A network automation team is using the NETCONF protocol to manage a fleet of Cisco IOS XE devices. They need to ensure that configuration changes are applied atomically and that they can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities must be supported and used to achieve these requirements? (Choose two.)
The :rollback-on-error capability ensures that if any operation within a <commit> fails, the server automatically rolls back the entire transaction to the previous state. This provides automatic error recovery and guarantees atomicity. Without it, a partial commit could leave the device in an inconsistent state. This capability is crucial for the team's requirement to roll back on error.
Why this answer
To achieve atomic configuration changes and rollback, the :candidate and :rollback-on-error capabilities are required. The :candidate capability enables editing a candidate datastore and committing changes atomically. The :rollback-on-error capability ensures that if any part of the commit fails, the entire transaction is rolled back.
Together, they provide the transactional integrity and error recovery the team needs.
Exam trap
The trap here is assuming that :validate or :writable-running alone can provide atomicity and rollback, when they only offer validation or direct editing without transactional guarantees.