Courseiva

CCNA Infra Automation Questions

75 of 132 questions · Page 1/2 · Infra Automation topic · Answers revealed

1
MCQmedium

A company uses Ansible to automate configuration of its Cisco IOS XE routers. The network team recently upgraded the routers' software from IOS 15.x to IOS XE 17.x. Since the upgrade, the Ansible playbook fails intermittently with the message: 'Failed to connect to the host via ssh: timed out'. However, the team can SSH manually to the routers from the Ansible control node without issues. The playbook uses the 'cisco.ios.ios_config' module with default SSH options. The routers have been configured with SSH version 2 and local authentication. The Ansible control node runs Red Hat Enterprise Linux 8. Which action should the network engineer take to resolve the issue?

A.Increase the SSH timeout in the Ansible configuration file (ansible.cfg) to 60 seconds.
B.Configure the routers to use SSH version 1 only.
C.Set the 'host_key_checking' option to False in ansible.cfg.
D.Use the 'ios_command' module instead of 'ios_config' to perform the tasks.
AnswerA

IOS XE 17.x introduces slower SSH negotiation, so Ansible's default connection timeout expires before authentication completes, while manual SSH succeeds because it waits longer. Raising the timeout in ansible.cfg lets the cisco.ios.ios_config module complete the handshake.

Why this answer

The intermittent SSH timeout after upgrading to IOS XE 17.x is likely due to slower key exchange algorithms (e.g., diffie-hellman-group-exchange-sha256) that increase connection setup time. Increasing the SSH timeout in ansible.cfg (e.g., setting timeout=60) gives the SSH handshake enough time to complete, avoiding the timeout. Forcing SSHv1 is not recommended as it is deprecated and may not be supported.

Host key checking (option C) does not affect timeout, and using a different module (option D) does not solve the underlying connectivity issue.

Exam trap

Candidates may think SSH timeout is always due to network latency or firewall drops, but it can be caused by slower cryptographic handshakes in newer IOS XE versions. Increasing SSH timeout is a simple fix.

How to eliminate wrong answers

Option A is wrong because increasing the SSH timeout in ansible.cfg would only mask the symptom; the underlying cause is the slow SSH key exchange negotiation, not a general timeout setting. Option C is wrong because disabling host_key_checking only skips the verification of the remote host's SSH key fingerprint; it does not affect the SSH transport layer timeout or the speed of the cryptographic handshake. Option D is wrong because the ios_command module also uses the same SSH transport and would experience the identical timeout issue; the problem is not specific to the ios_config module.

2
MCQhard

A DevOps team manages network infrastructure using Infrastructure as Code (IaC). They store configuration files in a Git repository and use CI/CD to deploy changes. What is the best practice to ensure that only validated configurations are applied to production devices?

A.Require a pull request with at least one approval before merging to the main branch
B.Allow any team member to push directly to the main branch after testing locally
C.Use a manual approval gate in the CI/CD pipeline that requires manager sign-off
D.Automate the deployment of every commit directly to production
AnswerA

Branch protection requiring an approving pull request gates merges, so unvalidated configuration never reaches the main branch that CI/CD deploys from. This enforces peer review before production devices receive changes, satisfying the constraint that only validated configurations are applied.

Why this answer

Requiring a pull request with at least one approval before merging to the main branch enforces peer review and validation of configuration changes. This ensures that only code that has been reviewed for correctness, syntax, and adherence to standards is merged, preventing erroneous or malicious configurations from reaching production via the CI/CD pipeline.

Exam trap

The trap here is that candidates may confuse a manual approval gate (Option C) with a technical validation step, but Cisco tests the understanding that peer code review (via pull requests) is the best practice for ensuring configuration correctness in IaC, not managerial sign-off.

How to eliminate wrong answers

Option B is wrong because allowing direct pushes to the main branch bypasses any review or validation, risking the deployment of untested or erroneous configurations. Option C is wrong because a manual approval gate by a manager does not guarantee technical validation of the configuration; it adds a non-technical bottleneck without ensuring code correctness. Option D is wrong because automating deployment of every commit directly to production eliminates all validation gates, making it impossible to catch errors before they impact production devices.

3
MCQmedium

A network automation engineer uses Terraform to manage Cisco Catalyst Center (formerly DNA Center) resources. What is the purpose of the Cisco Catalyst Center Terraform provider?

A.To execute a series of CLI commands on network devices in sequence
B.To write imperative scripts that configure network devices via SSH
C.To directly manage routers and switches without using Catalyst Center
D.To define and manage network infrastructure resources in a declarative state file
AnswerD

The Catalyst Center Terraform provider exposes network infrastructure as declarative resources, letting the engineer define intended device, site and template configuration in HCL state files rather than imperative API calls. Terraform reconciles actual Catalyst Center state against that declared configuration, satisfying the stem's requirement to manage resources through Terraform's declarative workflow.

Why this answer

The Cisco Catalyst Center Terraform provider allows network automation engineers to define and manage network infrastructure resources in a declarative state file. Terraform uses a desired-state approach where the configuration file describes the intended end state of resources, and the provider communicates with Catalyst Center's REST API to enforce that state, enabling idempotent and version-controlled infrastructure management.

Exam trap

The trap here is that candidates often confuse Terraform's declarative, API-driven model with imperative scripting or CLI-based automation, leading them to select options that describe procedural SSH or CLI workflows instead of recognizing the provider's role as an abstraction layer over Catalyst Center's REST API.

How to eliminate wrong answers

Option A is wrong because executing a series of CLI commands on network devices in sequence describes a procedural automation approach (e.g., using Ansible or a Python script with Netmiko), not the declarative, API-driven model of Terraform. Option B is wrong because writing imperative scripts that configure network devices via SSH is a traditional, non-declarative method that lacks Terraform's state management and idempotency; Terraform does not use SSH for device configuration. Option C is wrong because the Terraform provider for Catalyst Center does not directly manage routers and switches; it manages resources through Catalyst Center's northbound REST API, which in turn orchestrates device configurations via protocols like NETCONF or CLI.

4
MCQmedium

A developer is building a Python script that authenticates to the Cisco DNA Center REST API. The script must avoid hardcoding credentials in source control and must run unattended in a CI pipeline. The team already stores secrets in environment variables on the build agent. Which approach best meets these requirements?

A.Store the credentials in a plaintext YAML file in the repository and load it with a relative path.
B.Embed the username and password as string literals in the script and commit it to a private Git repository.
C.Prompt the operator for credentials with input() each time the pipeline executes.
D.Read the credentials with os.environ at runtime and pass them to the DNA Center authentication endpoint to obtain a token.
AnswerD

Pulling credentials from environment variables keeps them out of the codebase while allowing the script to run unattended, because the CI agent injects the values at execution time. The script then authenticates to the DNA Center token endpoint and uses the returned token for subsequent calls, which matches both the security and automation requirements.

Why this answer

Credentials supplied through environment variables let the same script run locally and in CI without modification, and they never land in the repository. The script authenticates against the DNA Center token service and reuses the resulting token for the API calls it needs, satisfying both the secrecy and unattended-execution constraints.

Exam trap

The trap here is assuming that a private repository or a separate config file makes stored credentials safe, when any committed secret is still exposed and violates the no-hardcoding requirement.

5
MCQmedium

A developer writes a Python script using Cisco's pyATS framework to test network reachability after a configuration change. What is a key advantage of using pyATS over a simple script that uses ping?

A.pyATS requires less code than a ping script
B.pyATS can test multiple devices in parallel
C.pyATS allows writing reusable test scripts with built-in test libraries
D.pyATS automatically generates test reports
AnswerC

pyATS provides reusable test scripts with built-in libraries such as Genie, offering structured parsing, assertions and reporting across devices. A plain ping script returns only reachability output, so pyATS satisfies the stem's need for maintainable, repeatable post-change verification rather than ad hoc checks.

Why this answer

PyATS is a test automation framework designed for network engineers, providing built-in test libraries (e.g., `pyats.aetest`) that enable writing reusable, modular test scripts. Unlike a simple ping script, pyATS supports structured test cases, data-driven testing, and integration with Cisco devices via libraries like `Genie`, allowing for comprehensive validation beyond basic reachability.

Exam trap

The trap here is that candidates confuse pyATS's parallel execution capability (which is achievable with other tools) with its core value proposition of providing a structured, reusable test framework with built-in libraries for network-specific validation.

How to eliminate wrong answers

Option A is wrong because pyATS typically requires more code to set up test infrastructure (e.g., testbed files, test cases) compared to a simple ping script, which can be a single line. Option B is wrong because while pyATS can test multiple devices in parallel, this is not a unique advantage—a simple script using threading or asyncio can also achieve parallel pings; the key advantage is the framework's test management and reusability. Option D is wrong because pyATS does not automatically generate test reports; it provides libraries to create custom reports (e.g., via `pyats.log` or integration with tools like `ATS`), but report generation requires explicit implementation.

6
MCQhard

In a CI/CD pipeline for network automation, a change is rolled back using a Git revert commit that triggers a new pipeline. The rollback playbook fails because the 'previous' configuration snapshot is missing. What should be implemented to prevent this?

A.Use a single source of truth like NetBox
B.Store configuration backups in a version-controlled repository before each change
C.Use the 'check mode' only
D.Disable rollback pipelines
AnswerB

A revert commit restores the previous configuration, but only if that snapshot was captured beforehand. Committing configuration backups to a version-controlled repository before each change guarantees the prior state exists and can be reapplied by the rollback pipeline.

Why this answer

Storing configuration backups in a version-controlled repository before each change ensures that a known-good 'previous' snapshot is always available for rollback, even if the Git revert commit only reverts the playbook code and not the device configuration. In CI/CD for network automation, the pipeline must have access to the exact prior state to restore it; version-controlled backups provide an immutable, auditable history that can be checked out by commit hash. This directly prevents the failure described, where the rollback playbook cannot find the previous configuration snapshot.

Exam trap

The trap is assuming that a Git revert of the playbook code is sufficient for rollback; candidates often overlook that the actual device configuration state must also be versioned and retrievable, not just the automation code.

How to eliminate wrong answers

Option A is wrong because a single source of truth like NetBox stores intended state, not necessarily the actual running configuration snapshots needed for rollback; it does not guarantee that a previous configuration can be restored. Option C is wrong because 'check mode' only simulates changes and does not create or store backups, so it cannot provide a rollback snapshot. Option D is wrong because disabling rollback pipelines removes the safety net entirely and does not solve the missing snapshot problem; it increases risk rather than preventing the failure.

7
MCQeasy

A CI/CD pipeline for network automation includes stages for linting, unit testing, and deployment. Which stage typically validates the syntax of Ansible playbooks?

A.Integration testing stage
B.Deployment stage
C.Unit testing stage
D.Linting stage
AnswerD

Linting parses Ansible playbooks with tools such as ansible-lint or yamllint, flagging syntax errors, malformed YAML and deprecated constructs before execution. This satisfies the pipeline's syntax-validation requirement, since unit testing exercises logic and deployment applies configuration, neither of which checks playbook syntax beforehand.

Why this answer

Linting is the stage that validates syntax and style for code or configuration files. In a CI/CD pipeline for network automation, the linting stage uses tools like `ansible-lint` to check Ansible playbooks for syntax errors, best practices, and idempotency issues before any testing or deployment occurs.

Exam trap

Cisco often tests the distinction between linting (syntax/style checks) and unit testing (functional correctness of code), leading candidates to mistakenly choose unit testing for syntax validation.

How to eliminate wrong answers

Option A is wrong because integration testing validates the interaction between components (e.g., network devices and Ansible modules) after deployment, not syntax. Option B is wrong because the deployment stage applies the playbook to production or staging environments, assuming syntax is already correct. Option C is wrong because unit testing validates individual functions or modules in isolation (e.g., Python unit tests for custom modules), not the YAML syntax of Ansible playbooks.

8
Multi-Selecteasy

Which TWO Ansible modules are commonly used for automating Cisco IOS devices?

Select 2 answers
A.junos_config
B.nxos_command
C.ios_config
D.ios_command
E.eos_config
AnswersC, D

Manages Cisco IOS configuration.

Why this answer

The `ios_config` module is correct because it is specifically designed to manage Cisco IOS device configurations by sending configuration commands via SSH or Telnet, using the CLI to apply changes to the running or startup configuration. This module is part of Ansible's `cisco.ios` collection and directly supports the IOS operating system, making it the standard choice for automating configuration tasks on Cisco IOS devices.

Exam trap

Cisco often tests the candidate's ability to distinguish between device-specific Ansible modules (e.g., `ios_config` vs. `nxos_command`) rather than generic command modules, so the trap here is assuming that any 'command' module works across all Cisco platforms, when in fact each OS family (IOS, NX-OS, IOS-XR) has its own dedicated modules in the Ansible collections.

