Courseiva

200-901 · topic practice

Infrastructure and Automation practice questions

This domain covers automating Cisco infrastructure using APIs, model-driven telemetry, and configuration tools. You must understand NETCONF/RESTCONF, YANG models, and Ansible modules for IOS and NX-OS. Questions test protocol details, datastore operations, and ordered configuration steps. Expect drag-and-drop and multiple-choice on real device automation workflows.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Infrastructure and Automation

What the exam tests

What to know about Infrastructure and Automation

Be able to write Python scripts using ncclient for NETCONF, choose correct Ansible modules for IOS, and know RESTCONF data formats. The most important thing: always commit candidate datastore changes in NETCONF, or they are lost.

NETCONF edit-config with candidate datastore requires commit or discard-commit.

Ansible modules ios_config and ios_command automate Cisco IOS device configuration and show commands.

RESTCONF typically supports JSON and XML data formats for operational data retrieval.

Ordering OSPF configuration steps: enable router ospf, network statements, area assignment.

Watch out for

Common Infrastructure and Automation exam traps

  • ▸Forgetting that candidate datastore changes need an explicit commit; assuming edit-config auto-commits.
  • ▸Confusing ios_config with ios_command; using ios_command for configuration changes instead of show commands.
  • ▸Believing RESTCONF only supports XML; it also supports JSON, which is often the default in examples.

Practice set

Infrastructure and Automation questions

20 questions · select your answer, then reveal the explanation

Which protocol is commonly used to retrieve real-time telemetry data from network devices in a streaming fashion?

Question 2hardmulti select
Read the full Ansible explanation →

Which THREE of the following are best practices for writing Ansible playbooks for network automation? (Select exactly 3.)

Question 3mediummultiple choice
Read the full DHCP explanation →

Refer to the exhibit. An automation script expects the interface IP address to be configured via DHCP. Based on the output, what is the current configuration source for the IP address?

Exhibit

Refer to the exhibit.

R1#show run | section interface GigabitEthernet0/1
interface GigabitEthernet0/1
 ip address 192.168.1.1 255.255.255.0
 duplex auto
 speed auto
!
R1#show ip interface GigabitEthernet0/1
GigabitEthernet0/1 is up, line protocol is up
  Internet address is 192.168.1.1/24
  Broadcast address is 255.255.255.255
  Address determined by non-volatile memory
  MTU is 1500 bytes
  Helper address is not set
  Directed broadcast forwarding is disabled
  Outgoing access list is not set
  Inbound  access list is not set

Refer to the exhibit. A Python script uses the YANG model to configure the interface. After applying this JSON payload via a PATCH request, what is the expected operational state of the interface?

Exhibit

Refer to the exhibit.

{
  "ietf-interfaces:interface": {
    "name": "GigabitEthernet0/1",
    "description": "Link to Core",
    "type": "iana-if-type:ethernetCsmacd",
    "enabled": false,
    "ietf-ip:ipv4": {
      "address": [
        {
          "ip": "10.10.10.1",
          "netmask": "255.255.255.0"
        }
      ]
    }
  }
}
Question 5easymultiple choice
Read the full Ansible explanation →

Refer to the exhibit. An Ansible playbook targeting a Cisco IOS device fails with this error. What is the most likely cause?

Exhibit

Refer to the exhibit.

Error: 'Failed to authenticate to device 192.168.1.100:22'
Question 6hardmultiple choice
Read the full Ansible explanation →

You are a network automation engineer at a large enterprise. The network consists of 200 Cisco Catalyst switches distributed across five data centers. Each switch runs IOS-XE and supports NETCONF. Your team uses a centralized Ansible control node to manage configurations. Recently, the security team mandated that all management access must use SSH keys instead of passwords. You updated the Ansible inventory to use SSH keys and tested on a few switches successfully. However, when you run the playbook against all switches, about 30 switches fail with the error: 'Authentication failed.' You verify that the SSH public key is correctly deployed on those switches via the console. What is the most likely cause of the failure?

Question 7hardmultiple choice
Read the full Ansible explanation →

You are automating the deployment of a new software image on a fleet of Cisco Nexus switches using Ansible. The switches are in a production environment and must have minimal downtime. You have a maintenance window of 30 minutes per switch. Your playbook performs the following steps: 1) Copy the image to the switch via SCP, 2) Set the boot variable to the new image, 3) Save the configuration, 4) Reload the switch. During a dry run on a test switch, you notice that the reload step takes 8 minutes, but the copy step takes 15 minutes due to slow link speed. For the production rollout, you need to reduce the overall time per switch. Which approach should you take?

Question 8hardmultiple choice
Study the full QoS explanation →

Refer to the exhibit. A network engineer applies this JSON-based QoS policy to a Cisco device using NETCONF/YANG. Which statement best describes the expected behavior for traffic from 10.0.0.0/24 with DSCP EF?

