Courseiva

CCNA Cisco Platforms and Development Questions

51 of 126 questions · Page 2/2 · Cisco Platforms and Development · Answers revealed

76
MCQmedium

A developer wants to send a message to a specific room in Webex using the API. The developer already has the room ID. Which API call is correct?

A.POST /v1/messages with body { 'roomId': 'Y2lzY29zcGFyazovL3VzL1JPT00v...', 'text': 'Hello' }
B.PUT /v1/messages with body { 'roomId': '...', 'text': 'Hello' }
C.POST /v1/rooms with body { 'title': 'New Room' }
D.GET /v1/messages with query parameter roomId='...'
AnswerA

The Webex messaging endpoint accepts POST /v1/messages, and targeting an existing space requires the roomId field in the JSON body alongside text. This call satisfies the constraint of using the already-obtained room ID to post into that specific room.

Why this answer

To send a message to a room, POST /v1/messages is used with roomId and text in the body.

77
MCQmedium

A developer wants to create a new room in Cisco Webex using the API. Which HTTP request is appropriate?

A.GET /v1/rooms
B.PUT /v1/rooms
C.POST /v1/rooms
D.DELETE /v1/rooms
AnswerC

Creating a room is a resource-creation action on the rooms collection, so the Webex REST API expects POST to /v1/rooms with the room title in the JSON body. GET retrieves, PUT updates, and DELETE removes; only POST creates a new room.

Why this answer

Creating a new Webex room is a resource-creation operation, which maps to HTTP POST against the /v1/rooms collection. POST /v1/rooms with a JSON body containing the title creates the room and returns its details. This follows standard REST semantics.

Exam trap

200-901 often tests HTTP verb semantics — candidates may pick PUT thinking it 'creates', but POST is required for collection-level creation.

How to eliminate wrong answers

Option A is wrong because GET /v1/rooms lists existing rooms rather than creating one. Option B is wrong because PUT is used to replace an existing resource identified by a URL, not to create a new room in a collection. Option D is wrong because DELETE /v1/rooms removes a room (and typically requires a roomId in the path).

78
MCQmedium

A developer is building a Python application that interacts with Cisco Meraki Dashboard API. The application needs to retrieve the list of organizations. Which HTTP header must be included in the request to authenticate?

A.Authorization: Bearer <API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.X-Auth-Token: <API_KEY>
D.api-key: <API_KEY>
AnswerB

The Meraki Dashboard API requires the API key to be passed in the X-Cisco-Meraki-API-Key header. This is the standard authentication method for all Meraki API calls. Without this header, the API returns a 401 Unauthorized response. The developer must include it in every request to access organization data.

Why this answer

The Meraki Dashboard API authenticates requests using the X-Cisco-Meraki-API-Key header. The API key is generated in the Meraki Dashboard and must be included in every API call. Other headers like Authorization: Bearer or X-Auth-Token are used by different Cisco platforms and will not work with Meraki.

Exam trap

The trap here is assuming that all Cisco APIs use the same authentication header, when in fact each platform has its own specific header name.

79
MCQeasy

Which Cisco platform provides a cloud-managed networking solution with a RESTful API that uses an API key in the X-Cisco-Meraki-API-Key header?

A.Cisco Webex
B.Cisco DNA Center
C.Cisco IOS XE
D.Cisco Meraki
AnswerD

Cisco Meraki's cloud dashboard exposes a RESTful API authenticated via the X-Cisco-Meraki-API-Key header, satisfying the stem's exact requirement. Unlike on-premises controllers such as DNA Center, which use token-based authentication, Meraki's cloud-managed model issues a per-organisation API key passed directly in that header.

Why this answer

The Meraki Dashboard API uses an API key in the X-Cisco-Meraki-API-Key header.

80
MCQhard

A developer is working with the Webex API to receive real-time notifications when a message is posted. Which resource should they create?

A.A webhook with resource 'messages' and event 'created'
B.A bot that polls the /v1/messages endpoint every second
C.A membership to the room to receive notifications
D.A webhook with resource 'rooms' and event 'created'
AnswerA

A webhook with resource 'messages' and event 'created' satisfies the real-time notification constraint: Webex pushes an HTTP POST to your target URL the instant a message is posted, avoiding polling. The 'created' event scopes delivery to new messages only, matching the stem's requirement precisely.

Why this answer

Webex webhooks allow you to subscribe to events like message.created.

81
Multi-Selectmedium

A developer is building a Python application that uses the Cisco Webex Teams REST API to manage memberships. The application must add a person to a space and later list the members of that space. Which two HTTP methods and endpoints should the application use? (Choose two.)

Select 2 answers
A.POST https://webexapis.com/v1/memberships with a JSON body containing roomId and personEmail
B.GET https://webexapis.com/v1/memberships?roomId={roomId}
C.POST https://webexapis.com/v1/rooms with a JSON body containing title and personEmail
D.PUT https://webexapis.com/v1/memberships with a JSON body containing roomId and personEmail
E.GET https://webexapis.com/v1/rooms?roomId={roomId}
AnswersA, B

The memberships resource is the correct endpoint for adding a person to a space. A POST request with roomId and personEmail in the JSON body creates the membership, and the API returns the new membership object including its ID. This matches the requirement to add a person to a space programmatically.

Why this answer

Webex Teams exposes membership management through the memberships resource. Creating a membership uses POST with roomId and personEmail in the body, while listing members uses GET with the roomId query parameter. The rooms resource is for space metadata, and PUT is for updating an existing membership, so neither fits the required add-and-list workflow.

Exam trap

The trap here is using the rooms endpoint to manage members, when membership creation and listing actually belong to the memberships resource.

82
MCQmedium

An administrator wants to receive real-time notifications when a new message is posted to a Webex room. Which Webex API resource should be used to configure this?

A.People API
B.Messages API
C.Webhooks API
D.Rooms API
AnswerC

The Webhooks API satisfies the real-time notification constraint by having Webex push an HTTP POST to your listener the moment a message is created in the room, eliminating polling. Subscriptions target specific resources and events, so a messages/created subscription on that room delivers immediate delivery.

