Courseiva

CCNA Cisco Platforms and Development Questions

75 of 126 questions · Page 1/2 · Cisco Platforms and Development · Answers revealed

1
MCQmedium

An application uses Cisco DNA Center APIs and needs to receive notifications when a new device is added. Which DNA Center API category should be used to set up event-driven notifications?

A.Platform
B.Change your network
C.Know your network
D.Run your network
AnswerA

Platform APIs include the event notification and webhook services that register subscribers and deliver DNA Center events, such as device-added, to an external endpoint. This satisfies the stem's event-driven requirement, unlike intent, command runner or integration APIs, which handle policy, CLI execution or third-party connectivity rather than push notifications.

Why this answer

The Platform API category in Cisco DNA Center provides the necessary endpoints for subscribing to event notifications, including the ability to create webhook subscriptions for events such as new device additions. This category includes the Event Management and Notification APIs that allow applications to receive real-time updates. The other categories focus on network operations, not event-driven integration.

Exam trap

The trap here is confusing the functional categories of DNA Center APIs with the Platform category, which specifically handles event subscriptions and notifications, leading candidates to choose a network operations category instead.

How to eliminate wrong answers

Option B is wrong because 'Change your network' APIs are used for configuration changes and provisioning, not for receiving event notifications. Option C is wrong because 'Know your network' APIs are for retrieving network inventory and topology information, not for subscribing to events. Option D is wrong because 'Run your network' APIs are for monitoring and troubleshooting network health, not for setting up event-driven notifications.

2
MCQmedium

An application sends many requests to the Meraki API and receives HTTP 429 errors. The response includes a 'Retry-After' header. What does this status code indicate?

A.The requested resource was not found
B.The server encountered an internal error
C.The API key is invalid
D.The client has exceeded the rate limit
AnswerD

HTTP 429 is 'Too Many Requests', returned when the client exceeds the Meraki API's rate limit. The Retry-After header tells the client how long to wait before retrying, confirming the request was throttled rather than rejected for authentication or syntax.

Why this answer

HTTP 429 status code means 'Too Many Requests', indicating that the client has exceeded the rate limit set by the API. The 'Retry-After' header tells the client how long to wait before making another request.

Exam trap

200-901 often tests the confusion between HTTP 429 and other 4xx/5xx codes, expecting candidates to know that 429 specifically means rate limiting and to use the Retry-After header.

How to eliminate wrong answers

Option A is wrong because 404 Not Found indicates the requested resource does not exist. Option B is wrong because 500 Internal Server Error indicates a server-side error. Option C is wrong because 401 Unauthorized or 403 Forbidden indicate invalid API key or insufficient permissions, not 429.

3
MCQmedium

A Webex bot needs to send a message to a room. The bot has the room ID. Which API endpoint should be used, and what is the correct HTTP method?

A.POST /v1/messages
B.PUT /v1/messages/{messageId}
C.GET /v1/messages
D.POST /v1/rooms
AnswerA

Sending a message to a room is a create operation on the messages collection, so the bot calls POST /v1/messages with the roomId in the JSON body. The room ID alone does not form a resource path for a GET or PUT.

Why this answer

The Webex Teams API uses POST /v1/messages to create and send a new message to a room. The request body must include the roomId and either text or markdown. This is the standard endpoint for sending messages, and it returns a 200 OK with the message details upon success.

Exam trap

200-901 often tests the distinction between HTTP methods and their typical CRUD operations, so candidates might incorrectly choose PUT for updating a message or GET for retrieving messages, but the question specifically asks for sending a message, which requires POST to the correct resource.

How to eliminate wrong answers

Option B is wrong because PUT /v1/messages/{messageId} is not a valid Webex API endpoint; messages cannot be updated via PUT. Option C is wrong because GET /v1/messages is used to list messages, not send them, and it requires query parameters like roomId. Option D is wrong because POST /v1/rooms is used to create a new room, not to send a message to an existing room.

4
MCQeasy

Which tool can be used to explore YANG models locally?

A.yangcatalog.org
B.Cisco DevNet sandbox
C.Postman
D.pyang
AnswerD

pyang is an open-source YANG validator and converter that parses YANG modules locally, letting engineers inspect tree structures, verify syntax and explore model hierarchies without a live device. It directly satisfies the requirement to explore YANG models offline.

Why this answer

pyang is a tool for validating and converting YANG models.

5
MCQeasy

Which Cisco platform uses NX-API to allow programmatic access to CLI commands via JSON?

A.Cisco Meraki
B.Cisco NX-OS
C.Cisco DNA Center
D.Cisco IOS XE
AnswerB

Cisco NX-OS exposes NX-API, which wraps CLI commands and returns structured JSON or XML over HTTP/HTTPS, enabling programmatic access. IOS, IOS-XE and ASA lack this native JSON CLI wrapper, so NX-OS is the platform matching the stem.

Why this answer

Cisco NX-OS is the network operating system that runs on Nexus switches and supports NX-API, which allows programmatic access to CLI commands via JSON (or XML) over HTTP/HTTPS. NX-API exposes the /ins endpoint for CLI execution and /api for model-driven REST access.

Exam trap

The trap is that candidates confuse NX-API (NX-OS) with RESTCONF (IOS XE) or DNA Center's Intent API, assuming all Cisco platforms use the same programmatic interface.

How to eliminate wrong answers

Option A is wrong because Cisco Meraki is a cloud-managed platform with its own REST API, not NX-API; NX-API is specific to NX-OS. Option C is wrong because Cisco DNA Center is a network controller with a REST API (Intent API), not NX-API. Option D is wrong because Cisco IOS XE supports RESTCONF and NETCONF/YANG, but not NX-API, which is exclusive to NX-OS.

6
MCQmedium

A developer is using the Meraki Dashboard API to list all organizations. The base URL is https://api.meraki.com/api/v1/. What is the correct endpoint and authentication method?

A.POST /organizations with Bearer token in Authorization header
B.GET /organizations with Basic Auth username and password
C.GET /organizations with X-Cisco-Meraki-API-Key header
D.GET /v1/organizations with Cookie authentication
AnswerC

The Meraki Dashboard API exposes organisations at GET /organizations under the /api/v1 base URL, and authentication uses the X-Cisco-Meraki-API-Key request header carrying the dashboard API key. This matches the stem's base URL and required listing operation exactly.

Why this answer

The Meraki Dashboard API uses a custom API key for authentication, sent via the `X-Cisco-Meraki-API-Key` header. To list all organizations, the correct HTTP method is GET, and the endpoint is `/organizations` (relative to the base URL `https://api.meraki.com/api/v1/`). This matches option C exactly.

Exam trap

The trap here is that candidates may confuse the Meraki API's custom header authentication with more common methods like Basic Auth or Bearer tokens, or incorrectly assume the endpoint path must include the version number again.

How to eliminate wrong answers

Option A is wrong because listing organizations is a read operation requiring GET, not POST; POST is used for creating resources. Option B is wrong because the Meraki API does not support Basic Auth; it requires a dedicated API key header. Option D is wrong because the endpoint includes `/v1/` redundantly (the base URL already contains the version), and the API uses a custom header, not cookie authentication.

7
MCQeasy

A developer is automating a Cisco IOS XE device with NETCONF over SSH. The developer must retrieve only the running configuration's hostname without pulling the entire configuration datastore. Which NETCONF operation should the developer use?

A.<copy-config> copying <running/> into <startup/> and then reading the response body
B.<get> with an empty filter, which returns operational and configuration state together
C.<edit-config> targeting <candidate/> with a merge operation on the hostname leaf
D.<get-config> with a source of <running/> and a subtree filter selecting the native hostname node
AnswerD

The get-config operation retrieves configuration data from a specified datastore, and the source element must name that datastore. Pairing <running/> with a subtree filter that matches the Cisco IOS XE native hostname leaf returns only that fragment instead of the whole running configuration, which is exactly what the scenario requires.

Why this answer

Reading a targeted piece of configuration from a NETCONF-capable device requires the read-oriented get-config operation, an explicit source datastore, and a filter that narrows the reply. Selecting the running datastore with a subtree filter that matches the IOS XE native hostname leaf returns exactly that value and nothing else, keeping the payload small and the device state unchanged.

Exam trap

The trap here is assuming the generic get operation is the right way to read configuration, when get-config is the operation designed for pulling filtered configuration from a named datastore.

8
MCQhard

An engineer wants to trigger an EEM applet when a specific syslog message appears. Which event detector should be used?

A.event timer cron
B.event interface
C.event cli pattern
D.event syslog pattern
AnswerD

The event syslog pattern detector matches incoming syslog messages against a regular expression, triggering the applet when the specified text appears. This directly satisfies the requirement to react to a specific syslog message rather than a timer or interface event.

Why this answer

EEM's syslog event detector triggers on syslog messages matching a pattern.

9
Multi-Selecthard

A network engineer is using Cisco DNA Center to automate network changes. Which THREE operations are part of the 'Change your network' API category? (Choose three.)

