Courseiva
mediumMultiple Choice

350-401 Practice Question: An Ansible playbook uses the uri module to make a…

An Ansible playbook uses the uri module to make a REST API call to Cisco DNA Center:

--- - hosts: localhost gather_facts: no tasks: - name: Get devices uri: url: "https://dna-center/api/v1/network-device" method: GET headers: X-Auth-Token: "{{ token }}" return_content: yes register: result

- debug: var: result.json

What is missing from this playbook?

⚠ Common exam trap

Cisco often tests the distinction between using a generic module like `uri` versus a dedicated collection, but the trap here is that candidates overlook the fundamental authentication prerequisite and focus on superficial issues like SSL certificates or inventory variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The playbook is missing a task to authenticate and obtain the X-Auth-Token before making the API call.

The playbook attempts to call the Cisco DNA Center API using the `uri` module with a placeholder `{{ token }}` for the X-Auth-Token header, but it never performs the initial authentication step to obtain that token. Cisco DNA Center requires a POST request to `/api/system/v1/auth/token` with valid credentials (username/password) to receive a token, which must then be used in subsequent API calls. Without this authentication task, the playbook will fail because the token variable is undefined or invalid.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The playbook is missing a task to authenticate and obtain the X-Auth-Token before making the API call.

    Why this is correct

    The DNA Center REST API is protected by token-based authentication. A playbook must first send a POST request to /dna/system/api/v1/auth/token using Basic Auth with valid credentials; the JSON response contains a Token field that must be passed in the X-Auth-Token header for all subsequent API calls. Without this initial task, the GET request in the playbook will be rejected with HTTP 401 Unauthorized, regardless of other settings.

  • ✗

    The playbook will work if the token is defined in the inventory file.

    Why it's wrong here

    Adding a token to the inventory file would be an insecure and ineffective workaround. Inventory variables are meant for host-specific data, not session credentials, and DNA Center access tokens are short-lived—they expire after a default timeout (typically 60 minutes). A hardcoded token would eventually become stale and cause authentication failures, so the token must be obtained dynamically via the authentication API within the playbook run.

  • ✗

    The playbook should use the 'cisco.dnac' collection instead of the uri module.

    Why it's wrong here

    The cisco.dnac collection is a convenience wrapper, not a requirement. The uri module can directly consume the DNA Center REST API if the playbook correctly implements the token exchange; the collection's modules still require credentials and internally perform the same authentication call. The root cause of the failure is the missing authentication step, not the choice of module, so swapping to the collection would not solve the problem unless the token is properly obtained.

  • ✗

    The playbook is missing the 'validate_certs: no' parameter to ignore SSL errors.

    Why it's wrong here

    While SSL validation errors are possible when DNA Center uses self-signed certificates, adding 'validate_certs: no' only bypasses certificate verification—it does not address the missing X-Auth-Token. The API will still return 401 because the request is unauthenticated. Moreover, disabling certificate validation is a security anti-pattern that should only be used in lab environments, and the primary fix here is authenticating to obtain a token.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.