Why this answer

Webhooks allow you to register for events like message.created. The webhook resource is used for this purpose.

83
MCQeasy

In DNA Center, which API category is used to deploy templates to devices?

A.Platform
B.Know your network
C.Change your network
D.Run your network
AnswerC

The "Change your network" API category in DNA Center handles configuration deployment, including applying templates to devices via the Template Programmer. It satisfies the stem's requirement to deploy templates, unlike Intent APIs (policy) or Integration APIs (events). This category directly provisions device configuration changes.

Why this answer

The 'Change your network' API category in Cisco DNA Center is specifically designed for network configuration and provisioning tasks, including deploying templates to devices. This category encompasses APIs that push configuration changes, such as applying CLI templates via the Template Programmer (formerly Template Editor) or provisioning new network settings, directly aligning with the action of deploying templates to network devices.

Exam trap

The trap here is that candidates confuse 'Run your network' (which involves monitoring and operational state) with 'Change your network' (which involves active configuration changes), leading them to select D because they associate 'running' with executing templates, but Cisco specifically separates read-only operations from write operations in its API categorization.

How to eliminate wrong answers

Option A is wrong because the 'Platform' API category provides foundational services like authentication, RBAC, and event notifications, not template deployment. Option B is wrong because 'Know your network' focuses on read-only APIs for inventory, topology, and assurance data, not on making configuration changes. Option D is wrong because 'Run your network' deals with operational tasks like device health monitoring and troubleshooting, not the active deployment of configuration templates.

84
MCQhard

An engineer is developing an EEM applet on a Cisco IOS XE device to run a CLI command when a specific syslog message appears. Which event trigger should be used?

A.event interface
B.event timer
C.event cli match
D.event syslog pattern
AnswerD

The event syslog pattern trigger fires the applet when an incoming syslog message matches a specified regular expression. That directly satisfies the requirement to react to a specific syslog message, unlike timer or interface-based triggers which cannot inspect log content.

Why this answer

The syslog pattern event trigger allows matching a specific syslog message pattern.

85
MCQmedium

A developer is using the Cisco DNA Center API and receives a token. How is this token typically used in subsequent API requests?

A.As a query parameter named token
B.In the request body
C.In the X-Auth-Token header
D.In the Authorization header as Bearer <token>
AnswerC

Cisco DNA Center issues a token on authentication, and subsequent calls must carry it in the X-Auth-Token HTTP header. This satisfies the API's authorisation requirement, letting the developer call protected endpoints without resending credentials each time.

Why this answer

The Cisco DNA Center API uses token-based authentication where the token is passed in the X-Auth-Token HTTP header for subsequent requests. This is the standard method specified in the Cisco DNA Center API documentation, ensuring the server can validate the session without relying on cookies or query parameters.

Exam trap

Cisco often tests the specific header name (X-Auth-Token) versus the more generic Authorization header with Bearer scheme, so the trap here is that candidates familiar with OAuth 2.0 may incorrectly choose Option D, not realizing that Cisco DNA Center uses its own proprietary header for token transmission.

How to eliminate wrong answers

Option A is wrong because passing the token as a query parameter named 'token' is insecure and not supported by the Cisco DNA Center API; tokens should never be exposed in URLs due to logging and caching risks. Option B is wrong because placing the token in the request body would require a specific API endpoint to accept it that way, but the standard for RESTful APIs like DNA Center is to use headers, not the body, for authentication. Option D is wrong because although Bearer tokens in the Authorization header are common in OAuth 2.0, the Cisco DNA Center API specifically requires the X-Auth-Token header, not the Authorization header; using the wrong header will result in an authentication failure.

86
Multi-Selectmedium

A developer is using the Cisco Meraki Dashboard API to manage networks. The developer needs to perform operations that require identifying a specific network. Which two identifiers are required when making a request to retrieve or modify a network? (Choose two.)

Select 2 answers
A.clientId
B.organizationId
C.deviceSerial
D.networkId
E.configTemplateId
AnswersB, D

The organizationId is required because networks belong to an organization. Many Meraki API endpoints, such as those for networks, are nested under /organizations/{organizationId}/networks. Without the organizationId, the API cannot determine which organization's networks to access, resulting in an error.

Why this answer

To target a specific network in the Meraki Dashboard API, both organizationId and networkId are required. The organizationId scopes the request to the correct organization, and the networkId identifies the particular network within that organization. Other identifiers like deviceSerial, clientId, or configTemplateId are used for different resources and are not part of the network identification path.

Exam trap

The trap here is assuming that a network can be identified by a single ID or by other resource IDs like device serial, when both organization and network IDs are needed.

87
MCQeasy

A developer wants to retrieve the list of network devices from Cisco DNA Center. Which API endpoint should be used?

A.GET /dna/intent/api/v1/site
B.POST /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/topology/l2/{vlanID}
D.GET /dna/intent/api/v1/network-device
AnswerD

GET /dna/intent/api/v1/network-device satisfies the requirement to retrieve the device inventory from Cisco DNA Center. The Intent API exposes network-device as a read-only collection, and issuing GET against it returns all managed devices with their details, matching the developer's need to list network devices.

Why this answer

The GET /dna/intent/api/v1/network-device endpoint returns a list of network devices managed by DNA Center.

88
Multi-Selectmedium

A developer is building an application that uses Cisco Webex Teams APIs to manage memberships in a space. The developer needs to perform two operations: add a new member to a space and remove an existing member from a space. Which two API requests should the developer use? (Choose two.)

Select 2 answers
A.DELETE /v1/rooms/{roomId}/members/{personId}
B.POST /v1/memberships with a JSON body containing 'roomId' and 'personEmail'.
C.POST /v1/rooms/{roomId}/members with a JSON body containing 'email'.
D.PUT /v1/memberships/{membershipId} with a JSON body containing 'personEmail'.
E.DELETE /v1/memberships/{membershipId}
AnswersB, E

To add a member to a Webex space, the developer must send a POST request to /v1/memberships with the room ID and the email of the person to add. The API creates a membership and returns the details. This is the correct method for adding a new member to a space.

