mediumMultiple Choice
350-401 Practice Question: An Ansible playbook uses the uri module to make a…
An Ansible playbook uses the uri module to make a REST API call to Cisco DNA Center:
--- - hosts: localhost gather_facts: no tasks: - name: Get devices uri: url: "https://dna-center/api/v1/network-device" method: GET headers: X-Auth-Token: "{{ token }}" return_content: yes register: result
- debug: var: result.json
What is missing from this playbook?
⚠ Common exam trap
Cisco often tests the distinction between using a generic module like `uri` versus a dedicated collection, but the trap here is that candidates overlook the fundamental authentication prerequisite and focus on superficial issues like SSL certificates or inventory variables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook is missing a task to authenticate and obtain the X-Auth-Token before making the API call.
The playbook attempts to call the Cisco DNA Center API using the `uri` module with a placeholder `{{ token }}` for the X-Auth-Token header, but it never performs the initial authentication step to obtain that token. Cisco DNA Center requires a POST request to `/api/system/v1/auth/token` with valid credentials (username/password) to receive a token, which must then be used in subsequent API calls. Without this authentication task, the playbook will fail because the token variable is undefined or invalid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The playbook is missing a task to authenticate and obtain the X-Auth-Token before making the API call.
Why this is correct
The DNA Center REST API is protected by token-based authentication. A playbook must first send a POST request to /dna/system/api/v1/auth/token using Basic Auth with valid credentials; the JSON response contains a Token field that must be passed in the X-Auth-Token header for all subsequent API calls. Without this initial task, the GET request in the playbook will be rejected with HTTP 401 Unauthorized, regardless of other settings.
- ✗
The playbook will work if the token is defined in the inventory file.
Why it's wrong here
Adding a token to the inventory file would be an insecure and ineffective workaround. Inventory variables are meant for host-specific data, not session credentials, and DNA Center access tokens are short-lived—they expire after a default timeout (typically 60 minutes). A hardcoded token would eventually become stale and cause authentication failures, so the token must be obtained dynamically via the authentication API within the playbook run.
- ✗
The playbook should use the 'cisco.dnac' collection instead of the uri module.
Why it's wrong here
The cisco.dnac collection is a convenience wrapper, not a requirement. The uri module can directly consume the DNA Center REST API if the playbook correctly implements the token exchange; the collection's modules still require credentials and internally perform the same authentication call. The root cause of the failure is the missing authentication step, not the choice of module, so swapping to the collection would not solve the problem unless the token is properly obtained.
- ✗
The playbook is missing the 'validate_certs: no' parameter to ignore SSL errors.
Why it's wrong here
While SSL validation errors are possible when DNA Center uses self-signed certificates, adding 'validate_certs: no' only bypasses certificate verification—it does not address the missing X-Auth-Token. The API will still return 401 because the request is unauthenticated. Moreover, disabling certificate validation is a security anti-pattern that should only be used in lab environments, and the primary fix here is authenticating to obtain a token.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
Key term
Ansible for Network Automation
Ansible for Network Automation is an open-source tool that allows network engineers to automate the configuration, management, and deployment of network devices like routers and switches using simple text files instead of manual commands.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.