easyMultiple Choice
350-401 Practice Question: An engineer is using Ansible to automate the…
An engineer is using Ansible to automate the configuration of NTP on a group of Cisco IOS-XE switches. The playbook uses the ios_ntp module. The engineer wants to ensure that the NTP configuration is applied only to switches that are in the 'core' group, not the 'access' group. The inventory file defines these groups. Which Ansible feature should the engineer use to restrict the playbook to the 'core' group?
⚠ Common exam trap
Cisco often tests the distinction between inventory-based targeting (using the 'hosts' field) versus runtime conditionals (using 'when') or command-line overrides (using 'limit'), leading candidates to overcomplicate the solution when the simplest, most direct method is correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'hosts' field in the play to 'core' instead of 'all'.
Setting the 'hosts' field in the play to 'core' directly targets only the switches in the 'core' group from the inventory. This is the standard Ansible method for restricting a playbook to a specific inventory group, ensuring that the ios_ntp module configures NTP only on those devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'when' clause to check if the switch is in the 'core' group using the 'group_names' variable.
Why it's wrong here
Using a when clause with the group_names variable would work, because group_names contains the list of inventory groups for each host, and you could condition on 'core' being in it. However, the play would still target all hosts in the inventory, meaning every node would be parsed and the condition evaluated, which is wasteful. The proper design-time approach is to narrow the target in the play's hosts field, not to run broadly and filter per-host.
- ✓
Set the 'hosts' field in the play to 'core' instead of 'all'.
Why this is correct
Setting hosts: core in the play header is the most direct, idempotent way to restrict execution to only those switches that belong to the 'core' inventory group. The hosts field accepts an inventory pattern or group name, and Ansible evaluates the pattern before the play starts, so no hosts outside the group are even considered for connection. This is the standard Ansible playbook design feature for targeting a subset of managed nodes.
- ✗
Use the 'limit' option when running the ansible-playbook command to specify the 'core' group.
Why it's wrong here
The --limit option is a command-line parameter for ansible-playbook that overrides the play's host pattern at runtime; it is not a feature written into the playbook itself. Using it would restrict the run to the 'core' group, but the question explicitly asks for a feature to use in the playbook, and limit is a manual CLI action that can be forgotten or misapplied. A playbook should encode its intended audience via the hosts field, not rely on operator-supplied limit flags.
- ✗
Define a variable in the 'core' group and use 'vars_prompt' to ask the engineer which group to run on.
Why it's wrong here
Defining a group variable and using vars_prompt to ask which group to run on mixes unrelated concepts: vars_prompt is for interactive variable entry, not for host targeting. Even if you collected the group name, you would still need to add an expression like hosts: '{{ target_group }}' or a conditional to actually use it, and the prompt would demand a manual response every run, breaking unattended automation. The correct playbook feature for restricting to a group is the hosts field directly, not an AI-driven variable prompt.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.