) and injecting them at runtime avoids hardcoding sensitive data in source code, pipeline configs, or environment files, reducing the risk of credential leakage and enabling centralized rotation and auditing. Option D is correct because integrating container image scanning (e.g., Trivy, Clair, Anchore, or native registry scanners) into the build pipeline detects known CVEs in base images and dependencies early, allowing vulnerabilities to be remediated before artifacts are promoted to production. Option B is not recommended because granting all developers write access to production violates least privilege and separation of duties, increasing the risk of accidental or malicious changes.

Option C is wrong because security testing must shift left and run before production deployment; testing only after deploying to production exposes live systems to unverified vulnerabilities. Option E is wrong because reusing a single API token across all pipeline stages removes stage isolation, so compromise of one stage grants broad access and prevents fine-grained, least-privilege scoping and revocation.

Exam trap

Cisco often tests the misconception that security testing can be deferred to post-production (Option C) or that shared credentials simplify management (Option E), but the correct answers emphasize proactive security (scanning early) and credential isolation (vault injection).

489
MCQmedium

A developer is troubleshooting an HTTP API call that returns a 404 status code. Which of the following is the most likely cause?

A.The server is unavailable due to maintenance
B.The requested URL endpoint does not exist
C.The server encountered an internal error
D.The client lacks proper authentication
AnswerB

HTTP 404 means the server received and understood the request but found no resource matching that URI. The endpoint path is wrong or removed, so the server cannot map it to a handler. This directly satisfies the stem's 404 symptom, unlike authentication or server errors.

Why this answer

HTTP 404 Not Found is a client-side error indicating the server could not find the requested resource at the specified URL. The most likely cause is that the endpoint path is incorrect, misspelled, removed, or not mapped to any route on the server. The server itself is reachable and processed the request, but no matching resource exists, which is precisely what 404 signifies.

Exam trap

200-901 often tests whether candidates can map HTTP status codes to their correct semantic category, so candidates confuse 404 with 401/403 (auth) or 500 (server error) and pick a plausible-sounding but wrong cause.

How to eliminate wrong answers

Option A is wrong because server unavailability due to maintenance typically produces a 503 Service Unavailable or a connection timeout, not a 404, since the server would not be able to respond with a resource-not-found status. Option C is wrong because an internal server error is represented by 500 Internal Server Error, which indicates the server encountered an unexpected condition while processing a valid request, not that the resource is missing. Option D is wrong because lack of proper authentication yields 401 Unauthorized (or 403 Forbidden for authorization failures), meaning the resource may exist but access is denied, which is distinct from the resource not being found.

490
Multi-Selecthard

A developer is writing unit tests for a Python function that interacts with a REST API. Which TWO practices are recommended to ensure tests are reliable and isolated? (Choose two.)

Select 2 answers
A.Include delays between test cases to simulate network latency.
B.Run tests in parallel to reduce execution time.
C.Mock external HTTP requests using a library like unittest.mock or responses.
D.Use real API endpoints to ensure the function works with actual data.
E.Assert that the function returns the expected data structure and values.
AnswersC, E

Mocking external HTTP requests prevents tests from depending on network availability or API rate limits. It allows you to simulate various responses, including errors, and ensures tests run quickly and deterministically. This isolation is crucial for reliable unit tests, as it removes external dependencies and focuses on the function's logic.

Why this answer

Mocking external HTTP requests and asserting on the function's output are key to reliable unit tests. Mocking isolates the code under test from external dependencies, while assertions validate correct behavior. Together, they ensure tests are fast, deterministic, and focused on logic.

The other practices either introduce dependencies or do not address isolation and reliability.

Exam trap

The trap here is thinking that testing against real APIs provides more confidence, but it actually makes tests unreliable and non-deterministic.

491
MCQmedium

Which Git branching strategy typically involves a long-lived 'develop' branch where feature branches are merged, and releases are created from a 'release' branch?

A.GitFlow
B.GitHub Flow
C.Trunk-based development
D.Feature branch workflow
AnswerA

GitFlow defines a long-lived develop branch that accumulates merged feature branches, with release branches cut from develop for stabilisation before merging into main. This matches the stem's described structure precisely, unlike trunk-based or GitHub Flow.

Why this answer

GitFlow is correct because it defines a long-lived 'develop' branch for integrating feature branches, and a separate 'release' branch for preparing releases. This strategy uses dedicated branches for features, releases, and hotfixes, with strict merging rules back to 'develop' and 'main'.

Exam trap

Cisco often tests the distinction between GitFlow's multiple long-lived branches (develop, release, main) and simpler workflows like GitHub Flow or trunk-based development, where candidates mistakenly assume any workflow with feature branches is GitFlow.

How to eliminate wrong answers

Option B (GitHub Flow) is wrong because it uses a single long-lived 'main' branch with short-lived feature branches, and releases are created directly from 'main' without a dedicated 'release' branch. Option C (Trunk-based development) is wrong because it relies on a single trunk branch (often 'main' or 'trunk') with very short-lived feature branches, and no long-lived 'develop' or 'release' branches. Option D (Feature branch workflow) is wrong because it typically merges feature branches directly into a shared branch (e.g., 'main') without a separate long-lived 'develop' branch or a dedicated 'release' branch.

492
MCQeasy

A developer is writing a Python script to interact with a Cisco DNA Center controller. The script needs to authenticate and obtain a token to make subsequent API calls. Which authentication method should the developer use?

A.Generate an API key in the DNA Center GUI and include it in the X-API-Key header.
B.POST to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.
C.HTTP Basic Authentication with username and password in the Authorization header.
D.Use OAuth 2.0 with a client ID and client secret to obtain an access token.
AnswerB

Cisco DNA Center uses token-based authentication. The developer must send a POST request to the '/dna/system/api/v1/auth/token' endpoint with the username and password encoded in Base64 in the Authorization header. The response contains a token that must be included in subsequent API calls as 'X-Auth-Token'. This is the standard method for DNA Center API authentication.

