350-401 Automation Practice Question
A company uses Cisco Catalyst Center (formerly DNA Center) for intent-based networking. After upgrading the Catalyst Center appliance, the engineer notices that some devices are unreachable via the network, but the Catalyst Center GUI shows them as 'Managed'. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between GUI state (which can be stale) and actual network reachability, leading candidates to focus on protocol misconfigurations (like SNMP or certificates) rather than the underlying IP connectivity change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP address of the Catalyst Center appliance changed after the upgrade
When the Catalyst Center appliance is upgraded, its IP address may change if the upgrade process resets network configuration or if the appliance is redeployed with a new IP. Devices are managed via IP-based communication (e.g., SSH, SNMP, NETCONF), and if the Catalyst Center IP changes, devices will still show as 'Managed' in the GUI because the database retains the device state, but the devices themselves cannot be reached because they are trying to communicate with the old IP address. This mismatch causes unreachability despite the managed status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMP community strings are misconfigured
Why it's wrong here
SNMP community strings are used for read/write access to a device's MIB, enabling Catalyst Center to poll performance metrics and apply configuration via SNMP. If the community strings are misconfigured, Catalyst Center would fail to authenticate SNMP requests, causing inventory polling to fail and the device to be marked as 'Unreachable' in the GUI. However, this does not indicate a loss of IP-level reachability—the device would still respond to ICMP echo requests. The root cause would appear as SNMP authentication timeouts, not as a network path failure.
- ✗
Devices were reassigned to different roles
Why it's wrong here
Device roles in Catalyst Center are logical designations such as access, distribution, core, or border, used for applying network profiles and intent-based policies. Reassigning these roles updates the design hierarchy and can trigger template re-provisioning, but it does not modify the device's IP address, routing tables, or management plane access. Consequently, a role reassignment cannot make an appliance lose IP connectivity to the devices. The symptom would be a policy or configuration drift issue, not an 'unreachable' state in the inventory.
- ✗
Certificate trust between devices and Catalyst Center expired
Why it's wrong here
Certificate trust between Catalyst Center and managed devices is used for encrypting and authenticating management sessions, such as NETCONF over SSH or TLS-based telemetry. When the trust expires, the secure channel fails to establish, and the device may report errors like 'certificate validation failed', but the underlying IP connectivity remains intact. The device is still pingable and can be reached on the network layer; only the cryptographic handshake fails. Therefore, an expired certificate would not cause the appliance to lose contact with the device at the network layer.
- ✓
The IP address of the Catalyst Center appliance changed after the upgrade
Why this is correct
If the Catalyst Center appliance's IP address is changed after an upgrade, the management network's routing and ARP entries are disrupted. Devices that are configured to send telemetry or accept management commands to/from the old IP address will no longer be reachable, because their ARP caches, DHCP reservations, or static routes still reference the previous address. Additionally, any access control lists on the devices that permit management traffic from the appliance's old IP will silently drop the new source address. This directly explains why all devices become unreachable after the upgrade, even though the appliance itself is up.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
Key term
Machine Learning in Assurance
Machine Learning in Assurance means using AI algorithms to automatically verify that network devices are configured correctly, secure, and operating as intended.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.