350-401 Automation Practice Question
A network engineer is building a Python script that must retrieve the operational state of all interfaces from a Cisco IOS XE device using RESTCONF. The engineer sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state and receives an HTTP 401 Unauthorized response. The device is reachable, RESTCONF is enabled, and the correct credentials are being used in the request. What is the most likely cause of the 401 response?
⚠ Common exam trap
The trap here is assuming a 401 error is caused by wrong credentials rather than by the Authorization header being absent or incorrectly formatted in the HTTP request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HTTP Basic Authentication credentials are not being sent because the Authorization header is missing or malformed.
An HTTP 401 Unauthorized response is returned when authentication credentials are missing or invalid. With RESTCONF on Cisco IOS XE, authentication is performed using HTTP Basic Authentication, so the request must include a correctly formed Authorization header. Since the credentials are known to be correct, the failure must stem from the header not being transmitted or being malformed, which is a common scripting oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The device's RESTCONF service is configured to use NETCONF over SSH instead of HTTPS, so the request must be sent to port 830.
Why it's wrong here
RESTCONF operates over HTTP/HTTPS and does not use port 830, which is for NETCONF over SSH. If the engineer were mistakenly connecting to a NETCONF port with an HTTP request, the failure would be a connection error or protocol mismatch, not an HTTP 401. The scenario states RESTCONF is enabled and the device is reachable.
- ✗
The RESTCONF API requires the Accept header to be set to application/yang-data+json.
Why it's wrong here
The Accept header specifies the desired response format and does not affect authentication. If it were missing or incorrect, the server might return 406 Not Acceptable or a default format, but not 401 Unauthorized. Authentication failures are independent of content negotiation headers, so this is not the cause of the 401 response in this scenario.
- ✓
The HTTP Basic Authentication credentials are not being sent because the Authorization header is missing or malformed.
Why this is correct
A 401 Unauthorized response indicates the server did not receive valid authentication credentials. RESTCONF over HTTPS typically uses HTTP Basic Authentication, which requires a properly formatted Authorization header containing base64-encoded username and password. If the script omits this header or encodes it incorrectly, the device rejects the request with 401 even though the credentials themselves are valid.
- ✗
The URL path should be /restconf/data/ietf-interfaces:interfaces instead of interfaces-state.
Why it's wrong here
The interfaces-state container is valid for retrieving operational state in the ietf-interfaces YANG model. Using interfaces instead would target configuration data, not state, but an incorrect path would produce 404 Not Found, not 401 Unauthorized. The 401 specifically points to an authentication issue, not a resource path problem.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.