Exhibit

Refer to the exhibit.

{
  "policy": {
    "name": "QoS-Policy",
    "match": {
      "dscp": "EF",
      "source_ip": "10.0.0.0/24"
    },
    "action": {
      "set_dscp": "AF41",
      "police": {
        "cir": "100000000",
        "bc": "10000000",
        "conform_action": "transmit",
        "exceed_action": "drop"
      }
    }
  }
}

An automation engineer wants to programmatically retrieve the interface configuration of a Cisco Nexus switch using NX-API. Which API call method is most appropriate?

Question 10mediummultiple choice
Read the full Ansible explanation →

During a CI/CD pipeline for network changes, a Jenkins job runs an Ansible playbook that applies configuration to a device. The playbook fails with a timeout error. What is the most likely cause?

Question 11hardmultiple choice
Read the full DHCP explanation →

An organization implements zero-touch provisioning (ZTP) for new Cisco routers using DHCP and TFTP. The provision script is not being executed even though the device obtains an IP address. The DHCP server logs show the option 67 (bootfile-name) and option 150 (tftp-server) are set. What is the most probable reason?

Question 12hardmultiple choice
Study the full ACL explanation →

A network engineer uses Ansible to apply a standard ACL to multiple routers. The playbook runs without errors, but the ACL is not applied on some routers. Upon checking, those routers have a different configuration revision due to a previous manual change. What is the best practice to ensure consistent application?

Question 13easymulti select
Read the full REST/YANG explanation →

Which TWO of the following are characteristics of the YANG data modeling language that make it suitable for network automation? (Select two)

Which TWO tools are commonly used for automated network compliance checking against a desired state? (Select two)

Question 15mediummultiple choice
Open the full VLAN trunking answer →

An automation engineer runs a Python script using the Cisco NXOS NX-API to retrieve the interface configuration. The JSON response shows the 'switchport access vlan' as '10'. However, VLAN 10 does not exist in the VLAN database. What is the expected behavior of the switch regarding this interface?

Exhibit

Refer to the exhibit.

! From a Nexus switch:
interface Ethernet1/1
  description Connected to Server
  switchport mode access
  switchport access vlan 10
  spanning-tree portfast
  no shutdown
Question 16mediummultiple choice
Study the full Python automation breakdown →

A developer is using Python requests library to interact with a Cisco IOS XE device's REST API. The call returns a 400 Bad Request status. The payload is correctly formatted JSON. What is the most likely cause?

A Python script sends the above REST API request to a Cisco Catalyst 9000 switch running IOS XE. The response is a 400 Bad Request. Which field is most likely missing from the JSON payload?

Exhibit

Refer to the exhibit.

POST /api/v1/vlan HTTP/1.1
Host: 192.168.1.100
Authorization: Bearer <token>
Content-Type: application/json

{
    "name": "Engineering",
    "vlanId": 10
}
Question 18hardmultiple choice
Read the full REST/YANG explanation →

A network engineer attempts to use RESTCONF to retrieve the running configuration of a Cisco IOS XE device. The GET request to '/restconf/data/Cisco-IOS-XE-native:native' returns a 405 Method Not Allowed error. What is the most likely cause?

Question 19hardmulti select
Read the full Ansible explanation →

A network automation engineer uses Ansible to manage a group of Cisco IOS XE devices. The playbook fails with 'unreachable' for some devices. Which TWO actions should the engineer take to troubleshoot the connectivity?

Question 20mediummultiple choice
Read the full REST/YANG explanation →

A NETCONF RPC reply indicates a validation failure. Based on the exhibit, what is the most probable reason for the failure?

Exhibit

Refer to the exhibit.

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0">
  <rpc-error>
    <error-type>protocol</error-type>
    <error-tag>operation-failed</error-tag>
    <error-severity>error</error-severity>
    <error-message>
      Edit operation failed: the candidate configuration does not pass validation.
    </error-message>
    <error-info>
      <bad-element>mtu</bad-element>
      <bad-namespace>urn:cisco:params:xml:ns:yang:Cisco-IOS-XE-native</bad-namespace>
    </error-info>
  </rpc-error>
</rpc-reply>

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Infrastructure and Automation sessions

Start a Infrastructure and Automation only practice session

Every question in these sessions is drawn from the Infrastructure and Automation domain — nothing else.

Related practice questions

Related 200-901 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-901 exam test about Infrastructure and Automation?
Be able to write Python scripts using ncclient for NETCONF, choose correct Ansible modules for IOS, and know RESTCONF data formats. The most important thing: always commit candidate datastore changes in NETCONF, or they are lost.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Infrastructure and Automation questions in a focused session?
Yes — the session launcher on this page draws every question from the Infrastructure and Automation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-901 topics?
Use the topic links above to move to related areas, or go back to the 200-901 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-901 exam covers. They are not copied from any real exam or dump site.