350-401 Automation Practice Question
A network automation team is using Ansible to push configuration changes to a fleet of Cisco IOS XE devices. The playbook uses the 'ios_config' module with the 'backup: yes' option. During a recent run, the playbook failed on one device due to a syntax error in the configuration lines. The team wants to ensure that if a failure occurs, the device automatically reverts to its previous configuration without manual intervention. Which Ansible feature should be used to achieve this?
⚠ Common exam trap
The trap here is assuming that the ios_config module has built-in rollback capabilities or that saving the configuration provides automatic recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a 'block' and 'rescue' section in the playbook to run a rollback task if the configuration fails.
To automatically revert to the previous configuration upon failure, the playbook must include error handling. Ansible's block/rescue construct allows tasks to be grouped, and if any task in the block fails, the rescue section runs. Within rescue, a task can invoke 'configure replace' using a saved configuration file, restoring the device to its prior state. This approach ensures atomic rollback without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'ios_config' module with the 'rollback' parameter set to 'yes'.
Why it's wrong here
The 'ios_config' module does not have a 'rollback' parameter. While Cisco IOS XE supports configuration rollback via the 'configure replace' command, Ansible's ios_config module does not natively expose this as a simple parameter. The team would need to implement rollback using other methods, such as the 'cli_command' module with 'configure replace'.
- ✓
Implement a 'block' and 'rescue' section in the playbook to run a rollback task if the configuration fails.
Why this is correct
Ansible's block/rescue structure allows error handling. The configuration task can be placed in a block, and if it fails, the rescue section can execute a rollback task, such as using 'cli_command' to run 'configure replace' with a previously saved configuration file. This provides automatic rollback without manual intervention, directly addressing the requirement.
- ✗
Set the 'ansible_command_timeout' to a higher value to prevent premature failure.
Why it's wrong here
Increasing the command timeout only affects how long Ansible waits for a command to complete. It does not provide rollback capability. If a syntax error occurs, the device will reject the configuration, and the timeout setting will not revert changes. This option misinterprets the cause of failure as a timeout rather than a configuration error.
- ✗
Enable 'config' mode with the 'save_when' parameter set to 'modified'.
Why it's wrong here
'save_when: modified' saves the running configuration to startup when changes are made, but it does not provide automatic rollback on failure. If the configuration fails, the running configuration may be partially applied. This option does not revert changes; it only persists them, which could worsen the situation by saving a broken configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.