350-401 Automation Practice Question
A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script establishes a session and sends an <edit-config> RPC with a candidate datastore. After sending the RPC, the script immediately sends a <commit> RPC, but the device returns an error indicating that the candidate datastore is not supported. Which statement explains the cause of this error?
⚠ Common exam trap
The trap here is assuming all NETCONF devices support the candidate datastore, when many Cisco IOS XE devices only support the running datastore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The device does not support the candidate datastore, so the script must use the running datastore directly.
The error indicates that the candidate datastore is not supported by the device. Cisco IOS XE devices often support only the running datastore for NETCONF edits. The candidate datastore allows a two-phase commit, but if it is not available, the script must target the running datastore. The <commit> operation is only for the candidate datastore. Therefore, the script should be changed to edit the running datastore directly, which applies changes immediately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The device requires the use of NETCONF over SSH instead of TLS for candidate datastore operations.
Why it's wrong here
NETCONF can run over SSH or TLS, but the transport does not affect datastore support. The error is specifically about the candidate datastore not being supported, which is a capability of the device's NETCONF server, not the transport. Switching to SSH would not enable the candidate datastore if the device does not support it. The script must adapt to the device's capabilities, which are advertised in the <hello> message.
- ✗
The script must first send a <lock> RPC on the candidate datastore before editing.
Why it's wrong here
Locking is a best practice to prevent concurrent modifications, but the error is about the candidate datastore being unsupported, not about locking. If the datastore were supported, locking might be required depending on the device, but the absence of a lock would typically produce a different error, such as 'lock denied' or 'resource unavailable'. Locking does not make an unsupported datastore available, so this action would not resolve the error.
- ✗
The script must send a <validate> RPC before the <commit> to ensure the candidate configuration is valid.
Why it's wrong here
Validation is a step that checks the candidate configuration for errors before committing, but it is only applicable if the candidate datastore is supported. The error occurs because the candidate datastore itself is not supported, so validation would also fail. The correct approach is to use the running datastore, where changes are applied immediately without a commit. Validation is not the issue here.
- ✓
The device does not support the candidate datastore, so the script must use the running datastore directly.
Why this is correct
The error explicitly states that the candidate datastore is not supported. Many Cisco IOS XE devices support only the running datastore for NETCONF edits, not the candidate datastore. The candidate datastore allows staging changes before committing, but if it is unsupported, the <edit-config> must target the running datastore. The script should be modified to use the running datastore instead of candidate, and the <commit> operation is unnecessary because changes take effect immediately.
Go deeper
Related to this question
Learn chapter
Network Automation and Programmability
Key term
Cisco DNA Center Automation
Cisco DNA Center Automation is a centralized software platform that simplifies network management by automatically configuring, monitoring, and troubleshooting Cisco devices using policy-driven intent and software tools.
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.