Courseiva

CCNA Infrastructure and Automation Questions

57 of 132 questions · Page 2/2 · Infrastructure and Automation · Answers revealed

76
MCQhard

An engineer is troubleshooting a NETCONF session that fails to establish with a Cisco IOS XE device. The SSH connection succeeds, but NETCONF capabilities are not exchanged. What is the most likely cause?

A.The device requires authentication via SSH keys but password was used.
B.The firewall is blocking port 830.
C.The device is running an older IOS version that does not support NETCONF.
D.The device's NETCONF server is not enabled.
AnswerD

SSH transport succeeding but no NETCONF capabilities appearing means the NETCONF subsystem is disabled on the device. Enabling it with the netconf-yang command starts the server, allowing the hello exchange and capability negotiation to complete.

Why this answer

NETCONF uses a client-server model where the server (the Cisco IOS XE device) must have the NETCONF server explicitly enabled. If the SSH transport succeeds but capabilities are not exchanged, it indicates the NETCONF subsystem is not active on the device. The `netconf-yang` feature must be enabled via `netconf-yang` in global configuration mode to start the NETCONF server and allow capability exchange.

Exam trap

Cisco often tests the distinction between SSH transport success and NETCONF protocol success, trapping candidates who assume a successful SSH connection implies NETCONF is fully operational.

How to eliminate wrong answers

Option A is wrong because the SSH connection succeeded, meaning authentication was accepted regardless of method (password or SSH keys); NETCONF capability exchange occurs after SSH transport is established, so authentication is not the issue. Option B is wrong because the SSH connection succeeded, which typically uses port 830 for NETCONF-over-SSH; if a firewall were blocking port 830, the SSH connection itself would fail, not just the capability exchange. Option C is wrong because even older IOS XE versions (e.g., 16.x) support NETCONF; the issue is not version compatibility but whether the NETCONF server is administratively enabled.

77
MCQhard

A developer is using the Cisco DNA Center Intent API to retrieve a list of network devices. The API requires a token obtained from the authentication endpoint. The developer's script successfully authenticates and receives a token, but subsequent GET requests to /dna/intent/api/v1/network-device return a 401 Unauthorized error. What is the most likely cause?

A.The developer must include a Basic authentication header with username and password.
B.The API endpoint requires a POST request instead of GET.
C.The token has expired and must be refreshed.
D.The token is not being sent in the X-Auth-Token header.
AnswerD

Cisco DNA Center requires the authentication token to be included in the X-Auth-Token header for all subsequent API calls. If the token is omitted or placed in a different header, the API returns 401 Unauthorized. The developer must add the header with the token value received from the authentication endpoint.

Why this answer

After authenticating to Cisco DNA Center, the returned token must be included in the X-Auth-Token header on all subsequent API requests. A missing or incorrectly named header causes a 401 Unauthorized response. The other options are less likely: token expiration would not occur immediately, the endpoint accepts GET, and Basic authentication is not used once a token is obtained.

Exam trap

The trap here is assuming that a 401 always means the token is expired or that credentials are wrong, when in fact the token may simply not be transmitted in the required header.

78
MCQmedium

An engineer is writing a Python script using the Cisco DevNet sandbox to configure OSPF on a CSR1000v via RESTCONF. What authentication method is typically used for RESTCONF requests?

A.No authentication
B.OAuth2
C.API token only
D.Basic authentication over HTTPS
AnswerD

RESTCONF requests to the CSR1000v sandbox carry an HTTP Basic authentication header containing base64-encoded username and password, transported inside the TLS tunnel that HTTPS provides. No OAuth token exchange or certificate-based mutual authentication is required.

Why this answer

RESTCONF typically uses Basic authentication over HTTPS (RFC 7235) because it is a lightweight, stateless mechanism that sends a base64-encoded username:password pair in the Authorization header. In the Cisco DevNet sandbox CSR1000v environment, this is the standard method for authenticating RESTCONF requests, as the sandbox provides a username and password for access.

Exam trap

Cisco often tests the distinction between RESTCONF and NETCONF authentication, where candidates might mistakenly think RESTCONF uses SSH keys or no authentication, but RESTCONF always requires HTTPS-based authentication, typically Basic.

How to eliminate wrong answers

Option A is wrong because RESTCONF requires authentication; no authentication would leave the device open to unauthorized configuration changes. Option B is wrong because OAuth2 is not typically used for RESTCONF on Cisco IOS-XE devices; it is more common in cloud-based APIs like Webex or Meraki. Option C is wrong because API token only is not a standard RESTCONF authentication method; while some Cisco platforms (e.g., DNA Center) use tokens, the CSR1000v sandbox relies on Basic authentication over HTTPS.

79
MCQhard

A Cisco DevNet engineer is configuring model-driven telemetry on a Cisco IOS-XE device. The telemetry subscription includes the following path: 'Cisco-IOS-XE-native:native/interface/GigabitEthernet[Name='1/0/1']/ip/address'. Which part of this path identifies a specific list instance?

A.Cisco-IOS-XE-native
B.[Name='1/0/1']
C.GigabitEthernet
D.ip/address
AnswerB

The bracketed predicate `[Name='1/0/1']` selects a single list entry by matching the key leaf `Name`, satisfying the stem's requirement to identify one specific list instance. In YANG, list nodes are keyed, and this XPath-style predicate filters the `GigabitEthernet` list down to the entry whose key equals `1/0/1`.

Why this answer

The XPath expression `[Name='1/0/1']` is a predicate filter that selects a specific list instance from the `GigabitEthernet` YANG list. In YANG model-driven telemetry, list keys are used to identify individual entries, and the predicate syntax `[key='value']` pinpoints exactly one instance within the list.

Exam trap

Cisco often tests whether candidates confuse the YANG module name or the list node name with the list instance identifier, leading them to pick the module or the list name instead of the key predicate.

How to eliminate wrong answers

Option A is wrong because `Cisco-IOS-XE-native` is the YANG module name, not a list instance identifier. Option C is wrong because `GigabitEthernet` is the YANG list node name, which represents the entire list of interfaces, not a specific instance. Option D is wrong because `ip/address` is a leaf path within the interface instance, not a list instance identifier.

80
Multi-Selectmedium

Which THREE are common best practices for implementing CI/CD in network automation?

Select 3 answers
A.Perform manual testing after every deployment
B.Use version control for all automation scripts and playbooks
C.Treat infrastructure configurations as code
D.Implement automated unit and integration tests
E.Store credentials and secrets in code repositories
AnswersB, C, D

Version control is essential for tracking changes and collaboration.

Why this answer

Version control (e.g., Git) is a fundamental CI/CD best practice: it tracks changes, enables rollbacks, and supports collaboration on automation scripts and playbooks. Without version control, you lose auditability and the ability to reliably reproduce network states, which violates the principle of infrastructure as code.

Exam trap

Cisco often tests the distinction between 'automation' and 'CI/CD best practices'—candidates may confuse manual testing (Option A) as a safety net, but the exam expects you to recognize that CI/CD relies on automated testing, not manual steps.

81
MCQhard

An automation engineer is using the Cisco SD-WAN (Viptela) API to retrieve a list of devices in the overlay. The engineer must authenticate and obtain a token before making subsequent API calls. Which authentication mechanism does the Cisco SD-WAN API use to issue a session token?

A.HTTP Basic authentication to /j_security_check with username and password, returning a JSESSIONID cookie
B.API key passed in the X-Auth-Token header for every request
C.OAuth 2.0 client credentials flow to /oauth/token with client ID and secret
D.SAML assertion posted to /saml/SSO with an identity provider
AnswerA

The Cisco SD-WAN (Viptela) API uses a session-based authentication model. The client posts credentials to /j_security_check, and the server responds with a JSESSIONID cookie that must be included in subsequent requests. This token-based session mechanism is the standard way to authenticate to the SD-WAN Manager (vManage) API.

Why this answer

The Cisco SD-WAN Manager (vManage) API authenticates clients by accepting a username and password at /j_security_check and returning a JSESSIONID cookie. That cookie must be included in the headers of subsequent API calls. This session-based approach is specific to SD-WAN and differs from token or key-based authentication used by other Cisco platforms.

Exam trap

The trap here is assuming all Cisco automation APIs use the same authentication, such as DNA Center's X-Auth-Token or Meraki's API key header.

82
MCQmedium

A developer is writing a Python script that calls the Cisco DNA Center Intent API. The API returns HTTP 429 responses during peak hours. The developer wants the script to retry failed requests automatically using exponential backoff. Which approach should be used?

A.Increase the requests timeout parameter to 300 seconds so the API has more time to respond before returning a 429.
B.Wrap the request in a while loop that sleeps for a fixed 60 seconds after every 429 response until the request succeeds.
C.Switch the script to use the ncclient library because it handles HTTP 429 responses natively for REST APIs.
D.Use the requests library with a Retry object configured with backoff_factor and status_forcelist mounted on an HTTPAdapter.
AnswerD

The requests library supports automatic retries through urllib3's Retry class. By setting backoff_factor and including 429 in status_forcelist, then mounting the adapter to the session, the script will retry with exponential backoff on rate-limit responses without custom retry loops.

Why this answer

HTTP 429 indicates the client exceeded the API rate limit. The requests library integrates urllib3's Retry mechanism, which can be configured with backoff_factor and status_forcelist to automatically retry on 429 with exponential delays. Mounting the adapter on a session applies this behavior to all requests, providing a clean, standard solution.

Exam trap

The trap here is assuming that increasing the timeout or adding a fixed sleep loop solves rate limiting, when the real solution is configuring retry behavior with exponential backoff.

83
MCQmedium

A developer must write a script that retrieves the running configuration from a Cisco IOS XE device using NETCONF. The script establishes an SSH session and begins the NETCONF capability exchange. Which XML element must the client send to request the device's running configuration using the standard NETCONF data model?

