350-401 Automation Practice Question
A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS devices. The administrator prefers a tool that uses YAML for playbooks and does not require installing software on the managed devices. Which tool should the administrator use?
⚠ Common exam trap
It's easy for candidates to confuse Ansible with other configuration management tools that also support agentless operation but use different languages or require more setup; Ansible uniquely uses YAML playbooks and is agentless.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ansible
Ansible is the correct choice because it is agentless, uses YAML for playbooks, and connects to Cisco IOS devices over SSH without requiring any software installation on the devices. It has a rich set of network modules, such as 'ios_config', that simplify configuration management. Other tools like Puppet and Chef use different languages and often require agents, making them less suitable for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Puppet
Why it's wrong here
Puppet typically requires an agent (Puppet agent) to be installed on managed nodes, although it can operate in agentless mode via SSH for some tasks. However, for network devices like Cisco IOS, Puppet often relies on proxy agents or specialized modules. The requirement for agentless operation and YAML playbooks points more directly to Ansible, as Puppet uses its own DSL (Puppet Language) for manifests, not YAML.
- ✓
Ansible
Why this is correct
Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to managed devices over SSH or NETCONF, so no agent software needs to be installed on the Cisco IOS devices. This makes it ideal for simple, push-based configuration management. Ansible modules like 'ios_config' allow network engineers to automate configuration changes across multiple devices efficiently.
- ✗
Chef
Why it's wrong here
Chef uses Ruby-based recipes and cookbooks, not YAML playbooks. It also typically requires a Chef agent installed on managed nodes. While Chef can manage network devices via specialized modules, it is not agentless in the same way as Ansible and does not use YAML for its configuration definitions. Therefore, it does not meet the administrator's criteria for simplicity and agentless operation.
- ✗
SaltStack
Why it's wrong here
SaltStack can operate in an agentless mode using SSH, but it uses YAML for its state files and typically requires a master-minion architecture. While it is powerful, it is more complex to set up than Ansible for simple push-based configuration. The administrator's preference for a simple, agentless tool with YAML playbooks aligns best with Ansible, which is widely used for network automation and has extensive Cisco IOS module support.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.