Why this answer

Cisco DNA Center API authentication requires a POST request to the '/dna/system/api/v1/auth/token' endpoint with Basic Auth credentials. The response includes a token that must be used in the 'X-Auth-Token' header for subsequent calls. This token-based approach ensures secure and session-managed access.

Exam trap

The trap here is assuming that DNA Center uses OAuth or static API keys like other platforms, when it actually uses a custom token endpoint with Basic Auth.

493
MCQhard

A developer needs to use Postman to test an API that uses Basic authentication. How should the credentials be configured in Postman?

A.Send the credentials in the request body as JSON
B.Use the Authorization tab, select Basic Auth, and enter username and password
C.Set the Authorization header to 'Bearer base64(username:password)'
D.Add a query parameter 'auth' with base64-encoded credentials
AnswerB

Configuring Basic Auth on the Authorization tab injects the credentials as a Base64-encoded `Authorization: Basic` header on every request, satisfying the stem's requirement to test a Basic-authenticated API. Postman handles encoding automatically, so the username and password need not be manually concatenated or encoded before sending.

Why this answer

Postman's Authorization tab provides a built-in Basic Auth type where you enter the username and password; Postman automatically Base64-encodes them and constructs the 'Authorization: Basic <credentials>' header per RFC 7617. This is the correct and standard way to configure Basic authentication in Postman.

Exam trap

200-901 often tests the difference between authentication schemes — candidates confuse Basic (Base64 user:pass) with Bearer (token) and pick the option that mentions Base64 but uses the wrong scheme or location.

How to eliminate wrong answers

Option A is wrong because Basic authentication credentials belong in the Authorization header, not the request body — sending them in the body is non-standard and the server will not recognize them as auth. Option C is wrong because the Bearer scheme is for token-based auth (OAuth 2.0), not Basic auth, and Basic auth uses the 'Basic' scheme with Base64(username:password), not 'Bearer'. Option D is wrong because passing credentials as a query parameter is insecure (they appear in logs and URLs) and is not how Basic auth works — the credentials must go in the Authorization header.

494
MCQmedium

A network engineer is troubleshooting a connectivity issue between two subnets. The engineer uses the traceroute command and observes that packets are reaching the destination but with high latency. Which of the following is the most likely cause of the high latency?

A.Network congestion causing packets to be queued at intermediate devices.
B.Incorrect subnet mask configuration on the source device.
C.A routing loop causing packets to traverse multiple hops repeatedly.
D.A firewall blocking ICMP packets, causing retransmissions.
AnswerA

Network congestion occurs when the volume of traffic exceeds the capacity of a link or device, causing packets to be buffered and delayed. This results in increased latency without necessarily causing packet loss. Traceroute would show increased round-trip times at the congested hop, while packets still reach the destination.

Why this answer

Network congestion causes packets to be queued at intermediate devices, increasing latency. Traceroute would show higher round-trip times at the congested hop, but packets still reach the destination. This is a common cause of high latency without packet loss.

Exam trap

The trap here is attributing high latency to routing loops or misconfigurations, which would typically cause packet loss or unreachability rather than just increased latency.

495
MCQeasy

A developer is deploying a containerized application to a Kubernetes cluster. To ensure that the application can securely access a third-party API, what is the best practice for storing the API key?

A.Store it as a Kubernetes Secret and mount it as an environment variable.
B.Hardcode the API key in the Docker image.
C.Use a service account token.
D.Store it in a ConfigMap and reference it from the pod.
AnswerA

Kubernetes Secrets hold sensitive data separately from the pod spec and image, satisfying the requirement to avoid hard-coding the API key. Mounting it as an environment variable injects the credential at runtime, so the container authenticates to the third-party API without exposing the key in source control or the image layer.

Why this answer

Storing the API key as a Kubernetes Secret and mounting it as an environment variable is correct because Secrets are the native Kubernetes mechanism for holding sensitive data such as API keys, passwords, and tokens. They are stored separately from pod specifications and can be injected as environment variables or mounted volumes, keeping credentials out of container images and source code.

Exam trap

200-901 often tests the Secret vs ConfigMap distinction — candidates pick ConfigMap because both store key-value data, but only Secrets are intended for sensitive credentials, and the exam expects you to know that distinction.

How to eliminate wrong answers

Option B is wrong because hardcoding the API key in the Docker image embeds the credential in every layer of the image, exposing it to anyone who pulls the image and making rotation extremely difficult. Option C is wrong because a service account token authenticates the pod to the Kubernetes API server, not to a third-party external API — it is the wrong credential type for this use case. Option D is wrong because ConfigMaps store non-sensitive configuration data in plaintext and are not designed for secrets; using a ConfigMap for an API key exposes it without the (limited) protections Secrets provide.

496
MCQhard

A Kubernetes pod needs to run a database that requires persistent storage. Which volume type should be used to store data that persists beyond the pod lifecycle?

A.emptyDir
B.PersistentVolumeClaim
C.configMap
D.hostPath
AnswerB

A PersistentVolumeClaim binds to a PersistentVolume, decoupling storage lifecycle from the pod so data survives pod deletion and rescheduling. This satisfies the stem's requirement for storage persisting beyond the pod lifecycle, unlike emptyDir or hostPath, which are tied to the pod or node.

Why this answer

PersistentVolumeClaim requests persistent storage that survives pod restarts. emptyDir is ephemeral, hostPath ties to a node, configMap is for configuration.

497
MCQmedium

A developer is using the Cisco Webex API to send a message to a specific room. They have the room ID. Which endpoint and method should they use?

A.PUT /v1/messages/{messageId}
B.POST /v1/messages with roomId in the body
C.POST /v1/rooms with roomId in the body
D.GET /v1/messages?roomId=...
AnswerB

Creating a message is a resource-creation action, so the Webex messaging API expects an HTTP POST to the /v1/messages collection endpoint. The target room is identified by passing roomId in the JSON request body, which routes the message to that specific room.

Why this answer

To send a message to a Webex room, the correct endpoint is POST /v1/messages with roomId in the body.