9
MCQeasy

A network engineer wants to automate the configuration of multiple Cisco IOS devices using Ansible. What is the minimum requirement on the control node to execute Ansible playbooks against these devices?

A.Ansible Tower license for automated network configuration
B.A PostgreSQL database to store inventory and credentials
C.A dedicated management server with Ansible Tower installed
D.A Linux or macOS control node with Python installed
AnswerD

Ansible runs agentlessly from a control node, which must be Linux or macOS with Python installed; no agent is needed on managed Cisco IOS devices. This satisfies the minimum control-node requirement for executing playbooks over SSH or network APIs.

Why this answer

Ansible uses a push-based architecture where the control node must be a Linux or macOS system with Python installed to execute playbooks. Python is required because Ansible itself is written in Python and relies on it for modules, SSH connections, and Jinja2 templating. No additional database, license, or dedicated management server is needed for basic network automation against Cisco IOS devices.

Exam trap

Cisco often tests the misconception that Ansible requires a dedicated server or commercial product like Ansible Tower, when in fact the minimum requirement is simply a Linux/macOS host with Python and the Ansible package installed.

How to eliminate wrong answers

Option A is wrong because Ansible Tower (now Red Hat Ansible Automation Platform) is a commercial web UI and API layer that adds RBAC, scheduling, and auditing, but it is not a minimum requirement; the open-source Ansible Engine can run playbooks directly from any control node. Option B is wrong because a PostgreSQL database is only required if you use Ansible Tower's inventory and credential storage; the default flat-file inventory and SSH keys or vault-encrypted credentials work without any database. Option C is wrong because a dedicated management server with Ansible Tower installed is an enterprise deployment pattern, not a minimum requirement; a standard Linux or macOS workstation with Ansible installed via pip or package manager suffices.

10
Drag & Dropmedium

Drag and drop the steps to configure OSPF on a Cisco router into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

OSPF configuration requires enabling the OSPF process, setting a router ID, and advertising networks in specific areas.

11
MCQeasy

An engineer needs to automate the backup of configuration files from multiple Cisco IOS devices to a central server. Which protocol is most appropriate for pushing configurations from the devices to the server?

B.FTP
D.SCP
AnswerD

SCP runs over SSH, providing encrypted, authenticated file transfer from IOS devices to a central server. Cisco IOS supports SCP natively via the archive or copy commands, satisfying the requirement to push configuration files securely.

Why this answer

SCP (Secure Copy Protocol) is the most appropriate choice because it provides encrypted, authenticated file transfers over SSH, ensuring the confidentiality and integrity of Cisco IOS configuration backups. It is natively supported on Cisco IOS devices and allows secure push operations to a central server without requiring additional software.

Exam trap

Cisco often tests the distinction between secure and insecure file transfer protocols in automation contexts, and the trap here is that candidates may choose TFTP due to its simplicity and common use in lab environments, overlooking the security requirements for production backups.

How to eliminate wrong answers

Option A is wrong because TFTP lacks any security mechanisms (no encryption or authentication) and is typically used for local network transfers like booting or initial configs, not for secure backups to a central server. Option B is wrong because FTP transmits credentials and data in cleartext and requires complex firewall configurations, making it insecure and less suitable for automated, secure backups. Option C is wrong because HTTP is not designed for file transfers in this context; it is stateless and insecure without HTTPS, and Cisco IOS devices do not natively support HTTP-based config push operations to a server.

12
Multi-Selecthard

Which TWO statements accurately describe characteristics of infrastructure as code (IaC) in network automation?

Select 2 answers
A.IaC eliminates the need for manual review of configuration changes before deployment.
B.IaC requires that all network devices be replaced with software-based equivalents.
C.IaC is only applicable to virtual network functions, not physical devices.
D.IaC tools use declarative or imperative models to define the desired state of network infrastructure.
E.IaC allows network configurations to be stored in version control and tested before deployment.
AnswersD, E

Declarative models specify the intended end state and let the tool reconcile differences, while imperative models issue explicit step-by-step commands. Both are genuine IaC approaches, so this statement correctly captures how IaC defines network infrastructure desired state rather than relying on manual configuration.

Why this answer

Option D is correct because IaC tools such as Terraform, Ansible, and Puppet/Chef operate on either declarative models (defining the desired end state, e.g., Terraform HCL) or imperative models (defining step-by-step commands, e.g., shell scripts), so both paradigms are valid ways to express the intended state of network infrastructure. Option E is correct because a core IaC practice is treating configuration as code: storing templates and playbooks in version control systems like Git, enabling peer review, diffing, and automated testing (e.g., CI pipelines, linters, and unit/integration tests) before pushing changes to production devices. Option A is wrong because IaC does not remove human review; change control, pull-request approvals, and validation remain essential safeguards even when automation applies the change.

Option B is wrong because IaC manages existing physical and virtual devices via APIs, SSH, NETCONF, or CLI—it does not require replacing hardware with software equivalents. Option C is wrong because IaC applies broadly to physical routers, switches, firewalls, and other appliances, not only to virtual network functions.

Exam trap

Cisco often tests the misconception that IaC is only for virtual or cloud environments, when in fact it is designed to manage any programmable network device, including physical hardware, via standard interfaces like NETCONF/RESTCONF.

13
MCQhard

A developer is building a Python application that calls the Cisco DNA Center Intent API to retrieve device health. The application must handle pagination and rate limiting gracefully. After receiving an HTTP 429 response, which action should the application take?

A.Read the Retry-After header and wait that many seconds before retrying the request.
B.Switch from HTTPS to HTTP to bypass the rate limiting mechanism.
C.Delete the existing authentication token and request a new one to reset the rate limit counter.
D.Immediately resend the same request in a tight loop until a 200 response is received.
AnswerA

An HTTP 429 indicates the client exceeded a rate limit, and well-behaved APIs include a Retry-After header specifying how long to wait. Honoring that value avoids hammering the service and prevents escalating throttling. This is the correct, standards-aligned response for the Cisco DNA Center Intent API and similar REST APIs.

Why this answer

When an API returns 429, the client must back off according to the server's Retry-After header rather than retrying aggressively or trying to evade the limit. Immediate retries, transport downgrades, and token rotation do not address the throttling and can worsen it. Respecting Retry-After is the standard, reliable way to recover from rate limiting against the Cisco DNA Center Intent API.

Exam trap

The trap here is treating a 429 like a transient network error that can be fixed by immediate retries, when it actually signals a deliberate throttle that requires honoring Retry-After.

14
MCQeasy

A developer wants to automate the configuration of multiple Cisco IOS-XE devices using Ansible. Which protocol should be used to ensure secure and idempotent configuration updates?

AnswerB

Ansible's ios_config and related modules connect over SSH, which IOS-XE supports natively and encrypts credentials and configuration traffic. SSH also underpins the idempotent module workflow, so repeated playbook runs converge devices to the declared state without insecure Telnet.

Why this answer

SSH (Secure Shell) is the correct protocol because it provides encrypted, authenticated remote access to Cisco IOS-XE devices, which is essential for secure automation. Ansible uses SSH to connect to network devices and execute configuration commands idempotently by comparing the desired state (defined in playbooks) against the current device state, ensuring only necessary changes are applied without duplication or disruption.

Exam trap

Cisco often tests the distinction between protocols used for monitoring (SNMP) versus those used for secure configuration management (SSH), and candidates may mistakenly choose SNMP because they associate it with network management, overlooking that Ansible specifically requires an interactive, secure shell for idempotent configuration pushes.

How to eliminate wrong answers

Option A (Telnet) is wrong because it transmits data in plaintext, including credentials and configuration commands, offering no encryption or security, and is not recommended for any production automation. Option C (SNMP) is wrong because it is primarily used for monitoring and retrieving device metrics (e.g., via MIBs), not for pushing idempotent configuration updates; SNMP Set operations are unreliable and lack the transactional, state-based idempotency that Ansible requires. Option D (HTTP) is wrong because it is unencrypted and insecure for configuration management; while HTTPS could be used with RESTCONF/NETCONF, the question specifies Ansible, which relies on SSH for network device automation, and HTTP alone does not provide the secure, idempotent configuration capabilities needed.

15
MCQmedium

A developer must build a Python script that reads a list of devices from a YAML inventory file and then pushes configuration to each device using NETCONF over SSH. The script must be reusable and must not hardcode credentials. Which approach best satisfies these requirements?

A.Use paramiko to open an interactive SSH shell and type configuration commands into the CLI prompt.
B.Use the requests library to POST XML configuration directly to the device management IP on port 830.
C.Use the ncclient library and hardcode the device list and credentials inside the script for simplicity.
D.Use the ncclient library, load the inventory with PyYAML, and retrieve credentials from environment variables.
AnswerD

ncclient is the standard Python library for NETCONF sessions and supports SSH transport. PyYAML parses the inventory file without hardcoding device data. Reading credentials from environment variables keeps secrets out of source code, which satisfies the reusability and security requirements described in the scenario.

Why this answer

The scenario requires a NETCONF client, a YAML parser, and externalized credentials. ncclient provides the NETCONF over SSH capability, PyYAML reads the inventory, and environment variables keep secrets out of the code. Together these choices meet both the protocol and the reusability requirements without embedding sensitive data.

Exam trap

The trap here is assuming that any SSH-based library can speak NETCONF, when NETCONF requires specific XML framing and capability negotiation that generic SSH tools do not provide.

16
MCQeasy

A network engineer is using Ansible to automate the configuration of a Cisco IOS XE device. The playbook must ensure that a specific banner is present on the device. Which Ansible module should the engineer use to accomplish this task in a vendor-supported way?

A.ios_banner
B.ios_user
C.ios_command
D.ios_config
AnswerA

The ios_banner module is specifically designed to manage banners on Cisco IOS devices. It allows you to configure the login, motd, exec, and other banners with idempotent behavior. This module is part of the cisco.ios collection and is the vendor-supported way to ensure a banner is present. Using it simplifies the playbook and ensures proper handling of device interactions.

Why this answer

Ansible provides vendor-specific modules for Cisco IOS, and the ios_banner module is designed to manage banner configurations. It ensures idempotency and handles the proper syntax for banners. While ios_config could push banner lines, it is less specialized and may not be idempotent without additional logic.

Using ios_banner is the recommended and supported approach for this task.

Exam trap

The trap here is thinking that ios_config is always the go-to module for any configuration, when specialized modules like ios_banner exist for specific tasks.

17
MCQmedium

A developer is writing a Python script that authenticates to Cisco DNA Center using the token-based authentication API. The script must obtain a token and reuse it for subsequent REST calls until it expires. Which HTTP header should the script include in each subsequent API request to pass the token?

A.X-Auth-Token: <token>
B.Cookie: session=<token>
C.Authorization: Bearer <token>
D.X-Cisco-Token: <token>
AnswerA

Cisco DNA Center returns an authentication token in the response body when you POST to /dna/system/api/v1/auth/token with Basic Auth credentials. That token must then be supplied in the X-Auth-Token HTTP header on every subsequent API call. This is the documented and required header for token-based authentication with DNA Center, making it the correct choice for the script.

Why this answer

Cisco DNA Center's token-based authentication flow returns a token from the /auth/token endpoint, and that token must be presented in the X-Auth-Token header for all subsequent API requests. Other common authentication headers like Authorization: Bearer or custom cookie schemes are not recognized by DNA Center. Using the correct header ensures the script can reuse the token until it expires, avoiding repeated authentication calls.

Exam trap

The trap here is assuming that DNA Center follows the standard OAuth 2.0 Bearer token pattern, when it actually uses a custom X-Auth-Token header.

18
MCQeasy

A DevOps team manages a hybrid cloud environment with on-premises Cisco Nexus switches and AWS VPCs using Terraform. They have a configuration management tool that pushes VLAN and interface configurations to the Nexus switches. Recently, they noticed that after a Terraform run that updates the AWS VPC subnets, some on-premises switches lose connectivity to the cloud. The team suspects a mismatch between the VLAN configurations on the Nexus switches and the AWS VPC subnets. They have a centralized source of truth stored in a Git repository containing YAML files for network definitions. Which action should the team take first to resolve the issue and prevent future occurrences?

A.Restore the Nexus switch configurations from the most recent backup.
B.Modify the Terraform scripts to automatically update Nexus switches when AWS VPC subnets change.
C.Compare the Git repository's YAML definitions with the actual switch configurations and AWS VPC subnets, then correct any discrepancies.
D.Manually reconfigure the VLANs on the Nexus switches to match the AWS VPC subnets.
AnswerC

Reconciling the Git YAML source of truth against live Nexus and AWS VPC state exposes the VLAN/subnet mismatch causing connectivity loss. This satisfies the requirement to identify the drift first before applying any corrective automation.