A.<get-config> with a <source> of <running/>
B.<edit-config> with a <target> of <candidate/>
C.<copy-config> with a <target> of <startup/>
D.<get> with a <filter> of type subtree
AnswerA

The NETCONF <get-config> operation retrieves configuration data from a specified datastore. Setting <source> to <running/> requests the active running configuration. This is the standards-based approach defined in RFC 6241 and works against IOS XE devices that advertise the :base:1.0 capability during the hello exchange.

Why this answer

NETCONF defines <get-config> specifically for reading configuration from a named datastore, and <running/> identifies the active configuration. The broader <get> returns state data too, while <edit-config> and <copy-config> modify data. Therefore <get-config> with a running source is the correct, standards-based request for retrieving the running configuration.

Exam trap

The trap here is reaching for the simpler <get> operation, which returns operational state as well and is not scoped to configuration data.

84
MCQeasy

A developer uses the Cisco DNA Center API to retrieve device inventory. The JSON response is shown. Which Python code snippet correctly extracts the serial number?

A.data['response'][0]['serialNumber']
B.data['serialNumber']
C.data['response']['serialNumber']
D.data[0]['serialNumber']
AnswerA

The DNA Center inventory response nests device records in a 'response' array, so indexing [0] selects the first device and ['serialNumber'] retrieves its serial value. This matches the JSON structure shown, unlike snippets that omit the array index or use incorrect key names.

Why this answer

The JSON response from the Cisco DNA Center device inventory API returns a list of devices under the 'response' key, and each device is a dictionary. The serial number for the first device is accessed by indexing into the list with [0] and then retrieving the 'serialNumber' key from that dictionary.

Exam trap

The trap here is that candidates mistakenly treat the JSON response as a flat dictionary or forget that the 'response' value is a list, leading them to omit the list index and incorrectly access 'serialNumber' directly from 'response'.

How to eliminate wrong answers

Option B is wrong because it assumes 'serialNumber' is a top-level key in the JSON response, but the actual structure nests it inside 'response' and then inside a list. Option C is wrong because it omits the list index, treating 'response' as a direct dictionary containing 'serialNumber', but 'response' is actually a list of device dictionaries. Option D is wrong because it attempts to index the top-level JSON object with [0], but the top-level is a dictionary, not a list, so this would raise a KeyError or TypeError.

85
MCQmedium

A large enterprise uses Cisco DNA Center to manage their campus network. They have deployed fabric technology for SD-Access. The network team wants to use the DNA Center REST API to automate the addition of new wireless users to a specific virtual network (VN) based on their location (building). They have identified the API endpoint for creating a user device in the fabric. However, when they send a POST request with the appropriate JSON body, they receive a 400 Bad Request error. The JSON payload includes the mandatory fields for hostname, MAC address, and VN name. What is the most likely cause of the error?

A.The API call requires an authentication token that is missing or expired.
B.The virtual network name provided does not exist in the fabric.
C.The MAC address format is incorrect (e.g., lowercase vs uppercase).
D.The user making the API call does not have sufficient privileges.
AnswerB

The fabric API validates the virtual network name against existing VNs in the SD-Access fabric. A 400 Bad Request with otherwise valid mandatory fields indicates the supplied VN name does not match any configured virtual network, so the payload fails validation before device creation.

Why this answer

The 400 Bad Request error indicates that the server cannot process the request due to a client-side issue, such as invalid data in the payload. Since the mandatory fields (hostname, MAC address, VN name) are provided, the most likely cause is that the virtual network (VN) name does not match any existing VN in the fabric. DNA Center validates the VN name against its fabric configuration; if the VN is not defined, the API rejects the request with a 400 error.

Exam trap

Cisco often tests the distinction between HTTP status codes (400 vs 401 vs 403) to see if candidates understand that 400 errors are client-side payload issues, not authentication or authorization problems.

How to eliminate wrong answers

Option A is wrong because a missing or expired authentication token would result in a 401 Unauthorized error, not a 400 Bad Request. Option C is wrong because DNA Center accepts MAC addresses in various formats (e.g., lowercase, uppercase, with or without colons) and normalizes them internally; an incorrect format would not cause a 400 error. Option D is wrong because insufficient privileges would result in a 403 Forbidden error, not a 400 Bad Request.

86
MCQmedium

A developer writes a script that calls a Cisco DNA Center intent API to create a new site. The first call returns HTTP 401 Unauthorized. The script already retrieved a token earlier in the same run. Which action should the script take next?

A.Change the HTTP method from POST to GET and resubmit the site creation payload.
B.Re-authenticate to obtain a fresh token and resend the request with the new token in the header.
C.Assume the site already exists and stop the script without further action.
D.Retry the identical request in a tight loop until it succeeds.
AnswerB

A 401 indicates the token was rejected, most commonly because it expired between retrieval and use. Re-authenticating against the DNA Center authentication endpoint yields a new token, and resending the original request with that token in the X-Auth-Token header is the correct recovery. This addresses the actual cause rather than masking it.

Why this answer

HTTP 401 means the authentication credential was not accepted, and the most common cause in DNA Center automation is a token that expired between acquisition and use. Re-authenticating to get a fresh token and resending the request with the updated X-Auth-Token header resolves the failure at its source and completes the site creation.

Exam trap

The trap here is reading 401 as a permissions or method problem and changing the request shape, when it actually points to an invalid or expired token that must be refreshed.

87
MCQhard

An engineer uses Ansible to push a configuration change to 100 switches. The playbook fails on 5 switches. What is the most efficient way to apply the change only to those 5?

A.Use Ansible's --limit with the retry file
B.Use --skip-tags on successful hosts
C.Re-run the playbook on all switches
D.Manually configure the 5 switches
AnswerA

Ansible writes failed hosts to a retry file, and --limit accepts that file to target only those hosts. This satisfies the requirement to reapply the change to the five failed switches without rerunning the playbook against all 100.

Why this answer

Ansible generates a retry file by default when a playbook fails on some hosts. Using `--limit @<retry-file>` re-runs the playbook only against the failed hosts, avoiding unnecessary execution on the 95 successful switches. This is the most efficient method because it targets only the problematic devices without manual intervention or full re-runs.

Exam trap

Cisco often tests the distinction between host-level filtering (`--limit`) and task-level filtering (`--tags`/`--skip-tags`), leading candidates to confuse `--skip-tags` as a way to skip hosts instead of tasks.

How to eliminate wrong answers

Option B is wrong because `--skip-tags` is used to skip tasks with specific tags, not to filter hosts; it would still run on all hosts. Option C is wrong because re-running the playbook on all 100 switches wastes time and resources on the 95 already-configured switches, which is inefficient. Option D is wrong because manually configuring 5 switches defeats the purpose of automation and is error-prone and time-consuming.

88
MCQeasy

Which tool is designed for infrastructure as code, uses a declarative language, and can automate configuration management across multiple devices?

A.Ansible
B.Git
C.Python
D.Postman
AnswerA

Ansible uses YAML playbooks to declare desired end state, then pushes configuration over SSH without installing agents on managed nodes. This satisfies the stem's three constraints simultaneously: infrastructure as code, declarative language, and multi-device automation, unlike imperative scripting tools that require sequential command specification.

Why this answer

Ansible is the correct answer because it is an infrastructure-as-code tool that uses a declarative YAML-based language (playbooks) to define desired system states. It automates configuration management across multiple devices agentlessly, using SSH or WinRM to push configurations, making it ideal for multi-device environments.

Exam trap

The trap here is that candidates may confuse Git (a version control tool) with infrastructure-as-code because Git is often used to store IaC files, but it does not perform automation or configuration management itself.

How to eliminate wrong answers

Option B (Git) is wrong because Git is a distributed version control system for tracking source code changes, not an infrastructure-as-code tool for automating configuration management. Option C (Python) is wrong because Python is a general-purpose programming language that requires imperative scripting to manage configurations, lacking the declarative language model and built-in multi-device automation of Ansible. Option D (Postman) is wrong because Postman is an API testing and development tool, not designed for infrastructure-as-code or configuration management across devices.

89
MCQmedium

An engineer needs to automate the deployment of VLAN configurations on a fleet of Cisco Catalyst 9000 switches running IOS-XE. The team uses Ansible Tower for automation. Which Ansible module should be used to push VLAN configuration idempotently?

A.ios_vlan
B.ios_command
C.ios_config
D.ios_interface
AnswerA

The ios_vlan module manages VLANs on Cisco IOS and IOS-XE devices through the network_cli connection, pushing configuration idempotently by comparing desired VLAN definitions against the device's running state. It satisfies the Catalyst 9000 IOS-XE constraint directly, unlike generic modules or those targeting other network operating systems.

Why this answer

The ios_vlan module is purpose-built for idempotent VLAN management on Cisco IOS-XE devices. It ensures that a VLAN with the specified VLAN ID, name, and state (active/suspend) is present or absent without affecting other VLANs, making it the correct choice for automating VLAN deployment idempotently.

Exam trap

Cisco often tests the distinction between generic configuration modules (ios_config) and resource-specific modules (ios_vlan), trapping candidates who assume any module that can push VLAN commands is sufficient for idempotent VLAN management.

How to eliminate wrong answers

Option B (ios_command) is wrong because it sends raw CLI commands and does not enforce idempotency; it blindly executes commands without checking current state, which can cause errors or duplicate configurations. Option C (ios_config) is wrong because it manages arbitrary configuration lines as a whole, not VLAN-specific resources; it can be used to push VLAN commands but lacks the idempotent, declarative VLAN handling that ios_vlan provides (e.g., it does not parse existing VLAN state to avoid re-adding). Option D (ios_interface) is wrong because it manages interface properties (e.g., switchport mode, access VLAN) but does not create, delete, or modify VLAN definitions themselves.