498
Multi-Selecthard

A developer is preparing a Python script that authenticates to a Cisco DNA Center controller, retrieves a list of network devices, and writes the inventory into a reusable module consumed by other teams. The team lead requires that the credentials never be stored in the source code. Which TWO practices satisfy that requirement? (Choose two.)

Select 2 answers
A.Load the credentials from a separate configuration file that is listed in .gitignore and provisioned on each host.
B.Encode the credentials with base64 inside the module so they are unreadable to anyone browsing the source.
C.Commit the credentials in an encrypted form and keep the decryption key in the same repository branch for convenience.
D.Read the credentials at runtime from environment variables that are set outside the repository on the execution host.
E.Hard-code the credentials as module-level constants but rename the variables so they are not obviously credentials.
AnswersA, D

A config file excluded by .gitignore is never committed, so the secret does not enter the repository history. Each environment supplies its own file, and the parsing code can be committed safely because it contains no secret values, satisfying the requirement while remaining convenient for other teams.

Why this answer

Secrets must be injected from outside the repository so that committed code never contains them. Environment variables and an ignored, per-host configuration file both achieve this, letting each consumer supply its own values while the module itself holds only the logic that reads them. Encoding or renaming secrets inside the source leaves the values in version history.

Exam trap

The trap here is treating encoding or renaming as protection, when only keeping the secret outside the committed source actually removes it.

499
MCQmedium

A developer is writing an application that needs to send a large amount of data reliably over a network. Which transport layer protocol should the developer use?

A.TCP
B.ICMP
C.HTTP
D.UDP
AnswerA

TCP provides connection-oriented, reliable delivery: sequence numbers, acknowledgements and retransmission recover lost or reordered segments, and flow control prevents overwhelming the receiver. This guarantees the integrity of large transfers, which the unreliable, best-effort UDP cannot.

Why this answer

TCP (Transmission Control Protocol) is the correct choice because it provides reliable, connection-oriented data delivery with acknowledgments, retransmission, and sequencing. This ensures that large amounts of data are transmitted without loss or corruption, which is critical for applications requiring data integrity.

Exam trap

Cisco often tests the distinction between transport-layer protocols (TCP vs. UDP) and higher-layer protocols (HTTP), so the trap here is that candidates might choose HTTP because it is commonly used for data transfer, forgetting that it is not a transport-layer protocol.

How to eliminate wrong answers

Option B (ICMP) is wrong because ICMP is a network-layer protocol used for error reporting and diagnostics (e.g., ping), not for reliable data transport. Option C (HTTP) is wrong because HTTP is an application-layer protocol that relies on TCP for reliable transport; it is not a transport-layer protocol itself. Option D (UDP) is wrong because UDP is connectionless and does not guarantee delivery, ordering, or retransmission, making it unsuitable for reliable large-data transfers.

500
Multi-Selectmedium

A developer is using Git for version control in a collaborative project and wants to ensure a clean, linear history. Which TWO practices help achieve a linear commit history? (Choose two.)

Select 2 answers
A.Use git rebase to integrate changes from the main branch into a feature branch before merging.
B.Use git merge with the --no-ff flag to always create a merge commit.
C.Use git commit --amend to modify the most recent commit.
D.Use git pull --rebase to fetch and rebase local changes on top of the remote branch.
E.Use git cherry-pick to apply specific commits from one branch to another.
AnswersA, D

Rebasing a feature branch onto the main branch rewrites the feature branch's commits to apply on top of the latest main, resulting in a linear history when merged. This avoids merge commits and keeps the commit graph clean. It is a common practice in teams that prefer a linear history, though it should be used with caution on shared branches.

Why this answer

To maintain a linear commit history, developers should rebase feature branches onto the main branch before merging and use git pull --rebase when updating from a remote. These practices avoid merge commits and keep the commit graph as a straight line. They are widely adopted in teams that prioritize a clean, readable history.

Exam trap

The trap here is thinking that merge commits are necessary for a linear history, but actually merge commits create a non-linear graph; rebasing and pull --rebase are the key practices.

501
MCQhard

A developer wants to automate the provisioning of a UCS server using Cisco Intersight. Which authentication method is recommended for programmatic access?

A.Basic authentication with username and password
B.API Key with HMAC signing
C.Session token from Intersight UI
D.OAuth2 with client credentials
AnswerB

Intersight's API Key with HMAC signing authenticates each programmatic request using a key ID and secret, avoiding interactive browser sign-in or stored passwords. This suits automated provisioning scripts, satisfying the requirement for secure non-interactive access to the UCS management platform.

Why this answer

Cisco Intersight recommends API key authentication with HMAC signing for programmatic access because it provides a secure, non-interactive method for automation scripts and tools. The API key consists of a key ID and a secret, and each request must include an HMAC signature generated from the request details, ensuring integrity and authenticity without exposing static credentials over the network.

Exam trap

Cisco often tests the distinction between interactive (session-based) and non-interactive (API key) authentication, leading candidates to mistakenly choose session tokens or basic auth because they are familiar from other Cisco platforms like UCS Manager or APIC.

How to eliminate wrong answers

Option A is wrong because basic authentication transmits the username and password in plaintext (Base64-encoded) with each request, which is insecure and not recommended for programmatic access to Intersight. Option C is wrong because a session token obtained from the Intersight UI is tied to a user session and requires interactive login, making it unsuitable for automated, headless provisioning workflows. Option D is wrong because OAuth2 with client credentials is not the standard or recommended method for Intersight; Intersight uses API key-based HMAC signing as its primary programmatic authentication mechanism.

502
MCQmedium

A network team uses an Ansible playbook to automate the configuration of multiple Cisco IOS XE devices. The playbook includes the 'ios_config' module. Which of the following best describes the purpose of the 'provider' parameter in the ios_config module?

A.It defines the connection details for the device.
B.It identifies the name of the playbook being used.
C.It specifies the configuration lines to be applied.
D.It sets the timeout for the module execution.
AnswerA

The provider parameter supplies the transport and authentication details the module needs to reach the device, such as host, username, password and connection type. Without it, ios_config cannot establish the session required to push configuration changes to the IOS XE device.