Why this answer

The Webex Teams API manages space memberships through the /v1/memberships resource. Adding a member requires a POST to /v1/memberships with the room ID and person's email. Removing a member requires a DELETE to /v1/memberships/{membershipId}.

These two operations correctly add and remove members. Other options use non-existent endpoints or incorrect HTTP methods.

Exam trap

The trap here is assuming that memberships are managed under a rooms endpoint or that PUT can be used to remove a member, rather than using the dedicated memberships resource.

89
MCQmedium

Which command enables the NX-API feature on a Cisco NX-OS device?

A.restconf enable
B.nxapi enable
C.feature nxapi
D.enable nxapi
AnswerC

`feature nxapi` activates the NX-API management interface on NX-OS, exposing CLI over HTTP/HTTPS for programmatic access. This satisfies the stem's requirement to enable the feature itself, since NX-API remains dormant until this command runs in configuration mode. Without it, REST calls to the device fail regardless of transport settings.

Why this answer

The global configuration command 'feature nxapi' enables the NX-API interface.

90
MCQmedium

A developer is using the Meraki Dashboard API to list all networks in an organization. The response includes a Link header with rel="next". What does this indicate?

A.The organization ID is invalid.
B.There are additional data pages to retrieve.
C.The API version is deprecated and should be updated.
D.The request is rate-limited and needs to wait.
AnswerB

The Link header with rel="next" signals cursor-based pagination: the current response is one page, and further networks remain. The developer must request the URL given in that header to retrieve the next page, satisfying the constraint of listing all networks rather than only the first batch.

Why this answer

Meraki uses Link headers for pagination; the next link indicates there are more pages of results to fetch.

91
Multi-Selecteasy

A network administrator wants to use Cisco Webex APIs to automate sending messages to a specific room. Which THREE pieces of information are required to send a message using POST /v1/messages?

Select 3 answers
A.X-Cisco-Meraki-API-Key header
B.Message body as plain text or markdown
C.Room ID or email of the recipient
D.User ID of the recipient
E.Bearer token for authentication
AnswersB, C, E

The request payload must carry the actual content to deliver, supplied as the message field in JSON, formatted as plain text or markdown. This satisfies the stem's requirement for the message content itself, distinct from routing and authentication data.

Why this answer

Option B is correct because POST /v1/messages requires a message payload, and the Webex Messages API accepts the content as either plain text or markdown in the request body. Option C is correct because the API requires a target destination, specified as either the roomId of the room or the toPersonEmail of the recipient. Option E is correct because every Webex API request must be authenticated with an OAuth Bearer token in the Authorization header.

Option A is incorrect because X-Cisco-Meraki-API-Key is used for the Meraki Dashboard API, not Webex messaging. Option D is incorrect because the Messages API does not require the recipient's user ID; it targets a room ID or recipient email instead.

Exam trap

200-901 often tests the confusion between Meraki API keys (X-Cisco-Meraki-API-Key) and Webex Bearer tokens — candidates who memorize 'Cisco API key' headers pick the wrong authentication method.

92
MCQhard

A developer is writing a Python script that uses the Cisco Meraki Dashboard API to retrieve a list of organizations. The script sends a GET request to https://api.meraki.com/api/v1/organizations but receives an HTTP 401 Unauthorized response. The developer has confirmed that the API key is correct and active. Which header must be included in the request to authenticate successfully?

A.Api-Key: <API_KEY>
B.Authorization: Bearer <API_KEY>
C.X-Cisco-Meraki-API-Key: <API_KEY>
D.X-Api-Key: <API_KEY>
AnswerC

The Meraki Dashboard API requires the API key to be passed in the X-Cisco-Meraki-API-Key header. Without this header, the API returns 401 Unauthorized even if the key itself is valid. Including this header with the correct key is the standard authentication method for all Meraki Dashboard API v1 endpoints.

Why this answer

The Meraki Dashboard API authenticates requests using the API key supplied in the X-Cisco-Meraki-API-Key header. When this header is missing or incorrectly named, the API returns 401 Unauthorized regardless of the key's validity. Therefore, the developer must include X-Cisco-Meraki-API-Key with the correct key value to successfully retrieve the list of organizations.

Exam trap

The trap here is assuming that a widely used scheme like Authorization: Bearer or a generic X-Api-Key header will work, when Meraki requires its own specific custom header.

93
Multi-Selectmedium

Which TWO of the following are categories of Cisco DNA Center APIs? (Choose two.)

Select 2 answers
A.Automate your network
B.Secure your network
C.Run your network
D.Monitor your network
E.Know your network
AnswersC, E

Run your network is one of the four documented Cisco DNA Center API categories, grouping endpoints for command runner, network health, and troubleshooting operations. It is a distinct category from Know your network, Platform, and Manage your network, satisfying the question's requirement.

Why this answer

DNA Center API categories include 'Know your network', 'Run your network', 'Change your network', and 'Platform'.

94
MCQmedium

An engineer needs to authenticate to the Cisco DNA Center API to obtain a token. What is the correct authentication method and endpoint?

A.POST /dna/system/api/v1/token with Bearer auth
B.GET /dna/intent/api/v1/auth/token with Basic auth header
C.POST /dna/system/api/v1/auth/token with API key in header
D.POST /dna/system/api/v1/auth/token with Basic auth header
AnswerD

Cisco DNA Center issues tokens via POST to /dna/system/api/v1/auth/token, authenticating with an HTTP Basic header containing the base64-encoded username and password. The response returns a token used as an X-Auth-Token header for subsequent API calls.

Why this answer

Cisco DNA Center uses Basic authentication (with username:password) to POST to /dna/system/api/v1/auth/token to obtain a token.

95
Multi-Selectmedium

A developer is using the Cisco Meraki Dashboard API to manage network devices. The developer needs to retrieve the list of organizations and then the list of networks within a specific organization. Which two API requests are required to accomplish this task? (Choose two.)