90
MCQhard

A DevOps team uses a CI/CD pipeline to deploy network configurations. They want to ensure that only authorized network engineers can trigger changes to production devices. Which integration is most appropriate?

A.Encrypt the Ansible vault password
B.Implement Role-Based Access Control (RBAC) on the CI/CD tool
C.Use a separate staging environment
D.Use a pre-commit hook in Git to validate YAML syntax
AnswerB

RBAC on the CI/CD tool restricts pipeline trigger permissions to authorised network engineers, directly enforcing the stated constraint that only those users may initiate production changes. It governs who can execute the deployment rather than how configurations are validated or approved.

Why this answer

Role-Based Access Control (RBAC) on the CI/CD tool directly restricts which users or groups can trigger pipeline jobs that modify production network devices. This ensures that only authorized network engineers have the permissions to execute changes, aligning with the principle of least privilege in deployment pipelines.

Exam trap

The trap here is that candidates confuse technical controls (like encryption or syntax validation) with authorization controls, assuming that protecting secrets or validating code is equivalent to restricting who can trigger a deployment.

How to eliminate wrong answers

Option A is wrong because encrypting the Ansible vault password protects secrets (e.g., credentials) but does not control who can trigger the pipeline or authorize changes to production devices. Option C is wrong because a separate staging environment validates configurations before production but does not enforce authorization on who can trigger the production deployment. Option D is wrong because a pre-commit hook in Git validates YAML syntax locally, which prevents malformed files but does not provide any access control over who can initiate the CI/CD pipeline or deploy to production.

91
MCQhard

A platform team stores network device configuration templates in a Git repository and wants every proposed change to be reviewed and validated before it reaches production devices. The team also needs an audit trail of who approved each change. Which Git-based workflow best meets these requirements?

A.Developers each maintain a personal fork and deploy from their fork to production after local testing, merging upstream only monthly.
B.Developers commit to short-lived feature branches, open pull requests, require peer approval and CI validation, then merge to main for deployment.
C.Developers commit directly to main but tag each commit with a version number, and deployments always reference the latest tag.
D.Developers push directly to the main branch, and a post-receive hook deploys the templates to devices immediately.
AnswerB

Feature branches isolate work, pull requests create a review gate, required approvals and CI checks validate changes before merge, and the merge history plus review records form an audit trail. This workflow uses Git's native collaboration model to enforce review and traceability before templates reach production.

Why this answer

Git-based change control with review and auditability is achieved through short-lived feature branches, pull requests with required approvals, automated CI validation, and merges to a protected main branch that triggers deployment. Direct pushes, personal-fork deployments, and tagging alone all skip the review gate and produce no approval record, so they cannot satisfy the validation and audit-trail requirements.

Exam trap

The trap here is equating version control with change control, when review gates and approval records come from the pull-request workflow rather than from Git storage alone.

92
MCQmedium

A developer is writing a Python script that authenticates to the Cisco DNA Center REST API. The script must include an authentication token in the HTTP headers of every subsequent API call. Which HTTP header should the developer populate with the token returned by the authentication endpoint?

A.X-Auth-Token
B.Authorization: Bearer
C.Cookie: sessionToken
D.X-Cisco-Token
AnswerA

Cisco DNA Center returns a token from the /dna/system/api/v1/auth/token endpoint that must be sent in the X-Auth-Token header on all subsequent requests. This is the vendor-specific header name DNA Center enforces for token-based authentication, so the script will receive 401 Unauthorized responses if it places the token anywhere else.

Why this answer

DNA Center issues a time-limited token from its authentication endpoint, and every subsequent REST call must present that token in the X-Auth-Token request header. Standard OAuth schemes, invented vendor headers, and cookie-based sessions are not honored by the controller, so only the documented X-Auth-Token header will authenticate the script successfully.

Exam trap

The trap here is assuming that a token is always sent with the standard Authorization: Bearer header, when DNA Center specifically requires X-Auth-Token.

93
MCQmedium

A developer is building an automation workflow that must react when an interface on a Cisco IOS XE device goes down. The workflow should subscribe to the device and receive structured event data as changes happen, rather than polling for state. Which technology should the developer use?

A.SNMP polling with the IF-MIB ifOperStatus object on a fixed interval
B.SSH into the device and run show interfaces on a scheduled cron job
C.NETCONF event notifications over an SSH session
D.RESTCONF GET requests against the ietf-interfaces YANG model
AnswerC

NETCONF's notification capability lets a client create a subscription to streams such as NETCONF or syslog, and the device pushes XML-encoded event data as changes occur. That matches the requirement to receive structured, event-driven updates instead of repeatedly polling the device for interface state.

Why this answer

Event-driven reaction requires a push mechanism. NETCONF event notifications let a client subscribe to a stream and receive XML events from the device as state changes occur, eliminating polling latency and unstructured parsing. SNMP polling, RESTCONF GETs, and scheduled CLI commands are all pull-based and return either delayed or unstructured data, so none deliver the required asynchronous, structured event stream.

Exam trap

The trap here is treating any programmatic interface as equivalent, when only a subscription-based push mechanism satisfies an event-driven requirement.

94
Multi-Selecthard

Which TWO of the following are true about NETCONF capabilities as defined in RFC 6241?

Select 2 answers
A.The <edit-config> operation supports 'merge', 'replace', 'create', 'delete', and 'remove' operations.
B.The <edit-config> operation replaces the entire configuration by default.
C.The <candidate> configuration datastore is optional and requires the :candidate capability.
D.The :rollback-on-error capability is mandatory.
E.The <running> configuration datastore is optional.
AnswersA, C

Correct – these are the standard operations defined in RFC 6241.

Why this answer

RFC 6241 defines the <edit-config> operation with the 'merge', 'replace', 'create', 'delete', and 'remove' operations. These allow granular modification of configuration data, with 'merge' being the default behavior if no operation attribute is specified.

Exam trap

Cisco often tests the distinction between mandatory and optional capabilities, and the default operation of <edit-config>, to catch candidates who confuse 'merge' with 'replace' or assume all datastores are optional.

95
MCQeasy

An automation script using Ansible tries to configure IP address 192.168.1.2 on GigabitEthernet0/1. After running, the interface remains administratively down. What is the first thing to check?

A.The VLAN configuration
B.The IP address is a duplicate
C.The interface is faulty
D.The 'no shutdown' command was not included in the configuration
AnswerD

Cisco IOS interfaces default to administratively down, so an IP address alone leaves the port disabled. Adding 'no shutdown' transitions it to up/up, which is precisely the state the stem reports as missing after the playbook run.

Why this answer

The 'no shutdown' command is required to administratively enable an interface on Cisco IOS devices. Without it, the interface remains in an administratively down state regardless of IP configuration. Ansible automation scripts must include this command in the task or playbook to bring the interface up.

Exam trap

Cisco often tests the distinction between interface configuration (IP address, VLAN) and interface state (shutdown/no shutdown), trapping candidates who assume that assigning an IP address automatically enables the interface.

How to eliminate wrong answers

Option A is wrong because VLAN configuration affects Layer 2 connectivity and trunking, not the administrative state of a routed interface; an interface can be administratively down even with correct VLAN settings. Option B is wrong because a duplicate IP address would cause a conflict or error message, but it would not prevent the interface from being administratively enabled; the 'no shutdown' command is still required. Option C is wrong because a faulty interface would typically show as 'down/down' or have CRC errors, not 'administratively down'; the administrative state is a software-controlled flag, not a hardware fault.

96
MCQhard

A network automation engineer is writing a Python script that uses the Meraki Dashboard API to update the VLAN configuration on a switch. The engineer needs to send a PUT request to the endpoint /devices/{serial}/switch/ports/{portId}. Which HTTP header must be included to authenticate the request?

A.X-Cisco-Meraki-API-Key: <API key>
B.Authorization: Basic <base64(API key:)>
C.X-Auth-Token: <API key>
D.Authorization: Bearer <API key>
AnswerA

The Meraki Dashboard API authenticates requests using the X-Cisco-Meraki-API-Key header, which contains the API key generated in the Meraki Dashboard. Without this header, the API returns a 401 Unauthorized response. The header name is specific to Meraki and must be used exactly as documented for the request to be accepted.

Why this answer

The Meraki Dashboard API requires the API key to be sent in the X-Cisco-Meraki-API-Key request header. This is a custom header defined by Meraki, and it must be present on every API call. Other authentication schemes such as Bearer tokens, X-Auth-Token, or Basic authentication are not supported for Meraki API keys, so requests using them will be rejected with an authentication error.

Exam trap

The trap here is assuming that all REST APIs use the Authorization header for API keys, when Meraki specifically requires a custom header named X-Cisco-Meraki-API-Key.

97
MCQhard

A large enterprise uses Cisco DNA Center to manage over 500 network devices across multiple sites. The network operations team wants to automate the validation of device compliance with a baseline configuration. They have a Python script that uses the Cisco DNA Center REST API to retrieve the device configuration and compare it against a golden configuration stored in a local file. Recently, the script started failing with a 401 HTTP response code when trying to authenticate. The team confirmed the username and password are correct and that the DNA Center server is reachable. The script uses the /api/system/v1/auth/token endpoint to obtain a token. Which of the following is the most likely cause of the 401 error?

A.The API endpoint requires a different HTTP method (e.g., POST vs GET).
B.The script is using an incorrect API version path (e.g., /v2 instead of /v1).
C.CORS (Cross-Origin Resource Sharing) is blocking the request.
D.The authentication token has expired and the script is not refreshing it.
AnswerD

The token obtained from /api/system/v1/auth/token is time-limited, so a long-running script that caches it will eventually present an expired credential and receive 401. Refreshing the token before each API call, or handling the expiry response, satisfies the requirement for continuous authentication against Cisco DNA Center.

