Courseiva
Automation →mediumMultiple Choice

350-401 Automation Practice Question

A network engineer is using the ncclient Python library to send NETCONF RPCs to a Cisco IOS XE device. The engineer wants to lock the running configuration datastore before making changes to prevent other NETCONF sessions from modifying it concurrently. Which NETCONF operation should be used?

⚠ Common exam trap

The trap here is assuming that Cisco IOS XE supports the candidate datastore like some other vendors; IOS XE only supports the running datastore.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

<lock> with <target><running/></target>

NETCONF provides a <lock> operation to lock a datastore, preventing other sessions from modifying it. The <target> element specifies the datastore to lock. On Cisco IOS XE, only the running datastore is supported, so the correct target is <running/>. Locking ensures that no other NETCONF session can edit the configuration until the lock is released with <unlock>. This is essential for maintaining configuration integrity during automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    <lock> with <target><candidate/></target>

    Why it's wrong here

    While <lock> can lock the candidate datastore, the scenario specifies locking the running configuration datastore. The candidate datastore is used in systems that support candidate configuration, but Cisco IOS XE does not support the candidate datastore. IOS XE supports only the running datastore. Therefore, attempting to lock the candidate datastore would fail or be unsupported.

  • ✗

    <commit> with <confirmed/>

    Why it's wrong here

    <commit> is used to commit changes from the candidate datastore to the running datastore, not to lock a datastore. The <confirmed> element is used for confirmed commit, which automatically rolls back if not confirmed. This is not a locking mechanism. The engineer wants to lock the running datastore, so <lock> is the correct operation.

  • ✗

    <edit-config> with <default-operation>replace</default-operation>

    Why it's wrong here

    <edit-config> is used to modify configuration, not to lock a datastore. The default-operation parameter specifies how to merge the configuration, but it does not provide locking. To prevent concurrent modifications, a lock must be acquired. The engineer needs to use <lock> before <edit-config> to ensure exclusive access.

  • ✓

    <lock> with <target><running/></target>

    Why this is correct

    The <lock> operation is used to lock a datastore, preventing other sessions from modifying it. The <target> element specifies which datastore to lock, in this case <running/>. This ensures exclusive access for the session. The lock must be released with <unlock> after changes are made. This is the correct operation to prevent concurrent modifications.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.