Select 2 answers
A.GET /api/v1/organizations/{organizationId}/networks
B.POST /api/v1/organizations/{organizationId}/networks
C.GET /api/v1/organizations/{organizationId}/devices
D.GET /api/v1/networks
E.GET /api/v1/organizations
AnswersA, E

This request retrieves the list of networks within the specified organization. The organizationId is obtained from the previous call. The response includes network details such as ID, name, and type. This is the correct endpoint to list networks for an organization in the Meraki Dashboard API.

Why this answer

To list organizations, use GET /api/v1/organizations. Then, to list networks within a specific organization, use GET /api/v1/organizations/{organizationId}/networks with the organization ID from the first response. These two calls together accomplish the task.

Exam trap

The trap here is assuming a global /networks endpoint exists, but the Meraki API always scopes networks under an organization.

96
MCQmedium

A developer is using the Meraki Dashboard API to retrieve a list of clients for a given network. The initial GET request returns a 429 HTTP status. What should the developer do to handle this response appropriately?

A.Convert the request to a POST method to bypass the rate limit
B.Check the Retry-After header and wait that many seconds before retrying
C.Ignore the 429 and send the request again with a different API key
D.Send a DELETE request to clear the rate limit counter
AnswerB

HTTP 429 signals rate limiting, and the Meraki Dashboard API returns a Retry-After header specifying the exact wait interval. Honouring that value prevents further throttling and failed calls, satisfying the stem's requirement to handle the response appropriately rather than retrying immediately.

Why this answer

The Meraki API rate limits at 5 requests per second. A 429 response includes a Retry-After header indicating the number of seconds to wait before retrying.

97
MCQmedium

A developer is using the Meraki Dashboard API to retrieve a list of devices in an organization. The API response is paginated. Which HTTP header does Meraki use to indicate the next page of results?

A.Link
B.X-Cisco-Meraki-API-Key
C.Retry-After
D.X-Next-Page
AnswerA

Meraki returns the next-page URL in the HTTP Link header, following RFC 5988, so the developer reads it directly rather than constructing offsets. This satisfies the pagination constraint: the response supplies the exact next-page endpoint, avoiding manual page-number arithmetic or cursor guessing.

Why this answer

Meraki uses the Link header with rel="next" for pagination, or alternatively the startingAfter/endingBefore parameters.

98
MCQeasy

A developer is writing a script that uses the Cisco DNA Center Intent API to retrieve a list of all sites in the network hierarchy. The developer needs to authenticate first. Which authentication method should be used to obtain a token for subsequent API calls?

A.Send a POST request to /dna/system/api/v1/auth/token with Basic authentication using the username and password.
B.Use OAuth 2.0 client credentials flow with a client ID and secret to obtain an access token.
C.Send a POST request to /dna/system/api/v1/auth/token with the username and password in the JSON body.
D.Send a GET request to /dna/system/api/v1/auth/token with an API key in the query string.
AnswerA

Cisco DNA Center's Intent API requires obtaining a token by posting to /dna/system/api/v1/auth/token with Basic authentication. The response contains a token that must be included in the X-Auth-Token header for subsequent calls. This is the documented authentication flow for DNA Center.

Why this answer

Cisco DNA Center's Intent API uses a token-based authentication flow. The client sends a POST to /dna/system/api/v1/auth/token with HTTP Basic authentication, and the response includes a token. That token is then sent in the X-Auth-Token header for subsequent API calls, such as retrieving the site hierarchy.

Exam trap

The trap here is assuming DNA Center uses API keys or OAuth 2.0, when it actually requires Basic authentication to obtain an X-Auth-Token.

99
Multi-Selectmedium

An engineer is using the Cisco Meraki Dashboard API to retrieve a list of all network clients for a specific network. Which TWO of the following are required to successfully make this API call?

Select 2 answers
A.Network ID in the URL path
B.Bearer token in the Authorization header
C.Organization ID in the URL path
D.API key as a query parameter
E.X-Cisco-Meraki-API-Key header with the API key
AnswersA, E

The network ID is required in the URL to identify the network.

Why this answer

The Meraki Dashboard API endpoint for listing network clients (GET /networks/{networkId}/clients) requires the network ID as a path parameter to identify the specific network from which to retrieve client data. Without the network ID in the URL, the API cannot determine which network's clients to return, making it a mandatory component of the request.

Exam trap

Cisco often tests the distinction between authentication methods (API key header vs. Bearer token) and the correct placement of identifiers (network ID vs. organization ID) to see if candidates understand the specific Meraki API authentication and resource hierarchy.

100
MCQmedium

In DNA Center, which API endpoint is used to retrieve a list of current network issues?

A.GET /dna/intent/api/v1/topology
B.POST /dna/system/api/v1/auth/token
C.GET /dna/intent/api/v1/issues
D.GET /dna/intent/api/v1/network-device
AnswerC

The /dna/intent/api/v1/issues endpoint is the Intent API resource dedicated to network issue retrieval, returning the current list of issues detected by DNA Center's assurance engine. It satisfies the stem's requirement for a list of current network issues rather than device or health data.

Why this answer

DNA Center's issues API is at /dna/intent/api/v1/issues.

101
MCQmedium

Which Cisco platform provides an API to retrieve a list of issues affecting the network?

A.Cisco IOS XE
B.Cisco Meraki
C.Cisco Webex
D.Cisco DNA Center
AnswerD

Cisco DNA Center exposes a REST API whose intent and assurance endpoints return network health and issue data, letting you retrieve a list of problems affecting the network. It is the platform built for this assurance function, unlike Meraki or SD-WAN Manager.

Why this answer

Cisco DNA Center includes issues API under the 'run your network' category.

102
MCQmedium

A developer is building a Python script that uses the Cisco Meraki Dashboard API. The script needs to retrieve the list of organizations the API key has access to. Which HTTP method and endpoint should the developer use?

A.POST /api/v1/organizations
B.GET /api/v1/organizations
C.GET /api/v0/organizations
D.PUT /api/v1/organizations
AnswerB

The Meraki Dashboard API uses GET /api/v1/organizations to list all organizations accessible by the API key. This endpoint returns an array of organization objects with id and name. The API key is passed in the X-Cisco-Meraki-API-Key header. This is the correct method and path for retrieving organizations.