Select 3 answers
A.Create and assign a site to a device
B.Run a command on a device via Command Runner
C.Initiate a Plug and Play (PnP) device provisioning
D.Deploy a configuration template to devices
E.Retrieve the list of network devices
AnswersA, C, D

Site creation is part of changing the network topology.

Why this answer

The 'Change your network' API category in Cisco DNA Center includes operations that actively modify the network state. Creating and assigning a site to a device is a configuration change that associates a physical location with a device, which directly alters the network's logical topology and is part of the site management workflow under this API category.

Exam trap

Cisco often tests the distinction between read-only (query/inventory) and write (change) API operations, and the trap here is that candidates mistakenly classify 'Run a command on a device' as a change because it interacts with a device, but it is a transient troubleshooting action, not a persistent configuration change.

10
MCQhard

A developer is using the Meraki Dashboard API to retrieve a list of clients for a network. After a successful request, the response includes a Link header with rel="next" pointing to the next page. What does this indicate about the API's pagination?

A.The API uses page-based pagination with page and perPage parameters.
B.The API uses offset-based pagination and the next page can be retrieved by incrementing an offset parameter.
C.The API uses Link header pagination and the next page can be retrieved by following the URL in the Link header.
D.The API uses cursor-based pagination with startingAfter/endingBefore parameters.
AnswerC

The Link header with rel="next" signals cursor-based pagination: the API returns a partial result set plus a URL for the following page. Following that URL directly retrieves the next batch, so the developer iterates until no rel="next" link remains.

Why this answer

Meraki API uses Link headers for pagination, and a rel="next" link indicates there are additional pages to fetch.

11
MCQmedium

An application needs to authenticate to Cisco DNA Center. Which authentication method is used?

A.API key in X-Cisco-DNA-Center-API-Key header
B.OAuth2 with client credentials grant
C.Bearer token in Authorization header with no prior step
D.Basic Auth over HTTPS to obtain a token
AnswerD

Correct. Basic Auth is used to get a token for subsequent API calls.

Why this answer

DNA Center uses Basic Auth to obtain a token via POST /dna/system/api/v1/auth/token.

12
MCQeasy

A network engineer wants to retrieve a list of all network devices from Cisco DNA Center using REST API. Which URL and HTTP method should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/topology/l2/{vlanID}
D.GET /dna/intent/api/v1/network-device
AnswerD

GET requests to `/dna/intent/api/v1/network-device` return the full device inventory from Cisco DNA Center's intent API, satisfying the requirement to retrieve, not modify, all network devices. The GET method is idempotent and read-only, matching the stem's retrieval constraint without side effects.

Why this answer

Cisco DNA Center provides the GET /dna/intent/api/v1/network-device endpoint to list all network devices.

13
MCQmedium

A developer is writing a Python script that uses the Cisco SD-WAN (vManage) API to create a device template. The API requires the request body to include the template configuration and the device model. Which HTTP method and resource path should the developer use?

A.PUT /dataservice/template/device/feature
B.DELETE /dataservice/template/device
C.POST /dataservice/template/device
D.GET /dataservice/template/device
AnswerC

POST to /dataservice/template/device creates a new device template in vManage. The request body must include the device model and the template configuration. This matches the requirement to create a device template, and POST is the correct method for resource creation on the vManage REST API.

Why this answer

Creating a device template in Cisco SD-WAN vManage requires an HTTP POST to the /dataservice/template/device resource. The request body must contain the device model and the configuration. GET retrieves, PUT updates, and DELETE removes, so only POST aligns with the create operation described in the scenario.

Exam trap

The trap here is confusing the feature template endpoint with the device template endpoint, or assuming that any write method such as PUT can create a resource.

14
MCQmedium

A developer is automating network configuration using Cisco DNA Center. They want to deploy a configuration template to multiple devices. Which API category should they use?

A.Change your network
B.Platform
C.Run your network
D.Know your network
AnswerA

Correct. Template deployment, plug and play are part of 'change your network'.

Why this answer

Template deployment falls under 'change your network' API category.

15
MCQmedium

When making API calls to Cisco Meraki Dashboard, what header must be included for authentication?

A.Authorization: Basic <base64>
B.Authorization: Bearer <token>
C.X-Cisco-Meraki-API-Key: <key>
D.Api-Key: <key>
AnswerC

Meraki Dashboard authenticates REST calls solely through the `X-Cisco-Meraki-API-Key` request header carrying the generated API key; no OAuth bearer token or session cookie is accepted. This satisfies the stem's requirement for the mandatory authentication header on every Dashboard API call.

Why this answer

Cisco Meraki Dashboard API uses a custom header for authentication rather than standard HTTP authentication schemes. The header `X-Cisco-Meraki-API-Key` must be included with the API key as its value. This is explicitly documented in the Meraki API reference and is required for all API requests to authenticate the caller.

Exam trap

Cisco often tests the fact that Meraki uses a custom header (`X-Cisco-Meraki-API-Key`) rather than the standard `Authorization` header, leading candidates to mistakenly choose `Authorization: Bearer <token>` or `Authorization: Basic <base64>`.

How to eliminate wrong answers

Option A is wrong because `Authorization: Basic <base64>` uses HTTP Basic Authentication, which is not supported by the Meraki Dashboard API; Meraki requires a custom header, not the standard Authorization header. Option B is wrong because `Authorization: Bearer <token>` uses OAuth 2.0 Bearer token authentication, which is not how Meraki authenticates API calls; Meraki uses a static API key in a custom header. Option D is wrong because `Api-Key: <key>` is a generic header name used by some other APIs (e.g., certain cloud services), but Meraki specifically requires the header name `X-Cisco-Meraki-API-Key`.

16
Multi-Selecthard

A developer is using the Cisco Webex Teams API to manage memberships in a space. Which two HTTP methods and corresponding endpoints are used to add a new member and to remove an existing member? (Choose two.)

Select 2 answers
A.POST /v1/memberships to add a member
B.DELETE /v1/memberships/{membershipId} to remove a member
C.PUT /v1/memberships/{membershipId} to update a member
D.DELETE /v1/rooms/{roomId}/members/{personId} to remove a member
E.POST /v1/rooms/{roomId}/members to add a member
AnswersA, B

To add a member to a Webex space, you send a POST request to /v1/memberships with a JSON body containing 'roomId', 'personEmail', and optionally 'isModerator'. This creates a new membership. The API returns the membership details. This is the correct method and endpoint for adding a member.

Why this answer

Adding a member to a Webex space is done with POST /v1/memberships, providing roomId and personEmail. Removing a member is done with DELETE /v1/memberships/{membershipId}. These are the standard methods for managing memberships.

Other methods like PUT are for updates, and the room-based endpoints do not exist.

Exam trap

The trap here is confusing membership management with room management, leading to incorrect endpoints under /v1/rooms.

17
Multi-Selecthard

A developer is building a Python application that uses the Cisco Meraki Dashboard API to update VLAN settings on a network. The application must handle API errors gracefully and avoid being rate-limited. The developer wants to implement logic that inspects the response status code and the Retry-After header. Which two actions should the developer take when the API returns HTTP 429? (Choose two.)

Select 2 answers
A.Immediately resend the same request with an incremented X-Retry-Count header to bypass the rate limit.
B.Read the Retry-After response header and pause requests for the specified number of seconds before retrying.
C.Implement exponential backoff starting from the Retry-After value and add jitter to spread retries across concurrent clients.
D.Switch the request from HTTPS to HTTP to reduce overhead and avoid rate limiting.
E.Rotate to a different API key for the same organization to reset the rate-limit counter.
AnswersB, C

Meraki's Dashboard API returns a Retry-After header on 429 responses that indicates how many seconds the client must wait. Honoring this header prevents further throttling and aligns with Meraki's documented rate-limit behavior. Simply pausing for a fixed interval without reading the header may retry too soon or waste time.

Why this answer

Meraki's Dashboard API enforces rate limits and returns HTTP 429 with a Retry-After header when exceeded. The robust client reads that header, waits the indicated time, and then retries using exponential backoff with jitter to avoid synchronized retries. Rotating keys or switching protocols does not change the per-organization limit and can introduce security or reliability problems.

Exam trap

The trap here is assuming that rate limits are tied to the API key or that a custom retry header can bypass them, when Meraki enforces limits per organization and expects clients to honor Retry-After.

18
MCQmedium

A Meraki dashboard API request to list networks returns a paginated response. The engineer notices a Link header in the response. What does this header typically contain?

A.The rate limit remaining
B.The total number of resources
C.A URL to the next page of results
D.An error message
AnswerC

Meraki's REST API paginates large collections, returning a Link header containing the URL of the next page of results, often with rel="next". The engineer follows that URL to retrieve subsequent networks until no Link header remains, indicating the final page.

Why this answer

Meraki uses Link headers for pagination, providing URLs for the next and previous pages.

19
MCQhard

A developer is using NX-API on a Cisco Nexus switch to execute CLI commands via JSON. Which endpoint and method should be used?