Why this answer

The 401 HTTP response code indicates an authentication failure. Since the username and password are confirmed correct and the server is reachable, the most likely cause is that the script obtained a token earlier but is now using an expired token without refreshing it. Cisco DNA Center tokens have a configurable timeout (default 1 hour), and the script must re-authenticate or refresh the token before it expires.

Exam trap

Cisco often tests the distinction between authentication (401) and authorization (403) errors, and the trap here is that candidates might blame the endpoint version or HTTP method when the real issue is token lifecycle management.

How to eliminate wrong answers

Option A is wrong because the /api/system/v1/auth/token endpoint requires a POST method with Basic Authentication, not a GET; if the script used GET, it would get a 405 Method Not Allowed, not a 401. Option B is wrong because the script is using /v1 which is the correct version for token generation; using /v2 would return a 404 Not Found, not a 401. Option C is wrong because CORS is a browser-enforced security mechanism that blocks cross-origin HTTP requests from JavaScript in a web page, not from a Python script running on a server or CLI; a Python script is not subject to CORS restrictions.

98
Multi-Selecthard

Which TWO statements correctly describe differences between model-driven telemetry and traditional SNMP polling?

Select 2 answers
A.SNMP supports push-based notifications using informs
B.Model-driven telemetry reduces device CPU usage compared to frequent SNMP polling
C.Model-driven telemetry can only be used with NETCONF
D.Model-driven telemetry uses a push model, while SNMP polling is a pull model
E.SNMP uses YANG models for data definition
AnswersB, D

Telemetry is more efficient as devices send data at intervals rather than being polled.

Why this answer

Model-driven telemetry uses a push model that sends data only when there is a change or at a configured interval, which significantly reduces the device CPU overhead compared to frequent SNMP polling, where the device must process and respond to each individual GET request from the NMS. This efficiency gain is a primary advantage of telemetry over traditional polling.

Exam trap

Cisco often tests the misconception that SNMP is purely pull-based and cannot push, but the trap here is that SNMP informs and traps are push mechanisms, so candidates must focus on the 'frequent polling' CPU reduction as the key differentiator, not the push/pull model alone.

99
MCQhard

A developer is designing a data model for network device configurations using YANG. They need to represent a list of interfaces where each interface has a name (string) and speed (enumeration). Which YANG statement correctly defines this structure?

A.leaf interface-list { type string; }
B.leaf-list interface { type string; }
C.list interface { key name; leaf name { type string; } leaf speed { type enumeration; } }
D.list interface { leaf name { type string; } leaf speed { type enumeration; } }
AnswerC

This defines a list with a key, and two leaves for name and speed.

Why this answer

YANG requires a `list` statement to define a collection of entries with multiple leafs, and a `key` statement to uniquely identify each list entry. The `list interface` with `key name` allows multiple interfaces, each having both a `name` (string) and `speed` (enumeration), matching the requirement exactly.

Exam trap

Cisco often tests the requirement of the `key` statement in a YANG `list`; candidates may forget that a list without a key is syntactically invalid, leading them to choose option D.

How to eliminate wrong answers

Option A is wrong because `leaf` defines a single scalar value, not a list of interfaces with multiple properties. Option B is wrong because `leaf-list` defines an ordered list of simple values (e.g., strings), not entries with multiple leafs like name and speed. Option D is wrong because it omits the mandatory `key` statement, which is required by YANG for any `list` to uniquely identify each entry; without a key, the list is invalid.

100
MCQhard

A developer is writing a Python script that uses the ncclient library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The script must filter the configuration to return only the interface configuration. Which filter type should be used in the <get-config> RPC to achieve this?

A.xpath filter
B.attribute filter
C.subtree filter
D.key filter
AnswerC

A subtree filter allows the client to specify a partial XML tree that matches the desired configuration nodes. By providing a filter with the <interfaces> container, the device returns only the matching interface configuration, which is exactly what the script needs.

Why this answer

NETCONF supports two standard filter types: subtree and xpath. The subtree filter is the most widely implemented and allows selective retrieval of configuration data by specifying an XML fragment. For retrieving only interface configuration, a subtree filter containing the <interfaces> node is the correct approach.

Exam trap

The trap here is confusing NETCONF filter types with other filtering mechanisms like XPath or proprietary filters, or assuming that any filter type can be used interchangeably.

101
MCQeasy

In a Python script using the 'requests' library to interact with Cisco DNA Center API, which function call is used to send a POST request with JSON data?

A.requests.post(url, json=data)
B.requests.patch(url, json=data)
C.requests.get(url, json=data)
D.requests.put(url, json=data)
AnswerA

The requests library's post function accepts a json keyword argument that serialises the Python dictionary and sets the Content-Type header to application/json automatically. Calling requests.post(url, json=data) therefore sends the POST request with JSON payload to the Cisco DNA Center API.

Why this answer

The `requests.post()` function is specifically designed to send HTTP POST requests, and passing the `json=data` parameter automatically serializes the Python dictionary to JSON and sets the `Content-Type` header to `application/json`. This is the standard way to create a resource via Cisco DNA Center's REST API endpoints that expect JSON payloads.

Exam trap

Cisco often tests the distinction between POST and PUT by having candidates confuse resource creation (POST) with resource replacement (PUT), especially when both methods accept a JSON body.

How to eliminate wrong answers

Option B is wrong because `requests.patch()` sends an HTTP PATCH request, which is used for partial updates to an existing resource, not for creating a new resource via POST. Option C is wrong because `requests.get()` sends an HTTP GET request, which is used to retrieve data, not to send a JSON payload to create a resource. Option D is wrong because `requests.put()` sends an HTTP PUT request, which is used to replace an entire resource, not to create a new one; POST is the correct HTTP method for resource creation in RESTful APIs.

102
Multi-Selectmedium

A network automation team is comparing configuration management tools for managing Cisco IOS XE devices. They want to understand which TWO statements accurately describe how Ansible differs from Puppet in this context. (Choose two.)

Select 2 answers
A.Puppet modules for network devices are executed as Python scripts over NETCONF, while Ansible modules for network devices are always compiled Ruby extensions.
B.Ansible requires a central server called a master, while Puppet runs entirely from a developer workstation without any server component.
C.Ansible and Puppet both require the managed Cisco IOS XE device to run a persistent agent daemon for configuration changes to be applied.
D.Ansible playbooks are written in YAML and executed in order, while Puppet manifests use a declarative DSL where resource ordering is largely determined by dependency metadata.
E.Ansible uses an agentless architecture and connects to managed devices over SSH or API, while Puppet traditionally requires an agent installed on the managed node.
AnswersD, E

Ansible tasks run top to bottom in the order written unless handlers or includes change flow, giving imperative-style sequencing. Puppet describes desired end state and uses relationships like require and notify to order resources. This difference affects how engineers reason about convergence and troubleshooting in network automation.

Why this answer

Ansible is agentless and push-based, using YAML playbooks executed in sequence, while Puppet traditionally uses agents and a declarative DSL with dependency-driven ordering. Those two architectural and authoring differences are accurate. The remaining statements invert the architectures, misstate module languages and transports, or wrongly claim both tools need a persistent agent on the network device.

Exam trap

The trap here is assuming both tools share the same agent model, when Ansible is agentless and Puppet's classic design depends on an agent checking in with a master.

103
MCQeasy

A network engineer is using Ansible to automate configuration changes on Cisco IOS XE devices. The engineer wants to ensure that the playbook applies a set of configuration lines only if they are not already present. Which Ansible module should be used to achieve idempotent configuration management?

A.ios_command
B.ios_vlan
C.ios_facts
D.ios_config
AnswerD

The ios_config module is designed for managing configuration on Cisco IOS devices. It is idempotent by default: it compares the desired configuration lines with the running configuration and only applies changes if they are missing. This makes it the correct choice for ensuring configuration lines are present without duplication.

Why this answer

The ios_config module is the correct choice because it is specifically built for idempotent configuration management on Cisco IOS devices. It checks the running configuration and only applies missing lines, ensuring the device reaches the desired state without redundant changes. The other modules either execute commands, manage specific resources like VLANs, or gather facts, none of which fulfill the requirement to apply arbitrary configuration lines idempotently.

Exam trap

The trap here is confusing modules that execute commands or gather facts with those that enforce configuration state; only ios_config provides idempotent configuration line management.

104
MCQmedium

A developer is building a Python tool that must retrieve the list of interfaces from a Cisco IOS XE device using the RESTCONF API. The device is reachable at https://10.1.1.1 and supports the ietf-interfaces YANG model. The developer wants to send the request and parse the JSON response. Which Python code snippet correctly performs this operation?

A.import requests response = requests.post('https://10.1.1.1/restconf/data/ietf-interfaces:interfaces', headers={'Content-Type': 'application/yang-data+json'}, auth=('admin', 'password')) interfaces = response.json()
B.import requests response = requests.get('https://10.1.1.1/restconf/data/ietf-interfaces:interfaces', headers={'Accept': 'application/json'}, auth=('admin', 'password')) interfaces = response.json()
C.import requests response = requests.get('https://10.1.1.1/restconf/data/ietf-interfaces:interfaces', headers={'Accept': 'application/yang-data+json'}, auth=('admin', 'password')) interfaces = response.json()
D.import requests response = requests.get('https://10.1.1.1/restconf/data/ietf-interfaces:interfaces', headers={'Content-Type': 'application/yang-data+json'}, auth=('admin', 'password')) interfaces = response.json()
AnswerC

This snippet uses requests.get with the correct RESTCONF URL path, sets the Accept header to application/yang-data+json, and supplies basic authentication. The response is parsed as JSON. This aligns with RESTCONF conventions for retrieving data from a YANG-modeled interface.

Why this answer

RESTCONF uses HTTP methods to manipulate YANG-modeled data. To retrieve data, a GET request is sent to the resource URL, with the Accept header set to application/yang-data+json to request JSON-encoded data. Basic authentication is commonly used.

