Courseiva
Automation →mediumMultiple Select

350-401 Automation Practice Question

A network engineer is building a Python script to interact with a Cisco IOS XE device using RESTCONF. The script must authenticate, retrieve interface configuration, and handle the response. Which two actions are required to successfully complete this task? (Choose two.)

⚠ Common exam trap

The trap here is conflating NETCONF and RESTCONF tooling, assuming that a NETCONF library or SNMP configuration contributes to RESTCONF access when RESTCONF is purely HTTP-based.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the RESTCONF agent on the device by entering the 'restconf' global configuration command and ensuring the HTTPS server is active.

Successful RESTCONF interaction requires enabling the RESTCONF agent and HTTPS server on the device, then issuing proper HTTP requests to the correct RESTCONF data URIs with appropriate media type headers. NETCONF libraries, SNMP settings, and client-side YANG tools do not enable or perform RESTCONF operations, so only enabling RESTCONF and using correct HTTP GET requests are required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the device with an SNMP community string so RESTCONF can authenticate the API session.

    Why it's wrong here

    SNMP community strings have no role in RESTCONF authentication. RESTCONF uses HTTP authentication mechanisms such as basic authentication with local or AAA credentials. Configuring SNMP does not enable or authorize RESTCONF access. This option confuses SNMP management with model-driven programmability and would not help the script authenticate.

  • ✗

    Use the 'ncclient' library to establish a NETCONF session on port 830 and then issue RESTCONF calls through that session.

    Why it's wrong here

    ncclient is a NETCONF client library and cannot issue RESTCONF calls. RESTCONF is an HTTP-based protocol, so it is accessed with an HTTP client such as Python's requests library. Mixing NETCONF transport with RESTCONF operations is technically impossible because they use different protocols and ports. This option misrepresents how RESTCONF is consumed.

  • ✓

    Enable the RESTCONF agent on the device by entering the 'restconf' global configuration command and ensuring the HTTPS server is active.

    Why this is correct

    RESTCONF is not enabled by default on IOS XE. The 'restconf' global command starts the RESTCONF agent, and it depends on the HTTPS server being active via 'ip http secure-server'. Without these, the device will not accept RESTCONF requests, resulting in connection failures or 401 errors. This step is mandatory before any RESTCONF API call can succeed.

  • ✗

    Install the 'yangsuite' package on the IOS XE device to validate the RESTCONF payloads before sending them.

    Why it's wrong here

    Yangsuite is a client-side tool for exploring and validating YANG models; it is not installed on IOS XE devices. IOS XE devices ship with YANG models internally. Installing a package on the router is not a prerequisite for RESTCONF operation. This option misunderstands where YANG tooling runs and does not contribute to the script's success.

  • ✓

    Send an HTTP GET request to the appropriate RESTCONF URI, such as /restconf/data/ietf-interfaces:interfaces, with the Accept header set to application/yang-data+json.

    Why this is correct

    RESTCONF uses standard HTTP methods and URIs rooted at /restconf. To retrieve interface configuration, a GET request to the correct data resource URI is required. The Accept header tells the server the desired response format, and application/yang-data+json requests JSON. Without specifying the correct URI and media type, the client may receive errors or unusable data.

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.