350-401 Automation Practice Question
A network engineer is using the Cisco SD-WAN vManage API to automate the creation of a new VPN template. The engineer sends a POST request to /dataservice/template/feature with a JSON body and receives an HTTP 400 Bad Request error. The JSON payload is syntactically valid. What is the most likely cause of this error?
⚠ Common exam trap
The trap here is assuming that a 400 error always means malformed JSON syntax, when it can also result from valid JSON that violates the API's schema requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The JSON payload contains a field value that violates the template schema, such as an invalid IP address format.
An HTTP 400 Bad Request from the vManage API indicates that the server cannot process the request due to client error, often because the JSON payload fails schema validation. Even with valid JSON syntax, incorrect field values or missing required attributes cause rejection. The engineer should validate the payload against the template schema and correct any semantic errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The API endpoint URL is incorrect and should include the '/template/feature' path without '/dataservice'.
Why it's wrong here
The vManage API base path is '/dataservice', so the URL is correct. An incorrect URL would typically return 404 Not Found. A 400 error indicates the server understood the request but found the content invalid, so the path is not the issue.
- ✗
The request must use HTTP instead of HTTPS because vManage does not support TLS for API calls.
Why it's wrong here
vManage APIs are accessed over HTTPS for security. Using HTTP would likely result in a connection error or redirect, not a 400 Bad Request. The 400 error is related to the request payload, not the transport protocol.
- ✓
The JSON payload contains a field value that violates the template schema, such as an invalid IP address format.
Why this is correct
An HTTP 400 Bad Request in vManage often indicates that the request body fails validation against the expected schema. Even if JSON syntax is correct, semantic errors like invalid IP addresses, missing required fields, or incorrect data types cause the API to reject the payload. Correcting the field values to match the template schema resolves the issue.
- ✗
The request is missing the 'X-XSRF-TOKEN' header required for CSRF protection.
Why it's wrong here
Missing CSRF token typically results in a 403 Forbidden response, not 400 Bad Request. While vManage requires CSRF tokens for state-changing operations, the absence would be flagged as an authorization issue. A 400 indicates a problem with the request syntax or content, not security headers.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.