The correct snippet follows these conventions, while the others misuse HTTP methods or headers.

Exam trap

The trap here is confusing the Accept header with the Content-Type header; Accept specifies the desired response format, while Content-Type describes the request body.

105
MCQeasy

A network automation engineer needs to retrieve the running configuration of a Cisco IOS XE device using NETCONF. Which ncclient method should be used to fetch the configuration without modifying the device?

A.get_config
B.edit_config
C.dispatch
D.commit
AnswerA

get_config retrieves configuration data from a specified datastore, such as running, without altering the device. It accepts a source datastore and an optional filter, making it the correct method for reading the running configuration in a read-only operation. This matches the scenario's requirement exactly.

Why this answer

Reading the running configuration over NETCONF requires a read operation against the running datastore. The ncclient get_config method is designed for exactly this purpose, accepting a source datastore and optional subtree or XPath filter. The other methods either modify state, apply staged changes, or send unvalidated raw RPCs.

Exam trap

The trap here is confusing the method that stages or applies changes with the method that simply reads configuration from a datastore.

106
Multi-Selecteasy

Which TWO statements are correct about Ansible inventory files? (Select exactly 2.)

Select 2 answers
A.Inventory files can be written in YAML format
B.Inventory files cannot contain variables for individual hosts
C.Inventory files must be in INI format only
D.Inventory files can define groups of devices
E.An inventory file can include a [vars] section to define group variables
AnswersA, D

Why this answer

Ansible inventory files define the hosts and groups that Ansible manages. They can be written in YAML format, which is a human-readable data serialization language that Ansible supports alongside the traditional INI format. This flexibility allows users to choose the format that best suits their automation needs, with YAML being particularly useful for complex inventories due to its support for structured data.

Exam trap

Cisco often tests the misconception that Ansible inventory files are limited to INI format, but the exam expects you to know that YAML is also a valid format, and that `[vars]` is not a standard section in Ansible inventories (group variables are handled differently).

107
MCQhard

A developer writes a Python script that uses ncclient to configure a loopback interface on a Cisco IOS XE router. The script calls edit_config against the candidate datastore and then exits without calling commit. The next day, the interface is missing from the running configuration. What is the most likely cause?

A.The candidate datastore was discarded because the session ended without a commit operation.
B.The running configuration was overwritten by a scheduled job that removed all loopback interfaces.
C.The edit_config operation requires a confirmed-commit timer to persist changes to the running datastore.
D.The device rejected the edit_config because loopback interfaces require a separate YANG module.
AnswerA

Changes written to the candidate datastore are not active until a commit is issued. When the NETCONF session closes without committing, the candidate datastore is discarded and the running configuration remains unchanged. This precisely explains why the interface disappeared the next day.

Why this answer

NETCONF separates candidate configuration from running configuration. Writing to the candidate datastore stages changes but does not activate them. Only a commit RPC copies the candidate contents to running.

When the session ends without commit, the candidate is discarded, which explains the missing interface.

Exam trap

The trap here is assuming that edit_config immediately changes the running configuration, when it only stages changes in the candidate datastore until a commit is issued.

108
MCQhard

A NETCONF manager sends a get-config request to a Cisco device and receives the above reply. The automation script expected the interface to be enabled. Which of the following is the best course of action to remediate the issue?

A.Send an rpc to reboot the device
B.Use CLI to enable the interface manually
C.Send an edit-config request with <enabled>true</enabled> for the interface
D.Send a get request again
AnswerC

This changes the configuration to enable the interface.

Why this answer

NETCONF uses the edit-config operation to modify device configuration programmatically. Since the automation script detected that the interface is disabled (enabled state is false), sending an edit-config request with <enabled>true</enabled> for that interface directly remediates the issue by setting the operational state to enabled, aligning with the expected state without manual intervention.

Exam trap

Cisco often tests the distinction between read-only operations (get, get-config) and write operations (edit-config), and the trap here is that candidates may think re-querying the device (Option D) or using CLI (Option B) is acceptable, when the correct approach is to use the appropriate NETCONF operation to modify the configuration programmatically.

How to eliminate wrong answers

Option A is wrong because rebooting the device via an rpc is an extreme, unnecessary action that does not specifically enable the interface and would cause service disruption. Option B is wrong because using CLI to enable the interface manually defeats the purpose of automation and NETCONF's programmatic management, and it is not a scalable or scripted solution. Option D is wrong because sending a get request again would only retrieve the current configuration again, not change the disabled state of the interface.

109
MCQeasy

A team is using Python scripts with netmiko to back up configurations from a large number of network devices. What is the primary advantage of using netmiko over direct paramiko for this task?

A.Netmiko supports only Cisco devices
B.Netmiko uses REST API instead of SSH
C.Netmiko is faster than paramiko
D.Netmiko simplifies the handling of device-specific prompts and command output
AnswerD

Netmiko wraps Paramiko with device-type drivers that automatically handle vendor-specific prompts, paging, and enable-mode transitions, so scripts do not need custom regex per platform. This directly addresses backing up configurations across many heterogeneous network devices, where raw Paramiko would require bespoke prompt handling for each.

Why this answer

Netmiko is built on top of Paramiko but adds a higher-level abstraction layer that automatically handles device-specific prompt detection, command output parsing, and SSH session management. This simplifies the backup process across heterogeneous devices by eliminating the need to manually write code for each device's unique prompt patterns and command responses.

Exam trap

Cisco often tests the misconception that Netmiko is a faster alternative to Paramiko, when in reality the advantage is about abstraction and ease of use, not raw performance.

How to eliminate wrong answers

Option A is wrong because Netmiko supports a wide range of vendors (Cisco, Juniper, Arista, HP, etc.), not just Cisco devices. Option B is wrong because Netmiko uses SSH (via Paramiko) for network device access, not REST API; REST API is a separate paradigm used with tools like requests or ncclient. Option C is wrong because Netmiko is not inherently faster than Paramiko; it adds overhead for prompt handling and session management, and performance depends on network latency and device responsiveness, not the library itself.

110
MCQmedium

A developer is writing a Python script that must authenticate to the Cisco DNA Center REST API and create a new site. The script stores the controller hostname, username, and password in environment variables. Which approach correctly obtains the authentication token required for subsequent API calls?

A.Send a POST request to /api/v1/token with the username and password in a JSON body, then read the 'access_token' field from the JSON response.
B.Send a POST request to /dna/system/api/v1/auth/token with the username and password in a JSON body, then read the 'Token' field from the JSON response.
C.Send a POST request to /dna/system/api/v1/auth/token with HTTP Basic authentication using the username and password, then read the 'Token' field from the JSON response.
D.Send a GET request to /dna/system/api/v1/auth/token with the username and password as query parameters, then read the 'Token' field from the JSON response.
AnswerC

Cisco DNA Center issues tokens through the /dna/system/api/v1/auth/token endpoint. The client must supply HTTP Basic credentials, and the JSON response contains a 'Token' value that is then placed in the X-Auth-Token header for later calls. This matches the documented authentication flow for the platform.

Why this answer

Cisco DNA Center authenticates API clients by exchanging HTTP Basic credentials for a time-limited token. The client posts to /dna/system/api/v1/auth/token, and the controller returns a JSON object whose 'Token' field is then used in the X-Auth-Token header. This is the only supported pattern among the choices, so the script must follow it to create sites successfully.

Exam trap

The trap here is assuming the token endpoint accepts credentials in a JSON body or as query parameters, when Cisco DNA Center actually requires HTTP Basic authentication.

111
MCQmedium

A developer is using Git to manage automation code. What is the primary advantage of using 'rebase' instead of 'merge' to integrate changes from a feature branch into the main branch?

A.Rebase automatically resolves all conflicts
B.Rebase is faster than merge
C.Rebase preserves the exact commit timestamps
D.Rebase results in a linear project history
AnswerD

Rebase replays each feature-branch commit onto the tip of the main branch, producing a linear history without merge commits. This keeps the commit graph readable and simplifies bisecting, unlike merge, which preserves branch topology via an explicit merge commit.

Why this answer

`git rebase` rewrites the commit history of the feature branch to appear as if it was branched from the latest commit on the main branch, resulting in a linear, clean project history. This avoids the merge commits that `git merge` creates, making the commit log easier to follow and debug. The primary advantage is not speed or conflict resolution, but a streamlined, non-branching history.

Exam trap

Cisco often tests the misconception that rebase is faster or automatically resolves conflicts, when in fact its true advantage is creating a linear history, which is critical for audit trails and debugging in automation workflows.

How to eliminate wrong answers

Option A is wrong because rebase does not automatically resolve conflicts; it replays each commit one by one, and if a conflict occurs, the developer must resolve it manually for each commit. Option B is wrong because rebase is not inherently faster than merge; in fact, rebase can be slower due to rewriting commits and requiring conflict resolution per commit, whereas merge creates a single merge commit. Option C is wrong because rebase does not preserve exact commit timestamps; it creates new commits with new timestamps (the time of the rebase operation), while merge retains the original commit timestamps.

112
MCQmedium

An engineer is writing a Python script that must authenticate to the Cisco Meraki Dashboard API and then retrieve the list of organizations the API key can access. Which authentication method and endpoint combination is correct?

A.Include the API key in the X-Cisco-Meraki-API-Key HTTP header and send GET to /api/v1/organizations.
B.Obtain an OAuth 2.0 bearer token from the Meraki identity service and send it to /api/v1/organizations.
C.Send the API key as a query string parameter named key to /api/v1/organizations.
D.Use HTTP Basic authentication with the API key as the username and a blank password against /api/v1/networks.
AnswerA

The Meraki Dashboard API authenticates each request with the API key supplied in the X-Cisco-Meraki-API-Key header, and the organizations endpoint is GET /api/v1/organizations. This combination returns the organizations visible to that key. It is the documented, correct way to begin any Meraki automation workflow.