Why this answer

The Meraki Dashboard API uses GET /api/v1/organizations to list organizations. The API key must be included in the X-Cisco-Meraki-API-Key header. This endpoint returns a JSON array of organizations.

Other methods like POST or PUT are for creating or updating resources, and the API version must be v1.

Exam trap

The trap here is confusing the API version or using an incorrect HTTP method for a read operation.

103
MCQhard

A developer needs to retrieve the hostname of a Cisco IOS XE device using RESTCONF. Which URI path is correct?

A./restconf/data/Cisco-IOS-XE-native:hostname
B./api/v1/device/hostname
C./restconf/data/Cisco-IOS-XE-native:native/hostname
D./restconf/data/hostname
AnswerC

RESTCONF exposes YANG-modelled data beneath /restconf/data, followed by the module-qualified path. Cisco-IOS-XE-native:native is the module and container, and hostname is the leaf within it, so this URI returns the device hostname via a GET request.

Why this answer

RESTCONF uses the YANG module namespace. The native hostname is at /restconf/data/Cisco-IOS-XE-native:native/hostname.

104
MCQhard

A developer is using the Cisco NX-API on a Cisco Nexus switch to retrieve the running configuration. The developer sends an HTTP POST request to the NX-API endpoint with the JSON payload: {"ins_api": {"version": "1.0", "type": "cli_show", "chassis": "1", "input": "show running-config", "output_format": "json"}}. The switch returns an error indicating that the command is not supported. What is the most likely reason?

A.The 'show running-config' command requires the 'cli_show_ascii' type instead of 'cli_show'.
B.The NX-API requires the 'input' field to be a list of commands, not a single string.
C.The 'output_format' should be set to 'ascii' instead of 'json'.
D.The 'chassis' field must be omitted for commands that are not chassis-specific.
AnswerA

The NX-API distinguishes between commands that return structured JSON output and those that return ASCII text. The 'show running-config' command does not have a JSON schema, so it must be requested with type 'cli_show_ascii'. Using 'cli_show' expects structured output and fails for this command. Thus, the developer must change the type.

Why this answer

The NX-API uses different types for commands: 'cli_show' for structured JSON output and 'cli_show_ascii' for ASCII text output. The 'show running-config' command does not support JSON output, so it must be requested with 'cli_show_ascii'. The error occurs because the developer used 'cli_show' with a command that lacks JSON support.

Changing the type to 'cli_show_ascii' resolves the issue.

Exam trap

The trap here is assuming that any show command can return JSON output, when in fact some commands only produce ASCII and require a different type.

105
MCQhard

A developer is writing a Python script that uses the Cisco Webex Teams API to create a new room and then add a user to that room. The script must handle the response from the room creation to extract the room ID for the subsequent membership call. Which HTTP status code should the developer expect from the room creation request, and which field in the response contains the room ID?

A.201 Created; the room ID is in the 'id' field of the JSON response.
B.200 OK; the room ID is in the 'roomId' field of the JSON response.
C.200 OK; the room ID is in the 'id' field of the JSON response.
D.201 Created; the room ID is in the 'roomId' field of the JSON response.
AnswerA

When a new room is successfully created via POST /v1/rooms, the Webex API returns HTTP 201 Created. The response body is a JSON object representing the room, including an 'id' field that uniquely identifies the room. This ID is then used in the membership endpoint.

Why this answer

Creating a room with POST /v1/rooms returns HTTP 201 Created, and the response JSON includes an 'id' field containing the room ID. This ID is required for subsequent operations like adding a membership. The other combinations either use the wrong status code or the wrong field name.

Exam trap

The trap here is mixing up the status code for creation (201) with the general success code (200) and confusing the room ID field name with a more descriptive but incorrect 'roomId'.

106
MCQmedium

A developer needs to retrieve the list of all networks in a specific Cisco Meraki organization. The developer has the organization ID and a valid API key. Which HTTP method and endpoint should be used?

A.GET /api/v1/organizations/{organizationId}/network
B.GET /api/v1/networks
C.POST /api/v1/organizations/{organizationId}/networks
D.GET /api/v1/organizations/{organizationId}/networks
AnswerD

This endpoint returns the list of networks within the specified organization. The organization ID is included in the path, and the API key is passed in the X-Cisco-Meraki-API-Key header. The response is a JSON array of network objects. This is the correct way to retrieve networks for an organization.

Why this answer

To list networks in a Meraki organization, the developer must use GET /api/v1/organizations/{organizationId}/networks. The organization ID is required in the path, and the API key authenticates the request. The response contains an array of network objects.

Other methods like POST are for creating networks, and incorrect paths will fail.

Exam trap

The trap here is omitting the organization ID or using the singular form of the resource name, which leads to a 404 error.

107
MCQhard

An application needs to retrieve all network clients from a specific Meraki network. The API response may be paginated. Which query parameters can be used to implement cursor-based pagination with the Meraki Dashboard API?

A.offset and limit
B.startingAfter and endingBefore
C.page and perPage
D.nextToken and previousToken
AnswerB

Cursor-based pagination in the Meraki Dashboard API uses the startingAfter and endingBefore parameters, which reference a record's identifier to fetch the next or previous page. This satisfies the stem's requirement for cursor-based paging rather than page-number or offset approaches.

Why this answer

Meraki supports cursor-based pagination using startingAfter and endingBefore parameters.

108
MCQmedium

A developer is building a Python script to create a new network in a Cisco Meraki organization. The developer must authenticate to the Dashboard API. Which HTTP header is used to pass the API key?

A.X-Cisco-Meraki-API-Key
B.Authorization: Bearer <token>
C.Authorization: Basic <base64-encoded-credentials>
D.X-Api-Key
AnswerA

The Meraki Dashboard API requires the API key in a custom HTTP header named X-Cisco-Meraki-API-Key. This header must be included in every request for authentication. The key is generated in the Meraki Dashboard under Organization > Settings. Using this header allows the API to identify the organization and authorize the action, such as creating a network.