Why this answer

The team's centralized source of truth in Git (YAML files) should be the authoritative reference for network definitions. By comparing these definitions against both the actual Nexus switch configurations and AWS VPC subnets, the team can identify and correct any drift or mismatch. This aligns with Infrastructure as Code (IaC) best practices, ensuring that all environments are synchronized from a single, version-controlled source before making any changes.

Exam trap

The trap here is that candidates may assume the immediate fix is to restore or manually reconfigure the switches (options A or D), rather than first validating the source of truth (Git) to identify the root cause of the mismatch, which is a core DevOps principle of treating infrastructure as code.

How to eliminate wrong answers

Option A is wrong because restoring from a backup does not address the root cause of the mismatch; it may reintroduce outdated configurations that do not match the current AWS VPC subnets, and it ignores the centralized Git repository as the source of truth. Option B is wrong because modifying Terraform scripts to automatically update Nexus switches would bypass the configuration management tool and the Git-based source of truth, potentially causing further inconsistencies and breaking the separation of concerns between cloud provisioning and on-premises network management. Option D is wrong because manually reconfiguring VLANs on the Nexus switches is error-prone, not scalable, and does not leverage the Git repository as the single source of truth, making it impossible to prevent future occurrences through automation and version control.

19
MCQeasy

A network automation engineer is writing a YAML playbook to push a banner configuration to a group of Cisco IOS XE routers. The engineer wants to use an agentless tool that connects over SSH and requires no software installed on the managed devices. Which tool fits this description?

A.Ansible
B.Chef Infra Client running on each router
C.A custom Bash script using scp to copy configuration files
D.Puppet with a master-agent architecture
AnswerA

Ansible is agentless by design: it connects to managed nodes over SSH, pushes modules and playbooks from the control node, and requires no long-running agent on the target. For Cisco IOS XE it uses modules such as ios_config to apply banner and other configuration. This matches every constraint in the scenario, including the YAML playbook format.

Why this answer

Ansible satisfies the agentless, SSH-based, YAML-driven requirements in one tool. Its ios_config and related modules push configuration changes to Cisco IOS XE devices without installing anything on them, and playbooks express the desired banner state declaratively. Competing configuration management tools rely on agents that cannot run on the routers themselves.

Exam trap

The trap here is treating Puppet or Chef as equally agentless because both can target network devices indirectly, when their standard architectures depend on an installed agent that Cisco routers do not host.

20
MCQeasy

A network automation engineer needs to retrieve the current interface configuration from a Cisco IOS XE device using RESTCONF. The device has RESTCONF enabled and the engineer wants to read the configuration data for interfaces in the 'ietf-interfaces' model. Which HTTP method and URL format should the engineer use?

A.GET https://device/restconf/data/ietf-interfaces:interfaces
B.GET https://device/restconf/operational/ietf-interfaces:interfaces
C.POST https://device/restconf/data/ietf-interfaces:interfaces
D.GET https://device/restconf/config/ietf-interfaces/interfaces
AnswerA

RESTCONF uses HTTP GET to read data, and the data resource is addressed under /restconf/data/ followed by the module name and a colon, then the container path. This URL matches the standard RESTCONF structure for retrieving the interfaces container from the ietf-interfaces YANG module, so it returns the requested configuration data.

Why this answer

RESTCONF maps YANG models to HTTP resources. To read configuration or state data, use GET with a URL rooted at /restconf/data/, followed by the module name and a colon, then the data node path. The ietf-interfaces module defines the interfaces container, so the correct URL is GET https://device/restconf/data/ietf-interfaces:interfaces.

Exam trap

The trap here is confusing RESTCONF's data path with NETCONF datastores or older draft URLs that used /restconf/config/ or /restconf/operational/.

21
MCQeasy

A YANG module defines a leaf named 'bandwidth' of type 'uint32'. What does this represent in the context of a network device?

A.A set of unique bandwidth values
B.A single integer value representing bandwidth in kilobits per second
C.A grouping of related bandwidth parameters
D.An ordered list of bandwidth values
AnswerB

A YANG leaf of type uint32 holds exactly one unsigned 32-bit integer, so 'bandwidth' represents a single scalar value rather than a list or container. The stem's constraint is the leaf keyword, which always models one atomic instance, here the interface's bandwidth expressed in kilobits per second.

Why this answer

In YANG, a 'leaf' node defines a single, scalar value of a specific data type. When the leaf is named 'bandwidth' with type 'uint32', it represents a single integer value, typically interpreted as kilobits per second (kbps) in the context of network device configuration (e.g., interface bandwidth). This aligns with the standard YANG data modeling approach where a leaf cannot hold multiple values or complex structures.

Exam trap

Cisco often tests the distinction between a 'leaf' (single value) and a 'leaf-list' (multiple values), so the trap here is that candidates may confuse a leaf with a list or container, especially when the leaf name 'bandwidth' might imply multiple possible values.

How to eliminate wrong answers

Option A is wrong because a 'leaf' in YANG cannot represent a set of unique values; sets are modeled using 'leaf-list' or 'list' nodes, not a single leaf. Option C is wrong because a grouping of related parameters is defined using a 'container' or 'grouping' statement in YANG, not a leaf. Option D is wrong because an ordered list of values is modeled with a 'leaf-list' (which can have ordered-by user or system), not a single leaf of type uint32.

22
MCQmedium

A network engineer is automating the deployment of VLANs across multiple switches using Ansible. The playbook fails with an error indicating that the VLAN ID already exists on one of the switches. Which approach should the engineer use to ensure the playbook completes without errors?

A.Modify the playbook to skip switches where the VLAN already exists.
B.Remove the VLAN from all switches before creating it again.
C.Use an idempotent Ansible module that checks for existing VLANs before creating them.
D.Add ignore_errors: yes to the VLAN creation task.
AnswerC

Idempotent modules such as ios_vlan query existing VLAN configuration before applying changes, so a pre-existing VLAN ID produces no error and no duplicate. This satisfies the requirement that the playbook complete successfully across switches with differing current state.

Why this answer

Ansible's idempotent modules, such as `ios_vlan` for Cisco IOS devices, are designed to check the current state of the device before making changes. If the VLAN already exists, the module will report 'ok' and not attempt to create it again, preventing the error and ensuring the playbook completes successfully. This aligns with Ansible's best practice of writing idempotent playbooks that produce the same result regardless of how many times they are run.

Exam trap

Cisco often tests the concept of idempotency in automation tools like Ansible, and the trap here is that candidates may think 'ignore_errors' is a valid workaround for configuration conflicts, when in fact it only hides failures without ensuring the desired state is achieved.

How to eliminate wrong answers

Option A is wrong because skipping switches where the VLAN already exists would require manual or dynamic inventory logic that is not built into a simple playbook; it would also defeat the purpose of automation by not ensuring consistent VLAN configuration across all switches. Option B is wrong because removing the VLAN from all switches before recreating it would cause unnecessary network disruption and downtime, violating the principle of minimal change in network automation. Option D is wrong because adding `ignore_errors: yes` would mask the error but not resolve the underlying issue; the VLAN creation task would still fail on the switch where the VLAN exists, and the playbook would continue without correcting the configuration, potentially leading to an inconsistent state.

23
MCQmedium

During an automation script run, a network device returns HTTP 429. What does this indicate?

A.Internal server error
B.Rate limiting
C.Authentication failure
D.Resource not found
AnswerB

HTTP 429 is the standard 'Too Many Requests' status code, returned when a client exceeds the server's permitted request rate within a given window. It directly signals rate limiting, satisfying the stem's scenario of an automation script being throttled by the network device.

Why this answer

HTTP 429 (Too Many Requests) indicates the client has sent too many requests in a given amount of time, triggering rate limiting on the server. In network automation, devices like routers or switches enforce rate limits to prevent resource exhaustion, often based on RFC 6585. This is common when automation scripts exceed API call thresholds, requiring retry logic with exponential backoff.

Exam trap

Cisco often tests HTTP 429 to distinguish it from HTTP 503 (Service Unavailable), which is a server overload but not specifically a client rate limit, and candidates may confuse the two due to both involving temporary unavailability.

How to eliminate wrong answers

Option A is wrong because HTTP 500 (Internal Server Error) indicates a server-side failure, not a client-side request limit. Option C is wrong because authentication failures return HTTP 401 (Unauthorized) or 403 (Forbidden), not 429. Option D is wrong because resource not found returns HTTP 404, which is unrelated to request throttling.

24
MCQmedium

A developer writes a Python script that calls the Cisco DNA Center Intent API. The script must authenticate once and reuse the returned token on subsequent requests instead of sending credentials with every call. Which HTTP header should the script include on each API request to present the token?

A.Content-Type: application/json
B.Authorization: Basic <base64-credentials>
C.X-Auth-Token: <token>
D.Cookie: session=<token>
AnswerC

Cisco DNA Center's authentication endpoint returns a token that clients must present in the X-Auth-Token request header on subsequent API calls. This avoids re-sending credentials and lets the controller validate the session quickly. The header name is case-insensitive per HTTP, but the exact spelling matters for clarity and for tools that generate requests from documentation examples.

Why this answer

After authenticating to the DNA Center Intent API, clients receive a token that must be sent in the X-Auth-Token header on every subsequent request. Basic credentials, cookies, and content type headers serve different purposes and do not carry the issued token. Reusing the token reduces credential exposure and matches how the controller expects stateless API calls to be authorized.

Exam trap

The trap here is assuming the token behaves like an OAuth bearer token placed in the Authorization header, when DNA Center uses its own X-Auth-Token header.

25
MCQmedium

A developer is building a Python script to configure a Cisco IOS XE device using NETCONF. The script must send an <edit-config> RPC that places the target datastore in candidate mode, changes the description of GigabitEthernet0/0, and commits the change. Which NETCONF capability must the device advertise for the script to use the candidate datastore?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:rollback-on-error:1.0
C.urn:ietf:params:netconf:capability:writable-running:1.0
D.urn:ietf:params:netconf:capability:validate:1.0
AnswerA

The candidate capability allows a client to edit a candidate datastore and then commit those changes to the running datastore. Because the script edits the candidate and commits, the device must advertise this capability. Without it, the client cannot use <edit-config> with a candidate target or issue <commit>, so this is the required capability for the described workflow.

Why this answer

The candidate capability is required because the script edits a candidate datastore and then commits the change to running. NETCONF capabilities are advertised in the server's <hello> message; a client must check for the candidate capability before using <edit-config> with a candidate target and <commit>. Rollback-on-error, validate, and writable-running serve different purposes and do not enable the candidate datastore workflow.

Exam trap

The trap here is assuming that any edit-config operation requires the candidate capability, when in fact only workflows that explicitly target the candidate datastore and commit need it.

26
Multi-Selecthard

Which THREE are benefits of using YANG as a data modeling language for network automation? (Select exactly 3.)

Select 3 answers
A.Enables validation of data constraints before applying changes
B.Allows direct execution of CLI commands on any device
C.Provides a standard way to define configuration and state data
D.Supports multiple serialization formats like JSON and XML
E.Promotes interoperability between different vendor devices
AnswersA, C, E

Why this answer

YANG (RFC 6020/7950) allows you to define data constraints such as ranges, mandatory elements, and type restrictions directly in the model. When you attempt to apply configuration via NETCONF or RESTCONF, the server validates the data against these constraints before committing, preventing invalid changes from being applied.

Exam trap

Cisco often tests the distinction between the data modeling language (YANG) and the transport protocols (NETCONF/RESTCONF) or serialization formats (JSON/XML), so the trap here is confusing the benefits of the model itself with the features of the protocols that use it.

27
Multi-Selectmedium

Which TWO methods are commonly used to discover network devices in an automation environment? (Select exactly 2.)

Select 2 answers
A.Manually entering device details into a spreadsheet
B.Using SNMP to bulk-configure devices
C.Monitoring DHCP logs to lease IP addresses to new devices
D.Using LLDP or CDP to retrieve directly connected neighbor information
E.Using a centralized controller like Cisco DNA Center to query device inventory
AnswersD, E

Why this answer

LLDP (IEEE 802.1AB) and CDP (Cisco Discovery Protocol) are Layer 2 protocols that allow network devices to advertise their identity, capabilities, and directly connected neighbors. In automation environments, these protocols enable dynamic discovery of the network topology without manual intervention, making them essential for automated inventory and mapping.