Why this answer

The Meraki Dashboard API authenticates requests with the API key placed in the X-Cisco-Meraki-API-Key header. To enumerate accessible organizations, the client sends a GET to /api/v1/organizations. Query-string keys, HTTP Basic auth, and OAuth bearer tokens are not the documented mechanism for this endpoint, so only the header-based approach with the correct path succeeds.

Exam trap

The trap here is assuming the API key can be passed as a query parameter or via Basic auth, when Meraki requires a dedicated request header named X-Cisco-Meraki-API-Key.

113
Multi-Selectmedium

A network automation team is evaluating tools to manage configuration drift across a fleet of Cisco IOS XE devices. They want to ensure that device configurations remain in the desired state and that any unauthorized changes are detected and remediated. Which two capabilities are essential for a configuration drift detection and remediation solution in this environment? (Choose two.)

Select 2 answers
A.Use of SNMP traps to alert on configuration change events.
B.Automated remediation that pushes the baseline configuration back to the device when drift is detected.
C.Real-time streaming telemetry with sub-second granularity for all interface counters.
D.Integration with a version control system to store configuration history and track changes.
E.Periodic collection of device configurations and comparison against a baseline.
AnswersB, E

Detecting drift is only half the solution; the team must also be able to remediate it. Automated remediation involves generating and applying the necessary configuration commands to restore the device to the baseline. This can be achieved with tools like Ansible playbooks or custom scripts that use NETCONF edit-config. Without automated remediation, drift would require manual intervention, which is error-prone and slow. This capability is essential for a complete solution.

Why this answer

A configuration drift detection and remediation solution must first identify when a device's configuration deviates from the baseline. This requires periodic collection and comparison. Once drift is found, the solution must be able to automatically restore the correct configuration.

These two capabilities form the core loop of detect and remediate. Other features like telemetry, version control, or SNMP traps are useful supplements but not essential for the fundamental task.

Exam trap

The trap here is confusing operational monitoring (like telemetry or SNMP traps) with configuration drift detection, which requires active baseline comparison and automated remediation.

114
MCQmedium

A company uses Ansible to automate network configuration. They have an Ansible control node that must reach all network devices. Which transport protocol does Ansible use by default to connect to Cisco IOS devices?

A.HTTP
B.Telnet
C.SSH
D.SNMP
AnswerC

Ansible's default connection for Cisco IOS modules is SSH, using the network_cli connection plugin to open an interactive shell session on port 22. This satisfies the stem's constraint of the transport protocol used by default from the control node to IOS devices.

Why this answer

Ansible uses SSH as its default transport protocol to connect to Cisco IOS devices because SSH provides encrypted, secure remote access and is the standard for network device management in modern environments. Ansible's native architecture relies on SSH for agentless communication, executing modules and playbooks over this secure channel without requiring additional software on the target devices.

Exam trap

Cisco often tests the misconception that Ansible uses Telnet or SNMP for legacy device compatibility, but the trap here is that Ansible defaults to SSH for secure, agentless automation, and candidates may confuse Ansible's connection methods with other tools like NETCONF or RESTCONF.

How to eliminate wrong answers

Option A is wrong because HTTP is not used by Ansible for device connections; it is an unencrypted protocol typically used for web-based management interfaces, not for Ansible's agentless automation. Option B is wrong because Telnet is an unencrypted, legacy protocol that Ansible does not use by default due to security concerns and lack of support for modern automation features. Option D is wrong because SNMP is a monitoring and management protocol used for reading and writing device configuration data via MIBs, but it is not a transport protocol for executing Ansible modules or playbooks.

115
MCQmedium

A network team is implementing automation to provision new switchports across a campus network. They decide to use a controller-based approach with Cisco DNA Center. What is the primary advantage of using DNA Center for this task?

A.It automatically rolls back any configuration that deviates from the standard.
B.It replaces all existing CLI commands with a graphical interface.
C.It allows intent-based automation where the desired state is defined and the controller pushes the necessary configuration.
D.It eliminates the need for any human intervention in network management.
AnswerC

DNA Center's intent-based model lets engineers declare the desired end state, such as a provisioned switchport, and the controller translates that intent into device-specific CLI across heterogeneous hardware. This satisfies the stem's controller-based provisioning requirement, removing per-device manual configuration and abstracting underlying platform differences.

Why this answer

Cisco DNA Center uses an intent-based networking model where the administrator defines the desired state (e.g., 'provision a switchport for access VLAN 10') and the controller automatically translates that intent into the necessary device configurations (CLI or NETCONF/YANG). This abstraction reduces manual errors and enforces consistency across the campus network without requiring per-device CLI scripting.

Exam trap

Cisco often tests the distinction between intent-based automation (defining the desired state) versus traditional script-based automation (pushing explicit commands), and the trap here is confusing 'intent-based' with 'fully autonomous' or 'error-correcting' systems.

How to eliminate wrong answers

Option A is wrong because DNA Center does not automatically roll back configurations that deviate from a standard; it can detect drift and alert the operator, but rollback typically requires a manual or policy-driven action. Option B is wrong because DNA Center does not replace all CLI commands with a graphical interface; it provides a GUI for high-level intent but still relies on underlying CLI, NETCONF, or RESTCONF for device-level configuration. Option D is wrong because DNA Center does not eliminate the need for human intervention; it automates many tasks but still requires human oversight for policy definition, troubleshooting, and exception handling.

116
MCQhard

An organization wants to automate the deployment of wireless configurations across multiple Meraki networks using the Meraki Dashboard API. What authentication method should the developer use in the API requests?

A.Provide username and password in the Authorization header with Basic auth
B.Use OAuth2 client credentials grant and pass a bearer token
C.Include an API key in the X-Cisco-Meraki-API-Key header
D.Generate a JSON Web Token (JWT) signed with a shared secret
AnswerC

The Meraki Dashboard API authenticates requests by placing an API key in the X-Cisco-Meraki-API-Key header, which the developer must include on every call. This header-based key satisfies the requirement to automate wireless configuration deployment across multiple networks.

Why this answer

The Meraki Dashboard API uses a simple API key for authentication, not OAuth2 or JWT. The key must be included in the `X-Cisco-Meraki-API-Key` header of every request. This is the only supported method for authenticating with the Meraki API, as documented by Cisco Meraki.

Exam trap

Cisco often tests the misconception that all REST APIs use OAuth2 or Basic Auth, but the Meraki API specifically uses a custom header-based API key, which candidates may overlook in favor of more common authentication methods.

How to eliminate wrong answers

Option A is wrong because the Meraki Dashboard API does not support HTTP Basic authentication with username and password; it requires an API key. Option B is wrong because the Meraki API does not use OAuth2; it uses a static API key for all requests. Option D is wrong because the Meraki API does not accept JSON Web Tokens (JWTs); it relies solely on the API key in the custom header.

117
MCQeasy

A network engineer is using Ansible to automate configuration changes on a group of Cisco IOS XE devices. The engineer wants to ensure that the playbook only makes changes if the device configuration differs from the desired state, and that the playbook reports whether any changes were made. Which Ansible feature should the engineer rely on?

A.Conditionals using the when clause
B.Tags that limit which tasks run
C.Handlers that run only when notified
D.Idempotent modules that report changed status
AnswerD

Ansible modules such as ios_config are designed to be idempotent, meaning they only apply changes when the current configuration differs from the desired state. They also return a 'changed' status that indicates whether any modification occurred. This directly supports the requirement to avoid unnecessary changes and to report whether changes were made.

Why this answer

Ansible network modules like ios_config are idempotent and report a changed status. They compare the desired configuration with the running configuration and only apply differences, then indicate whether any change occurred. This satisfies both the need to avoid unnecessary changes and to know when changes were made.

Handlers, tags, and conditionals serve different purposes and do not provide this behavior on their own.

Exam trap

The trap here is thinking that any Ansible feature that controls execution, like tags or conditionals, also provides idempotency, when idempotency is a property of the module itself.

118
Multi-Selectmedium

A developer is using the Cisco DNA Center Intent API to manage network devices. The developer needs to programmatically retrieve a list of all devices that match a specific hostname pattern. Which two actions must be performed to accomplish this? (Choose two.)

Select 2 answers
A.Send a GET request to the /dna/intent/api/v1/network-device endpoint and filter the response by hostname using query parameters or client-side processing.
B.Send a POST request to the /dna/intent/api/v1/network-device endpoint with a JSON body containing the hostname pattern.
C.Obtain an authentication token by sending a POST request to the DNA Center token endpoint with valid credentials.
D.Configure SNMPv3 on all devices to allow DNA Center to poll them for hostname information.
E.Use the PUT method to update the device hostname before retrieving the list.
AnswersA, C

The /dna/intent/api/v1/network-device endpoint returns a list of all network devices. To filter by hostname pattern, the developer can either use supported query parameters if available or retrieve all devices and filter client-side. This is the correct endpoint for retrieving device inventory, and it must be called with the authentication token.

Why this answer

To retrieve devices by hostname pattern via the DNA Center Intent API, the developer must first authenticate to obtain a token, then issue a GET request to the network-device endpoint and filter the results. Authentication is always required, and the GET method is used for read operations. The other options involve incorrect HTTP methods, unnecessary device configuration, or actions that do not contribute to the retrieval task.

Exam trap

The trap here is thinking that SNMP configuration or POST requests are needed, when the API simply requires a token and a GET call to the device inventory endpoint.

119
MCQhard

Using the Cisco DNA Center API, an engineer wants to create a new site with building and floor information. Which HTTP method and endpoint should be used?

A.PUT /dna/intent/api/v1/site
B.GET /dna/intent/api/v1/site
C.POST /dna/intent/api/v1/site
D.POST /dna/intent/api/v1/site/create
AnswerC

Creating a site is a resource-creation operation, so the Cisco DNA Center intent API requires POST to /dna/intent/api/v1/site with the building and floor payload. GET would only retrieve existing sites, and PUT would update an existing one.