Why this answer

The Meraki Dashboard API authenticates requests using an API key passed in the X-Cisco-Meraki-API-Key HTTP header. This is a custom header specific to Meraki, and it must be present in all API calls. Other authentication schemes like Bearer tokens or Basic auth are not used.

Understanding the correct header is essential for successful API integration.

Exam trap

The trap here is assuming that all REST APIs use standard OAuth or Basic authentication headers, overlooking Meraki's custom header requirement.

109
MCQmedium

An administrator is configuring a Cisco Meraki Dashboard API integration. After receiving a 429 HTTP response, what header should be examined to determine when the request can be retried?

A.X-RateLimit-Reset
B.Retry-After
C.X-Cisco-Meraki-API-Key
D.Location
AnswerB

The Retry-After header tells the client how many seconds to wait before retrying, directly addressing rate limiting signalled by HTTP 429. Reading it prevents repeated rejected calls and satisfies the requirement to determine the correct retry timing.

Why this answer

Meraki's rate limit returns a 429 status with a Retry-After header indicating the number of seconds to wait before retrying.

110
MCQmedium

A developer is building a Python application that must authenticate to Cisco Webex APIs on behalf of a service account. The application will run unattended and must not require interactive user login. The developer has already registered an integration in the Webex Developer Portal and obtained the client ID and client secret. Which OAuth 2.0 grant type should the application use?

A.Implicit grant
B.Authorization Code grant
C.Resource Owner Password Credentials grant
D.Client Credentials grant
AnswerD

The Client Credentials grant allows an application to authenticate using only its client ID and client secret, without any user interaction. This is exactly the scenario described: an unattended service account that needs to call Webex APIs programmatically. It is the standard OAuth 2.0 mechanism for machine-to-machine authentication.

Why this answer

For an unattended service account that must call Webex APIs without any user interaction, the Client Credentials grant is the correct OAuth 2.0 flow. It uses the client ID and client secret directly to obtain an access token, eliminating the need for a browser redirect or user credentials. This is the standard approach for machine-to-machine integrations.

Exam trap

The trap here is assuming that any OAuth 2.0 grant type can work for an unattended service, when only the Client Credentials grant avoids interactive user login.

111
MCQeasy

Which YANG model is an OpenConfig model commonly used for interface configuration?

A.openconfig-interfaces
B.Cisco-IOS-XE-interfaces
C.ietf-interfaces
D.openconfig-routing-policy
AnswerA

Correct. OpenConfig's interface model is oc-interfaces (openconfig-interfaces).

Why this answer

OpenConfig models include oc-interfaces for interface configuration.

112
MCQmedium

Which YANG model is an OpenConfig model used for interface configuration?

A.oc-yang-interfaces
B.ietf-interfaces
C.Cisco-IOS-XE-interfaces
D.openconfig-interfaces
AnswerD

The `openconfig-interfaces` module directly satisfies the stem's requirement for an OpenConfig interface configuration model. Unlike IETF or vendor-native YANG modules, OpenConfig models use a vendor-neutral schema, so this module configures interfaces consistently across multi-vendor devices via NETCONF or RESTCONF.

Why this answer

OpenConfig is a vendor-neutral, community-driven data model standard for network configuration and state. The 'openconfig-interfaces' YANG model is the OpenConfig model specifically designed for interface configuration, providing a consistent, model-driven approach across different network operating systems. Option D is correct because it directly names the OpenConfig model for interfaces.

Exam trap

Cisco often tests the distinction between vendor-neutral OpenConfig models, IETF standard models, and Cisco proprietary native models, expecting candidates to recognize that 'openconfig-interfaces' is the correct OpenConfig model name, not a generic or IETF-prefixed alternative.

How to eliminate wrong answers

Option A is wrong because 'oc-yang-interfaces' is not a recognized YANG model name; OpenConfig models use the prefix 'openconfig-', not 'oc-yang-'. Option B is wrong because 'ietf-interfaces' is the IETF standard YANG model for interface management (RFC 7223), not an OpenConfig model. Option C is wrong because 'Cisco-IOS-XE-interfaces' is a Cisco proprietary native YANG model specific to IOS XE platforms, not an OpenConfig model.

113
MCQmedium

An administrator needs to retrieve the hostname of an IOS XE device using RESTCONF. Which URL and data path should they use?

A.GET /restconf/data/Cisco-IOS-XE-native:native/hostname
B.GET /api/v1/device/hostname
C.POST /restconf/data/Cisco-IOS-XE-native:native/hostname
D.GET /restconf/data/ietf-interfaces:interfaces
AnswerA

RESTCONF exposes IOS XE configuration through the Cisco-IOS-XE-native YANG model, so the hostname leaf sits under the native container. The GET request targets that data path, satisfying the requirement to retrieve the device hostname via RESTCONF.

Why this answer

RESTCONF on IOS XE uses the native YANG model; the hostname is under /Cisco-IOS-XE-native:native/hostname.

114
MCQeasy

Which tool is used to explore and validate YANG models?

A.Postman
B.cURL
C.YANGman
D.pyang
AnswerD

pyang parses YANG modules, validates their syntax and semantics against RFC rules, and can render tree diagrams, making it the standard tool for exploring and validating YANG models. It directly satisfies the requirement to check model correctness.

Why this answer

pyang is a Python-based tool for validating and converting YANG models.

115
MCQhard

A network engineer is using Cisco IOS XE RESTCONF to retrieve the hostname of a device. The device has already enabled netconf-yang and restconf. Which URL path should be used?

A./restconf/data/hostname
B./restconf/data/Cisco-IOS-XE-native:native/hostname
C./restconf/operations/hostname
D./restconf/config/Cisco-IOS-XE-native:native/hostname
AnswerB

The YANG module Cisco-IOS-XE-native models native IOS XE configuration, and its hostname leaf sits under the native container. RESTCONF addresses data nodes as /restconf/data/{module}:{container}/{leaf}, so this path retrieves the hostname directly, satisfying the requirement to read that value over RESTCONF.

