Courseiva
easyMultiple Choice

350-401 Practice Question: An engineer is automating the configuration of…

An engineer is automating the configuration of SNMPv3 on a large number of Cisco IOS-XE devices using Ansible. The playbook uses the ios_snmp_server module. The engineer wants to ensure that the SNMP configuration is applied only if the device is running a specific IOS version that supports SNMPv3. Which Ansible feature should the engineer use to conditionally execute the task?

⚠ Common exam trap

Cisco often tests the distinction between static task selection (tags) and dynamic conditional execution (when), leading candidates to mistakenly choose 'tags' for runtime version checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'when' clause with a condition on the 'ansible_net_version' fact.

The 'when' clause in Ansible allows conditional execution of a task based on a fact or variable. The 'ansible_net_version' fact, gathered by the ios_facts module, contains the exact IOS version string. By using 'when: ansible_net_version is version('X.Y.Z', '>=')', the engineer can ensure the SNMPv3 configuration task runs only on devices running a supported IOS version, avoiding errors on unsupported platforms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the 'tags' feature to selectively run the SNMP task only on certain devices.

    Why it's wrong here

    Tags are static labels attached to tasks or plays at authoring time; they are selected via --tags or --skip-tags on the command line, not evaluated per-host during a run. A tagged task either runs for every host in the play or for none, depending on the tag list, so it cannot react to the per-device ansible_net_version fact. Thus, tags are useful for grouping tasks by purpose, not for making device-specific execution decisions.

  • ✗

    Use the 'register' directive to capture the output and then use 'failed_when' to skip the task.

    Why it's wrong here

    The register directive stores a task's result in a variable so you can inspect output or status later, and failed_when specifies an expression that, when true, artificially marks the task as failed. To use these for conditional SNMP execution, you would need to run the SNMP task on every device, register its result, then fail it on hosts where the version doesn't match—an awkward, error-prone workaround that would require ignore_errors and still waste resources. The intended mechanism for skipping a task before it runs is a when clause, which evaluates facts before the task is attempted.

  • ✓

    Use the 'when' clause with a condition on the 'ansible_net_version' fact.

    Why this is correct

    The when clause is the standard Ansible mechanism for per-host conditional execution; it evaluates a Jinja2 expression against facts such as ansible_net_version, and if the expression is false, the task is skipped entirely for that host. For network devices, facts must first be gathered via a module like ios_facts, which populates ansible_net_version with the IOS image version. Using 'when: ansible_net_version is version('16.9', '>=')' is the correct, declarative way to run the SNMP task only on devices matching the version criteria.

  • ✗

    Use the 'block' and 'rescue' structure to handle version mismatches.

    Why it's wrong here

    Block and rescue are Ansible's error-handling constructs: block groups tasks, and rescue defines tasks that run only if a task inside the block fails, similar to try/catch in programming languages. To handle version mismatches with this structure, you would have to deliberately cause a task to fail on unsupported devices and then use rescue to perform the SNMP task—a convoluted approach that inverts the intended flow and treats a version check as an exception rather than a normal condition. Conditional task execution based on facts is better left to when, which prevents the task from running in the first place instead of recovering after a failure.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.