Why this answer

The POST HTTP method is used to create a new resource on the server, and the Cisco DNA Center API endpoint `/dna/intent/api/v1/site` is designed to accept a POST request with a JSON payload containing site, building, and floor details. This follows RESTful conventions where POST is the standard method for resource creation, and the API documentation specifies this exact endpoint for adding a new site hierarchy.

Exam trap

The trap here is that candidates often confuse POST with PUT or assume a 'create' suffix is needed in the endpoint, but Cisco tests the exact RESTful convention where POST on the base resource URI is the correct method for creation.

How to eliminate wrong answers

Option A is wrong because the PUT method is typically used for updating an existing resource or creating a resource at a specific URI, but the Cisco DNA Center API for site creation explicitly requires POST, not PUT. Option B is wrong because the GET method is used for retrieving information, not creating resources; it would return existing site data, not create a new site. Option D is wrong because the endpoint `/dna/intent/api/v1/site/create` does not exist in the Cisco DNA Center API; the correct endpoint is `/dna/intent/api/v1/site` without the `/create` suffix, and the creation action is implied by the POST method.

120
MCQmedium

A Python script uses the ncclient library to connect to a Cisco NX-OS device over NETCONF. After establishing the session, the script executes an editing operation with candidate datastore. Which additional step is required to make the changes take effect immediately on the running configuration?

A.Execute a discard-changes operation on the candidate datastore
B.Execute a validate operation on the candidate datastore
C.No additional step is needed; candidate changes are automatically applied to running
D.Execute a commit operation on the candidate datastore
AnswerD

Commit copies candidate to running, making changes active.

Why this answer

When using NETCONF with the candidate datastore on Cisco NX-OS, changes are staged in the candidate configuration and do not affect the running configuration until a commit operation is explicitly sent. The commit operation copies the candidate configuration to the running datastore, making the changes take effect immediately. Without this step, the candidate changes remain unapplied.

Exam trap

Cisco often tests the distinction between the candidate and running datastores, trapping candidates who assume that editing the candidate automatically updates the running configuration, which is only true for the 'candidate' datastore on some platforms like Juniper but not for NX-OS NETCONF.

How to eliminate wrong answers

Option A is wrong because discard-changes is used to revert the candidate datastore to the running configuration, discarding any uncommitted edits; it does not apply changes. Option B is wrong because validate checks the syntactic and semantic correctness of the candidate configuration but does not apply it to the running datastore. Option C is wrong because the candidate datastore is a separate, working copy; changes are not automatically applied to running — a commit is required per RFC 6241.

121
MCQeasy

An automation engineer needs to retrieve the current running configuration from a Cisco IOS XE device using RESTCONF over HTTPS. The device supports the ietf-netconf-monitoring YANG module. Which HTTP method and URI should be used to fetch the configuration data represented by a specific YANG model?

A.POST https://<device>/restconf/data/<yang-module>:<container>
B.GET https://<device>/restconf/data/<yang-module>:<container>
C.GET https://<device>/restconf/operations/<yang-module>:<rpc>
D.PUT https://<device>/restconf/data/<yang-module>:<container>
AnswerB

RESTCONF maps YANG data nodes directly onto URI paths under /restconf/data, and GET retrieves the representation of the addressed resource. The colon separates the module name from the data node path, which is the standard convention. This is the correct way to read configuration or state data from a device that implements the RESTCONF protocol.

Why this answer

RESTCONF exposes YANG-modeled data under the /restconf/data URI, and the colon-delimited path identifies the module and node. A GET is the safe, idempotent method for reading that resource. POST and PUT are write-oriented, and /restconf/operations is reserved for RPC invocation, so none of them retrieves configuration data.

The engineer should issue a GET against the data path.

Exam trap

The trap here is confusing the /restconf/data path used for configuration and state data with the /restconf/operations path used for invoking YANG RPCs.

122
MCQeasy

Based on the exhibit, what is the frequency of the telemetry subscription?

A.Every 500 seconds
B.Every 500 milliseconds
C.When the management connection is re-established
D.On-change only
AnswerB

The subscription's sample interval field in the exhibit specifies 500 milliseconds, so telemetry is pushed at that cadence. Frequency is determined by the configured period value, not by transport protocol or encoding, making 500 milliseconds the correct reading.

Why this answer

The exhibit shows a telemetry subscription with a 'period' of 500, which in Cisco model-driven telemetry (MDT) is expressed in milliseconds. Therefore, the frequency is every 500 milliseconds, making option B correct.

Exam trap

Cisco often tests the unit of the 'period' value, and the trap here is that candidates assume the value is in seconds (like many other network timers) instead of milliseconds, leading them to choose 'Every 500 seconds'.

How to eliminate wrong answers

Option A is wrong because 500 seconds would be an unusually long interval for telemetry updates and the period value in Cisco MDT is always in milliseconds, not seconds. Option C is wrong because a re-establishment-based subscription is a different type (e.g., 'periodic' vs 'on-change' vs 'connection-based'), and the exhibit explicitly shows a periodic subscription with a numeric period value. Option D is wrong because 'on-change' subscriptions do not use a numeric period; they trigger only when the monitored data changes, whereas the exhibit shows a fixed period of 500.

123
MCQhard

A developer is creating a YANG data model for a new interface feature. The model must allow the user to choose from a predefined set of values for the 'duplex' leaf. Which YANG statement should be used to restrict the values to 'full', 'half', and 'auto'?

A.choice duplex-options { case full; case half; case auto; }
B.type string;
C.type leafref { path '/other:duplex-list'; }
D.type enumeration { enum full; enum half; enum auto; }
AnswerD

The enumeration type restricts the duplex leaf to a fixed, predefined set of named values, which is exactly the constraint the model requires. Unlike a string pattern or union, enumeration rejects any value outside full, half and auto, giving schema-level validation.

Why this answer

The 'type enumeration' statement in YANG defines a leaf that can only take one of the explicitly listed enum values. By specifying 'enum full;', 'enum half;', and 'enum auto;', the developer restricts the 'duplex' leaf to exactly those three predefined strings, which matches the requirement.

Exam trap

Cisco often tests the distinction between YANG's 'choice' statement (which selects among different schema branches) and the 'enumeration' type (which restricts a single leaf's value), leading candidates to mistakenly choose 'choice' when they need a value restriction.

How to eliminate wrong answers

Option A is wrong because 'choice' and 'case' in YANG are used to model a selection among different schema nodes (e.g., different leafs or containers), not to restrict the value of a single leaf to a set of strings. Option B is wrong because 'type string;' would allow any arbitrary string value, providing no restriction to 'full', 'half', or 'auto'. Option C is wrong because 'type leafref' references the value of another leaf in the data tree; it does not define an inline set of allowed values, and the path '/other:duplex-list' would require a separate list node that may not exist or may not contain the desired restriction.

124
Multi-Selectmedium

A developer is designing unit tests for a Python function that calls a Cisco Meraki Dashboard API endpoint to retrieve organization inventory. The tests must run quickly in CI without making real network calls, and must verify that the function builds the correct request. Which TWO practices should the developer implement? (Choose two.)

Select 2 answers
A.Insert a fixed sleep of thirty seconds before each assertion to let the API respond.
B.Assert on the recorded request's URL, HTTP method, and the presence of the API key header.
C.Disable all assertions and rely on the test passing if no exception is raised during the call.
D.Mock the HTTP client so the function's request is intercepted and a canned JSON response is returned.
E.Point the function at the live Meraki Dashboard API and compare the response to a previously saved response body.
AnswersB, D

Verifying the captured request's URL, verb, and authentication header confirms the function builds the correct Meraki call without contacting the service. This is the behavioral contract the unit test should protect, and it catches regressions such as a wrong endpoint path or a missing X-Cisco-Meraki-API-Key header before they reach integration testing.

Why this answer

Unit tests for API-calling code should isolate the function from the network and assert on the request it constructs. Mocking the HTTP client provides deterministic responses, while checking the method, URL, and authentication header verifies the contract with the Meraki Dashboard API. Together these keep the suite fast, repeatable, and meaningful in CI.

Exam trap

The trap here is believing that hitting the live Meraki API in a unit test proves correctness, when it actually introduces flakiness and rate-limit failures that a mocked client avoids entirely.

125
MCQeasy

An engineer must push a configuration change to a Cisco IOS XE router using NETCONF. The engineer wants to stage the change so it can be previewed and later committed or discarded, rather than applying it immediately to the running configuration. Which NETCONF capability enables this behavior?

A.urn:ietf:params:netconf:capability:notification:1.0
B.urn:ietf:params:netconf:capability:candidate:1.0
C.urn:ietf:params:netconf:capability:writable-running:1.0
D.urn:ietf:params:netconf:capability:rollback-on-error:1.0
AnswerB

The candidate capability gives the device a separate candidate datastore where edits are staged. An engineer can edit the candidate, review it with a get-config against that datastore, then commit it to running or discard it, which is precisely the preview-and-commit workflow described in the scenario.

Why this answer

NETCONF advertises supported capabilities during hello exchange. The candidate datastore capability creates a staging area separate from running, letting an engineer apply edits, inspect them, and then commit or discard. Writable-running applies changes immediately, rollback-on-error only handles failed transactions, and notification streams events, so none of those provide the preview-then-commit workflow.

Exam trap

The trap here is confusing capabilities that affect configuration application with the candidate datastore, which is the only one that stages edits for review before commit.

126
MCQmedium

A DevOps engineer is implementing Infrastructure as Code (IaC) for network devices. Which of the following practices is most critical to ensure that the environment state matches the desired configuration defined in code?