A.GET /restconf/data/Cisco-NX-OS-device:cli
B.POST /api/cli with XML body
C.GET /ins?cmd=show version
D.POST /ins with JSON body
AnswerD

NX-API's JSON-RPC interface accepts commands at the /ins endpoint via HTTP POST, with the CLI commands supplied in the JSON body. GET is unsuitable because it cannot carry the command payload, and /cli returns plain text rather than JSON.

Why this answer

NX-API on Cisco Nexus switches exposes a REST endpoint at /ins that accepts POST requests with a JSON body containing the CLI commands to execute. The JSON body includes parameters such as 'ins_api' with 'version', 'type' (cli_show), 'chunk', 'sid', 'input' (the command), and 'output_format' (json). This is the standard way to run show commands programmatically via NX-API.

Exam trap

The trap is that candidates confuse NX-API's /ins endpoint with RESTCONF paths or assume a GET request with a query parameter, when NX-API requires POST with a JSON body.

How to eliminate wrong answers

Option A is wrong because /restconf/data/Cisco-NX-OS-device:cli is a RESTCONF/YANG path, not the NX-API endpoint; NX-API uses /ins, not RESTCONF. Option B is wrong because NX-API accepts JSON (or XML) but the endpoint is /ins, not /api/cli, and XML is not required. Option C is wrong because GET /ins?cmd=show version uses the wrong HTTP method and query-string style; NX-API requires POST with a structured JSON body, not a GET with a cmd parameter.

20
MCQmedium

A developer is using the Meraki Dashboard API to list the organizations accessible by the API key. They send a GET request to https://api.meraki.com/api/v1/organizations. What is the correct way to pass the API key?

A.In the Authorization header as Bearer token
B.In the URL as a query parameter: ?apiKey=...
C.In the request body as JSON
D.In the X-Cisco-Meraki-API-Key header
AnswerD

The Meraki Dashboard API authenticates every call with a dedicated request header rather than a query string or bearer token. Supplying the key as X-Cisco-Meraki-API-Key satisfies the stem's requirement for the correct method when issuing GET https://api.meraki.com/api/v1/organizations, keeping credentials out of the URL and logs.

Why this answer

Meraki Dashboard API uses the X-Cisco-Meraki-API-Key header for authentication.

21
MCQeasy

A developer wants to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint should they use?

A.GET /dna/intent/api/v1/topology/l2/{vlanID}
B.GET /dna/intent/api/v1/network-device
C.POST /dna/system/api/v1/auth/token
D.GET /dna/intent/api/v1/issues
AnswerB

The GET /dna/intent/api/v1/network-device endpoint targets Cisco DNA Center's Intent API, returning the full inventory of managed network devices. Its HTTP GET method and network-device resource path satisfy the requirement to retrieve, not modify, device listings.

Why this answer

The correct endpoint is GET /dna/intent/api/v1/network-device as per Cisco DNA Center API documentation.

22
Multi-Selecthard

A developer is using the Cisco DNA Center API to manage devices. The developer needs to perform operations that are part of the 'Site Management' API category. (Choose two.)

Select 2 answers
A.Retrieve device health
B.Assign a device to a site
C.Configure SNMP settings on a device
D.Create a new network profile
E.Create a new site
AnswersB, E

Assigning a device to a site is another key operation in Site Management. This is done via endpoints such as POST /dna/intent/api/v1/site/{siteId}/device. It associates a network device with a specific site, enabling site-based monitoring and policy enforcement. This operation is fundamental for site-based management.

Why this answer

The Site Management API category in Cisco DNA Center includes operations for creating, updating, and deleting sites, as well as associating devices with sites. Creating a new site and assigning a device to a site are both part of this category. Other operations like retrieving device health or configuring SNMP belong to different API categories.

Exam trap

The trap here is confusing Site Management with other DNA Center API categories such as Device Monitoring or Network Settings.

23
Multi-Selectmedium

A developer is working with the Meraki Dashboard API to manage SSIDs. Which TWO statements about pagination are correct? (Choose two.)

Select 2 answers
A.Pagination is handled automatically by the client library; no action required
B.The 'page' query parameter is used to specify page number
C.The 'endingBefore' parameter is used to go to the previous page
D.The 'startingAfter' parameter can be used to fetch the next page of results
E.The Link header contains a 'last' URL for the final page
AnswersC, D

endingBefore retrieves items before a given ID, effectively moving backward.

Why this answer

Meraki uses the Link header with 'prev' and 'next' URLs for pagination. Additionally, the startingAfter and endingBefore query parameters allow manual pagination.

24
MCQmedium

A developer is writing a Python script to interact with a Cisco IOS XE device using the NETCONF protocol. The script uses the ncclient library to establish a connection and retrieve the running configuration. Which method should the developer use to retrieve the configuration?

A.manager.edit_config(target='running')
B.manager.get(filter=('subtree', 'running'))
C.manager.dispatch(rpc='get-config')
D.manager.get_config(source='running')
AnswerD

In ncclient, the get_config method retrieves configuration data from a specified datastore. Using source='running' fetches the running configuration. This is the correct method for retrieving configuration via NETCONF. The method returns a response object containing the configuration in XML format, which can then be parsed.

Why this answer

The ncclient library provides the get_config method to retrieve configuration from a NETCONF server. The source parameter specifies the datastore, such as 'running' for the running configuration. The get method is for state data, edit_config is for modifying configuration, and dispatch is for custom RPCs.

Therefore, the correct method is manager.get_config(source='running').

Exam trap

The trap here is confusing get_config with get; the former retrieves configuration, while the latter retrieves state data.

25
Multi-Selecthard

A developer is building a Cisco Webex bot that needs to automatically respond to messages. Which THREE resources/endpoints are essential for this functionality? (Choose three.)

Select 3 answers
A.Rooms API
B.People API
C.Licenses API
D.Webhooks API
E.Messages API
AnswersA, D, E

The Rooms API lets the bot enumerate and inspect Webex spaces, supplying the roomId that every message response must target. Without it, the bot cannot determine which conversation to post into, so it satisfies the requirement to respond automatically to messages received across multiple rooms.

Why this answer

Essential endpoints are Messages (to send/receive), Webhooks (to get notified of events), and Rooms (to interact with rooms). People is useful but not essential for bot functionality.

26
MCQeasy

Which Cisco platform provides a cloud-managed dashboard with a REST API that uses an API key in the header and has a rate limit of 5 requests per second?

A.Cisco Webex
B.Cisco Meraki
C.Cisco DNA Center
D.Cisco IOS XE
AnswerB

Cisco Meraki's cloud-managed dashboard exposes a REST API authenticated with an API key in the request header and enforces a documented rate limit of 5 requests per second per organisation, matching all three stated constraints.

Why this answer

Cisco Meraki is a cloud-managed networking platform whose Dashboard API is RESTful, uses an API key passed in the X-Cisco-Meraki-API-Key header, and enforces a rate limit of 5 requests per second per organization. This matches the question's description exactly.

Exam trap

The trap is that candidates confuse Cisco DNA Center's token-based API with Meraki's API-key-based API, or assume Webex because it is also cloud-based, missing the specific rate limit and header details.

How to eliminate wrong answers

Option A is wrong because Cisco Webex is a collaboration platform (meetings, messaging) with its own REST API, but it is not a cloud-managed network dashboard and does not use the Meraki API key header or 5 req/s limit. Option C is wrong because Cisco DNA Center is an on-premises (or private cloud) controller for enterprise networks; its API uses token-based authentication (X-Auth-Token) and different rate limits, not a simple API key in the header. Option D is wrong because Cisco IOS XE is a network operating system, not a cloud-managed dashboard; it exposes RESTCONF/NETCONF but not a Meraki-style API key header.

27
MCQhard

A developer is using the Cisco Meraki Dashboard API to update the VLAN configuration on a switch port. The API call returns a 404 Not Found error. The developer has verified that the API key is valid and the organization ID and network ID are correct. What is the most likely cause of the 404 error?

A.The API key does not have write permissions for the network.
B.The request body is missing required parameters.
C.The API endpoint URL is incorrect or the resource does not exist.
D.The Meraki Dashboard API rate limit has been exceeded.
AnswerC

A 404 Not Found indicates that the server cannot find the requested resource. Even with valid IDs, if the endpoint path is wrong (e.g., misspelled 'vlans' or wrong API version) or the specific port does not exist, the server returns 404. The developer should double-check the URL structure and ensure the port identifier is valid for that switch.

Why this answer

A 404 Not Found error means the server cannot locate the requested resource. Common causes include an incorrect endpoint URL, a non-existent resource ID (such as a port that does not exist on the switch), or a typo in the path. Authentication issues yield 401, permission issues yield 403, bad request bodies yield 400, and rate limits yield 429.

Therefore, the developer should verify the URL and resource identifiers.

Exam trap

The trap here is confusing 404 with permission or authentication errors, which have different status codes (403 and 401 respectively).