Why this answer

The 'provider' parameter in the ios_config module is a dictionary that encapsulates the connection details required to access the network device, such as hostname, username, password, port, and transport protocol (e.g., SSH). This allows the module to establish a session with the Cisco IOS XE device before applying configuration changes. Without the provider, the module would not know how to reach or authenticate to the target device.

Exam trap

Cisco often tests the distinction between the 'provider' parameter (connection details) and the 'lines' parameter (configuration commands), leading candidates to mistakenly think 'provider' specifies the configuration content.

How to eliminate wrong answers

Option B is wrong because the playbook name is defined in the playbook file itself (e.g., the name field under a play), not in the ios_config module's provider parameter. Option C is wrong because the configuration lines to be applied are specified using the 'lines' or 'parents' parameters within the ios_config module, not the provider. Option D is wrong because timeout settings are configured via a separate 'timeout' parameter in the provider dictionary or directly in the module, not as the primary purpose of the provider parameter.

503
MCQeasy

An engineer needs to automate the deployment of a new VLAN across multiple switches. Which tool is best suited for this task?

A.NetFlow
B.Syslog
C.Ansible
D.SNMP
AnswerC

Ansible's agentless architecture pushes declarative configuration over SSH, letting a single playbook apply identical VLAN definitions across many switches simultaneously. This directly satisfies the stem's requirement to automate deployment across multiple devices, unlike manual CLI entry or per-device scripting, and needs no software installed on the switches themselves.

Why this answer

Ansible is the correct tool because it is an agentless automation platform that uses SSH to push configuration changes, such as VLAN deployment, to network devices. It allows engineers to define the desired state of VLANs in YAML playbooks and apply them consistently across multiple switches without manual intervention.

Exam trap

Cisco often tests the distinction between monitoring protocols (NetFlow, Syslog, SNMP) and automation tools (Ansible, Puppet, Chef), leading candidates to mistakenly choose SNMP because they recall it can write configurations, but they overlook its lack of idempotency and scalability for multi-switch VLAN deployment.

How to eliminate wrong answers

Option A is wrong because NetFlow is a network protocol used for traffic monitoring and analysis, not for configuration deployment. Option B is wrong because Syslog is a standard for message logging and does not provide any mechanism to push configuration changes to devices. Option D is wrong because SNMP is primarily used for monitoring and reading device statistics via MIBs, and while it can write some configuration values (SNMP SET), it is not designed for reliable, idempotent, or scalable VLAN deployment across multiple switches.

504
MCQhard

A Kubernetes cluster is configured with a NetworkPolicy that allows ingress traffic only from pods with label 'app: frontend'. A new backend service needs to communicate with the database pod. What must be done to allow this?

A.Delete the existing NetworkPolicy
B.Add label 'app: backend' to the database pod
C.Modify the NetworkPolicy to include an additional rule allowing from pods with label 'app: backend'
D.Create a new NetworkPolicy for the database
AnswerC

Modifying the existing NetworkPolicy to add an ingress rule that allows pods with label 'app: backend' is the correct approach. It permits the needed traffic while preserving the existing restriction that only 'app: frontend' pods are allowed by default. This is the most secure and appropriate solution.

Why this answer

The existing NetworkPolicy only allows ingress from pods with label 'app: frontend'. To allow the backend service (which presumably has label 'app: backend') to communicate with the database pod, the best practice is to modify the existing NetworkPolicy to include an additional ingress rule that allows pods with label 'app: backend'. This preserves the existing security restrictions while permitting the new traffic.

Deleting the policy (option A) would remove all ingress restrictions, which is less secure and not necessary unless explicitly required. Option B only adds a label to the database pod and does not affect the NetworkPolicy's source selection. Option D creates a new policy, but because NetworkPolicies are additive, the existing policy still denies traffic from the backend, so a new policy alone would not work unless it selects the same pod and explicitly allows the traffic; modifying the existing policy is simpler and more appropriate.

Exam trap

Candidates may think that deleting the restrictive NetworkPolicy is the easiest solution, but the question asks what 'must be done' to allow the backend service while maintaining security. The correct approach is to add an ingress rule to the existing policy for the backend label, not to remove all restrictions.

How to eliminate wrong answers

Option B is wrong because adding the label 'app: backend' to the database pod does not change the source of traffic; the NetworkPolicy filters based on the source pod's labels, not the destination pod's labels. Option C is wrong because modifying the NetworkPolicy to include an additional rule for pods with label 'app: backend' would allow the backend service to reach the database, but this is not the only correct approach; the question asks 'what must be done', and deleting the policy is a valid and simpler solution, but the answer explicitly marks A as correct, so C is not the required action. Option D is wrong because creating a new NetworkPolicy for the database does not override the existing policy; Kubernetes NetworkPolicies are additive, so the existing policy would still block traffic from pods without the 'app: frontend' label, and the new policy would only add additional rules, not remove the restriction.

505
MCQeasy

Which tool is specifically designed for model-driven programmability using YANG data models?

A.NETCONF
B.SNMP
C.CLI
D.Ansible
AnswerA

NETCONF uses YANG-modelled datastores and RPC operations to configure and retrieve device state, satisfying the stem's requirement for model-driven programmability. Unlike SNMP's MIBs or CLI scraping, NETCONF's protocol operations map directly onto YANG schema nodes, giving structured, transactional configuration rather than imperative command sequences.

Why this answer

NETCONF is the correct answer because it is a network management protocol specifically designed to operate with YANG data models, using XML or JSON encoding to transport configuration and state data. YANG defines the structure of the data, and NETCONF provides the operations (get, edit-config, etc.) to manipulate that data in a model-driven, programmatic way. This makes NETCONF the standard tool for model-driven programmability in modern network automation.

Exam trap

Cisco often tests the distinction between a protocol that natively uses YANG (NETCONF) versus tools that can work with YANG but are not designed specifically for it (like Ansible), so the trap here is assuming any automation tool that supports YANG qualifies as 'specifically designed' for model-driven programmability.

