Courseiva
Automation →hardMultiple Select

350-401 Automation Practice Question

A network automation engineer is using NETCONF to configure a Cisco IOS XE device. The engineer wants to ensure that the configuration changes are applied atomically and that the device can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities should the engineer verify are supported by the device? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse validation or writable-running with atomicity and rollback, which are specifically provided by :candidate and :rollback-on-error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

:rollback-on-error

To achieve atomic configuration changes and rollback on error with NETCONF, the device must support the :candidate and :rollback-on-error capabilities. The :candidate capability provides a staging area for changes, allowing them to be applied as a single transaction. The :rollback-on-error capability ensures that if any part of the transaction fails, the entire change set is discarded, reverting to the previous configuration. Together, they enable reliable and safe configuration management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    :writable-running

    Why it's wrong here

    :writable-running allows direct edits to the running configuration, but it does not provide atomic transactions or rollback capabilities. Changes are applied immediately and individually, so an error could leave the configuration in an inconsistent state. While it is useful for simple edits, it does not meet the requirement for atomicity and rollback. Thus, it is not the correct capability to verify for this scenario.

  • ✗

    :validate

    Why it's wrong here

    :validate allows the engineer to validate a candidate configuration against the device's YANG models before committing. While validation is important, it does not by itself provide atomicity or rollback. The engineer could validate and still encounter errors during commit. The requirements specifically mention atomic application and rollback, which are provided by other capabilities. Thus, :validate alone is insufficient.

  • ✗

    :startup

    Why it's wrong here

    :startup indicates that the device has a separate startup configuration datastore. While this is useful for saving configurations across reboots, it does not provide atomic transactions or rollback of configuration changes. The engineer could still make changes that are not atomic. Therefore, :startup is not relevant to the requirement for atomicity and rollback during configuration.

  • ✓

    :rollback-on-error

    Why this is correct

    :rollback-on-error is a NETCONF capability that ensures if any part of a configuration transaction fails, the entire transaction is rolled back to the previous state. This directly supports the requirement for atomicity and automatic rollback. It works in conjunction with the candidate datastore. Therefore, verifying this capability is necessary to guarantee that errors do not leave the device in a partially configured state.

  • ✓

    :candidate

    Why this is correct

    The :candidate capability indicates that the device supports a candidate configuration datastore. This allows the engineer to make changes to a candidate configuration, validate them, and then commit them atomically. It also enables rollback to a previous configuration if needed. Without this capability, atomic transactions and rollback are not possible. Therefore, verifying :candidate is essential for the described requirements.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.