A.Using Jinja2 templates to generate device configurations.
B.Ensuring that the automation tool is idempotent.
C.Using version control for all configuration files.
D.Implementing rollback procedures for failed deployments.
AnswerB

Idempotent automation reapplies the declared configuration without duplicating or compounding changes, so repeated runs converge the device state onto the desired configuration. This directly satisfies the stem's requirement that environment state match the code-defined desired state, rather than drifting after each execution.

Why this answer

Idempotency ensures that applying the same configuration multiple times always results in the same desired state, regardless of the current state of the device. This is the most critical practice for IaC because it prevents configuration drift and guarantees that the environment state matches the code-defined configuration. Without idempotency, repeated runs of the automation tool could introduce unintended changes or fail to correct deviations.

Exam trap

Cisco often tests the concept that idempotency is the core principle of IaC for state convergence, tempting candidates to choose version control or rollback procedures because they are familiar best practices, but they do not directly ensure the environment state matches the code.

How to eliminate wrong answers

Option A is wrong because Jinja2 templates are a tool for generating configuration files from variables, but they do not ensure that the applied configuration matches the desired state; they only help with parameterization and reuse. Option C is wrong because version control tracks changes to configuration files over time but does not enforce that the live environment state matches the code; it is a best practice for auditability, not for state convergence. Option D is wrong because rollback procedures handle failed deployments by reverting to a previous state, but they do not guarantee that the environment state matches the desired configuration defined in code; they are a recovery mechanism, not a preventive or corrective one.

127
Multi-Selectmedium

A developer is writing a Python script that uses the Cisco DNA Center Intent API to retrieve a list of all network devices. The script must handle pagination to ensure all devices are returned. Which TWO parameters are used to control pagination in the Cisco DNA Center API? (Choose two.)

Select 2 answers
A.limit
B.start
C.size
D.offset
E.page
AnswersA, D

The limit parameter defines the maximum number of records to return in a single response. It controls the page size. Together with offset, it allows the client to iterate through the full dataset in manageable chunks.

Why this answer

Cisco DNA Center uses offset and limit query parameters to implement pagination. The offset indicates the starting record, and limit sets the page size. By looping with increasing offset values, the script can retrieve all devices.

Other parameter names like page, size, or start are not used by this API.

Exam trap

The trap here is assuming that common pagination parameter names like page or size are used, when Cisco DNA Center specifically uses offset and limit.

128
MCQmedium

A developer is using the Meraki API to retrieve a list of networks for an organization. Which HTTP method and endpoint should be used?

A.GET /organizations/{organizationId}/networks
B.POST /organizations/{organizationId}/networks
C.GET /networks
D.PUT /organizations/{organizationId}/networks
AnswerA

The Meraki Dashboard API exposes organisation networks as a REST resource; listing them is a read operation, so GET is correct, and the endpoint nests networks under the organisation ID. This satisfies the requirement to retrieve, not modify, the network list.

Why this answer

The Meraki API uses RESTful conventions where retrieving a list of resources is done with a GET request. The endpoint GET /organizations/{organizationId}/networks returns all networks belonging to a specific organization, as documented in the Meraki API reference. This matches the standard pattern for listing child resources under a parent resource.

Exam trap

Cisco often tests the distinction between HTTP methods (GET vs POST vs PUT) and the necessity of proper resource scoping (including the organization ID), so the trap here is assuming a flat /networks endpoint exists or that POST can be used for retrieval.

How to eliminate wrong answers

Option B is wrong because POST is used to create a new resource, not to retrieve a list; using POST for retrieval violates REST principles and the Meraki API specification. Option C is wrong because /networks is not a valid top-level endpoint; the Meraki API requires the organization ID to scope the request, as networks are always associated with an organization. Option D is wrong because PUT is used to update an existing resource, not to retrieve a list; it would either fail or be interpreted incorrectly by the API.

129
MCQhard

In a network automation workflow, a developer needs to ensure idempotency. What does idempotency mean in this context?

A.The script uses a single API call
B.Running the script once produces the same result as running it multiple times
C.The script can recover from failures
D.The script can run on multiple devices simultaneously
AnswerB

Idempotency means repeated execution converges on the same end state without duplicating changes, because the tool compares desired configuration against current device state. This satisfies the workflow's requirement that reruns after partial failure remain safe.

Why this answer

Idempotency in network automation means that executing an operation multiple times results in the same network state as executing it once. For example, using a REST API PUT request to set a VLAN configuration will leave the device in the same state whether the request is sent once or repeatedly, because PUT is inherently idempotent. This prevents unintended side effects like duplicate VLANs or interface misconfigurations when a script is retried due to network failures or timeouts.

Exam trap

Cisco often tests idempotency by pairing it with failure recovery or concurrency, hoping candidates confuse idempotency with fault tolerance or parallel execution.

How to eliminate wrong answers

Option A is wrong because a single API call does not guarantee idempotency; for instance, a POST request that creates a resource is not idempotent and can create duplicates. Option C is wrong because failure recovery (e.g., retry logic or rollback) is a separate reliability concern, not a definition of idempotency; idempotency ensures safe retries but does not itself handle recovery. Option D is wrong because running a script on multiple devices simultaneously relates to parallelism or concurrency, not idempotency; idempotency applies per-operation regardless of the number of targets.

130
MCQhard

An automation engineer is writing a Python script that uses the ncclient library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The device requires SSH and uses the default NETCONF port. Which code snippet correctly establishes a NETCONF session and retrieves the configuration?

A.from ncclient import manager with manager.connect(host='10.1.1.1', port=22, username='admin', password='pass', hostkey_verify=False) as m: config = m.get_config(source='running')
B.from ncclient import manager with manager.connect(host='10.1.1.1', port=830, username='admin', password='pass', hostkey_verify=False) as m: config = m.get(source='running')
C.from ncclient import manager with manager.connect(host='10.1.1.1', port=830, username='admin', password='pass', hostkey_verify=False) as m: config = m.get_config(source='running')
D.from ncclient import manager with manager.connect(host='10.1.1.1', port=22, username='admin', password='pass', hostkey_verify=False) as m: config = m.get(source='running')
AnswerC

This snippet correctly uses port 830, the default for NETCONF over SSH. It establishes a connection with manager.connect and retrieves the running configuration using get_config with source='running'. The hostkey_verify=False is often used in lab environments to bypass host key checking.

Why this answer

NETCONF over SSH uses port 830 by default. The ncclient library provides manager.connect to establish a session and get_config to retrieve configuration data. The source parameter specifies the datastore, such as 'running'.

Using the correct port and method ensures successful communication with the device.

Exam trap

The trap here is assuming that NETCONF uses the standard SSH port 22, when in fact it uses port 830 by default.

131
MCQeasy

An engineer needs to modify the running configuration of a Cisco IOS-XE device using a protocol that is stateless and uses HTTP methods. Which protocol should be used?

A.NETCONF
B.SNMP
C.RESTCONF
D.CLI
AnswerC

RESTCONF is stateless and uses HTTP methods such as GET, POST, PATCH and DELETE to manipulate the running configuration. NETCONF is stateful and uses SSH transport, while SNMP and NETCONF do not match the HTTP-method requirement.

Why this answer

RESTCONF is the correct choice because it is a stateless protocol that uses standard HTTP methods (GET, POST, PUT, PATCH, DELETE) to manipulate YANG-defined data stores on a Cisco IOS-XE device. Unlike NETCONF, which is stateful and session-oriented, RESTCONF operates over HTTP without maintaining session state, making it ideal for lightweight, RESTful automation.

Exam trap

Cisco often tests the distinction between NETCONF and RESTCONF, where candidates mistakenly choose NETCONF because it is more familiar for network automation, but the question specifically requires a stateless protocol using HTTP methods, which only RESTCONF satisfies.

How to eliminate wrong answers

Option A is wrong because NETCONF is a stateful protocol that relies on SSH or TLS and uses RPC-based operations, not stateless HTTP methods. Option B is wrong because SNMP uses UDP and a manager-agent model with GET/SET/TRAP operations, not HTTP methods, and is not designed for modifying running configurations via RESTful APIs. Option D is wrong because CLI (Command-Line Interface) is a human-interactive interface that does not use HTTP methods and is not a protocol for programmatic, stateless configuration management.

132
Multi-Selecthard

A network engineer is troubleshooting an Ansible playbook that targets Cisco IOS XE devices over SSH. The playbook connects successfully but fails when applying configuration, and the engineer suspects the connection plugin and transport settings. Which TWO actions should the engineer take to verify and correct the connection configuration? (Choose two.)

Select 2 answers
A.Confirm that ansible_connection is set to network_cli for the device group.
B.Increase the ansible_port value to 830 to enable configuration over SSH.
C.Verify that ansible_network_os is set to ios for the IOS XE hosts.
D.Configure ansible_become_method to enable and use sudo on the device.
E.Set ansible_connection to local and run all modules on the control node.
AnswersA, C

Network devices are not managed like Linux hosts with an SSH shell that Ansible can script arbitrarily. The network_cli connection plugin opens an interactive CLI session, handles prompts, and enables the platform-specific modules to push configuration. If the connection is left at the default ssh or paramiko setting, configuration modules may load but fail to apply changes because they cannot drive the device CLI correctly.

Why this answer

Network automation with Ansible requires the network_cli connection plugin and a correct ansible_network_os value so the right terminal and module behavior is selected. Using the local connection, switching to the NETCONF port, or applying Linux privilege escalation semantics all misrepresent how IOS XE devices are managed. Confirming the connection type and platform identifier addresses the most common causes of successful login but failed configuration.

Exam trap

The trap here is treating a network device like a Linux host, assuming local execution or sudo-style escalation applies, when network_cli and enable mode are required.

← PreviousPage 2 of 2 · 132 questions total

Ready to test yourself?

Try a timed practice session using only Infrastructure and Automation questions.