Exam trap

Cisco often tests the distinction between discovery protocols (LLDP/CDP) and management protocols (SNMP), so candidates may mistakenly think SNMP is used for discovery when it is actually used for reading MIBs after discovery is complete.

28
MCQmedium

A network administrator is tasked with automating the deployment of a new VLAN configuration across a fabric of Cisco ACI switches. Which automation tool is best suited for interacting with the APIC REST API?

A.Bash scripting with curl
B.Chef
C.Puppet
D.Ansible
AnswerD

Ansible provides a native Cisco ACI module that interacts directly with the APIC REST API, letting the administrator declaratively push VLAN configuration across the fabric. It satisfies the automation requirement without bespoke scripting, unlike manual CLI or generic tools lacking ACI-aware modules.

Why this answer

Ansible is the best-suited tool because it provides a dedicated module (cisco.aci.aci_rest) that directly interacts with the APIC REST API, allowing declarative automation of VLAN and other ACI configurations. Unlike generic scripting, Ansible abstracts the HTTP requests and handles idempotency, authentication, and error handling natively for the ACI fabric.

Exam trap

Cisco often tests the misconception that any scripting tool (like Bash with curl) is sufficient for automation, but the key is choosing a tool with native, purpose-built modules for the specific API, not just the ability to make HTTP requests.

How to eliminate wrong answers

Option A is wrong because Bash scripting with curl is a low-level, manual approach that requires writing custom code for every API call, lacks idempotency, and does not provide the structured, reusable automation framework needed for consistent ACI deployments. Option B is wrong because Chef is a configuration management tool designed for node-based infrastructure (e.g., servers) and does not have native modules or resources for interacting with the Cisco APIC REST API; it would require extensive custom scripting. Option C is wrong because Puppet, like Chef, is primarily a configuration management tool for server nodes and lacks built-in support for the ACI APIC REST API, making it inefficient for automating network fabric configurations.

29
MCQeasy

What is the default transport protocol for NETCONF sessions?

AnswerB

NETCONF uses SSH as its default transport, running over TCP port 830 to provide an encrypted, authenticated channel for configuration and state retrieval. TLS is optional rather than default, so SSH satisfies the stem's requirement.

Why this answer

NETCONF (Network Configuration Protocol) uses SSH as its default transport protocol, as specified in RFC 6242. SSH provides the required secure, authenticated, and encrypted channel for NETCONF sessions, ensuring confidentiality and integrity of configuration data exchanged between the client and server.

Exam trap

Cisco often tests the distinction between 'default' and 'optional' transports, so the trap here is that candidates may confuse TLS (which is supported but not default) with the mandatory SSH transport, or assume HTTP is used because NETCONF is XML-based and HTTP is commonly associated with XML APIs.

How to eliminate wrong answers

Option A is wrong because HTTP is not a transport protocol for NETCONF; NETCONF over HTTP is not defined in any standard, and HTTP lacks the built-in encryption and authentication required for secure network device configuration. Option C is wrong because TLS is an optional transport for NETCONF (as per RFC 7589), not the default; the default remains SSH, and TLS is used only when explicitly configured. Option D is wrong because SNMP is a separate protocol for network management and monitoring, not a transport for NETCONF; SNMP uses UDP or TCP, but it does not carry NETCONF messages.

30
Multi-Selectmedium

A developer is writing a Python script that will authenticate to a Cisco DNA Center controller and then call multiple REST API endpoints. The script must handle authentication securely and manage the token lifecycle. Which two practices should the developer follow? (Choose two.)

Select 2 answers
A.Store the username and password in environment variables or a secrets manager rather than in the script.
B.Disable TLS certificate verification to simplify HTTPS calls to the controller.
C.Reuse the authentication token for all subsequent API calls until it expires, then obtain a new one.
D.Call the authentication endpoint before every API request to guarantee a fresh token.
E.Hardcode the token in the script to avoid repeated authentication calls during development.
AnswersA, C

Credentials embedded in source code can leak through version control, logs, or shared repositories. Reading them from environment variables or a secrets manager keeps them out of the codebase and supports rotation. This is a foundational secure coding practice for API automation.

Why this answer

Secure automation requires protecting credentials and managing tokens efficiently. Storing secrets outside the code prevents leaks, and reusing a valid token until expiration avoids unnecessary authentication calls. The other options either weaken security or add avoidable overhead that can trigger rate limits.

Exam trap

The trap here is treating authentication as something to repeat for every call, when tokens are meant to be cached and reused until they expire.

31
MCQeasy

A network automation engineer needs to ensure that a Python script can securely store and retrieve API credentials for Cisco DNA Center without hardcoding them in the script. Which method is the most appropriate?

A.Embed the credentials directly in the Python script as constants.
B.Use environment variables to hold the credentials and access them via os.environ in the script.
C.Store the credentials in a YAML file that is committed to the same Git repository as the script.
D.Store the credentials in a plain text file on the local filesystem and read them at runtime.
AnswerB

Environment variables are a common and secure way to inject secrets into applications at runtime. They are not stored in the codebase and can be managed by the operating system or container orchestration. This approach keeps credentials out of source control and allows different environments to use different values.

Why this answer

Using environment variables keeps credentials out of source code and allows them to be managed securely by the deployment environment. This is a widely accepted practice for handling secrets in automation scripts. It avoids the risks of hardcoding or storing secrets in version control, and it supports different credentials per environment.

Exam trap

The trap here is assuming that storing credentials in a file within the repository is acceptable as long as it is not the main script, but version control exposure remains a critical risk.

32
Multi-Selecteasy

Which TWO are valid capabilities advertised during a NETCONF session?

Select 2 answers
A.urn:ietf:params:netconf:capability:url:1.0
B.urn:ietf:params:netconf:capability:writable-running:2.0
C.urn:ietf:params:netconf:capability:validate:2.0
D.urn:ietf:params:netconf:base:1.0
E.urn:ietf:params:netconf:capability:interleave:1.0
AnswersA, D

This is the URL capability for NETCONF.

Why this answer

The URL capability (urn:ietf:params:netconf:capability:url:1.0) is a standard NETCONF capability that allows a client to specify a URL as the source or target of operations like <copy-config> or <edit-config>. Option D is correct because urn:ietf:params:netconf:base:1.0 is the mandatory base capability that every NETCONF session must advertise, as defined in RFC 6241, indicating support for the core NETCONF protocol operations.

Exam trap

Cisco often tests the exact version numbers of NETCONF capabilities, and the trap here is that candidates assume all capabilities use version 2.0 (confusing them with YANG module revisions or other protocols), but in reality, the standard NETCONF capabilities defined in RFC 6241 are all version 1.0.

33
MCQhard

A developer is building a Python application that consumes the Cisco Meraki Dashboard API. The application must handle rate limiting gracefully when it performs many calls in a short period. Which response should the application check to determine that it has exceeded the rate limit and must wait before retrying?

A.HTTP 403 Forbidden
B.HTTP 401 Unauthorized
C.HTTP 429 Too Many Requests
D.HTTP 503 Service Unavailable
AnswerC

The Meraki Dashboard API returns HTTP 429 when a client exceeds the allowed call rate. A well-behaved client should inspect this status, read the Retry-After header when present, and pause before retrying. Handling 429 explicitly prevents the application from hammering the API and being throttled further.

Why this answer

Meraki enforces per-organization call limits and communicates throttling with the 429 Too Many Requests status. The application should catch that status, honor any Retry-After header, and back off before retrying. Authentication and permission errors use different codes, and server outages use 503, so only 429 correctly identifies rate limiting.

Exam trap

The trap here is confusing throttling with authorization or availability failures and retrying on the wrong status code.

34
MCQeasy

In the Ansible playbook snippet, what connection method is typically used for the ios_config module to communicate with the devices?

A.local
B.network_cli
C.netconf
D.httpapi
AnswerB

The ios_config module runs on the control node but targets Cisco IOS devices over SSH, so the playbook uses the network_cli connection plugin, which handles CLI prompt and privilege escalation rather than a local or API-based transport.

Why this answer

The ios_config module is designed for Cisco IOS devices and requires a persistent network connection to send configuration commands. The network_cli connection method establishes an SSH session that remains open for the duration of the playbook task, allowing the module to send multiple CLI commands and handle prompts. This is the recommended connection method for ios_config because it supports privilege escalation and command responses needed for configuration changes.

Exam trap

Cisco often tests the distinction between connection methods by making candidates think 'local' is correct because it runs on the control node, but the trap is that ios_config requires a persistent SSH session to the device, which only network_cli provides.

How to eliminate wrong answers

Option A is wrong because 'local' connection runs the module on the control node without opening a persistent SSH session to the device, which prevents ios_config from properly handling interactive prompts and privilege escalation. Option C is wrong because 'netconf' uses XML-based NETCONF protocol over SSH, which is not supported by the ios_config module (it is used with the ios_netconf module instead). Option D is wrong because 'httpapi' uses RESTCONF or other HTTP-based APIs, which are not applicable to the CLI-based ios_config module.

35
MCQhard

Refer to the exhibit. Based on the YANG model snippet, what is the data type of the 'mask' leaf?

A.inet:ipv4-address
B.inet:ipv4-prefix-length
C.uint8
D.string
AnswerB

The `mask` leaf is typed as `inet:ipv4-prefix-length`, a YANG built-in derived type restricting values to 0–32. This satisfies the exhibit's requirement for a subnet mask length rather than a dotted-decimal address, since the type enforces an integer prefix length consistent with the model's IPv4 addressing constraint.

Why this answer

The 'mask' leaf is defined with the type 'inet:ipv4-prefix-length', which represents a decimal integer from 0 to 32 indicating the number of leading 1 bits in the subnet mask (e.g., 24 for /24). This is the correct data type for a prefix length in YANG models, not an IPv4 address or a generic string.

Exam trap

Cisco often tests the distinction between 'inet:ipv4-address' (a full address) and 'inet:ipv4-prefix-length' (the /N notation), tricking candidates who confuse the subnet mask value with its prefix length representation.

How to eliminate wrong answers

Option A is wrong because 'inet:ipv4-address' is a dotted-decimal IPv4 address (e.g., 192.168.1.1), not a prefix length. Option C is wrong because 'uint8' is a generic 8-bit unsigned integer (0-255) but lacks the semantic constraint of 0-32 that 'inet:ipv4-prefix-length' enforces. Option D is wrong because 'string' would allow arbitrary text, which is not appropriate for a numeric prefix length that must be validated as an integer between 0 and 32.

36
MCQmedium

A company uses a centralized automation server that runs Ansible playbooks. What is the best security practice for storing SSH credentials?

A.Store credentials in a public repository
B.Use Ansible Vault
C.Hardcode credentials in playbooks
D.Use plain text inventory files
AnswerB

Ansible Vault encrypts sensitive variables and files at rest using AES-256, so SSH credentials are never stored as plaintext on the centralised automation server. This satisfies the stem's requirement for secure credential storage within playbook workflows.

Why this answer

Ansible Vault is the recommended security practice for encrypting sensitive data like SSH credentials. It allows you to store encrypted variables and files within your playbooks or inventory, protecting secrets at rest while enabling decryption at runtime via a password or key file. This avoids exposing credentials in plain text, which is critical for centralized automation servers that may be accessed by multiple users or integrated into CI/CD pipelines.

Exam trap

Cisco often tests the misconception that 'inventory files are safe if stored locally' or that 'hardcoding is acceptable for small teams,' but the exam expects candidates to recognize that any plain text storage of credentials violates security best practices, and Ansible Vault is the standard built-in solution for encryption.

How to eliminate wrong answers

Option A is wrong because storing credentials in a public repository exposes them to unauthorized access, violating the principle of least privilege and potentially leading to security breaches. Option C is wrong because hardcoding credentials in playbooks embeds secrets in plain text within version control, making them visible to anyone with repository access and preventing easy rotation. Option D is wrong because using plain text inventory files stores SSH credentials unencrypted, which is insecure and defeats the purpose of a centralized automation server that should enforce encryption at rest.

37
MCQhard

A developer is writing a unit test for a Python function that calls the Cisco DNA Center API to fetch device health. The test must not perform real network calls and should verify that the function parses a sample JSON response correctly. Which approach best satisfies these requirements?

A.Increase the requests timeout value and retry on failure so the test tolerates slow DNA Center responses.
B.Run the test against a live Cisco DNA Center sandbox and assert that the returned health values are non-empty.
C.Point the function at a recorded HTTP proxy that replays previously captured DNA Center responses.
D.Use the unittest.mock library to patch the function's requests call so it returns a mock response object whose json method yields the sample data.
AnswerD

Patching the HTTP call with unittest.mock prevents real network traffic and lets the test supply a controlled response object. The function under test then exercises its parsing logic against known JSON, producing deterministic results. This isolates the unit under test and satisfies both the no-network and parsing-verification requirements.

