mediumMultiple Choice
350-401 Practice Question: Given the following Ansible playbook snippet: ---…
Given the following Ansible playbook snippet: --- - name: Configure SNMP hosts: routers gather_facts: no tasks: - name: SNMP community ios_config: lines: - snmp-server community public RO What is the result of this playbook?
⚠ Common exam trap
350-401 often tests whether candidates know that 'RO' is a valid IOS abbreviation and that ios_config is idempotent and does not save to startup-config by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It configures an SNMP community string 'public' with read-only access.
The ios_config module pushes the line 'snmp-server community public RO' into the device's running configuration. On Cisco IOS, 'RO' is the valid abbreviation for read-only when defining an SNMP community string, so the playbook successfully creates a read-only community named 'public'. The playbook does not gather facts and does not specify a 'save_when' parameter, so it modifies the running config only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It configures an SNMP community string 'public' with read-only access.
Why this is correct
The ios_config module pushes the listed configuration lines verbatim to the device, so 'snmp-server community public RO' creates community string 'public' with read-only access. Because gather_facts is disabled, no fact collection interferes; the task simply applies the SNMP community as specified.
- ✗
It fails because 'RO' is not a valid keyword; it should be 'read-only'.
Why it's wrong here
RO is the valid IOS keyword for a read-only community string; read-only is not accepted syntax, so the task succeeds rather than failing. It is tempting because read-only describes the permission accurately in plain English, but IOS expects the abbreviated RO form on the command line.
- ✗
It configures the community string only for SNMPv3.
Why it's wrong here
The snmp-server community command configures SNMPv1/v2c community strings; SNMPv3 uses users and groups with authentication and privacy, not community strings. It is tempting because SNMPv3 is the secure alternative to community-based access, but the syntax shown belongs to the v1/v2c model.
- ✗
It removes any existing SNMP community strings.
Why it's wrong here
ios_config with only lines adds or updates the specified command; it does not negate other snmp-server community entries, so existing strings remain. It is tempting because ios_config can remove lines when a parent or match parameter is used, but that behaviour is not triggered by this snippet.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Ansible for Network Automation
Ansible for Network Automation is an open-source tool that allows network engineers to automate the configuration, management, and deployment of network devices like routers and switches using simple text files instead of manual commands.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.