350-401 Automation Practice Question
A network engineer is writing a Python script to query interface statistics from a Cisco IOS XE device using NETCONF. The script must establish a secure session that supports configuration and state data retrieval. Which transport protocol and port should the engineer use for the NETCONF session?
⚠ Common exam trap
Watch out — candidates often confuse NETCONF with RESTCONF, which uses HTTPS on port 443, or assuming NETCONF over TLS is the default on Cisco IOS XE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH over TCP port 22
NETCONF is transported over SSH, which by default listens on TCP port 22. This provides a secure, encrypted connection suitable for configuration and state data retrieval. Other protocols like TLS or HTTP are either not supported on Cisco IOS XE for NETCONF or are used for different APIs such as RESTCONF. The engineer must use SSH on port 22 to establish a NETCONF session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSH over TCP port 22
Why this is correct
NETCONF uses SSH as its transport protocol, and the standard port for SSH is TCP 22. This provides a secure, encrypted channel for NETCONF messages. The engineer should connect to port 22 to establish the NETCONF session, which supports both configuration and state data retrieval via RPCs.
- ✗
HTTPS over TCP port 443
Why it's wrong here
HTTPS on port 443 is used for RESTCONF, not NETCONF. While RESTCONF also supports secure data retrieval and configuration, the scenario specifically asks for NETCONF. NETCONF uses SSH over port 22. Using HTTPS would require a different API and would not be compatible with NETCONF RPCs.
- ✗
TLS over TCP port 6513
Why it's wrong here
NETCONF over TLS is defined in RFC 7589 and uses port 6513, but Cisco IOS XE devices typically do not support NETCONF over TLS. The scenario requires a secure session that works on Cisco IOS XE, where NETCONF is enabled over SSH. TLS is not the standard transport for NETCONF on these devices.
- ✗
HTTP over TCP port 80
Why it's wrong here
HTTP is not a secure protocol and is not used for NETCONF. NETCONF requires a secure transport such as SSH or TLS. Port 80 is used for unencrypted HTTP, which does not provide the necessary security for NETCONF sessions. This option would not work for a secure NETCONF connection.
Visual reference
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.