Why this answer

Unit tests should isolate the code under test from external systems. Patching the HTTP call with unittest.mock replaces the real request with a mock response containing sample JSON, so the parsing logic is exercised deterministically without any network traffic. Proxies, live sandboxes, and retry tuning all leave real calls in place.

Exam trap

The trap here is equating 'no live production system' with 'no network calls', when even a replay proxy or sandbox still makes real HTTP requests that break unit-test isolation.

38
Multi-Selectmedium

A network automation solution uses YANG data models to describe network configurations. Which THREE statements about YANG are true? (Select THREE)

Select 3 answers
A.YANG can be used in conjunction with NETCONF and RESTCONF.
B.YANG models are always written in XML syntax.
C.YANG is used to define both configuration and state data.
D.YANG is a data modeling language used to define the structure of data.
E.YANG is a replacement for SNMP.
AnswersA, C, D

Both protocols use YANG models.

Why this answer

YANG is a data modeling language that defines the structure and constraints of configuration and state data, and it is designed to be used with NETCONF (RFC 6241) and RESTCONF (RFC 8040) as the transport protocols. This makes option A correct because YANG models are encoded in XML or JSON and exchanged via these protocols.

Exam trap

Cisco often tests the misconception that YANG is tied to a specific encoding (like XML) or that it replaces SNMP entirely, when in fact YANG is encoding-agnostic and complements SNMP by providing structured, transactional configuration management.

39
MCQmedium

A developer is writing a Python script that authenticates to a Cisco IOS XE device using NETCONF over SSH on port 830. The script must send a candidate configuration and commit it atomically. Which NETCONF capability must the device advertise for the script to use the candidate datastore?

A.urn:ietf:params:netconf:capability:writable-running:1.0
B.urn:ietf:params:netconf:capability:candidate:1.0
C.urn:ietf:params:netconf:capability:rollback-on-error:1.0
D.urn:ietf:params:netconf:capability:validate:1.1
AnswerB

The candidate capability URI is exactly what signals the device supports a separate candidate datastore that can be edited, validated, and committed atomically. Without this capability in the hello message, the client cannot legally target <candidate/> in edit-config or issue a commit, so the script would fail. Advertising this capability is a prerequisite for the transactional workflow the developer requires.

Why this answer

The candidate datastore capability is the only one that introduces a separate staging area plus a commit operation, enabling atomic configuration changes. Writable-running, rollback-on-error, and validate are separate capabilities that do not create a candidate store. When a NETCONF client must edit offline and commit transactionally, the hello message must include the candidate capability URI before the client can target candidate in edit-config.

Exam trap

The trap here is assuming that rollback-on-error or validate implies a candidate datastore, when in fact candidate is its own distinct capability URI that must be advertised independently.

40
Multi-Selecteasy

An engineer is automating the configuration of SNMP on Cisco routers using Ansible. Which two modules are commonly used for this purpose? (Select TWO)

Select 2 answers
A.cisco.ios.ios_interface
B.cisco.ios.ios_config
C.cisco.ios.ios_snmp_server
D.cisco.ios.ios_command
E.cisco.ios.ios_banner
AnswersB, C

The cisco.ios.ios_config module pushes arbitrary configuration lines, including SNMP commands such as snmp-server community and snmp-server host, to Cisco IOS devices. It satisfies the automation constraint by applying raw CLI snippets idempotently over SSH, letting Ansible configure SNMP without a dedicated SNMP-specific module.

Why this answer

The cisco.ios.ios_config module is correct because it allows you to push raw CLI configuration lines to Cisco IOS devices, including SNMP-related commands like 'snmp-server community' or 'snmp-server host'. The cisco.ios.ios_snmp_server module is correct because it is a dedicated Ansible module that provides structured, idempotent management of SNMP server settings (e.g., communities, hosts, traps) without requiring raw CLI lines.

Exam trap

Cisco often tests the distinction between general-purpose modules like ios_config and purpose-built modules like ios_snmp_server, expecting candidates to recognize that both can configure SNMP but the dedicated module is more appropriate for structured automation.

41
MCQhard

Refer to the exhibit. A developer receives this response when making a POST request to the Cisco DNA Center API to create a new device. What is the most likely issue?

A.The request body is missing the required field 'ipAddress'.
B.The API endpoint is incorrect.
C.The device IP address is already in use.
D.The API token has expired.
AnswerA

Cisco DNA Center validates the JSON payload against its schema, and a missing mandatory attribute such as ipAddress triggers a 400 error naming that field. The response therefore indicates the body omitted a required property rather than an authentication or endpoint fault.

Why this answer

The error response includes a field 'missingParameters' with the value 'ipAddress', which explicitly indicates that the request body did not include the required 'ipAddress' field. Cisco DNA Center's API for device creation requires this field to identify the device on the network. Without it, the API cannot proceed with adding the device, resulting in a 400 Bad Request.

Exam trap

Cisco often tests the ability to read API error responses carefully, where candidates might overlook the 'missingParameters' field and incorrectly assume a token or endpoint issue instead of a missing required field.

How to eliminate wrong answers

Option B is wrong because the API endpoint is likely correct; a wrong endpoint would typically return a 404 Not Found or a different error message, not a 'missingParameters' error. Option C is wrong because if the IP address were already in use, the API would return a conflict error (e.g., 409 Conflict) with a message like 'Device already exists', not a missing field error. Option D is wrong because an expired token would result in a 401 Unauthorized or 403 Forbidden response, not a 400 Bad Request with parameter validation details.

42
MCQhard

In a CI/CD pipeline for network changes, which practice best ensures that a configuration push does not disrupt production traffic?

A.Disable rollback
B.Canary deployment
C.Push all changes at once
D.Skip validation
AnswerB

Canary deployment pushes the configuration to a small subset of devices first, allowing traffic impact to be observed before fleet-wide rollout. This limits blast radius, satisfying the requirement that a configuration push does not disrupt production traffic.

Why this answer

Canary deployment is the correct practice because it gradually introduces the configuration change to a small subset of devices or traffic before full rollout. This allows monitoring for adverse effects and automatic rollback if issues arise, minimizing the risk of production disruption. In a CI/CD pipeline for network changes, this approach aligns with incremental validation and risk mitigation.

Exam trap

Cisco often tests the misconception that 'push all changes at once' is efficient and safe, but the trap here is that it ignores the principle of incremental risk reduction, which is fundamental to CI/CD best practices for network automation.

How to eliminate wrong answers

Option A is wrong because disabling rollback removes the safety net to revert a failed configuration push, increasing the risk of prolonged disruption. Option C is wrong because pushing all changes at once maximizes the blast radius and makes it difficult to isolate the cause of any failure. Option D is wrong because skipping validation bypasses critical checks (e.g., syntax, reachability, or policy compliance), which can directly cause misconfigurations that disrupt traffic.

43
Multi-Selectmedium

A developer is writing a Python script to interact with a Cisco IOS XE device using the NETCONF protocol. The script must retrieve the running configuration and then modify it. Which two actions must the script perform to establish a NETCONF session and retrieve the running configuration? (Choose two.)

Select 2 answers
A.Open an SSH session to the device on port 830 and exchange <hello> messages.
B.Send a <get> RPC with a filter of <config/> to retrieve the running configuration.
C.Send a <get-config> RPC with a <source> of <running/> to retrieve the running configuration.
D.Authenticate using the NETCONF username and password over HTTPS on port 443.
E.Use the <copy-config> RPC to copy the running datastore to a local file.
AnswersA, C

NETCONF uses SSH as its transport, and the default port is 830. After the SSH connection is established, the server and client exchange <hello> messages to advertise capabilities and session IDs. This handshake is mandatory before any RPCs can be sent, so opening the SSH session and exchanging hellos is a required step.

Why this answer

To establish a NETCONF session, the client opens an SSH connection to port 830 and exchanges <hello> messages with the server. Once the session is established, the client can send RPCs. To retrieve the running configuration, the client sends a <get-config> RPC with <source><running/></source>.

The other options either use the wrong RPC, the wrong transport, or an operation that does not read configuration into the session.

Exam trap

The trap here is confusing NETCONF with RESTCONF, leading to assumptions about HTTPS and port 443, or mixing up the <get> and <get-config> RPCs.

44
MCQeasy

A network automation team wants to run a Python script that uses the ncclient library to retrieve configuration from a Cisco IOS XE device over NETCONF. The device is reachable on TCP port 830. Which transport and port combination must the script use?

A.HTTP transport on TCP port 80
B.SSH transport on TCP port 22
C.SSH transport on TCP port 830
D.TLS transport on TCP port 6513
AnswerC

NETCONF runs over an SSH subsystem and Cisco IOS XE listens on TCP port 830 for NETCONF sessions. The ncclient library's connect method uses the SSH transport by default, so specifying port 830 with SSH is the correct combination for retrieving configuration from the device.

Why this answer

NETCONF on Cisco IOS XE is exposed as an SSH subsystem on TCP port 830. The ncclient library negotiates the SSH transport and then exchanges XML capabilities and RPCs. Using SSH on the NETCONF port is the documented combination, so the script must target TCP 830 rather than the standard CLI port or a TLS-based alternative.

Exam trap

The trap here is confusing the standard SSH CLI port 22 with the dedicated NETCONF-over-SSH port 830, which serve different services on the same device.

45
MCQmedium

An engineer is tasked with automating the backup of running configurations from 50 routers. Which approach is most scalable?

A.SSH manually to each router and copy config
B.Schedule a cron job on each router to SCP config
C.Use SNMP to capture config
D.Use an Ansible playbook with ios_config backup
AnswerD

Ansible's ios_config module with the backup parameter retrieves running configurations from each device and stores them locally, using SSH rather than screen-scraping. Executing one playbook against a 50-router inventory satisfies the scalability constraint, since parallel host execution replaces 50 manual sessions, and Microsoft Entra ID integration is unnecessary for device-level CLI automation.

Why this answer

An Ansible playbook with the ios_config module's backup option is the most scalable approach because it uses a push-based automation model that can manage all 50 routers from a single control node, leveraging SSH for secure transport and idempotent configuration management without requiring any agent on the routers.

Exam trap

Cisco often tests the misconception that SNMP can be used for configuration backup, but SNMP is designed for read-only monitoring of OIDs, not for retrieving or storing entire configuration files, which requires a file transfer or CLI-based method.

How to eliminate wrong answers

Option A is wrong because manually SSHing to each router is not scalable for 50 devices, introduces human error, and defeats the purpose of automation. Option B is wrong because scheduling a cron job on each router to SCP the config requires individual configuration on every device, does not centralize management, and still relies on per-router setup, which is not scalable. Option C is wrong because SNMP is designed for monitoring and retrieving MIB data, not for capturing full running configurations; it lacks the ability to reliably back up the entire configuration file and is not a standard method for configuration backup.

46
MCQeasy

A junior developer is writing a Python script to gather interface statistics from a Cisco IOS-XE device using NETCONF. They use the 'ncclient' library and successfully connect. They want to retrieve the operational status of all interfaces. Which YANG model and XPATH expression should they use to get the operational data?

A.Model: ietf-interfaces, XPATH: /interfaces-state/interface
B.Model: cisco-native, XPATH: /native/interface
C.Model: ietf-interfaces, XPATH: /interfaces/interface
D.Model: ietf-interfaces, XPATH: /interfaces-state
AnswerA

Interfaces-state contains operational data per IETF standard.

Why this answer

The 'ietf-interfaces' YANG model defines the '/interfaces-state' container specifically for operational state data (e.g., status, counters), as per RFC 7223. The XPATH '/interfaces-state/interface' retrieves the list of all interfaces with their operational status, which is exactly what the developer needs. The 'ncclient' library can filter using this XPATH to get read-only operational data from a NETCONF-enabled Cisco IOS-XE device.

Exam trap

Cisco often tests the distinction between configuration and operational data in YANG models, and the trap here is that candidates confuse '/interfaces/interface' (configuration) with '/interfaces-state/interface' (operational state), or they pick a too-broad XPATH like '/interfaces-state' instead of the specific list node.

How to eliminate wrong answers

Option B is wrong because 'cisco-native' is a proprietary Cisco model for configuration data, not operational state, and '/native/interface' would return configured interfaces, not their operational status. Option C is wrong because '/interfaces/interface' under 'ietf-interfaces' targets the configuration container, which holds intended settings, not operational state (status, counters). Option D is wrong because '/interfaces-state' is the correct container, but the XPATH is too broad—it returns the entire container rather than the list of interfaces; the developer needs '/interfaces-state/interface' to get each interface's operational data.