Why this answer

The correct URL path for retrieving configuration data via RESTCONF is /restconf/data/{module-name}:{container-path}. In Cisco IOS XE, the hostname is modeled under the Cisco-IOS-XE-native module within the 'native' container, so the full path is /restconf/data/Cisco-IOS-XE-native:native/hostname. This follows RFC 8040, which defines the 'data' resource for accessing configuration and state data, and requires the module name prefix when the node is not in the default namespace.

Exam trap

The trap here is confusing RESTCONF resource types (data vs. config vs. operations) and forgetting the mandatory YANG module prefix and container hierarchy, which leads candidates to choose simplified but invalid paths like /restconf/data/hostname.

How to eliminate wrong answers

Option A is wrong because it omits the required YANG module name and container hierarchy; /restconf/data/hostname does not correspond to any valid data node in the Cisco IOS XE YANG model. Option C is wrong because /restconf/operations is used to invoke RPCs (e.g., custom actions), not to read configuration data like hostname. Option D is wrong because /restconf/config is not a valid RESTCONF resource type; the correct resource for configuration data is /restconf/data, and using /restconf/config would result in a 404 or 400 error.

116
MCQmedium

When using the NX-API on Cisco NX-OS, which HTTP method is used to send CLI commands in JSON format?

A.POST
B.PUT
C.GET
D.PATCH
AnswerA

NX-API accepts CLI commands wrapped in JSON via HTTP POST, since the command payload is submitted in the request body. GET cannot carry a body reliably, so POST is the method used to send show or configuration commands to the NX-OS device.

Why this answer

NX-API uses POST requests to the /ins endpoint with a JSON body containing the CLI commands and the type (cli_show or cli_conf).

117
MCQmedium

Which NX-OS API method allows sending CLI commands in JSON format without enabling any additional features?

A.NX-API method 'cli' with JSON encoding
B.RESTCONF with YANG data
C.SNMP with MIB objects
D.NETCONF with XML data
AnswerA

NX-API's 'cli' method accepts JSON-encoded requests over HTTP/HTTPS, converting them into CLI commands executed on the device. Crucially, it requires no extra feature enablement beyond the NX-API infrastructure itself, satisfying the stem's constraint of sending CLI commands in JSON format without enabling additional features.

Why this answer

The NX-API 'cli' method with JSON encoding allows an administrator to send standard NX-OS CLI commands wrapped in a JSON payload over HTTP/HTTPS to the NX-API endpoint, and it works without enabling additional model-driven features like RESTCONF or NETCONF. It is the simplest NX-API method because it reuses existing CLI syntax rather than requiring YANG models. This is why it is the correct answer for sending CLI commands in JSON without extra feature enablement.

Exam trap

The trap is assuming any JSON-based API (RESTCONF) is the answer — candidates overlook that NX-API 'cli' method is the one that accepts raw CLI commands in JSON without enabling model-driven features.

How to eliminate wrong answers

Option B is wrong because RESTCONF with YANG data requires enabling the RESTCONF feature and uses YANG-modeled resources, not raw CLI commands in JSON. Option C is wrong because SNMP with MIB objects is a monitoring/protocol mechanism using OIDs, not a JSON CLI transport. Option D is wrong because NETCONF with XML data requires enabling NETCONF and uses XML-encoded RPCs against YANG models, not JSON CLI commands.

118
Multi-Selecthard

A network automation engineer is evaluating options for model-driven programmability on Cisco devices. Which THREE are valid YANG model sources or tools? (Choose three.)

Select 3 answers
A.pyang
B.NETCONF
C.Cisco native YANG models
D.yangcatalog.org
E.oc-interfaces
AnswersA, C, D

pyang is a YANG data modeling tool.

Why this answer

pyang is a YANG tool, yangcatalog.org is a repository, and Cisco native models are valid sources. OpenConfig is a standard, but oc-interfaces is a model, not a source/tool.

119
MCQmedium

A developer wants to create a Webex webhook that triggers when a new message is posted in any room the bot is in. Which resource event should they subscribe to?

A.resource: 'messages', event: 'updated'
B.resource: 'rooms', event: 'created'
C.resource: 'messages', event: 'created'
D.resource: 'memberships', event: 'created'
AnswerC

Webex webhooks subscribe to a resource and event pair. 'messages' with 'created' fires when a new message is posted, matching the stem's requirement. Subscribing to 'rooms' or 'updated' events would not trigger on new messages in rooms the bot belongs to.

Why this answer

To trigger on new messages, subscribe to 'messages' resource with 'created' event.

120
MCQmedium

Which EEM applet action is used to execute a CLI command when an event triggers?

A.action 1.0 event "..."
B.action 1.0 set 1.0 "..."
C.action 1.0 cli command "..."
D.action 1.0 syslog msg "..."
AnswerC

The `action 1.0 cli command` statement runs an EXEC-mode CLI command when the applet's event fires, satisfying the requirement to execute a command on trigger. The `cli` keyword specifies the action type, while `command` supplies the exact string to run, distinguishing it from other actions such as `syslog` or `reload`.

Why this answer

EEM uses 'action' with a sequence number and 'cli' keyword to execute commands.

121
MCQmedium

A developer is creating a Python script that uses the Cisco Webex Teams REST API. The script needs to read the WEBCEX_ACCESS_TOKEN environment variable and include it as a Bearer token in the HTTP Authorization header for every request. Which code snippet correctly accomplishes this?

A.headers = {'Authorization': os.environ['WEBEX_ACCESS_TOKEN']}
B.headers = {'Authorization': 'Basic ' + os.environ['WEBEX_ACCESS_TOKEN']}
C.headers = {'Authorization': 'Bearer ' + os.environ['WEBEX_ACCESS_TOKEN']}
D.headers = {'Authorization': 'Token ' + os.getenv('WEBEX_ACCESS_TOKEN')}
AnswerC

This snippet retrieves the token from the environment variable and constructs the correct 'Bearer <token>' string for the Authorization header. The Webex Teams API requires this exact header format for authentication. Using os.environ ensures the token is not hard-coded, which is a security best practice. The concatenation is valid because os.environ returns a string.