28
MCQeasy

When using the Meraki Dashboard API, what HTTP header is used to pass the API key?

A.API-Key: <key>
B.X-Cisco-Meraki-API-Key: <key>
C.Authorization: Bearer <key>
D.Meraki-API-Key: <key>
AnswerB

The Meraki Dashboard API authenticates each request by placing the API key in the X-Cisco-Meraki-API-Key request header. This satisfies the stem's requirement, since the key is passed as a custom HTTP header rather than a query string or bearer token.

Why this answer

Meraki requires the API key in the X-Cisco-Meraki-API-Key header.

29
MCQmedium

A developer wants to use the Cisco Webex API to send a message to a specific person by email. Which parameter should be used in the POST /v1/messages request?

A.personId
B.toPersonEmail
C.recipientEmail
D.roomId
AnswerB

The Webex messages endpoint accepts toPersonEmail to address a recipient directly by their email address. This satisfies the stem's requirement to send a message to a specific person identified by email, rather than by person ID or room ID.

Why this answer

To send a message to a person, use the toPersonEmail parameter instead of roomId.

30
MCQeasy

Which Cisco DNA Center API is used to retrieve a list of network devices?

A.GET /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/topology
C.GET /dna/intent/api/v1/issue
D.GET /dna/intent/api/v1/site
AnswerA

The GET method against /dna/intent/api/v1/network-device queries Cisco DNA Center's Intent API inventory collection, returning the full device list as JSON. This satisfies the stem's requirement to retrieve, rather than modify, network devices, since GET is the read-only HTTP verb mapped to that resource.

Why this answer

The Cisco DNA Center Intent API endpoint GET /dna/intent/api/v1/network-device is specifically designed to return a list of all network devices managed by DNA Center. It provides details such as device ID, hostname, management IP, platform, software version, and reachability status. This is the canonical endpoint for device inventory retrieval, making it the correct choice.

Exam trap

The trap here is confusing the network-device endpoint with other intent APIs like topology or site, which also return network-related data but not a simple device list. Candidates might assume any endpoint under /dna/intent/api/v1/ returns devices, but each has a specific purpose.

How to eliminate wrong answers

Option B is wrong because GET /dna/intent/api/v1/topology returns network topology information (nodes and links), not a device list. Option C is wrong because GET /dna/intent/api/v1/issue retrieves issues or alarms, not device inventory. Option D is wrong because GET /dna/intent/api/v1/site returns site hierarchy information, not a list of devices.

31
MCQeasy

An administrator wants to retrieve a list of all network devices from Cisco DNA Center using the REST API. Which authentication method must be used first to obtain a token?

A.Basic Authentication to /dna/system/api/v1/auth/token
B.API key in the X-Cisco-Meraki-API-Key header
C.Bearer token passed directly in the first request
D.OAuth 2.0 with client credentials grant
AnswerA

Basic Authentication encodes the administrator's credentials and posts them to /dna/system/api/v1/auth/token, which returns a time-limited token. Cisco DNA Center requires this token exchange before any other API call, satisfying the stem's constraint that a token must be obtained first.

Why this answer

Cisco DNA Center uses Basic Authentication to authenticate to the /dna/system/api/v1/auth/token endpoint, which returns a token for subsequent API calls.

32
MCQeasy

A developer wants to get the current user's information from the Webex API. Which endpoint should they use?

A.GET /v1/people/me
B.POST /v1/messages
C.GET /v1/webhooks
D.GET /v1/rooms
AnswerA

GET /v1/people/me returns the authenticated user's own profile, identified by the access token, so no user ID is needed. Other people endpoints require an explicit personId, making them unsuitable for retrieving the current user's information.

Why this answer

The Webex API endpoint GET /v1/people/me returns the profile information of the authenticated user, which is exactly what the developer needs. It uses the OAuth token of the current user to identify 'me'. Other endpoints serve different resources like messages, webhooks, or rooms.

Exam trap

The trap is confusing resource endpoints (messages, rooms, webhooks) with the identity endpoint; candidates might pick a familiar resource but forget that 'me' is the canonical way to get the current user.

How to eliminate wrong answers

Option B is wrong because POST /v1/messages is used to send a message to a room, not to retrieve user information. Option C is wrong because GET /v1/webhooks lists webhooks configured by the user, not the user's own profile. Option D is wrong because GET /v1/rooms lists rooms the user belongs to, not the user's identity details.

33
MCQeasy

A developer needs to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint and HTTP method should be used?

A.POST /dna/intent/api/v1/issues
B.POST /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/l2/{vlanID}
AnswerC

The `GET /dna/intent/api/v1/network-device` endpoint retrieves all network devices from Cisco DNA Center, satisfying the stem’s requirement to “retrieve a list” by using the HTTP GET method, which is idempotent and safe for read-only operations. This contrasts with POST, which would create a new resource, and DELETE, which would remove devices. The path’s `/network-device` resource collection directly maps to the requested data set.

Why this answer

The correct API to get the device list is GET /dna/intent/api/v1/network-device. Authentication is handled separately via POST /dna/system/api/v1/auth/token.

34
Multi-Selecthard

Which three actions can an EEM applet perform when triggered? (Choose three.)

Select 3 answers
A.Modify a YANG data model
B.Execute a CLI command
C.Send a syslog message
D.Set a variable
E.Create a new VLAN
AnswersB, C, D

Action cli command runs a command.

Why this answer

EEM (Embedded Event Manager) applets can execute CLI commands when triggered by an event. This allows automation of operational tasks such as configuration changes or troubleshooting commands without manual intervention.

Exam trap

Cisco often tests the distinction between EEM's built-in actions and actions that require a CLI command to achieve, such as creating a VLAN, which is not a direct EEM action but must be done via a CLI command.

35
MCQmedium

A developer is using the Cisco NX-OS REST API (NX-API) to configure a Cisco Nexus switch. The developer wants to send a JSON payload to create a new VLAN. Which HTTP method and headers are required to use the NX-API REST interface?

A.POST with Content-Type: application/xml and an XML body containing the VLAN configuration.
B.POST with Content-Type: application/json and a JSON body containing the VLAN configuration.
C.PUT with Content-Type: application/json and a JSON body containing the VLAN configuration.
D.GET with Content-Type: application/json and a JSON body containing the VLAN configuration.
AnswerB

NX-API REST uses HTTP POST to send configuration commands or JSON payloads. The Content-Type header must be application/json when sending JSON. The body contains the configuration in JSON format, such as the VLAN creation object. This is the standard way to configure via NX-API REST.

Why this answer

NX-API REST uses HTTP POST to send configuration payloads. When sending JSON, the Content-Type header must be application/json. The body contains the JSON representation of the configuration, such as the VLAN object.

Other methods or content types do not match the requirement to send a JSON payload for configuration.

Exam trap

The trap here is assuming PUT is used for creation in REST, but NX-API specifically uses POST for configuration changes, and the Content-Type must match the payload format.

36
MCQhard

A developer is using the Cisco NX-OS API on a Nexus switch. The developer wants to retrieve the running configuration using a Python script that sends an HTTP POST request. Which command must be configured on the switch to enable this capability?

A.ip http server
B.feature nxapi
C.feature netconf
D.feature restconf
AnswerB

The 'feature nxapi' command enables the NX-API feature on a Cisco NX-OS device. This allows the switch to accept HTTP/HTTPS requests for CLI commands and retrieve configuration or operational data. Without this feature enabled, the switch will not respond to NX-API requests. It is the essential first step for using the NX-OS API.

Why this answer

To enable the NX-API on a Cisco NX-OS device, the 'feature nxapi' command must be configured. This allows the switch to accept HTTP/HTTPS requests for CLI commands. Other features like NETCONF or RESTCONF are separate protocols and do not enable NX-API.

Exam trap

The trap here is confusing NX-API with other management protocols like NETCONF or RESTCONF, or assuming that enabling the HTTP server is sufficient, when the specific 'feature nxapi' command is required.

37
MCQeasy

A developer wants to receive real-time notifications when a new message is posted in a Webex room. Which Webex API resource should they use?

A.Webhooks
B.Memberships API
C.Rooms API
D.Messages API polling
AnswerA

Webhooks push event notifications to a supplied HTTPS endpoint the moment a message is created, satisfying the real-time constraint. Polling the messages resource would introduce latency and unnecessary API calls, so webhooks are the designed mechanism for immediate room activity alerts.

Why this answer

Webhooks provide real-time HTTP callbacks triggered by events in Webex, such as a new message being posted. By registering a webhook on the 'messages' resource with the 'created' event, the developer's server receives a POST request immediately when a message is sent, eliminating the need for polling.

Exam trap

Cisco often tests the distinction between synchronous polling (Messages API) and asynchronous event-driven notifications (Webhooks), trapping candidates who assume polling is acceptable for real-time requirements.