47
MCQmedium

A developer is writing a Python script that uses the ncclient library to configure a Cisco IOS XE device over NETCONF. The script must push a candidate configuration, validate it, and then commit it atomically. Which sequence of NETCONF operations should the script use to guarantee the configuration is only applied if it passes validation?

A.get-config, edit-config with the candidate datastore, then discard-changes
B.edit-config with the running datastore, validate, then commit
C.lock the running datastore, edit-config with the running datastore, then unlock
D.edit-config with the candidate datastore, validate, then commit
AnswerD

The candidate datastore allows a configuration to be staged without affecting the running configuration. After edit-config loads the candidate, the validate operation checks syntax and constraints, and commit applies it atomically. This sequence ensures the change is applied only if validation succeeds, which matches the requirement for validated, atomic deployment.

Why this answer

NETCONF separates staging from activation through the candidate datastore and the commit operation. Loading the candidate with edit-config, validating it, and then committing ensures the configuration is syntactically and semantically correct before it becomes active, and the commit is atomic. This is the standard approach for safe, transactional configuration changes on devices that support the candidate capability.

Exam trap

The trap here is assuming that validate must be called after commit, or that the running datastore supports transactional commit like the candidate datastore does.

48
Multi-Selecthard

Which THREE practices help ensure idempotent network automation? (Select three)

Select 3 answers
A.Using the 'state' parameter in Ansible modules to define desired state
B.Using a transactional approach (e.g., configure candidate and commit)
C.Running commands multiple times to ensure they are applied
D.Checking the current state before applying changes
E.Always appending new configuration commands to the running config
AnswersA, B, D

This ensures the module only takes action if the current state does not match the desired state.

Why this answer

Using the 'state' parameter in Ansible modules (e.g., 'state: present' or 'state: absent') explicitly declares the desired end state of a resource. This allows the module to compare the current state against the desired state and only make changes if necessary, ensuring that running the playbook multiple times produces the same result without unintended side effects.

Exam trap

Cisco often tests the misconception that simply running a command multiple times or appending configuration ensures idempotency, when in fact true idempotency requires state checking and declarative desired-state definitions.

49
MCQmedium

A developer is writing a Python script that uses the Meraki Dashboard API to page through a very large organization's list of network devices. The developer wants to iterate through all pages of results without manually constructing page URLs. Which approach should be used?

A.Send a POST request to the devices endpoint with a body containing a startingIndex field that the API uses to return the next slice.
B.Send a single GET request and read the HTTP Link response header to follow the next page URL until no Link header is returned.
C.Send a single GET request with the query parameter perPage set to the organization's total device count so all devices return in one response.
D.Rely on the X-RateLimit-Remaining response header; when it reaches zero, the API automatically returns the next page of devices.
AnswerB

The Meraki Dashboard API returns pagination metadata in the HTTP Link response header, using rel="next" to point at the following page. A client that reads this header and keeps following the next URL will traverse every page without hand-building offsets or page numbers, which is exactly what the scenario requires.

Why this answer

Meraki paginates large collections and advertises the subsequent page through the HTTP Link response header with rel="next". A client that inspects headers and follows that URL iterates the entire collection robustly, which is the documented pattern for traversing large result sets. Approaches that assume a single oversized page, misuse POST, or repurpose rate-limit headers all fail to advance through the data.

Exam trap

The trap here is assuming pagination is controlled by a query parameter or rate-limit header rather than by the Link response header that Meraki actually returns.

50
MCQeasy

An automation engineer is using the Cisco DNA Center REST API to retrieve a list of network devices. The API call returns HTTP status code 200. What does this indicate?

A.The request succeeded but no content is returned.
B.The request was created successfully.
C.The request was successful and data is returned.
D.The request failed due to a client error.
AnswerC

HTTP 200 means the request succeeded and the response body carries the requested device list, satisfying the engineer's goal of retrieving devices via the Cisco DNA Center REST API. Other 2xx codes also signal success, but 200 specifically confirms data is returned.

Why this answer

HTTP status code 200 indicates a successful GET request where the server has processed the request and is returning the requested data in the response body. In the context of the Cisco DNA Center REST API, a 200 response to a GET /network-device call means the list of network devices was successfully retrieved and is included in the response payload.

Exam trap

Cisco often tests the distinction between 200 OK and 204 No Content, expecting candidates to know that 200 always includes a response body while 204 explicitly does not, even though both are successful.

How to eliminate wrong answers

Option A is wrong because HTTP 200 does not mean 'no content' — that is indicated by status code 204 (No Content), which is used for successful requests that intentionally return no body. Option B is wrong because a 201 (Created) status code indicates successful creation of a resource, not a retrieval; 200 is used for successful GET, PUT, or DELETE operations that return data. Option D is wrong because client errors are represented by 4xx status codes (e.g., 400 Bad Request, 401 Unauthorized), not 2xx success codes.

51
MCQmedium

A network automation engineer is writing a Python script to configure multiple devices. Which library is most appropriate for SSH-based interactions?

A.requests
B.socket
C.Netmiko
D.paramiko
AnswerC

Netmiko abstracts SSH transport for multi-vendor network devices, handling prompt detection and enable-mode escalation that raw Paramiko requires manually. It satisfies the stem's SSH-based interaction constraint across multiple device types, unlike RESTCONF or SNMP libraries.

Why this answer

Netmiko is a Python library built on top of Paramiko that simplifies SSH connections to network devices. It provides high-level methods for sending commands, handling prompts, and managing device interactions, making it the most appropriate choice for automating configuration tasks across multiple devices.

Exam trap

Cisco often tests the distinction between Paramiko (a general SSH library) and Netmiko (a network-device-specific library built on Paramiko), leading candidates to choose Paramiko because they recognize it as an SSH library without considering the higher-level abstractions Netmiko provides for network automation.

How to eliminate wrong answers

Option A is wrong because the requests library is designed for HTTP/HTTPS API calls, not for SSH-based interactions. Option B is wrong because the socket library provides low-level network communication primitives and lacks the SSH protocol handling needed for device configuration. Option D is wrong because while Paramiko is a valid SSH library, it requires manual handling of authentication, channel management, and command output parsing, making it less suitable than Netmiko for multi-device automation scenarios.

52
MCQmedium

Based on the exhibit, which interface is in a state that prevents it from sending or receiving IP traffic?

A.GigabitEthernet0/2
B.GigabitEthernet0/0
C.GigabitEthernet0/1
D.None of the interfaces are down
AnswerC

It is administratively down, so no traffic can pass.

Why this answer

Interface GigabitEthernet0/1 is in the 'administratively down' state, as indicated by the 'down' status in the 'Status' column and the 'down' in the 'Protocol' column. This means the interface has been manually disabled with the 'shutdown' command, preventing it from sending or receiving any IP traffic. In contrast, interfaces that are 'up/up' can forward traffic, while 'up/down' indicates a Layer 1 issue but still allows Layer 2 control plane traffic.

Exam trap

Cisco often tests the distinction between 'administratively down' (Status: down) and 'up/down' (Status: up, Protocol: down), where candidates mistakenly assume any 'down' protocol means no IP traffic is possible, but only the administratively down state explicitly prevents all traffic due to manual shutdown.

How to eliminate wrong answers

Option A is wrong because GigabitEthernet0/2 shows 'up' in both Status and Protocol columns, meaning it is fully operational and can send/receive IP traffic. Option B is wrong because GigabitEthernet0/0 shows 'up' in Status and 'down' in Protocol, indicating a Layer 1 connectivity issue (e.g., no cable or faulty transceiver) but the interface is not administratively disabled; it still attempts to send/receive Layer 2 frames, though IP traffic may fail due to the protocol being down. Option D is wrong because GigabitEthernet0/1 is indeed in a state that prevents IP traffic (administratively down), so not all interfaces are operational.

53
Multi-Selectmedium

Which TWO of the following are characteristics of a declarative automation model? (Select exactly 2.)

Select 2 answers
A.It requires procedural scripts
B.You specify the desired end state
C.Idempotency is not a concern
D.The tool handles ordering and dependencies
E.You specify the exact steps to achieve the state
AnswersB, D

Declarative models require the operator to define the intended end state, such as interfaces up with specific VLANs, leaving the tool to reconcile actual against desired. This contrasts with imperative models that list sequential commands.

Why this answer

Option B is correct because a declarative automation model is defined by describing the desired end state (for example, a Terraform HCL resource block or an Ansible task declaring 'state: present'), and the tool then works out how to reach that state. Option D is correct because in declarative tools the engine itself determines execution order and resolves dependencies, such as Terraform building a dependency graph from resource references or Ansible handling task ordering and handlers. Option A is incorrect because procedural scripts are the hallmark of imperative, not declarative, automation.

Option C is incorrect because idempotency is a core concern and benefit of declarative models, ensuring repeated runs converge to the same state without unwanted changes. Option E is incorrect because specifying exact steps is the defining trait of an imperative model, whereas declarative models specify the outcome, not the steps.

Exam trap

Cisco often tests the distinction between declarative and imperative models by presenting options that sound plausible but reverse the roles, such as confusing 'specify the end state' with 'specify the exact steps', or assuming idempotency is irrelevant in declarative models.

54
Multi-Selectmedium

Which TWO of the following are benefits of using NETCONF over SNMP for network automation? (Select exactly 2.)

Select 2 answers
A.Structured data models (YANG)
B.Lower CPU usage on devices
C.Binary data encoding
D.Transactional configuration changes
E.Simple polling mechanism
AnswersA, D

YANG provides standardised, hierarchical data models that NETCONF encodes in XML, giving automation tools machine-readable schema and validation. SNMP's flat MIB structure and opaque OIDs cannot express configuration intent this precisely, satisfying the structured-model benefit.

Why this answer

Option A is correct because NETCONF uses YANG data models to define configuration and state data in a structured, hierarchical, vendor-neutral way, which is far more suitable for programmatic automation than SNMP's flat MIB/OID model. Option D is correct because NETCONF supports transactional configuration changes via candidate datastores, commit, confirmed-commit, and rollback-on-error, so a set of edits either fully applies or is rolled back, unlike SNMP SET operations which are not transactionally grouped. Option B is not a defining benefit of NETCONF over SNMP; NETCONF over SSH can actually be more resource-intensive than lightweight SNMP polling, and CPU usage depends on implementation.

Option C is wrong because NETCONF typically uses XML (text) encoding, not binary encoding, while SNMP can use BER binary encoding. Option E is wrong because simple polling is characteristic of SNMP monitoring, whereas NETCONF is designed for configuration management and uses RPC-based sessions, not simple polling.

Exam trap

Cisco often tests the misconception that NETCONF is 'lighter' than SNMP, but the trap here is that NETCONF's XML and SSH overhead actually increase CPU usage, while SNMP's binary encoding and UDP make it more efficient for simple monitoring tasks.

55
Multi-Selectmedium

A developer is building a Python script that consumes a REST API exposed by a Cisco controller. The script must authenticate using a token obtained from a login endpoint and then call protected resources. Which TWO practices are appropriate for handling authentication and session state in this script? (Choose two.)

Select 2 answers
A.Disable TLS certificate verification so the login request succeeds against the controller's self-signed certificate.
B.Send the username and password with every API request instead of obtaining a token.
C.Handle token expiry by detecting an authentication failure response and re-authenticating to obtain a fresh token before retrying the request.
D.Hard-code the token value in the script so it never needs to be fetched at runtime.
E.Store the token returned by the login endpoint and include it in an Authorization or X-Auth-Token header on subsequent requests.
AnswersC, E

Tokens expire after a defined lifetime, and protected calls then return an authentication error. Detecting that response and logging in again to refresh the token keeps the script running unattended, which is essential for long-lived automation that cannot rely on a single token lasting forever.

Why this answer

Token-based controller APIs require the client to obtain a token at login, present it on subsequent protected calls, and refresh it when it expires. Storing and attaching the token in a request header satisfies the session requirement, and detecting an authentication failure to re-login keeps unattended scripts working. Replaying credentials, hard-coding tokens, and disabling TLS verification are insecure or nonfunctional alternatives.

Exam trap

The trap here is treating the token as a one-time artifact or bypassing TLS, when the real requirements are header-based reuse and expiry refresh.

56
MCQhard

When using NETCONF to edit the configuration of a Cisco IOS XE device, an engineer receives an <rpc-error> with error-tag 'in-use' and error-app-tag 'data-exists'. What does this error indicate?

A.The NETCONF session was closed due to a timeout.
B.The RPC message was malformed.
C.The configuration being added already exists on the device.
D.The device does not have the required user permissions.
AnswerC

NETCONF maps YANG data-exists violations to the in-use error-tag, meaning the target datastore already holds the node being created. The edit is rejected because the configuration being added already exists, so the engineer must merge or replace rather than create it.

