hardMultiple Select
350-401 Practice Question: Which three statements about Ansible modules for…
Which three statements about Ansible modules for Cisco IOS-XE are true? (Choose three.)
⚠ Common exam trap
The trap is that candidates may assume ios_facts only gathers interface statistics (it gathers much more) or that ios_lldp is limited to global configuration (it supports interface-level), leading them to incorrectly exclude the true statements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ios_config module supports idempotent configuration changes by comparing the desired state with the running configuration.
Option A is correct because ios_config is the declarative configuration module for IOS-XE: it renders the candidate lines, compares them against the device's running configuration (via the network_cli connection and the device's show running-config output), and only pushes the diff, which makes repeated runs idempotent. Option B is correct because ios_command is the read-only module designed to run arbitrary operational (show) commands on IOS-XE and return structured results in the stdout/stdout_lines keys, which can then be parsed by filters or subsequent tasks. Option D is correct because ios_vlan manages VLAN resources on Cisco IOS/IOS-XE devices, allowing VLANs to be created, modified (name, state), and removed declaratively. Option C is not correct because ios_facts collects a broad set of facts—including hardware, software version, hostname, interfaces, and IP addressing—not just interface statistics. Option E is not correct because ios_lldp supports interface-level parameters (such as enabling/disabling LLDP per interface via the interfaces option), not only the global enable/disable state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ios_config module supports idempotent configuration changes by comparing the desired state with the running configuration.
Why this is correct
The ios_config module compares the supplied configuration lines against the device's running configuration and pushes only the missing lines, so repeated runs produce no further change. This satisfies the idempotency requirement rather than blindly reapplying commands each execution.
- ✓
The ios_command module can be used to execute show commands and capture output for parsing.
Why this is correct
The ios_command module runs operational show commands on IOS-XE devices and returns their output as structured data, satisfying the requirement to capture command results for parsing. Unlike configuration modules, it makes no persistent changes, so it fits read-only verification tasks such as gathering interface or routing state.
- ✗
The ios_facts module gathers only interface statistics from the device.
Why it's wrong here
The ios_facts module collects a broad set of system facts, including hardware, configuration and interface details, not just interface statistics. It is tempting because gathering interface data is a common Ansible task, and ios_facts does return that among many other facts, so it would suit a playbook needing general device inventory.
- ✓
The ios_vlan module is used to create and delete VLANs on Cisco IOS devices.
Why this is correct
The ios_vlan module manages VLAN configuration on Cisco IOS and IOS-XE devices, letting you create and delete VLANs declaratively. This satisfies the stem's requirement for a true statement about Ansible modules for IOS-XE, since VLAN provisioning is a core supported operation within the Cisco IOS collection.
- ✗
The ios_lldp module can only enable LLDP globally, not on specific interfaces.
Why it's wrong here
The ios_lldp module manages LLDP globally and per interface, so restricting it to global enablement is false. It is tempting because LLDP configuration is often applied device-wide, but the module's interface-level parameters make per-interface enablement the correct capability.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.