350-401 Automation Practice Question
A network engineer is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS XE switches. The engineer prefers to write the automation tasks in YAML and does not want to install any software on the switches. Which tool should be used?
⚠ Common exam trap
The trap here is assuming that all configuration management tools are agentless or use YAML; in reality, Puppet and Chef require agents and use their own DSLs, while Ansible is known for being agentless and YAML-based.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ansible
Ansible is an agentless automation tool that uses YAML playbooks, making it ideal for simple configuration pushes to network devices without installing agents. Puppet and Chef typically require agents and use different DSLs, while SaltStack, although YAML-based, often involves a more complex architecture. Ansible's simplicity and native support for Cisco IOS XE modules align with the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Puppet
Why it's wrong here
Puppet typically requires an agent installed on managed nodes, although it can operate in agentless mode using SSH for some modules. However, its configuration is written in a domain-specific language (DSL) rather than YAML, and it is more complex for simple configuration pushes. The scenario specifies agentless and YAML, which aligns better with Ansible.
- ✓
Ansible
Why this is correct
Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to network devices via SSH or other protocols without requiring any software installation on the managed devices. This matches the engineer's requirements: simple, agentless, and YAML-based configuration management for Cisco IOS XE switches.
- ✗
SaltStack
Why it's wrong here
SaltStack can operate in an agentless mode using SSH, but its primary configuration is written in YAML for states, yet it often requires a master and minion architecture. For network devices, it may need additional setup. Ansible is more commonly used for agentless network automation with YAML and has extensive Cisco module support.
- ✗
Chef
Why it's wrong here
Chef uses a Ruby-based DSL for defining configurations and generally requires a Chef client (agent) on managed nodes. While it can use SSH for some tasks, it is not primarily agentless and does not use YAML for playbooks. The engineer's preference for YAML and no agent installation points away from Chef.
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
YAML for Network Config
YAML for Network Config is a human-readable data serialization language used to define, automate, and manage network device configurations in a structured text format.
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.