350-401 Automation Practice Question
A network automation team is using the ncclient Python library to configure a Cisco IOS XE router via NETCONF. The engineer wants to ensure the configuration changes are applied atomically and that the device automatically rolls back if any part of the change fails. Which NETCONF capability must the engineer verify is advertised by the device before relying on this behavior?
⚠ Common exam trap
It's easy for candidates to confuse the candidate datastore capability with confirmed-commit, assuming that using a candidate automatically provides rollback when in fact only confirmed-commit does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
urn:ietf:params:netconf:capability:confirmed-commit:1.0
To achieve atomic configuration with automatic rollback, the NETCONF confirmed-commit capability is required. It allows a commit to be provisional until explicitly confirmed; if confirmation is not received within the timeout, the device reverts to the prior configuration. Verifying that the device advertises this capability ensures the automation can rely on rollback semantics rather than leaving the device in an inconsistent state after a failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
urn:ietf:params:netconf:capability:candidate:1.0
Why it's wrong here
The candidate capability allows configuration changes to be made on a candidate datastore and then committed, but it does not by itself guarantee automatic rollback on failure. While candidate is often used with confirmed-commit, the atomic rollback behavior specifically depends on the confirmed-commit capability. Candidate alone only provides a staging area and does not trigger rollback if a commit fails.
- ✗
urn:ietf:params:netconf:capability:writable-running:1.0
Why it's wrong here
The writable-running capability indicates that the running datastore can be edited directly via NETCONF. It does not provide any rollback or atomicity guarantees. If changes are made directly to the running datastore and a failure occurs mid-way, the device may be left partially configured. This capability is about write access, not about transactional safety or automatic rollback.
- ✗
urn:ietf:params:netconf:capability:validate:1.0
Why it's wrong here
The validate capability allows the client to validate a configuration against the device's YANG models before committing it. Validation helps catch syntax or semantic errors, but it does not provide automatic rollback if the commit itself fails or if the change is not confirmed. The engineer specifically needs rollback behavior, which is delivered by confirmed-commit, not by validate alone.
- ✓
urn:ietf:params:netconf:capability:confirmed-commit:1.0
Why this is correct
The confirmed-commit capability enables a commit operation that must be confirmed within a specified timeout; if confirmation does not occur, the device automatically reverts to the previous configuration. This provides the automatic rollback behavior the engineer needs. Without this capability, a failed or unconfirmed commit would leave the device in the new configuration state, so verifying its advertisement is essential for atomic, safe changes.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco DNA Center Automation
Cisco DNA Center Automation is a centralized software platform that simplifies network management by automatically configuring, monitoring, and troubleshooting Cisco devices using policy-driven intent and software tools.
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.