350-401 Automation Practice Question
A network administrator wants to use a declarative, agentless automation tool to push VLAN configurations to a group of Cisco IOS XE switches. The tool should connect over SSH, use YAML playbooks, and require no software installation on the switches. Which tool best fits these requirements?
⚠ Common exam trap
The trap here is assuming any configuration management tool with a Cisco module is agentless, when Puppet, Chef, and SaltStack typically require agents that cannot run on IOS XE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ansible with the cisco.ios collection and an inventory of the switches
Ansible is the only option that is agentless, connects via SSH, and uses YAML playbooks. The cisco.ios collection supplies modules purpose-built for IOS XE VLAN and configuration management. Puppet, Chef, and SaltStack all generally require an agent on managed nodes, which cannot be installed on Cisco IOS XE switches, so they do not satisfy the agentless requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SaltStack with minions deployed on each switch and states written in YAML
Why it's wrong here
SaltStack typically uses a master-minion architecture where minions run on managed nodes. Deploying a Salt minion on a Cisco IOS XE switch is not supported. Although Salt states can be written in YAML, the agent requirement disqualifies it. This option fails the agentless requirement central to the scenario.
- ✗
Chef Infra Client installed on each switch with recipes written in Ruby
Why it's wrong here
Chef requires the Chef Infra Client agent to be installed on managed nodes. Cisco IOS XE switches do not support installing arbitrary agents. Chef recipes are written in Ruby DSL, not YAML. This option fails the agentless and YAML criteria and is not a viable approach for IOS XE switches.
- ✗
Puppet with the Cisco IOS module installed on each switch
Why it's wrong here
Puppet typically requires an agent on managed nodes, or at least a master-agent architecture. While it can be agentless in some proxy modes, the standard model installs a Puppet agent on the device, which is not possible on most Cisco IOS XE switches. It also uses its own DSL rather than YAML playbooks, so it does not meet the stated criteria.
- ✓
Ansible with the cisco.ios collection and an inventory of the switches
Why this is correct
Ansible is agentless, connecting over SSH, and uses YAML playbooks. The cisco.ios collection provides modules like ios_vlan and ios_config to manage IOS XE devices. No software needs to be installed on the switches beyond SSH and proper credentials. This matches all requirements: declarative, agentless, YAML-based, and SSH connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.