200-901 Infrastructure and Automation Practice Question
An engineer is troubleshooting a NETCONF session that fails to establish with a Cisco IOS XE device. The SSH connection succeeds, but NETCONF capabilities are not exchanged. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between SSH transport success and NETCONF protocol success, trapping candidates who assume a successful SSH connection implies NETCONF is fully operational.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The device's NETCONF server is not enabled.
NETCONF uses a client-server model where the server (the Cisco IOS XE device) must have the NETCONF server explicitly enabled. If the SSH transport succeeds but capabilities are not exchanged, it indicates the NETCONF subsystem is not active on the device. The `netconf-yang` feature must be enabled via `netconf-yang` in global configuration mode to start the NETCONF server and allow capability exchange.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The device requires authentication via SSH keys but password was used.
Why it's wrong here
SSH key versus password authentication is settled during the SSH handshake; since that connection succeeded, credentials are not the cause of the missing capability exchange. Key-based authentication is the correct choice when password logins are disabled by policy.
- ✗
The firewall is blocking port 830.
Why it's wrong here
Port 830 carries NETCONF over SSH, but the stem states the SSH connection succeeded, so the firewall is not blocking the session. Firewall rules on port 830 are the correct focus when the TCP connection itself cannot be established.
- ✗
The device is running an older IOS version that does not support NETCONF.
Why it's wrong here
IOS XE releases that support NETCONF are widely deployed, and the SSH transport already succeeded, so an unsupported version would not explain the missing capability exchange. Version checks are relevant when SSH itself fails or the NETCONF subsystem is absent from the image.
- ✓
The device's NETCONF server is not enabled.
Why this is correct
SSH transport succeeding but no NETCONF capabilities appearing means the NETCONF subsystem is disabled on the device. Enabling it with the netconf-yang command starts the server, allowing the hello exchange and capability negotiation to complete.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.