How to eliminate wrong answers

Option B (SNMP) is wrong because SNMP uses MIBs (Management Information Bases) defined by SMI (Structure of Management Information), not YANG data models, and it is primarily used for monitoring rather than model-driven configuration. Option C (CLI) is wrong because CLI is a human-oriented, command-line interface that is not model-driven and does not use YANG; it relies on proprietary, device-specific commands. Option D (Ansible) is wrong because Ansible is an automation tool that can use YANG models indirectly via modules (e.g., ios_config), but it is not specifically designed for model-driven programmability using YANG; it is a general-purpose configuration management tool.

506
MCQhard

A company is deploying a containerized application to a Kubernetes cluster. The security team requires that the container runs as a non-root user and that the root filesystem is read-only. Which Kubernetes security context settings should be applied to the pod specification to meet these requirements?

A.securityContext: { runAsUser: 0, readOnlyRootFilesystem: true }
B.securityContext: { privileged: false, readOnlyRootFilesystem: true }
C.securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true }
D.securityContext: { runAsNonRoot: true, readOnlyRootFilesystem: true }
AnswerD

This securityContext sets runAsNonRoot to true, which ensures the container does not run as UID 0, and readOnlyRootFilesystem to true, which mounts the root filesystem as read-only. These are the exact settings required to enforce the security policies. They can be applied at the pod or container level, but container-level is more granular.

Why this answer

To enforce that a container runs as a non-root user, the securityContext must include runAsNonRoot: true. To make the root filesystem read-only, readOnlyRootFilesystem: true must be set. These can be combined in a single securityContext block.

Other settings like allowPrivilegeEscalation or privileged do not guarantee non-root execution, so they are not sufficient.

Exam trap

The trap here is assuming that allowPrivilegeEscalation: false or privileged: false automatically ensures the container runs as non-root, when they do not.

507
MCQhard

A developer is using the Cisco DNA Center REST API to retrieve a list of all network devices. The API requires authentication. The developer wants to avoid hardcoding credentials and instead use a token-based authentication mechanism. Which authentication method should the developer use?

A.API key passed in the X-Auth-Token header
B.Basic Authentication with base64-encoded username and password
C.Token-based authentication using the /dna/system/api/v1/auth/token endpoint
D.OAuth 2.0 with client credentials grant
AnswerC

DNA Center provides a token endpoint at /dna/system/api/v1/auth/token. The developer sends a POST with Basic Auth credentials to receive a time-limited token, which is then used in the X-Auth-Token header for subsequent API calls. This is the correct token-based method and avoids hardcoding credentials in each request.

Why this answer

DNA Center's REST API uses a token-based authentication flow. The developer must first call the authentication endpoint with Basic Auth to obtain a token, then include that token in the X-Auth-Token header for all subsequent requests. This approach is more secure than sending credentials with every call and is the standard method for DNA Center automation.

Exam trap

The trap here is confusing DNA Center's token authentication with OAuth 2.0 or static API keys, which are not used by the platform.

508
MCQmedium

A developer needs to retrieve the current user's details from Webex API. Which endpoint should they call?

A.GET /v1/people/me
B.GET /v1/rooms?me=true
C.POST /v1/people
D.GET /v1/people?email=current@user.com
AnswerA

GET /v1/people/me returns the authenticated user's own profile, resolving identity directly from the bearer token rather than requiring a person ID. This satisfies the stem's requirement to retrieve the current user's details without first querying another endpoint to discover their identifier.

Why this answer

GET /v1/people/me returns details of the authenticated user.

509
MCQeasy

A network automation script uses RESTCONF to retrieve operational data from a Cisco device. What data format is typically supported by RESTCONF?

A.YAML
B.Plain text
C.XML or JSON
D.CSV
AnswerC

RESTCONF encodes data as either XML or JSON, negotiated through the Accept and Content-Type headers. This satisfies the stem's requirement for the format typically supported when retrieving operational data, since RESTCONF, unlike SNMP or NETCONF's XML-only encoding, permits JSON payloads alongside XML.

Why this answer

RESTCONF (RFC 8040) is a REST-like protocol that uses HTTP methods to access structured data defined by YANG models. It natively supports both XML and JSON as data serialization formats, allowing clients to choose the format via the Accept header or URL suffix (e.g., .xml or .json). This makes XML and JSON the correct answer because they are the only formats explicitly defined in the RESTCONF specification for encoding configuration and operational data.

Exam trap

Cisco often tests the misconception that RESTCONF supports YAML because of its popularity in automation tools like Ansible, but RESTCONF strictly uses XML and JSON per RFC 8040, and YAML is not a valid encoding in the standard.

How to eliminate wrong answers

Option A is wrong because YAML is not a supported data format in RESTCONF; RESTCONF uses XML and JSON as defined in RFC 8040, and YAML is not part of the standard. Option B is wrong because plain text lacks the structured, hierarchical representation required by YANG data models, and RESTCONF requires a structured format like XML or JSON for data serialization. Option D is wrong because CSV is a flat, row-based format that cannot represent the nested, tree-like data structures of YANG models, and it is not supported by RESTCONF.

510
MCQeasy

A network engineer is evaluating configuration management tools for a Cisco environment. The engineer wants to describe the push-based model where a central server runs playbooks that connect to managed devices over SSH to apply changes. Which tool uses this architecture?

A.Chef
B.Puppet
C.SaltStack
D.Ansible
AnswerD

Ansible is agentless and push-based: the control node executes playbooks and connects to managed devices over SSH to apply tasks. This matches the described architecture exactly, since no software agent must be installed on the Cisco devices and the central server initiates every change.

Why this answer

Ansible's defining architecture is agentless and push-based: the control node runs playbooks and opens SSH sessions to managed devices to execute modules. Puppet and Chef rely on agents that pull configuration, and SaltStack's signature design uses minion agents, so only Ansible matches the described model.

Exam trap

The trap here is assuming that any automation tool connects over SSH, when most agent-based tools pull policy instead of pushing it.

