350-401 Automation Practice Question
A network engineer is writing a Python script using the ncclient library to retrieve the running configuration from a Cisco IOS XE device. The script connects using NETCONF over SSH on port 830. The engineer wants to filter the response to only include interface configuration data. Which NETCONF operation should be used to retrieve the configuration with a filter?
⚠ Common exam trap
Many candidates confuse <get> with <get-config>; <get> retrieves both configuration and state data, while <get-config> retrieves only configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
<get-config> with a <source> of <running> and a <filter> element.
The <get-config> operation is specifically designed to retrieve configuration data from a datastore. It supports a <filter> element to select specific portions of the configuration, such as interfaces. This allows the engineer to retrieve only the desired data, reducing payload size and processing time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
<get> with a <filter> element.
Why it's wrong here
<get> retrieves both configuration and state data from the device. While it can include a filter, it is not specific to configuration and may return operational data as well. For retrieving only configuration, <get-config> is the correct operation. Using <get> could return extra data, making it less precise for configuration retrieval.
- ✗
<copy-config> with a <source> of <running>.
Why it's wrong here
<copy-config> copies configuration from one datastore to another, such as from running to startup. It does not return the configuration to the client in a filtered manner. It is used for backup or persistence, not for retrieving specific configuration data. Thus, it is not the correct operation for this scenario.
- ✗
<edit-config> with a <target> of <running>.
Why it's wrong here
<edit-config> is used to modify configuration, not retrieve it. It loads configuration data into a specified target datastore. It does not return configuration data. Therefore, it cannot be used to retrieve the running configuration. The engineer needs a read operation, not a write operation.
- ✓
<get-config> with a <source> of <running> and a <filter> element.
Why this is correct
<get-config> is the NETCONF operation used to retrieve configuration data. It requires a <source> element specifying the configuration datastore (e.g., <running>) and can include a <filter> to limit the data returned. This is the correct way to retrieve a subset of the running configuration, such as interface configuration.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.