mediumMultiple Choice
350-401 Practice Question: A Python script using Netmiko is written to send…
A Python script using Netmiko is written to send a command to a Cisco router:
from netmiko import ConnectHandler
device = { 'device_type': 'cisco_ios', 'ip': '192.168.1.1', 'username': 'admin', 'password': 'cisco', 'secret': 'enable'
}
connection = ConnectHandler(**device) connection.enable() output = connection.send_command('show ip interface brief')
print(output)
connection.disconnect()
What is the potential issue with this script?
⚠ Common exam trap
Cisco often tests the distinction between syntactically correct code and robust code, trapping candidates who assume a script that 'looks right' will always work, ignoring the need for error handling in automation scripts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The script lacks exception handling for authentication or connection failures, which can cause the script to crash.
The script lacks exception handling (e.g., try-except blocks) to catch authentication failures, connection timeouts, or device unreachable errors. Without this, if the device is down, credentials are wrong, or the SSH/Telnet service is unavailable, the script will crash with an unhandled exception, making it unreliable for production automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The script will fail because 'device_type' should be 'cisco_ios_telnet' for telnet connections.
Why it's wrong here
The claim that 'device_type' should be 'cisco_ios_telnet' is incorrect because Netmiko's 'cisco_ios' driver is designed to handle SSH connections, while 'cisco_ios_telnet' is a separate driver specifically for telnet sessions. The script's connection method is SSH, as indicated by the use of standard SSH authentication parameters, so 'cisco_ios' is the appropriate device type. Changing it to 'cisco_ios_telnet' would force a telnet connection and likely fail if the device does not have telnet enabled.
- ✗
The script will work correctly without any issues.
Why it's wrong here
The script will not necessarily work 'without any issues' because it lacks exception handling for authentication failures, connection timeouts, and other network errors. While it might succeed on a perfectly stable network with valid credentials, any temporary disruption or misconfiguration would cause an uncaught exception to propagate and the script to crash abruptly. The absence of try/except blocks or custom error handling makes the script fragile and unsuitable for production automation.
- ✗
The script will fail because 'secret' is misspelled; it should be 'enable_secret'.
Why it's wrong here
The parameter name 'secret' is actually the correct Netmiko keyword argument for specifying the enable password used to enter privileged EXEC mode. Netmiko does not use 'enable_secret'—that is not a recognized argument and would raise a TypeError if passed. Therefore, 'secret' is not misspelled; it is the expected key, and the script's failure is entirely unrelated to this parameter.
- ✓
The script lacks exception handling for authentication or connection failures, which can cause the script to crash.
Why this is correct
The script lacks exception handling for authentication or connection failures, which means any Netmiko exception such as AuthenticationException, NetmikoTimeoutException, or ssh_exception.NetmikoTimeoutException will propagate up and crash the script. In real-world environments, network devices may reject credentials, have SSH disabled, or become temporarily unreachable, and without try/except blocks the automation halts immediately. Properly designed scripts should catch these specific exceptions, log meaningful error messages, and optionally implement retry logic to ensure resilience.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.