511
Matchingmedium

Match each JSON data type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

"hello"

42

true

[1, 2, 3]

{"key": "value"}

Why these pairings

JSON supports basic data types: string (e.g., "hello"), number (e.g., 42), boolean (true/false), null, array, and object. Common confusions include misidentifying boolean values as strings or strings as numbers.

512
MCQmedium

An automation team wants to build a custom Slack bot that receives a message when a Cisco IOS XE device sends a syslog event indicating an interface went down. Which combination of technologies should the team use to implement this event-driven workflow?

A.Use Ansible to run a playbook on a schedule that checks interface status and posts to Slack.
B.Configure the device to send syslog to a collector, and have the collector trigger a webhook to the Slack API.
C.Subscribe to model-driven telemetry on the device and have the bot pull data from the telemetry receiver.
D.Poll the device every minute with NETCONF get_config to detect interface state changes, then call the Slack API.
AnswerB

Syslog is a push mechanism, so the device sends events to a collector without polling. The collector can parse the message and call the Slack API webhook to notify the bot. This is a standard event-driven pattern that matches the requirement for near real-time notification.

Why this answer

Syslog is inherently push-based, so configuring the device to send events to a collector is the most direct way to detect an interface-down event. The collector can then invoke the Slack API webhook, creating an event-driven pipeline. Polling approaches add latency and may miss transient events.

Exam trap

The trap here is choosing a polling method because it feels simpler, when the scenario explicitly requires reacting to an event as it happens.

513
MCQeasy

Which Meraki API response header provides information for paginating through a large result set?

A.Content-Range
B.Link
C.X-RateLimit-Remaining
D.Retry-After
AnswerB

The Link response header returns RFC 5988 web-linking metadata, including rel="next", rel="prev", rel="first" and rel="last" URLs. This satisfies the stem's pagination constraint: Meraki's API caps results per page, so clients follow the rel="next" URL to retrieve subsequent records until no further link is supplied.

Why this answer

Meraki uses the Link header (LinkHeader) with 'next' and 'prev' URLs, or alternatively the startingAfter/endingBefore parameters. The Link header is standard for pagination.

514
MCQmedium

A company has multiple subnets. A device in subnet 192.168.1.0/24 needs to communicate with a device in subnet 192.168.2.0/24. What is required for this communication?

A.A DNS server
B.A VLAN
C.A bridge
D.A router or Layer 3 switch
AnswerD

A router or Layer 3 switch performs inter-subnet routing, forwarding packets between the 192.168.1.0/24 and 192.168.2.0/24 broadcast domains. Since these are distinct IP subnets, Layer 2 switching alone cannot bridge them; a Layer 3 device is required to satisfy the cross-subnet communication constraint.

Why this answer

Devices in different subnets (192.168.1.0/24 and 192.168.2.0/24) are on separate Layer 3 networks. To forward packets between these subnets, a router or Layer 3 switch is required to perform IP routing, using the destination IP address to determine the next hop. Without a Layer 3 device, the frames cannot leave the local broadcast domain.

Exam trap

Cisco often tests the misconception that a VLAN alone enables communication between subnets, but VLANs only isolate traffic at Layer 2; a Layer 3 device is always needed to route between different subnets.

How to eliminate wrong answers

Option A is wrong because a DNS server resolves hostnames to IP addresses but does not forward packets between subnets; routing is a Layer 3 function, not a naming service. Option B is wrong because a VLAN segments a single switch into multiple broadcast domains at Layer 2, but it does not route between subnets; inter-VLAN communication still requires a Layer 3 device. Option C is wrong because a bridge operates at Layer 2 to connect two network segments within the same subnet, forwarding frames based on MAC addresses; it cannot route between different IP subnets.

515
MCQhard

An engineer is using EEM on an IOS XE device. They want to trigger an applet when a specific syslog message appears. Which event trigger type should they use?

A.event syslog pattern
B.event interface
C.event cli match
D.event timer
AnswerA

The `event syslog pattern` trigger matches syslog messages against a regular expression, firing the applet when the specified pattern appears in the device log. This directly satisfies the stem's requirement to react to a specific syslog message, unlike timer, interface, or SNMP-based triggers.

Why this answer

The 'event syslog pattern' trigger in EEM (Embedded Event Manager) is specifically designed to fire an applet when a syslog message matching a regex pattern is logged. It watches the device's syslog stream and activates the applet when the pattern matches. This is the canonical trigger for reacting to specific log events on IOS XE.

Exam trap

The trap here is confusing the trigger source — candidates often pick 'event cli match' because they conflate 'matching a pattern' with CLI input, when the question explicitly says a syslog message is the trigger.

How to eliminate wrong answers

Option B is wrong because 'event interface' triggers on interface state changes (up/down) or interface counters, not on syslog message content. Option C is wrong because 'event cli match' triggers when a user types a CLI command matching a regex, not when a syslog message appears. Option D is wrong because 'event timer' triggers on a scheduled time interval (countdown, cron, absolute), not on log content.

516
Multi-Selecthard

A developer is preparing a Python script that will be committed to a shared Git repository used by a team of network automation engineers. The team wants to ensure that sensitive credentials and environment-specific files are never committed. Which TWO actions should the developer take? (Choose two.)

Select 2 answers
A.Use environment variables to supply credentials at runtime instead of hardcoding them.
B.Add a .gitignore file listing files such as .env and credentials.json.
C.Store the credentials in a README.md file so the team can easily find them.
D.Run git add . to stage all files, then manually unstage credentials before committing.
E.Commit the credentials file once, then delete it in a later commit.
AnswersA, B

Reading credentials from environment variables keeps secrets out of the codebase entirely. The script can access them at runtime without any sensitive values being stored in Git. This complements .gitignore by removing the need to commit credentials at all, satisfying the team's requirement to protect sensitive information.

Why this answer

The team needs to prevent sensitive files from entering Git. A .gitignore file excludes specified files and patterns from being tracked, and using environment variables for credentials means secrets never need to be stored in the repository. Committing credentials even temporarily, storing them in documentation, or relying on manual unstaging all risk exposing secrets and do not provide a reliable safeguard.