Why this answer

The error-tag 'in-use' combined with the error-app-tag 'data-exists' in NETCONF indicates that the configuration operation (e.g., <edit-config> with operation 'create') attempted to add a configuration element that already exists in the running datastore. NETCONF uses these standardized error tags per RFC 6241 to signal that the requested operation cannot be completed because the target data node is already present, preventing duplicate configuration entries.

Exam trap

Cisco often tests the distinction between NETCONF <edit-config> operations (create vs. merge vs. replace) and their corresponding error tags, leading candidates to confuse 'in-use' with permission or syntax errors.

How to eliminate wrong answers

Option A is wrong because a session timeout would generate an <rpc-error> with error-tag 'session-timeout' or 'transport-error', not 'in-use'. Option B is wrong because a malformed RPC message would produce error-tag 'malformed-message' or 'operation-failed', not 'in-use'. Option D is wrong because insufficient permissions would result in error-tag 'access-denied' or 'authorization-error', not 'in-use'.

57
MCQeasy

When using the Cisco Meraki Dashboard API to create an HTTP webhook for network alerts, which authentication method is required in the request header?

A.Authorization: Bearer <token>
B.Include the API key as a query parameter.
C.Authorization: Basic <base64>
D.X-Cisco-Meraki-API-Key: <your_api_key>
AnswerD

The Meraki Dashboard API authenticates every call with a custom header, X-Cisco-Meraki-API-Key, carrying the user-generated key. This satisfies the stem's requirement for the header-based credential, unlike OAuth bearer tokens or basic authentication, which the API does not accept.

Why this answer

The Cisco Meraki Dashboard API requires authentication via a custom HTTP header named `X-Cisco-Meraki-API-Key`, where the value is your API key. This is the only supported method for authenticating requests to the Meraki API, as documented in the official API reference. Option D correctly specifies this header, making it the required authentication method for creating an HTTP webhook for network alerts.

Exam trap

Cisco often tests the distinction between standard authentication methods (Bearer tokens, Basic Auth) and vendor-specific custom headers, so the trap here is that candidates may assume a common standard like OAuth 2.0 or Basic Auth applies, when the Meraki API explicitly requires its own proprietary header.

How to eliminate wrong answers

Option A is wrong because the Meraki API does not use OAuth 2.0 Bearer tokens; it uses a custom API key header instead. Option B is wrong because passing the API key as a query parameter is insecure and not supported by the Meraki API; the key must be sent in a header. Option C is wrong because HTTP Basic Authentication (Base64-encoded credentials) is not used by the Meraki API; it relies solely on the `X-Cisco-Meraki-API-Key` header.

58
Multi-Selectmedium

Which THREE of the following are key principles of Infrastructure as Code (IaC) as applied to network automation?

Select 3 answers
A.Manual configuration is preferred for critical devices.
B.Configuration should be idempotent.
C.Configuration should be validated through automated testing.
D.Temporary scripts should be used for one-time changes.
E.All configuration code should be stored in version control.
AnswersB, C, E

Idempotency ensures consistent state.

Why this answer

Idempotency ensures that applying the same configuration multiple times results in the same final state, preventing unintended changes. In network automation, tools like Ansible or Terraform use idempotent modules (e.g., `ios_config`) to verify the current device state before applying changes, avoiding configuration drift or repeated command failures.

Exam trap

Cisco often tests the misconception that IaC allows manual overrides for critical devices or that one-time scripts are acceptable, but the exam expects you to recognize that all changes must be code-driven, version-controlled, and idempotent to ensure consistency and auditability.

59
Multi-Selectmedium

A network engineer is preparing an Ansible playbook that will configure VLANs on a fleet of Cisco IOS XE switches. The playbook must authenticate to each device securely and must be able to reference the device-specific variables that the playbook expects. (Choose two.)

Select 2 answers
A.Hard-code the enable password directly inside each task's ios_config module arguments.
B.Define host and group variables for each switch in the inventory so tasks can reference the expected variable names.
C.Pass the credentials as extra variables on the ansible-playbook command line and rely on shell history being cleared.
D.Create a separate playbook for every switch and store the credentials only in that switch's playbook.
E.Store device credentials in an Ansible Vault-encrypted variable file and reference those variables in the playbook.
AnswersB, E

Ansible resolves variables from inventory host_vars and group_vars, making device-specific values available to tasks. Defining them there ensures the playbook references resolve correctly for each switch. This is the standard mechanism for supplying per-device data such as management addresses and platform-specific settings.

Why this answer

Secure authentication in Ansible is achieved by encrypting secrets with Ansible Vault and letting the playbook load them at runtime, while per-device values are supplied through inventory host_vars and group_vars. Together these satisfy both requirements: credentials stay protected, and the playbook can reference the variables it expects for each switch.

Exam trap

The trap here is treating any working method of supplying credentials as acceptable, when only encrypted storage plus proper variable resolution meets the stated security and reference requirements.

60
MCQmedium

A network team uses an Ansible playbook to automate the configuration of multiple Cisco IOS XE devices. The playbook includes the 'ios_config' module. Which of the following best describes the purpose of the 'provider' parameter in the ios_config module?

A.It defines the connection details for the device.
B.It identifies the name of the playbook being used.
C.It specifies the configuration lines to be applied.
D.It sets the timeout for the module execution.
AnswerA

The provider parameter supplies the transport and authentication details the module needs to reach the device, such as host, username, password and connection type. Without it, ios_config cannot establish the session required to push configuration changes to the IOS XE device.

Why this answer

The 'provider' parameter in the ios_config module is a dictionary that encapsulates the connection details required to access the network device, such as hostname, username, password, port, and transport protocol (e.g., SSH). This allows the module to establish a session with the Cisco IOS XE device before applying configuration changes. Without the provider, the module would not know how to reach or authenticate to the target device.

Exam trap

Cisco often tests the distinction between the 'provider' parameter (connection details) and the 'lines' parameter (configuration commands), leading candidates to mistakenly think 'provider' specifies the configuration content.

How to eliminate wrong answers

Option B is wrong because the playbook name is defined in the playbook file itself (e.g., the name field under a play), not in the ios_config module's provider parameter. Option C is wrong because the configuration lines to be applied are specified using the 'lines' or 'parents' parameters within the ios_config module, not the provider. Option D is wrong because timeout settings are configured via a separate 'timeout' parameter in the provider dictionary or directly in the module, not as the primary purpose of the provider parameter.

61
MCQeasy

An engineer needs to automate the deployment of a new VLAN across multiple switches. Which tool is best suited for this task?

A.NetFlow
C.Ansible
AnswerC

Ansible's agentless architecture pushes declarative configuration over SSH, letting a single playbook apply identical VLAN definitions across many switches simultaneously. This directly satisfies the stem's requirement to automate deployment across multiple devices, unlike manual CLI entry or per-device scripting, and needs no software installed on the switches themselves.

Why this answer

Ansible is the correct tool because it is an agentless automation platform that uses SSH to push configuration changes, such as VLAN deployment, to network devices. It allows engineers to define the desired state of VLANs in YAML playbooks and apply them consistently across multiple switches without manual intervention.

Exam trap

Cisco often tests the distinction between monitoring protocols (NetFlow, Syslog, SNMP) and automation tools (Ansible, Puppet, Chef), leading candidates to mistakenly choose SNMP because they recall it can write configurations, but they overlook its lack of idempotency and scalability for multi-switch VLAN deployment.

How to eliminate wrong answers

Option A is wrong because NetFlow is a network protocol used for traffic monitoring and analysis, not for configuration deployment. Option B is wrong because Syslog is a standard for message logging and does not provide any mechanism to push configuration changes to devices. Option D is wrong because SNMP is primarily used for monitoring and reading device statistics via MIBs, and while it can write some configuration values (SNMP SET), it is not designed for reliable, idempotent, or scalable VLAN deployment across multiple switches.

62
MCQeasy

Which tool is specifically designed for model-driven programmability using YANG data models?

A.NETCONF
C.CLI
D.Ansible
AnswerA

NETCONF uses YANG-modelled datastores and RPC operations to configure and retrieve device state, satisfying the stem's requirement for model-driven programmability. Unlike SNMP's MIBs or CLI scraping, NETCONF's protocol operations map directly onto YANG schema nodes, giving structured, transactional configuration rather than imperative command sequences.

Why this answer

NETCONF is the correct answer because it is a network management protocol specifically designed to operate with YANG data models, using XML or JSON encoding to transport configuration and state data. YANG defines the structure of the data, and NETCONF provides the operations (get, edit-config, etc.) to manipulate that data in a model-driven, programmatic way. This makes NETCONF the standard tool for model-driven programmability in modern network automation.

Exam trap

Cisco often tests the distinction between a protocol that natively uses YANG (NETCONF) versus tools that can work with YANG but are not designed specifically for it (like Ansible), so the trap here is assuming any automation tool that supports YANG qualifies as 'specifically designed' for model-driven programmability.

How to eliminate wrong answers

Option B (SNMP) is wrong because SNMP uses MIBs (Management Information Bases) defined by SMI (Structure of Management Information), not YANG data models, and it is primarily used for monitoring rather than model-driven configuration. Option C (CLI) is wrong because CLI is a human-oriented, command-line interface that is not model-driven and does not use YANG; it relies on proprietary, device-specific commands. Option D (Ansible) is wrong because Ansible is an automation tool that can use YANG models indirectly via modules (e.g., ios_config), but it is not specifically designed for model-driven programmability using YANG; it is a general-purpose configuration management tool.

63
MCQeasy

A network automation script uses RESTCONF to retrieve operational data from a Cisco device. What data format is typically supported by RESTCONF?

A.YAML
B.Plain text
C.XML or JSON
D.CSV
AnswerC

RESTCONF encodes data as either XML or JSON, negotiated through the Accept and Content-Type headers. This satisfies the stem's requirement for the format typically supported when retrieving operational data, since RESTCONF, unlike SNMP or NETCONF's XML-only encoding, permits JSON payloads alongside XML.

Why this answer

RESTCONF (RFC 8040) is a REST-like protocol that uses HTTP methods to access structured data defined by YANG models. It natively supports both XML and JSON as data serialization formats, allowing clients to choose the format via the Accept header or URL suffix (e.g., .xml or .json). This makes XML and JSON the correct answer because they are the only formats explicitly defined in the RESTCONF specification for encoding configuration and operational data.

Exam trap

Cisco often tests the misconception that RESTCONF supports YAML because of its popularity in automation tools like Ansible, but RESTCONF strictly uses XML and JSON per RFC 8040, and YAML is not a valid encoding in the standard.

How to eliminate wrong answers

Option A is wrong because YAML is not a supported data format in RESTCONF; RESTCONF uses XML and JSON as defined in RFC 8040, and YAML is not part of the standard. Option B is wrong because plain text lacks the structured, hierarchical representation required by YANG data models, and RESTCONF requires a structured format like XML or JSON for data serialization. Option D is wrong because CSV is a flat, row-based format that cannot represent the nested, tree-like data structures of YANG models, and it is not supported by RESTCONF.

64
MCQeasy

A network engineer is evaluating configuration management tools for a Cisco environment. The engineer wants to describe the push-based model where a central server runs playbooks that connect to managed devices over SSH to apply changes. Which tool uses this architecture?

A.Chef
B.Puppet
C.SaltStack
D.Ansible
AnswerD

Ansible is agentless and push-based: the control node executes playbooks and connects to managed devices over SSH to apply tasks. This matches the described architecture exactly, since no software agent must be installed on the Cisco devices and the central server initiates every change.

Why this answer

Ansible's defining architecture is agentless and push-based: the control node runs playbooks and opens SSH sessions to managed devices to execute modules. Puppet and Chef rely on agents that pull configuration, and SaltStack's signature design uses minion agents, so only Ansible matches the described model.

Exam trap

The trap here is assuming that any automation tool connects over SSH, when most agent-based tools pull policy instead of pushing it.

65
Matchingmedium

Match each JSON data type to its example.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

"hello"

42

true

[1, 2, 3]

{"key": "value"}

Why these pairings

JSON supports basic data types: string (e.g., "hello"), number (e.g., 42), boolean (true/false), null, array, and object. Common confusions include misidentifying boolean values as strings or strings as numbers.

66
MCQmedium

An automation team wants to build a custom Slack bot that receives a message when a Cisco IOS XE device sends a syslog event indicating an interface went down. Which combination of technologies should the team use to implement this event-driven workflow?