How to eliminate wrong answers

Option B (Memberships API) is wrong because it manages room membership (add/remove/list members) and does not expose message events. Option C (Rooms API) is wrong because it handles room creation, listing, and updates, not real-time message notifications. Option D (Messages API polling) is wrong because polling requires repeated GET requests to check for new messages, which is inefficient and not real-time; Webex explicitly recommends webhooks over polling for event-driven notifications.

38
MCQmedium

A network engineer is using Cisco DNA Center's Intent API to retrieve a list of all devices in the inventory. The engineer wants to filter the results to only include devices that are reachable and managed. Which HTTP method and endpoint should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/network-device
C.PUT /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/device
AnswerB

The GET /dna/intent/api/v1/network-device endpoint returns the list of all network devices in the DNA Center inventory. It supports query parameters such as reachabilityStatus and managementState to filter results. This is the correct endpoint for retrieving device inventory information from the Intent API.

Why this answer

To retrieve the device inventory from Cisco DNA Center, the engineer must use the GET method on the /dna/intent/api/v1/network-device endpoint. This endpoint returns a JSON list of devices and supports query parameters like reachabilityStatus and managementState to filter results. The other methods either modify resources or target incorrect paths, making them unsuitable.

Exam trap

The trap here is confusing the HTTP method for listing resources with methods that create or update, or using an incorrect endpoint path that omits 'network-'.

39
MCQhard

A developer is using the Meraki Dashboard API to retrieve a list of clients for a network. The API returns a 429 error. What should the developer do to handle this correctly?

A.Ignore the error and continue, as 429 is a temporary issue.
B.Wait for the number of seconds specified in the Retry-After header before retrying.
C.Switch to a different base URL to bypass the limit.
D.Increase the request rate by using multiple API keys in parallel.
AnswerB

A 429 signals rate limiting, and the Meraki Dashboard API returns a Retry-After header giving the exact backoff interval. Honouring that value respects the documented rate-limit window, so the retry succeeds rather than being throttled again. Immediate retries or fixed delays ignore the server-supplied timing and risk further 429 responses.

Why this answer

A 429 HTTP status code indicates 'Too Many Requests,' meaning the client has exceeded the rate limit imposed by the Meraki Dashboard API. The correct handling is to respect the Retry-After header, which specifies the number of seconds the client must wait before retrying the request, as per RFC 7231 Section 7.1.3. This ensures compliance with API rate limits and prevents further throttling or temporary blocking.

Exam trap

Cisco often tests the misconception that 429 is a transient error like a 503 Service Unavailable, leading candidates to think they can simply retry immediately or ignore it, rather than understanding that 429 specifically requires honoring the Retry-After header for rate-limit compliance.

How to eliminate wrong answers

Option A is wrong because ignoring a 429 error and continuing will likely result in continued failures or a temporary ban, as the API enforces rate limits to protect server resources. Option C is wrong because switching to a different base URL does not bypass rate limits; rate limits are applied per API key or client, not per URL endpoint. Option D is wrong because increasing the request rate with multiple API keys in parallel would exacerbate the rate-limit violation, and using multiple keys without coordination may still trigger per-key limits or violate the API's terms of service.

40
MCQhard

In Cisco DNA Center, which API category includes the ability to deploy a configuration template to devices?

A.Change your network
B.Run your network
C.Know your network
D.Platform
AnswerA

The "Change your network" category covers configuration and deployment operations, including template deployment to devices via the DNA Center template APIs. This satisfies the stem's requirement for the API category that deploys configuration templates, rather than monitoring or inventory categories.

Why this answer

The 'Change your network' category includes template deployment, plug and play, and other configuration changes.

41
MCQhard

A network engineer wants to automate a configuration change on a Cisco IOS XE device when a specific syslog message appears. Which tool should they use?

A.RESTCONF with a Python script polling the device
B.SNMP trap receiver
C.EEM applet configured to match the syslog pattern and execute CLI commands
D.NETCONF with a YANG-based notification subscription
AnswerC

Embedded Event Manager applets run on the IOS XE device itself, matching syslog patterns via event statements and triggering CLI actions through action statements. This delivers the required local, event-driven automation without external orchestration tooling.

Why this answer

EEM (Embedded Event Manager) is a built-in Cisco IOS XE feature that allows the device to react to local events, including syslog messages. An EEM applet can be configured with an event syslog pattern to match a specific syslog message and an action to execute CLI commands, enabling automated configuration changes directly on the device. This is the most direct and native way to trigger a configuration change based on a syslog message without external dependencies.

Exam trap

The trap here is confusing EEM with external automation tools like RESTCONF or NETCONF, or assuming that SNMP traps can trigger CLI commands; candidates must remember that EEM is the native on-device automation engine for event-driven actions.

How to eliminate wrong answers

Option A is wrong because RESTCONF with polling is an external pull-based approach that introduces latency and requires a separate server; it does not natively react to syslog events. Option B is wrong because SNMP trap receivers are external systems that collect traps but do not automatically execute CLI commands on the device; they are for monitoring, not automation. Option D is wrong because NETCONF with YANG-based notification subscriptions is not supported on Cisco IOS XE for this purpose; while NETCONF supports notifications, IOS XE does not provide a native mechanism to subscribe to syslog events and trigger CLI commands via NETCONF.

42
MCQmedium

An organization uses Cisco DNA Center and wants to programmatically deploy a configuration template to multiple devices. Which API category should be used?

A.Platform
B.Change your network
C.Run your network
D.Know your network
AnswerB

The Intent API's "Change your network" category covers configuration operations, including deploying templates to devices. It satisfies the stem's requirement for programmatic template deployment across multiple devices, unlike monitoring or integration categories that only read data or connect platforms.

Why this answer

The 'Change your network' API category in Cisco DNA Center is specifically designed for making configuration changes, including deploying templates to devices. It provides endpoints for template deployment, configuration management, and other write operations. This aligns with the goal of programmatically deploying a configuration template to multiple devices.

Exam trap

The trap here is confusing the API categories based on their names; candidates might think 'Run your network' is for deploying configurations because it sounds operational, but it's actually for monitoring and troubleshooting.

How to eliminate wrong answers

Option A is wrong because the Platform API category provides foundational services like authentication, not configuration deployment. Option C is wrong because 'Run your network' APIs are for operational tasks such as monitoring and troubleshooting, not for deploying configurations. Option D is wrong because 'Know your network' APIs are for discovery and inventory, not for making changes.

43
MCQeasy

A developer needs to send a message to a Webex room using the API. Which HTTP method and endpoint should they use?

A.GET /v1/messages
B.PUT /v1/messages
C.DELETE /v1/messages
D.POST /v1/messages
AnswerD

Creating a message is a resource-creating operation, so the Webex messaging API expects POST against the /v1/messages collection endpoint, with the roomId and text in the JSON body. GET on that path would only list messages.

Why this answer

To send a message, use POST to /v1/messages with the room ID and message body.

44
MCQmedium

Which authentication method is used by the Cisco Meraki Dashboard API?

A.JWT token in the Authorization header
B.OAuth 2.0 token in the Authorization header
C.HTTP Basic authentication with username and password
D.API key in the X-Cisco-Meraki-API-Key header
AnswerD

The Meraki Dashboard API authenticates every call with a static API key passed in the X-Cisco-Meraki-API-Key request header, satisfying the stem's requirement for the dashboard's native authentication method. Unlike OAuth 2.0 bearer tokens, which Meraki does not issue for dashboard API access, this header-based key is the sole supported credential.

Why this answer

Meraki Dashboard API uses an API key passed in the X-Cisco-Meraki-API-Key header.

45
MCQhard

A network administrator wants to use EEM on an IOS XE device to send a syslog message whenever a specific CLI command is entered. Which event detector should be used?

A.event syslog pattern
B.event interface
C.event cli match
D.event timer
AnswerC

The event cli detector triggers an EEM applet when CLI input matches a specified regular expression, which is exactly the requirement to react to a particular command being entered. Other detectors watch syslog, SNMP, timers or interface counters, none of which fire on command entry.

Why this answer

The 'event cli match' detector in EEM triggers when the CLI input on the device matches a specified regular expression pattern. This is exactly what the administrator needs: to detect when a specific CLI command is entered and then take action (send a syslog message). The 'match' keyword uses a regex to compare against the command string typed by the user.

Exam trap

The trap here is confusing event detectors: candidates might think 'event syslog pattern' can detect CLI commands because CLI commands often generate syslog messages, but the detector specifically watches syslog output, not CLI input.

How to eliminate wrong answers

Option A is wrong because 'event syslog pattern' triggers on syslog messages generated by the device, not on CLI command entry. Option B is wrong because 'event interface' triggers on interface state changes (up/down), not CLI commands. Option D is wrong because 'event timer' triggers based on a time schedule (absolute or periodic), not on CLI input.

46
MCQmedium

A developer is building a Python application that manages Cisco IOS XE devices through the Python library ncclient. The application must apply a configuration change atomically, validate it before committing, and avoid persisting the change if validation fails. Which approach should the developer take?