Exam trap

The trap here is believing that deleting a committed credentials file removes it from history, when Git retains all past commits unless history is rewritten.

517
MCQeasy

A developer is building a container image for an application and wants to minimize the attack surface by ensuring the container does not run as root. The image is based on a Linux distribution. Which Dockerfile instruction should be used to specify a non-root user for the container process?

A.EXPOSE
B.ENTRYPOINT
C.WORKDIR
D.USER
AnswerD

The USER instruction sets the user name or UID that subsequent RUN, CMD, and ENTRYPOINT instructions run as. Placing USER appuser after creating the user ensures the container process starts without root privileges, which reduces the impact of a compromise and satisfies the requirement.

Why this answer

The USER instruction changes the identity used for the container process and for later build steps. Creating a dedicated unprivileged account and switching to it before the final CMD or ENTRYPOINT ensures the application does not run as root. Other instructions affect networking, working directory, or the startup command, but none of them alter process privileges.

Exam trap

The trap here is confusing the instruction that documents a listening port with the one that changes the runtime user identity.

518
MCQmedium

When using RESTCONF to configure a network device, what Content-Type header should be set in the HTTP request to indicate YANG data in JSON format?

A.application/yang
B.application/yang-data+json
C.application/xml
D.application/json
AnswerB

RESTCONF uses the YANG-derived media type application/yang-data+json to signal JSON-encoded YANG data in the request body. Setting it as Content-Type tells the device how to parse the payload, satisfying the stem's requirement to indicate YANG data in JSON format.

Why this answer

RFC 8040 defines the media type for YANG-modeled data encoded in JSON as 'application/yang-data+json'. When sending a RESTCONF request with a JSON body, the Content-Type header must be set to this value so the device knows to parse the payload against the YANG model using the JSON encoding rules.

Exam trap

200-901 often tests the distinction between generic JSON/XML media types and the YANG-specific '+json' structured suffix, catching candidates who assume 'application/json' is always accepted.

How to eliminate wrong answers

Option A is wrong because 'application/yang' is not a registered media type for RESTCONF payloads; YANG is the modeling language, not the wire format. Option C is wrong because 'application/xml' would indicate XML-encoded data, which RESTCONF supports as 'application/yang-data+xml', not plain XML. Option D is wrong because 'application/json' is generic JSON and does not tell the device the payload conforms to YANG data rules, so RESTCONF servers reject it.

519
MCQhard

A developer is writing a Python script that uses the Cisco Meraki Dashboard API to update the VLAN configuration of a network. The script reads the API key from an environment variable and places it in the appropriate request header. Which header should the developer set, and what happens if the key is invalid?

A.Set Authorization to a Bearer token; an invalid key produces an HTTP 403 Forbidden response
B.Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 401 Unauthorized response
C.Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 404 Not Found response
D.Set X-Meraki-Token; an invalid key produces an HTTP 429 Too Many Requests response
AnswerB

The Meraki Dashboard API authenticates requests with a dedicated header named X-Cisco-Meraki-API-Key carrying the organization's key. When that key is missing, revoked, or malformed, the dashboard rejects the call with a 401 Unauthorized status. This matches the scenario's requirement to read the key from an environment variable and place it in the correct header.

Why this answer

The Meraki Dashboard API uses a purpose-built header for API key authentication rather than standard HTTP bearer tokens. Placing the organization key in X-Cisco-Meraki-API-Key authenticates the call, and an invalid or revoked key yields a 401 Unauthorized response. Reading the key from an environment variable keeps credentials out of source control while still populating the correct header.

Exam trap

The trap here is assuming Meraki uses the same bearer-token authorization header as OAuth-based Cisco APIs, which leads to sending credentials in the wrong place.

520
MCQeasy

A developer is testing a REST API with curl and wants the response to include only the HTTP status code and response headers, discarding the body. Which curl option accomplishes this?

A.curl -o headers.txt https://api.example.com/devices
B.curl -d @payload.json https://api.example.com/devices
C.curl -X POST https://api.example.com/devices
D.curl -I https://api.example.com/devices
AnswerD

The -I option sends a HEAD request, so the server returns headers and status without a response body. This matches the goal of seeing only the status code and headers. It is the standard curl way to inspect metadata such as content type, cache directives, or rate-limit fields without downloading the full representation.

Why this answer

The -I option issues a HEAD request, which asks the server for the same headers it would send for a GET but without the body. This is ideal for checking status codes, content types, and rate-limit headers cheaply. It is a safe, idempotent inspection method that avoids transferring large payloads during API testing.

Exam trap

The trap here is confusing -o, which redirects the body to a file, with -I, which suppresses the body entirely by using the HEAD method.

521
MCQmedium

When using the Cisco DNA Center intent API to retrieve issues, the response includes a Link header with rel="next" and a URL. What type of pagination is this?

A.Offset/limit pagination
B.Cursor-based pagination via Link header
C.Page-based pagination
D.No pagination
AnswerB

A Link header carrying rel="next" with an opaque URL is cursor-based pagination: the server dictates the next page location rather than the client computing offsets. This satisfies the scenario's identification of the pagination style used by the DNA Center issues endpoint.

Why this answer

A Link header containing rel="next" with a URL is the standard HTTP mechanism for cursor-based (or token-based) pagination, where the server returns an opaque link to the next page rather than requiring the client to compute offsets. Cisco DNA Center's intent API uses this pattern, returning a Link header with rel="next" and rel="prev" as applicable. The client simply follows the URL until no next link is present.

Exam trap

200-901 often tests whether candidates recognize the Link header as cursor-based pagination rather than assuming all pagination uses offset/limit or page parameters — the header form is the giveaway.

How to eliminate wrong answers

Option A is wrong because offset/limit pagination uses query parameters like ?offset=100&limit=50, not a Link header with rel="next". Option C is wrong because page-based pagination uses ?page=2&size=50 style parameters, again not a Link header. Option D is wrong because the presence of a rel="next" Link header explicitly indicates pagination is in use; the API is not returning all results in one response.