Why this answer

The Webex Teams API uses OAuth 2.0 bearer tokens, so the Authorization header must be in the format 'Bearer <token>'. The code must read the token from the environment variable and concatenate it with the 'Bearer ' prefix. Using os.environ or os.getenv is appropriate, but the scheme must be 'Bearer'.

The other options either use the wrong scheme or omit the prefix, leading to authentication failures.

Exam trap

The trap here is assuming that any Authorization header with the token will work, forgetting that the 'Bearer' prefix is mandatory for OAuth 2.0 bearer tokens.

122
MCQhard

A developer needs to send a message to a specific room in Webex using the API. What is the correct endpoint and required body parameter for the room destination?

A.POST /v1/messages with roomId parameter
B.POST /v1/messages with toPersonEmail parameter
C.POST /v1/memberships with roomId
D.POST /v1/rooms with message text
AnswerA

POST /v1/messages accepts a roomId body parameter, which targets a specific Webex room directly rather than resolving a recipient email or person ID. This satisfies the stem's requirement to address a room destination, since roomId uniquely identifies that space within the Webex messaging API.

Why this answer

To send a message to a Webex room, use POST /v1/messages with the roomId parameter to specify the target room.

123
MCQhard

An EEM applet is triggered when a specific syslog message pattern appears. Which action should be used to send a custom syslog message?

A.action 1.0 cli command "show logging"
B.action 1.0 syslog msg "Custom event occurred"
C.action 1.0 info type routername
D.action 1.0 set 1.0 _syslog_msg "Custom event"
AnswerB

The syslog action within an EEM applet emits a custom message to the logging facility. Specifying action 1.0 syslog msg with the text string generates the custom syslog output when the applet's pattern match triggers.

Why this answer

In an EEM applet, to send a custom syslog message, the correct action is 'action 1.0 syslog msg "Custom event occurred"'. This action explicitly generates a syslog message with the specified text. It is the standard way to emit a custom syslog from EEM.

Exam trap

The trap is that candidates might confuse CLI command actions with syslog actions, or use incorrect syntax like 'set _syslog_msg'; the exam tests knowledge of EEM action keywords.

How to eliminate wrong answers

Option A is wrong because 'action 1.0 cli command "show logging"' executes a CLI command, which would display logging but not send a custom syslog message. Option C is wrong because 'action 1.0 info type routername' sets an information variable, not a syslog action. Option D is wrong because 'action 1.0 set 1.0 _syslog_msg "Custom event"' is not valid EEM syntax; the correct action is 'syslog msg'.

124
MCQmedium

A network automation engineer needs to retrieve the Layer 2 topology for a specific VLAN from Cisco DNA Center. Which API endpoint should be used?

A.GET /dna/intent/api/v1/issues
B.GET /dna/intent/api/v1/site
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/topology/l2/{vlanID}
AnswerD

The DNA Center topology API exposes layer 2 topology per VLAN through the intent path with the vlanID path parameter, returning nodes and links for that broadcast domain. This satisfies the stem's requirement to retrieve Layer 2 topology scoped to a specific VLAN.

Why this answer

The endpoint GET /dna/intent/api/v1/topology/l2/{vlanID} is used to retrieve Layer 2 topology for a VLAN.

125
Multi-Selectmedium

A developer is building an application that interacts with the Webex API to create rooms and send messages. The application needs to receive real-time notifications when a new message is posted in any room. Which TWO actions should the developer take? (Choose two.)

Select 2 answers
A.Poll the GET /v1/messages endpoint every second
B.Provide a target URL where the webhook sends the notification
C.Use the 'roomId' parameter to filter messages
D.Register a webhook for the 'message.created' event
E.Send a POST request to /v1/webhooks with 'resource: messages' and 'event: seen'
AnswersB, D

A webhook requires a reachable HTTPS target URL, because Webex POSTs each event payload to that endpoint rather than the app polling. Supplying it satisfies the real-time notification requirement, since without a registered target the subscription cannot deliver anything.

Why this answer

Option B is correct because Webex webhooks require the developer to supply a targetUrl — an HTTPS endpoint on their own publicly reachable service — where Webex will POST the notification payload when the subscribed event fires. Option D is correct because real-time notification of a new message is delivered by registering a webhook whose event is 'created' and whose resource is 'messages' (i.e., message.created), which is exactly the trigger Webex uses for newly posted messages. Option A is wrong because polling GET /v1/messages every second is inefficient, rate-limit prone, and not a real-time push mechanism.

Option C is wrong because roomId is a filter/query parameter for listing messages, not a mechanism for receiving notifications. Option E is wrong because 'seen' is not a valid message event for this purpose and the payload described does not register a message-created subscription.

Exam trap

200-901 often tests the difference between polling and webhooks; candidates may choose polling for simplicity, but the question asks for real-time notifications, which requires webhooks.

126
MCQeasy

A developer is creating a Python script to interact with a Cisco NX-OS device using the NX-API. The script will send HTTP requests to the device's management IP. Which command must be configured on the NX-OS device to enable the NX-API feature?

A.ip http server
B.nxapi enable
C.feature http-server
D.feature nxapi
AnswerD

The command 'feature nxapi' enables the NX-API feature on Cisco NX-OS devices. Without this command, the device does not listen for HTTP/HTTPS API requests. This is the correct and required configuration step to allow programmatic access via the NX-API.

Why this answer

On Cisco NX-OS, the NX-API is enabled by entering the global configuration command 'feature nxapi'. This activates the API and allows the device to accept HTTP/HTTPS requests on the management interface. Other commands like 'ip http server' do not provide the NX-API functionality, so they cannot be used as substitutes.

Exam trap

The trap here is assuming that enabling the generic HTTP server is sufficient for NX-API, when a specific feature command is required.

← PreviousPage 2 of 2 · 126 questions total

Ready to test yourself?

Try a timed practice session using only Cisco Platforms and Development questions.