A.Issue a discard-changes operation against running after each edit-config to confirm the edit was accepted
B.Lock the candidate datastore, edit the candidate, validate it with the validate operation, then commit and unlock
C.Send an edit-config directly to the running datastore with the default merge operation
D.Use the copy-config operation to copy running into startup, then edit startup directly
AnswerB

The candidate datastore exists specifically to stage changes before they take effect. Locking prevents concurrent edits, the validate operation checks the staged configuration, and commit applies it only when validation succeeds. This sequence meets the atomic, validated, non-persistent-on-failure requirement and is the standard ncclient workflow for transactional configuration.

Why this answer

Transactional configuration over NETCONF depends on a staging datastore and an explicit validation step. Locking the candidate, editing it, running the validate operation, and then committing ensures the change is checked before it becomes active. If validation fails, the candidate can be discarded and running is never touched, satisfying the atomic and non-persistent requirements.

Exam trap

The trap here is treating the running datastore as if it were staged, when only the candidate datastore supports validate-then-commit semantics.

47
MCQhard

A developer is writing a Python script to interact with a Cisco Meraki Dashboard API. The script retrieves a list of organizations and then, using the organization ID, retrieves the networks for that organization. The API returns a 200 OK with a JSON body and a Link header containing a URL for the next page. The developer wants to ensure all networks are retrieved. Which approach should the developer take?

A.Parse the Link header and follow the URL for the next page until no Link header is present.
B.Parse the response for an 'offset' field and use it in subsequent requests until the offset equals the total count.
C.Use the 'perPage' query parameter set to 1000 to retrieve all networks in a single request.
D.Send the same GET request with an increased 'page' query parameter until an empty array is returned.
AnswerA

The Meraki Dashboard API uses pagination via the Link header. When more results exist, the Link header includes a rel="next" URL. By following that URL until no next link is provided, the developer can retrieve all networks. This is the correct method to handle pagination in the Meraki API.

Why this answer

The Meraki Dashboard API implements pagination using the Link header, which contains a URL for the next page of results. To retrieve all networks, the developer must follow the 'next' link until it is absent. Other methods like using a 'page' parameter, increasing 'perPage', or looking for an 'offset' field do not align with the API's design and will not work.

Exam trap

The trap here is assuming that pagination is done with simple page numbers or offsets, rather than the cursor-based Link header used by Meraki.

48
MCQhard

A developer is using the Meraki Dashboard API and receives an HTTP 429 status code with a Retry-After header. What is the correct interpretation?

A.The API key is invalid and the request should be re-authenticated.
B.The rate limit has been exceeded; the client should wait the number of seconds specified in Retry-After before retrying.
C.The server is temporarily unavailable; the client should retry immediately.
D.The request was successful but the response is too large.
AnswerB

HTTP 429 signals the Meraki Dashboard API rate limit has been exceeded. The Retry-After header specifies the number of seconds the client must wait before issuing another request; retrying earlier risks further throttling. This is a throttling response, not an authentication or server error.

Why this answer

HTTP 429 status code indicates 'Too Many Requests', meaning the client has exceeded the rate limit imposed by the Meraki Dashboard API. The Retry-After header specifies the number of seconds the client must wait before sending a new request to avoid further throttling. This is a standard rate-limiting mechanism defined in RFC 6585.

Exam trap

Cisco often tests the distinction between HTTP 429 (rate limiting) and 503 (server unavailable), and candidates may confuse Retry-After with a suggestion rather than a mandatory wait period.

How to eliminate wrong answers

Option A is wrong because an invalid API key would result in a 401 Unauthorized or 403 Forbidden status, not 429. Option C is wrong because a 429 status specifically indicates rate limiting, not server unavailability (which would be 503 Service Unavailable), and retrying immediately would continue to exceed the limit. Option D is wrong because a successful request returns a 2xx status code, and a response that is too large would typically result in a 413 Payload Too Large or be handled via pagination, not a 429.

49
Multi-Selecthard

Which TWO of the following are features of the DNA Center 'Platform' API category?

Select 2 answers
A.Template deployment
B.Path trace
C.Task management
D.Event notifications
E.Device inventory
AnswersC, D

Task management belongs to the Platform API category, exposing asynchronous job operations such as checking task status and results. It lets callers track long-running operations initiated through other DNA Center APIs, distinct from Intent or Know Your Network categories.

Why this answer

The Platform category includes event notifications and task management.

50
MCQmedium

A developer wants to use Cisco NX-API on a Nexus switch to execute a CLI command via JSON. What must be enabled on the switch first?

A.feature nxapi
B.ip http server
C.netconf-yang
D.restconf
AnswerA

NX-API is disabled by default on Nexus switches and must be activated with the command 'feature nxapi' in configuration mode. Enabling this feature starts the HTTP/HTTPS listener that accepts JSON-formatted CLI requests, satisfying the stem's prerequisite.

Why this answer

The 'feature nxapi' command enables NX-API on NX-OS.

51
MCQeasy

A developer needs to configure a Cisco IOS XE device using NETCONF and wants to ensure the session supports candidate configuration and confirmed commit. Which capability must the device advertise in its NETCONF hello message?

A.urn:ietf:params:netconf:capability:writable-running:1.0
B.urn:ietf:params:netconf:capability:candidate:1.0
C.urn:ietf:params:netconf:capability:startup:1.0
D.urn:ietf:params:netconf:capability:rollback-on-error:1.0
AnswerB

The candidate capability means the device supports a candidate configuration datastore that can be edited, validated, and then committed atomically. Combined with confirmed-commit, this allows the developer to stage changes and have them automatically rolled back if the commit is not confirmed, which is exactly the safe configuration workflow described.

Why this answer

NETCONF defines capabilities in the hello exchange, and candidate configuration is advertised via the candidate capability URN. When a device supports it, clients can edit the candidate datastore, validate it, and commit atomically. Confirmed commit builds on this by requiring an explicit confirmation within a timeout, otherwise the device reverts.

The candidate capability is therefore the prerequisite for the described workflow.

Exam trap

The trap here is assuming that writable-running is enough for transactional changes, when candidate configuration and confirmed commit require the candidate capability specifically.

52
MCQeasy

A network engineer is using the Cisco DNA Center Intent API to retrieve a list of all sites. Which HTTP method and endpoint should be used?

A.GET /dna/intent/api/v1/site
B.GET /dna/system/api/v1/site
C.GET /dna/intent/api/v1/sites
D.POST /dna/intent/api/v1/site
AnswerA

The Cisco DNA Center Intent API provides a GET endpoint at /dna/intent/api/v1/site to retrieve all sites. This endpoint returns a list of sites defined in the network hierarchy. It is a read-only operation that requires authentication via an X-Auth-Token header obtained from the authentication API. This is the correct way to list sites.

Why this answer

To retrieve a list of sites in Cisco DNA Center, the correct API call is a GET request to /dna/intent/api/v1/site. This endpoint is part of the Intent API and returns all sites. Authentication is required using a token from the authentication API.

Other methods or paths do not perform this function.

Exam trap

The trap here is confusing the singular and plural forms of the endpoint or using the wrong base path for the Intent API.

53
MCQeasy

Using the Cisco DNA Center API, which endpoint should be queried to retrieve the Layer 2 topology for a specific VLAN?

A.GET /dna/intent/api/v1/issues
B.GET /dna/intent/api/v1/topology/l2/{vlanID}
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/physical-topology
AnswerB

The DNA Center intent API exposes Layer 2 topology through the topology/l2 path, and appending the VLAN identifier scopes results to that broadcast domain. Querying this endpoint with GET returns nodes and links for the specified VLAN, matching the requirement.

Why this answer

Cisco DNA Center provides /dna/intent/api/v1/topology/l2/{vlanID} to retrieve Layer 2 topology information for a given VLAN.

54
MCQmedium

A developer wants to retrieve the current user's Webex profile information. Which API endpoint should be called?

A.GET /v1/people
B.GET /v1/people/me
C.GET /v1/memberships/me
D.GET /v1/rooms/me
AnswerB

GET /v1/people/me returns the authenticated user's own profile, resolving the caller's identity from the OAuth token rather than requiring an explicit person ID. This satisfies the stem's requirement to retrieve the current user's Webex profile information without knowing or supplying their identifier in advance.

Why this answer

The /v1/people/me endpoint returns details about the authenticated user.

55
MCQeasy

A developer is writing a Python script to interact with a Cisco DNA Center controller. The script needs to authenticate and obtain a token to make subsequent API calls. Which authentication method should the developer use?

A.Generate an API key in the DNA Center GUI and include it in the X-API-Key header.
B.POST to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.
C.HTTP Basic Authentication with username and password in the Authorization header.
D.Use OAuth 2.0 with a client ID and client secret to obtain an access token.
AnswerB

Cisco DNA Center uses token-based authentication. The developer must send a POST request to the '/dna/system/api/v1/auth/token' endpoint with the username and password encoded in Base64 in the Authorization header. The response contains a token that must be included in subsequent API calls as 'X-Auth-Token'. This is the standard method for DNA Center API authentication.

