350-401 Automation Practice Question
A network automation engineer is developing a Python script using the ncclient library to configure a Cisco IOS XE device via NETCONF. The engineer wants to lock the running datastore, apply a candidate configuration, validate it, and then commit it. Which sequence of ncclient operations correctly performs this workflow?
⚠ Common exam trap
The trap here is mixing datastores—locking running while editing candidate, or editing running directly—which breaks the candidate-based transactional model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
manager.lock('candidate') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
The correct NETCONF workflow with a candidate datastore involves locking the candidate, editing it, validating it, committing to running, and unlocking. This ensures configuration changes are atomic and can be validated before application. The ncclient library maps these to lock, edit_config, validate, commit, and unlock methods. Using the candidate datastore is essential for this sequence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
manager.lock('candidate') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
Why this is correct
This sequence correctly locks the candidate datastore, edits it with the desired configuration, validates the candidate, commits the changes to running, and then unlocks the candidate. This follows the NETCONF confirmed-commit workflow and is the standard approach when using the candidate datastore with ncclient. It ensures atomicity and prevents conflicts.
- ✗
manager.lock('running') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('running')
Why it's wrong here
This sequence locks the running datastore but then edits the candidate datastore. Locking running does not protect candidate, and committing without a prior lock on candidate may fail if another session holds the lock. The correct workflow locks the candidate datastore before editing it, then validates and commits. This sequence is inconsistent and may lead to errors.
- ✗
manager.lock('candidate') manager.edit_config(target='running', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
Why it's wrong here
This locks the candidate datastore but then edits the running datastore. The lock on candidate is irrelevant to editing running, and editing running directly bypasses the candidate workflow. The subsequent validate on candidate will not include the changes made to running, and commit may fail or commit nothing. The operations are inconsistent and will not achieve the desired result.
- ✗
manager.lock('running') manager.edit_config(target='running', config=config_payload) manager.validate('running') manager.commit() manager.unlock('running')
Why it's wrong here
Editing the running datastore directly does not use the candidate datastore, so validate and commit operations are not applicable. The validate operation typically works on candidate, and commit is used to apply candidate to running. This sequence would likely raise errors because validate on running is not supported, and commit may not be valid without a candidate.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco DNA Center Automation
Cisco DNA Center Automation is a centralized software platform that simplifies network management by automatically configuring, monitoring, and troubleshooting Cisco devices using policy-driven intent and software tools.
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.