hardMultiple Choice
350-401 Practice Question: Writes an Ansible playbook to configure a VLAN on…
A network engineer writes an Ansible playbook to configure a VLAN on a Cisco Nexus switch:
```yaml --- - name: Configure VLAN hosts: nxos_switches gather_facts: no tasks: - name: Create VLAN 100 cisco.nxos.nxos_vlan: vlan_id: 100 name: test_vlan state: present ```
What is a potential issue with this playbook?
⚠ Common exam trap
Many exam-takers assume Ansible modules for network devices work like Linux modules without needing explicit connection and privilege escalation directives, leading them to overlook the mandatory `connection: network_cli` and `become: yes` settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook is missing the 'connection: network_cli' and 'become: yes' directives to enable privileged mode.
Ansible modules for Cisco NX-OS require `connection: network_cli` (or `ansible_connection: network_cli`) to use the CLI transport, and `become: yes` to elevate privileges to enable mode (similar to `enable` on a switch). Without these, the playbook will fail to authenticate or execute privileged commands, as the `nxos_vlan` module needs to send configuration commands that require enable access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The module name is incorrect; it should be 'nxos_vlan_config' instead of 'nxos_vlan'.
Why it's wrong here
The cisco.nxos collection specifically provides a module named nxos_vlan for VLAN configuration, and it is the correct module to use here. There is no module named 'nxos_vlan_config' in current versions of the collection; 'nxos_config' is for arbitrary configuration commands, not dedicated VLAN management. Therefore, the module name is not the cause of the failure.
- ✓
The playbook is missing the 'connection: network_cli' and 'become: yes' directives to enable privileged mode.
Why this is correct
Ansible network modules for NX-OS require the connection variable to be set to 'network_cli' so that the module can establish a persistent SSH session to the network device. In addition, 'become: yes' with 'become_method: enable' is needed to enter privileged exec mode, otherwise the module cannot execute configuration commands. Omitting these directives means the playbook will fail or the module will be unable to apply the VLAN configuration.
- ✗
The VLAN ID must be a string, not an integer.
Why it's wrong here
The vlan_id parameter for the cisco.nxos.nxos_vlan module accepts an integer type, so passing a numeric value is perfectly valid. The module automatically converts the integer to the required CLI string during execution. Therefore, using an integer for vlan_id does not cause any error and is not the reason the playbook is failing.
- ✗
The 'state: present' is invalid; it should be 'state: create'.
Why it's wrong here
In Ansible modules, 'state: present' is the standard way to ensure a resource exists, and it is the correct value for the nxos_vlan module. There is no valid state option called 'create' in this module; the available states are 'present' and 'absent'. Thus, the playbook's use of 'state: present' is not a mistake.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
YAML for Network Config
YAML for Network Config is a human-readable data serialization language used to define, automate, and manage network device configurations in a structured text format.
Key term
Ansible for Network Automation
Ansible for Network Automation is an open-source tool that allows network engineers to automate the configuration, management, and deployment of network devices like routers and switches using simple text files instead of manual commands.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.