Why this answer

Cisco DNA Center API authentication requires a POST request to the '/dna/system/api/v1/auth/token' endpoint with Basic Auth credentials. The response includes a token that must be used in the 'X-Auth-Token' header for subsequent calls. This token-based approach ensures secure and session-managed access.

Exam trap

The trap here is assuming that DNA Center uses OAuth or static API keys like other platforms, when it actually uses a custom token endpoint with Basic Auth.

56
MCQmedium

A developer is using the Cisco Webex API to send a message to a specific room. They have the room ID. Which endpoint and method should they use?

A.PUT /v1/messages/{messageId}
B.POST /v1/messages with roomId in the body
C.POST /v1/rooms with roomId in the body
D.GET /v1/messages?roomId=...
AnswerB

Creating a message is a resource-creation action, so the Webex messaging API expects an HTTP POST to the /v1/messages collection endpoint. The target room is identified by passing roomId in the JSON request body, which routes the message to that specific room.

Why this answer

To send a message to a Webex room, the correct endpoint is POST /v1/messages with roomId in the body.

57
MCQhard

A developer is using the Cisco DNA Center REST API to retrieve a list of all network devices. The API requires authentication. The developer wants to avoid hardcoding credentials and instead use a token-based authentication mechanism. Which authentication method should the developer use?

A.API key passed in the X-Auth-Token header
B.Basic Authentication with base64-encoded username and password
C.Token-based authentication using the /dna/system/api/v1/auth/token endpoint
D.OAuth 2.0 with client credentials grant
AnswerC

DNA Center provides a token endpoint at /dna/system/api/v1/auth/token. The developer sends a POST with Basic Auth credentials to receive a time-limited token, which is then used in the X-Auth-Token header for subsequent API calls. This is the correct token-based method and avoids hardcoding credentials in each request.

Why this answer

DNA Center's REST API uses a token-based authentication flow. The developer must first call the authentication endpoint with Basic Auth to obtain a token, then include that token in the X-Auth-Token header for all subsequent requests. This approach is more secure than sending credentials with every call and is the standard method for DNA Center automation.

Exam trap

The trap here is confusing DNA Center's token authentication with OAuth 2.0 or static API keys, which are not used by the platform.

58
MCQmedium

A developer needs to retrieve the current user's details from Webex API. Which endpoint should they call?

A.GET /v1/people/me
B.GET /v1/rooms?me=true
C.POST /v1/people
D.GET /v1/people?email=current@user.com
AnswerA

GET /v1/people/me returns the authenticated user's own profile, resolving identity directly from the bearer token rather than requiring a person ID. This satisfies the stem's requirement to retrieve the current user's details without first querying another endpoint to discover their identifier.

Why this answer

GET /v1/people/me returns details of the authenticated user.

59
MCQeasy

Which Meraki API response header provides information for paginating through a large result set?

A.Content-Range
B.Link
C.X-RateLimit-Remaining
D.Retry-After
AnswerB

The Link response header returns RFC 5988 web-linking metadata, including rel="next", rel="prev", rel="first" and rel="last" URLs. This satisfies the stem's pagination constraint: Meraki's API caps results per page, so clients follow the rel="next" URL to retrieve subsequent records until no further link is supplied.

Why this answer

Meraki uses the Link header (LinkHeader) with 'next' and 'prev' URLs, or alternatively the startingAfter/endingBefore parameters. The Link header is standard for pagination.

60
MCQhard

An engineer is using EEM on an IOS XE device. They want to trigger an applet when a specific syslog message appears. Which event trigger type should they use?

A.event syslog pattern
B.event interface
C.event cli match
D.event timer
AnswerA

The `event syslog pattern` trigger matches syslog messages against a regular expression, firing the applet when the specified pattern appears in the device log. This directly satisfies the stem's requirement to react to a specific syslog message, unlike timer, interface, or SNMP-based triggers.

Why this answer

The 'event syslog pattern' trigger in EEM (Embedded Event Manager) is specifically designed to fire an applet when a syslog message matching a regex pattern is logged. It watches the device's syslog stream and activates the applet when the pattern matches. This is the canonical trigger for reacting to specific log events on IOS XE.

Exam trap

The trap here is confusing the trigger source — candidates often pick 'event cli match' because they conflate 'matching a pattern' with CLI input, when the question explicitly says a syslog message is the trigger.

How to eliminate wrong answers

Option B is wrong because 'event interface' triggers on interface state changes (up/down) or interface counters, not on syslog message content. Option C is wrong because 'event cli match' triggers when a user types a CLI command matching a regex, not when a syslog message appears. Option D is wrong because 'event timer' triggers on a scheduled time interval (countdown, cron, absolute), not on log content.

61
MCQhard

A developer is writing a Python script that uses the Cisco Meraki Dashboard API to update the VLAN configuration of a network. The script reads the API key from an environment variable and places it in the appropriate request header. Which header should the developer set, and what happens if the key is invalid?

A.Set Authorization to a Bearer token; an invalid key produces an HTTP 403 Forbidden response
B.Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 401 Unauthorized response
C.Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 404 Not Found response
D.Set X-Meraki-Token; an invalid key produces an HTTP 429 Too Many Requests response
AnswerB

The Meraki Dashboard API authenticates requests with a dedicated header named X-Cisco-Meraki-API-Key carrying the organization's key. When that key is missing, revoked, or malformed, the dashboard rejects the call with a 401 Unauthorized status. This matches the scenario's requirement to read the key from an environment variable and place it in the correct header.

Why this answer

The Meraki Dashboard API uses a purpose-built header for API key authentication rather than standard HTTP bearer tokens. Placing the organization key in X-Cisco-Meraki-API-Key authenticates the call, and an invalid or revoked key yields a 401 Unauthorized response. Reading the key from an environment variable keeps credentials out of source control while still populating the correct header.

Exam trap

The trap here is assuming Meraki uses the same bearer-token authorization header as OAuth-based Cisco APIs, which leads to sending credentials in the wrong place.

62
Multi-Selecthard

A developer is building an automation script to retrieve network device details from Cisco DNA Center. The script needs to authenticate and then call the device list API. Which THREE steps are required in the correct sequence?

Select 3 answers
A.Send a GET request to /dna/intent/api/v1/network-device
B.Enable cookie-based authentication in the HTTP client
C.Use the token in the Authorization header as Bearer token for subsequent requests
D.Send a POST request to /dna/system/api/v1/auth/token with Basic Auth
E.Include the token as a query parameter in the device list request
AnswersA, C, D

Correct. After authenticating and obtaining the token, the GET request to /dna/intent/api/v1/network-device is the step that retrieves the device list. It must include the Bearer token in the Authorization header, which is established in the previous step (option C).

Why this answer

The correct sequence begins with D: the script must POST to /dna/system/api/v1/auth/token using HTTP Basic Auth (base64-encoded username:password) to obtain a JWT token from Cisco DNA Center. Next, C is required because that token must be presented on every subsequent API call in the Authorization header using the Bearer scheme (Authorization: Bearer <token>), which is how DNA Center validates the caller. Finally, A is required because the device inventory is retrieved with a GET request to /dna/intent/api/v1/network-device, the Intent API endpoint that returns the network device list.

Option B is incorrect because DNA Center's token-based authentication does not rely on HTTP cookies. Option E is incorrect because the token must be sent in the Authorization header, not as a query parameter, which would be insecure and unsupported.

Exam trap

The exam often tests the correct order of steps for Cisco DNA Center API authentication. Candidates may forget that the GET request to retrieve devices is a distinct step in the sequence and may incorrectly assume that steps C and D are sufficient. Additionally, they may confuse token-based authentication with cookie-based or query parameter authentication.

63
MCQmedium

A developer is building a Python application that uses the Webex Teams API to send a message to a specific room. The developer has the room ID and a valid access token. Which HTTP method and endpoint should be used?

A.POST /v1/messages with roomId and text in the JSON body
B.GET /v1/messages with roomId as a query parameter
C.PUT /v1/messages with roomId and text in the JSON body
D.POST /v1/rooms/{roomId}/messages with text in the JSON body
AnswerA

The Webex Teams API uses POST /v1/messages to create a message. The request must include the roomId and text parameters in the JSON body. The access token is passed in the Authorization header as a Bearer token. This is the correct method and endpoint for sending a message to a room.

Why this answer

To send a message to a Webex Teams room, the developer must use POST /v1/messages with the roomId and text in the JSON body. The access token is provided in the Authorization header. Other methods like GET are for listing messages, and PUT is for updating existing messages.

The endpoint must be exactly as documented.

Exam trap

The trap here is using a nested endpoint or the wrong HTTP method for creating a message.

64
MCQhard

A developer needs to register a Webex webhook that triggers when a new message is posted in any room the bot is a member of. Which resource and event should be specified?

A.resource: 'rooms', event: 'created'
B.resource: 'messages', event: 'updated'
C.resource: 'messages', event: 'created'
D.resource: 'memberships', event: 'created'
AnswerC

Webex webhooks subscribe to a resource and event pair. Specifying resource 'messages' with event 'created' fires the webhook whenever a new message is posted in any room the bot belongs to, matching the required trigger scope exactly.