522
MCQhard

A developer must configure a Cisco IOS XE device programmatically and needs the device to validate configuration changes against a data model before they are committed, with the ability to discard invalid candidate configurations. Which approach satisfies this requirement?

A.Use NETCONF with the candidate datastore, edit-config, validate, and commit operations.
B.Use SNMP set requests against the MIB to write configuration objects.
C.Use RESTCONF with a PATCH to the running datastore directly.
D.Send CLI commands over an SSH channel using a Python paramiko session and parse the output.
AnswerA

NETCONF supports a candidate datastore where edits are staged, a validate operation that checks the candidate against the device's YANG models, and a commit that applies it atomically. If validation fails, the candidate can be discarded without touching the running configuration. This is exactly the model-driven, transactional workflow the requirement describes.

Why this answer

A candidate datastore combined with validate and commit gives the developer a staged, model-checked, transactional change workflow. Invalid edits are caught before they reach the running configuration, and a failed validation simply discards the candidate, preserving service. This matches the requirement for pre-commit validation and the ability to abandon bad configurations.

Exam trap

The trap here is equating any model-driven interface, such as RESTCONF against the running datastore, with transactional validation, when only the candidate-datastore workflow provides staged validate and commit semantics.

523
Multi-Selecthard

Which THREE of the following are valid methods to handle API rate limiting in a Python automation script? (Select exactly 3.)

Select 3 answers
A.Parse the Retry-After header from the response
B.Use a token bucket algorithm to control request rate
C.Sleep for a fixed amount of time between requests
D.Ignore the limit and send requests faster
E.Implement retry logic with exponential backoff
AnswersA, B, E

The Retry-After header tells the client exactly how many seconds to wait before retrying, so parsing it respects the server's advertised rate-limit window rather than guessing. This directly satisfies the scenario's need to handle 429 responses without breaching the API's throttling policy.

Why this answer

Option A is correct because the Retry-After header, returned with HTTP 429 (Too Many Requests) or 503 responses, tells the client exactly how many seconds to wait before retrying, making it a standards-based way to honor server-imposed rate limits. Option B is correct because a token bucket algorithm explicitly controls the request rate by issuing tokens at a defined rate and consuming one per request, allowing bursts up to the bucket capacity while preventing sustained over-limit traffic. Option E is correct because retry logic with exponential backoff progressively increases the delay between attempts (e.g., 1s, 2s, 4s, 8s, often with jitter), which reduces request pressure and avoids hammering an API that is throttling the client.

Option C is not among the marked answers because a fixed sleep interval is a crude, static approach that does not adapt to the server's actual limit signals and can either waste time or still exceed the quota. Option D is clearly wrong because ignoring the limit and sending requests faster will trigger further 429 responses, potential IP bans, or account suspension rather than handling the rate limit.

Exam trap

Cisco often tests the distinction between a fixed sleep (which is naive and not adaptive) versus dynamic methods like parsing Retry-After or using exponential backoff, and candidates mistakenly think a static delay is sufficient for rate limiting.

524
MCQhard

A developer maintains a Python package that other teams import. The package's setup.py currently pins an HTTP library to an exact version, and a consuming team reports that pip refuses to install their project because they require a newer minor release of the same library. Which change to the dependency specification best resolves the conflict while still protecting against breaking major upgrades?

A.Raise the pin to the newest available exact version, such as requests==2.31.0, so both projects use the same release.
B.Replace the exact pin with a compatible-release specifier such as requests>=2.28,<3.0 so minor and patch updates are allowed.
C.Pin the library to a specific older major version such as requests==1.2.3 to guarantee compatibility with existing code.
D.Remove the library from the dependency list entirely so pip installs whichever version the consuming project happens to request.
AnswerB

A range that permits newer 2.x releases while excluding 3.0 lets the consuming team install its required minor version and still blocks a breaking major upgrade. This resolves the resolver conflict without abandoning protection against incompatible changes, which is exactly the balance the scenario demands.

Why this answer

Dependency specifications should express the range the package actually supports. A lower bound with an upper bound below the next major version allows compatible minor and patch upgrades, which satisfies the consuming team's requirement while still guarding against breaking changes. Exact pins and removed declarations either block valid upgrades or leave the dependency undeclared.

Exam trap

The trap here is thinking that any exact pin is the safest choice, when exact pins are what create resolver conflicts across projects.

525
Multi-Selecthard

Which THREE are best practices for securing a CI/CD pipeline?

Select 3 answers
A.Use dynamic application security testing (DAST) tools
B.Allow manual approval for production deployments
C.Store credentials in the source code repository
D.Run all pipeline steps as the same user
E.Use static application security testing (SAST) tools
AnswersA, B, E

DAST probes the running application from the outside, exercising live endpoints to expose injection, authentication and configuration flaws that static review cannot reach. It satisfies the stem's requirement for pipeline security by catching runtime vulnerabilities before deployment, complementing SAST and dependency scanning within the CI/CD stages.

Why this answer

Option A is correct because DAST tools test the running application from the outside, simulating real attacks against deployed staging or production-like environments to uncover runtime vulnerabilities such as injection flaws, authentication issues, and misconfigurations that static analysis cannot detect. Option B is correct because requiring manual approval before production deployments creates a human gate that prevents unreviewed or malicious code from being automatically promoted to production, supporting change control and separation of duties. Option E is correct because SAST tools analyze source code, bytecode, or binaries early in the pipeline to detect insecure coding patterns like hardcoded secrets, SQL injection, and buffer overflows before the artifact is built or deployed.

Option C is wrong because storing credentials in the source code repository exposes secrets to anyone with repo access and to history leaks; secrets should be kept in a dedicated secrets manager or vault. Option D is wrong because running all pipeline steps as the same user violates least privilege and allows a compromised step to escalate across the entire pipeline; each stage should use isolated, minimally privileged identities.

Exam trap

Cisco often tests the distinction between DAST and SAST, where candidates may incorrectly think only one is needed, but the exam expects both as complementary practices for comprehensive security coverage.

Page 6

Page 7 of 13

Page 8