A.Use Ansible to run a playbook on a schedule that checks interface status and posts to Slack.
B.Configure the device to send syslog to a collector, and have the collector trigger a webhook to the Slack API.
C.Subscribe to model-driven telemetry on the device and have the bot pull data from the telemetry receiver.
D.Poll the device every minute with NETCONF get_config to detect interface state changes, then call the Slack API.
AnswerB

Syslog is a push mechanism, so the device sends events to a collector without polling. The collector can parse the message and call the Slack API webhook to notify the bot. This is a standard event-driven pattern that matches the requirement for near real-time notification.

Why this answer

Syslog is inherently push-based, so configuring the device to send events to a collector is the most direct way to detect an interface-down event. The collector can then invoke the Slack API webhook, creating an event-driven pipeline. Polling approaches add latency and may miss transient events.

Exam trap

The trap here is choosing a polling method because it feels simpler, when the scenario explicitly requires reacting to an event as it happens.

67
MCQhard

A developer must configure a Cisco IOS XE device programmatically and needs the device to validate configuration changes against a data model before they are committed, with the ability to discard invalid candidate configurations. Which approach satisfies this requirement?

A.Use NETCONF with the candidate datastore, edit-config, validate, and commit operations.
B.Use SNMP set requests against the MIB to write configuration objects.
C.Use RESTCONF with a PATCH to the running datastore directly.
D.Send CLI commands over an SSH channel using a Python paramiko session and parse the output.
AnswerA

NETCONF supports a candidate datastore where edits are staged, a validate operation that checks the candidate against the device's YANG models, and a commit that applies it atomically. If validation fails, the candidate can be discarded without touching the running configuration. This is exactly the model-driven, transactional workflow the requirement describes.

Why this answer

A candidate datastore combined with validate and commit gives the developer a staged, model-checked, transactional change workflow. Invalid edits are caught before they reach the running configuration, and a failed validation simply discards the candidate, preserving service. This matches the requirement for pre-commit validation and the ability to abandon bad configurations.

Exam trap

The trap here is equating any model-driven interface, such as RESTCONF against the running datastore, with transactional validation, when only the candidate-datastore workflow provides staged validate and commit semantics.

68
Multi-Selecthard

Which THREE of the following are valid methods to handle API rate limiting in a Python automation script? (Select exactly 3.)

Select 3 answers
A.Parse the Retry-After header from the response
B.Use a token bucket algorithm to control request rate
C.Sleep for a fixed amount of time between requests
D.Ignore the limit and send requests faster
E.Implement retry logic with exponential backoff
AnswersA, B, E

The Retry-After header tells the client exactly how many seconds to wait before retrying, so parsing it respects the server's advertised rate-limit window rather than guessing. This directly satisfies the scenario's need to handle 429 responses without breaching the API's throttling policy.

Why this answer

Option A is correct because the Retry-After header, returned with HTTP 429 (Too Many Requests) or 503 responses, tells the client exactly how many seconds to wait before retrying, making it a standards-based way to honor server-imposed rate limits. Option B is correct because a token bucket algorithm explicitly controls the request rate by issuing tokens at a defined rate and consuming one per request, allowing bursts up to the bucket capacity while preventing sustained over-limit traffic. Option E is correct because retry logic with exponential backoff progressively increases the delay between attempts (e.g., 1s, 2s, 4s, 8s, often with jitter), which reduces request pressure and avoids hammering an API that is throttling the client.

Option C is not among the marked answers because a fixed sleep interval is a crude, static approach that does not adapt to the server's actual limit signals and can either waste time or still exceed the quota. Option D is clearly wrong because ignoring the limit and sending requests faster will trigger further 429 responses, potential IP bans, or account suspension rather than handling the rate limit.

Exam trap

Cisco often tests the distinction between a fixed sleep (which is naive and not adaptive) versus dynamic methods like parsing Retry-After or using exponential backoff, and candidates mistakenly think a static delay is sufficient for rate limiting.

69
MCQmedium

A team uses Chef to manage network device configurations. Which component of Chef is responsible for storing configuration policy and distributing it to nodes?

A.Knife
B.Chef Server
C.Chef Client
D.Supermarket
AnswerB

Chef Server acts as the central hub, storing cookbooks, recipes and policy data, then distributing them to managed nodes on request. This satisfies the stem's requirement for the component holding configuration policy and pushing it out, unlike the workstation or client, which author or apply it locally.

Why this answer

The Chef Server is the central hub that stores configuration policies (cookbooks, roles, environments, data bags) and distributes them to nodes via a REST API. When a Chef Client runs on a node, it authenticates with the Chef Server and downloads the relevant policy to converge the node to the desired state. This makes the Chef Server the authoritative source of configuration policy in a Chef architecture.

Exam trap

Cisco often tests the distinction between the Chef Server (policy storage/distribution) and the Chef Client (policy execution), tempting candidates to confuse the agent with the central repository.

How to eliminate wrong answers

Option A is wrong because Knife is a command-line tool used by administrators to interact with the Chef Server (e.g., upload cookbooks, bootstrap nodes), but it does not store or distribute policy itself. Option C is wrong because the Chef Client is an agent that runs on nodes to apply configuration locally; it pulls policy from the Chef Server but does not store or distribute it. Option D is wrong because Supermarket is a public community repository for sharing cookbooks, not a component that stores or distributes policy within an organization's own infrastructure.

70
Multi-Selecthard

A developer is writing a Python script that calls the Cisco DNA Center Intent API to create a new network device. The script must send a JSON body and authenticate with a token. Which TWO HTTP request components are required for this API call to succeed? (Choose two.)

Select 2 answers
A.Cookie: JSESSIONID from a prior login
B.X-Auth-Token header containing the authentication token
C.Authorization: Basic with the username and password
D.Content-Type: application/json
E.Accept-Encoding: gzip
AnswersB, D

Every Intent API call after authentication must include the token returned by the token endpoint in the X-Auth-Token header. Omitting it causes a 401 Unauthorized response. This header is the controller's required mechanism for proving that the caller has already authenticated successfully.

Why this answer

Creating a device through the DNA Center Intent API requires a JSON body, so Content-Type must be application/json, and the call must be authenticated with the token in the X-Auth-Token header. Compression headers and browser-style cookies or Basic credentials do not satisfy these two mandatory requirements.

Exam trap

The trap here is believing that Basic credentials or a session cookie can substitute for the X-Auth-Token header once authentication has already occurred.

71
MCQmedium

A developer is writing a Python script that calls the Cisco DNA Center Intent API to retrieve a list of network devices. The script must handle the case where the API returns a 401 Unauthorized response by obtaining a new authentication token and retrying the request. Which Python construct should be used to implement this retry with token refresh?

A.A while loop that continuously sends the same request with the same token until a 200 OK response is received.
B.A conditional statement that checks the response status code before sending the request and, if it is not 200, aborts the script.
C.A try/except block that catches requests.exceptions.HTTPError, checks the response status code, and if it is 401, obtains a new token using the DNA Center authentication endpoint and retries the original request.
D.A for loop that iterates over a list of predefined tokens, sending the request with each token until one succeeds.
AnswerC

This approach correctly handles the 401 by catching the HTTPError raised by raise_for_status(), then re-authenticating via the DNA Center token endpoint and retrying. It directly addresses the scenario's requirement to refresh the token and retry on unauthorized responses, making it the appropriate Python construct for this error-handling flow.

Why this answer

The correct approach uses exception handling to catch the HTTP error from the failed request, then performs a token refresh via the DNA Center authentication API and retries the original request. This pattern is essential for robust API clients that must handle token expiration. The other options either loop without refreshing credentials, use static tokens, or abort without recovery, none of which solve the authentication failure scenario.

Exam trap

The trap here is assuming that simply retrying the same request will eventually succeed, when in fact the token must be refreshed first.

72
MCQeasy

Which data format is most commonly used in REST API requests and responses in modern network automation?

A.YAML
B.XML
C.CSV
AnswerD

JSON dominates REST API payloads because its lightweight, human-readable key-value structure maps directly onto HTTP request bodies and parses natively in Python, satisfying the modern network automation requirement for simple serialisation between scripts and controllers.

Why this answer

JSON (JavaScript Object Notation) is the most commonly used data format in REST API requests and responses for modern network automation because it is lightweight, language-agnostic, and natively supported by most programming languages and network devices. REST APIs typically use JSON over HTTP due to its ease of parsing, compact structure, and alignment with web development practices, making it the de facto standard for exchanging structured data in automation workflows like those with Cisco NSO, Ansible, or Python scripts.

Exam trap

The trap here is that candidates may confuse YAML's prevalence in configuration management (e.g., Ansible) with REST API data interchange, or assume XML's historical role in SOAP extends to modern REST, leading them to overlook JSON's dominance in actual API payloads.

How to eliminate wrong answers

Option A is wrong because YAML, while popular in configuration files (e.g., Ansible playbooks), is not the primary format for REST API payloads; it lacks native HTTP content-type support and is less commonly used in request/response bodies. Option B is wrong because XML, though historically used in SOAP APIs and some legacy REST implementations, is verbose, requires more parsing overhead, and has been largely superseded by JSON in modern REST APIs due to simplicity and performance. Option C is wrong because CSV is a tabular data format unsuitable for hierarchical or nested structures common in REST API responses, and it lacks standard schema support for complex objects like device configurations or network states.

73
Multi-Selectmedium

A network automation team is evaluating tools to manage the configuration of Cisco IOS XE devices. They need a solution that uses a declarative, agentless approach and can be extended with custom modules. Which two characteristics describe Ansible in this context? (Choose two.)

Select 2 answers
A.It uses a declarative playbook written in YAML to define the desired state of the network.
B.It maintains a local database of device configurations and enforces them periodically.
C.It uses Ruby-based manifests to define infrastructure as code.
D.It uses SSH to connect to network devices and does not require a software agent on the managed nodes.
E.It requires a central server called a master and agents installed on each managed device.
AnswersA, D

Ansible playbooks are written in YAML and describe the desired end state of the system. The playbook contains tasks that use modules to enforce that state. This declarative model allows the automation to be idempotent and readable, which aligns with the team's requirement for a declarative approach.

Why this answer

Ansible is an agentless automation tool that connects to managed nodes over SSH or other protocols, and it uses declarative YAML playbooks to define desired state. These two characteristics distinguish it from agent-based tools like Puppet or Chef, which require agents and use their own domain-specific languages. The team's need for agentless and declarative automation is met by these features.

Exam trap

The trap here is mixing up Ansible with agent-based tools like Puppet or Chef, which use Ruby or a master-agent model and maintain a central database.

74
MCQeasy

A DevOps team wants to version control their network configurations. Which tool should they use?

A.Puppet
B.Jenkins
C.Git
D.Docker
AnswerC

Git provides distributed version control with commit history, branching and merging, satisfying the team's need to track changes to network configuration files over time. Unlike CI/CD orchestrators or configuration management tools, Git directly addresses versioning itself, letting engineers diff revisions and roll back faulty changes precisely.

Why this answer

Git is a distributed version control system that tracks changes in source code and configuration files, making it the ideal tool for version controlling network configurations. Unlike configuration management tools, Git provides commit history, branching, and rollback capabilities specifically designed for version control.

Exam trap

Cisco often tests the distinction between version control tools (Git) and configuration management tools (Puppet, Ansible) or CI/CD tools (Jenkins), leading candidates to confuse the purpose of each tool in the DevOps pipeline.

How to eliminate wrong answers

Option A is wrong because Puppet is a configuration management tool that enforces desired state on systems, not a version control system for tracking changes to configuration files. Option B is wrong because Jenkins is a continuous integration/continuous delivery (CI/CD) automation server, not a version control tool. Option D is wrong because Docker is a containerization platform for packaging applications and their dependencies, not a version control system.

75
MCQeasy

A developer runs the command `git clone https://github.com/example/netconfig.git` on a workstation, then edits a file named `vlans.yml`. Before editing, the developer wants to confirm which remote repository the local clone is tracking for push and fetch operations. Which command should be run?

A.git diff HEAD
B.git remote -v
C.git log --oneline
D.git status
AnswerB

This command lists all configured remotes together with their fetch and push URLs. Because the clone was created from a URL, the default remote named origin is registered automatically, and this command confirms the exact repository the local branch will push to and fetch from. It is the fastest way to verify tracking configuration before committing and pushing changes.

Why this answer

The git remote -v command enumerates each configured remote and prints its fetch and push URLs, which directly confirms which repository the local clone is linked to. Other commands inspect working tree state, commit history, or local diffs, none of which expose remote configuration. Verifying remotes before pushing avoids accidentally sending commits to an unintended upstream repository.

Exam trap

The trap here is assuming that git status reports the remote repository URL, when it only reports local branch and file state.

Page 1 of 2 · 132 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infra Automation questions.