Why this answer

To listen for new messages in any room the bot is in, use the 'messages' resource and 'created' event.

65
Multi-Selectmedium

Which THREE of the following are valid event triggers for an EEM applet on Cisco IOS XE? (Choose THREE.)

Select 3 answers
A.timer
B.cli match
C.snmp trap
D.http request
E.syslog pattern
AnswersA, B, E

EEM supports timer-based events.

Why this answer

EEM applets support timer-based event triggers, such as absolute time, countdown, or watchdog timers, allowing automation of actions at specified intervals or after a delay. This is a core EEM feature defined in Cisco IOS XE for scheduling tasks without external input.

Exam trap

Cisco often tests the exact EEM event trigger keywords, and candidates mistakenly assume 'snmp trap' is valid because SNMP traps are common network events, but the correct trigger is 'event snmp notification' or 'event snmp oid', not 'trap'.

66
Multi-Selecthard

Which three components are required to set up a Webex webhook for message creation events? (Choose three.)

Select 3 answers
A.Resource type (e.g., "messages")
B.Room ID to filter messages
C.API access token as a query parameter
D.Target URL to receive notifications
E.Event type (e.g., "created")
AnswersA, D, E

Resource specifies what to monitor.

Why this answer

A is correct because every Webex webhook must specify a resource type to define which API resource triggers the webhook. For message creation events, the resource type must be "messages" to indicate that the webhook listens for changes to message resources. Without this, the webhook cannot know which data model to monitor.

Exam trap

Cisco often tests the distinction between required fields (resource, event, target URL) and optional filters (like roomId), leading candidates to incorrectly select optional parameters as mandatory components.

67
MCQhard

A developer is working with Meraki API to list all clients on a network. The response is paginated. Which parameter allows the developer to specify the starting point for the next page?

A.nextToken
B.startingAfter
C.page
D.offset
AnswerB

`startingAfter` accepts the identifier of the last record from the previous page, so the Meraki API returns only records positioned after it. This directly satisfies the stem's requirement to specify the starting point for the next page, unlike `perPage`, which only controls page size.

Why this answer

Meraki uses startingAfter and endingBefore parameters for cursor-based pagination.

68
MCQmedium

When using RESTCONF on Cisco IOS XE, which URL retrieves the hostname configuration?

A.GET /restconf/data/ietf-interfaces:interfaces
B.GET /restconf/data/openconfig-interfaces:interfaces
C.GET /restconf/data/Cisco-IOS-XE-native:native/interface
D.GET /restconf/data/Cisco-IOS-XE-native:native/hostname
AnswerD

RESTCONF exposes the native data model at /restconf/data/, and the hostname leaf sits under the Cisco-IOS-XE-native:native container. A GET on that exact path returns the configured hostname, matching the YANG-modelled URL structure IOS XE publishes.

Why this answer

The native YANG model Cisco-IOS-XE-native contains the hostname under /native/hostname.

69
MCQeasy

A network engineer needs to retrieve a list of all network devices from Cisco DNA Center. Which API endpoint should they use?

A.POST /dna/system/api/v1/auth/token
B.GET /dna/intent/api/v1/issues
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/l2/{vlanID}
AnswerC

GET /dna/intent/api/v1/network-device targets the Intent API's network-device resource, returning the full device inventory Cisco DNA Center manages. The GET method satisfies the read-only retrieval the engineer requires, and the endpoint path matches the platform's versioned REST structure, so no filtering or configuration change is needed.

Why this answer

The correct endpoint to retrieve the device list in Cisco DNA Center is GET /dna/intent/api/v1/network-device.

70
MCQmedium

A Meraki API request is receiving HTTP 429 responses. According to the Meraki rate limit, what should the developer do?

A.Switch to the DNA Center API.
B.Use a different API key.
C.Reduce the number of concurrent requests and wait for the Retry-After header value.
D.Immediately retry the request without delay.
AnswerC

Meraki returns HTTP 429 when the rate limit is exceeded, and the Retry-After header specifies how long to pause. Throttling concurrent requests and honouring that value prevents further throttling and aligns the client with the documented limit.

Why this answer

Meraki returns 429 with a Retry-After header indicating the number of seconds to wait.

71
MCQeasy

A developer wants to send a message to a Webex room using the API. Which HTTP method and endpoint should they use?

A.POST /v1/rooms
B.PUT /v1/messages
C.GET /v1/messages
D.POST /v1/messages
AnswerD

Sending a message creates a new resource in the Webex messaging collection, so the POST method targets /v1/messages with the roomId and text in the JSON body. GET retrieves existing messages, and PUT or DELETE would modify or remove them, not send.

Why this answer

To send a message, use POST to /v1/messages with roomId or toPersonEmail.

72
MCQmedium

A developer is writing a Python script that uses the Cisco Meraki Dashboard API. The script must read the API key from an environment variable named MERAKI_API_KEY and include it in every request. Which header should the script set?

A.Api-Key: <API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.Authorization: Bearer <API_KEY>
D.X-Auth-Token: <API_KEY>
AnswerB

Meraki Dashboard API authenticates requests using a custom header named X-Cisco-Meraki-API-Key whose value is the API key generated in the dashboard. This header must be present on every call, and the script can populate it from the environment variable to avoid hardcoding the secret in source code.

Why this answer

The Meraki Dashboard API expects the API key in a custom HTTP header called X-Cisco-Meraki-API-Key. This is the only header that authenticates the request; standard Authorization or generic API key headers are ignored. Reading the key from an environment variable and placing it in that header keeps credentials out of source code while allowing the script to call Meraki endpoints successfully.

Exam trap

The trap here is assuming that Meraki uses a standard Authorization: Bearer header when it actually requires a vendor-specific X-Cisco-Meraki-API-Key header.

73
MCQmedium

A network automation engineer is using Cisco NX-OS with NX-API enabled. The engineer wants to send a JSON-RPC request to the device to retrieve the running configuration. Which URL format and HTTP method should be used to send the request to the NX-API endpoint?

A.POST to https://<device-ip>/ins with form-encoded parameters and a Content-Type of application/x-www-form-urlencoded.
B.GET to https://<device-ip>/api/v1/config with query parameters for the command.
C.PUT to https://<device-ip>/restconf/data/Cisco-NX-OS-device:config
D.POST to https://<device-ip>/ins with a JSON body containing the RPC parameters.
AnswerD

NX-API exposes an /ins endpoint that accepts JSON-RPC or XML requests over HTTPS for CLI-based commands. Sending a POST with the proper JSON body containing the command and parameters is the documented way to retrieve configuration. This endpoint is specifically designed for programmatic access to NX-OS CLI.

Why this answer

NX-API provides a JSON-RPC interface at the /ins endpoint over HTTPS. To run show commands and retrieve the running configuration, the client sends an HTTP POST with a JSON body specifying the command and parameters. Other endpoints such as RESTCONF or form-encoded requests are not part of the NX-API JSON-RPC mechanism.

Exam trap

The trap here is confusing NX-API's JSON-RPC endpoint with RESTCONF or generic REST patterns, leading to incorrect URL and HTTP method choices.

74
MCQmedium

A developer wants to send a message to a Webex room using the API. The message should contain a simple text body. Which endpoint and parameter are required?

A.GET /v1/messages with query parameter 'roomId'
B.POST /v1/memberships with body parameter 'message'
C.POST /v1/rooms with body parameter 'text'
D.POST /v1/messages with body parameter 'roomId' and 'text'
AnswerD

The Webex messaging endpoint accepts a POST to /v1/messages, where the JSON body supplies the target 'roomId' and the message content via the 'text' parameter. This pairing delivers a plain-text message to the specified room, matching the developer's simple text-body requirement.

Why this answer

To send a message, a POST request is made to /v1/messages with a JSON body containing roomId and text (or markdown). roomId identifies the target room.

75
MCQeasy

A developer is writing a script to interact with the Cisco DNA Center Intent API. The script needs to retrieve a list of all devices in the inventory. Which HTTP method and endpoint should the developer use?

A.GET /dna/intent/api/v1/network-device
B.POST /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/inventory
D.GET /dna/intent/api/v1/device
AnswerA

The Cisco DNA Center Intent API provides the /dna/intent/api/v1/network-device endpoint to retrieve the list of devices in the inventory. A GET request to this endpoint returns a JSON array of device objects. This is the standard endpoint for device inventory retrieval in DNA Center.

Why this answer

The Cisco DNA Center Intent API uses the /dna/intent/api/v1/network-device endpoint with a GET method to retrieve the device inventory. This is the documented and standard way to list all devices. Other paths or methods do not correspond to the actual API and would fail.

Exam trap

The trap here is guessing a shorter or more intuitive endpoint name like /device or /inventory instead of the exact documented resource name network-device.

Page 1 of 2 · 126 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cisco Platforms and Development questions.