Courseiva
Automation →mediumMultiple Choice

350-401 Automation Practice Question

A network engineer is automating the deployment of VLANs across multiple switches using Ansible. The playbook runs successfully on most switches, but one switch fails with an error indicating that the VLAN configuration command is not recognized. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often assume a module or connectivity issue, but Cisco tests the understanding that different IOS versions or platforms (e.g., IOS vs. CatOS) have distinct VLAN CLI syntax, which Ansible modules must handle via conditional logic or version-specific variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch runs a different IOS version with different VLAN CLI syntax

The most likely cause is that the switch runs a different IOS version with different VLAN CLI syntax. Ansible executes commands via SSH, and if the switch expects a different command format (e.g., 'vlan 10' vs. 'vlan database' on older CatOS), the playbook will fail with a command-not-recognized error. This is a common issue when automating across heterogeneous network devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ansible lacks the appropriate module for VLAN configuration

    Why it's wrong here

    Ansible does have a dedicated ios_vlan module (part of the cisco.ios collection) specifically for creating and modifying VLANs on IOS devices. If the module were truly missing, the playbook would fail on every switch with a 'module not found' or similar error during task resolution, not on just one host. The fact that only a single switch experiences a CLI-level error while others succeed proves the module is present and functional.

  • ✗

    The inventory file has a syntax error for that specific host

    Why it's wrong here

    Ansible parses the entire inventory file (whether INI or YAML) before executing any tasks, so a syntax error on any host would cause the playbook to abort with a parse error before a single device is contacted. That would affect all hosts, not produce a per-host CLI error on one switch. A syntactically invalid host definition cannot be reached individually because the inventory cannot be loaded at all.

  • ✓

    The switch runs a different IOS version with different VLAN CLI syntax

    Why this is correct

    VLAN configuration syntax is not identical across all Cisco IOS versions: older IOS releases traditionally used 'vlan database' mode, while modern IOS-XE and many IOS 15.x train support interface configuration mode with 'vlan <vlan-id>'. If the playbook uses commands like 'vlan <id>' inside interface config or relies on VTP-related syntax that the specific IOS version does not recognize, the switch will return a '% Invalid input' error at the CLI. This failure would occur only on switches running that divergent IOS version, while other switches with compatible syntax execute successfully.

  • ✗

    SSH connectivity to the switch is blocked by an ACL

    Why it's wrong here

    If SSH to the switch were blocked by an ACL, Ansible would fail to establish a transport connection, timing out or receiving a connection refused before any CLI command is sent. That would produce an unreachable or connection failure message, not a CLI parsing error about VLAN syntax. Since the reported error is specifically a command rejection from the device (e.g., 'invalid input'), the switch was reachable and the failure occurred at the configuration stage, making an ACL blocking SSH an unlikely cause.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.