easyMultiple Choice
350-401 Practice Question: Is automating the collection of syslog messages…
A network engineer is automating the collection of syslog messages from a Cisco ASA firewall using a Python script that connects via SSH and runs 'show log'. The script uses the paramiko library. The script works for a few minutes, but then the SSH connection drops with an error 'Server connection dropped'. The engineer suspects that the ASA is closing the connection due to inactivity. What is the best way to keep the connection alive?
⚠ Common exam trap
Cisco often tests the distinction between application-layer workarounds (like running dummy commands) and proper transport-layer keepalive mechanisms, and the trap here is that candidates mistakenly think running a periodic command is the simplest or most reliable solution, when in fact it is inefficient and can disrupt the automation workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'keepalive' parameter in the paramiko Transport object to send keepalive packets every 30 seconds.
The paramiko library provides a built-in keepalive mechanism via the `Transport` object's `set_keepalive()` method. This sends TCP keepalive packets at the specified interval (e.g., 30 seconds) to prevent the ASA firewall from closing the SSH session due to inactivity. Unlike application-layer workarounds, this operates at the transport layer and does not consume CPU cycles on the ASA for command execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the buffer size in the paramiko SSH client.
Why it's wrong here
Increasing the buffer size in the Paramiko SSH client only adjusts the internal read/receive buffer size, which affects throughput or memory usage during data transfer. It does not generate any traffic on an idle connection, so a firewall or SSH server that enforces an idle timeout will still close the session. The buffer is unrelated to the transport-layer keepalive mechanism that periodically sends packets to keep the connection alive.
- ✗
Run a dummy command like 'show clock' every 30 seconds to keep the session active.
Why it's wrong here
Running a dummy command like 'show clock' every 30 seconds can indirectly prevent an idle timeout because it generates activity, but it is not a real keepalive. Each command consumes network device CPU cycles, adds unnecessary output that may pollute your logs or automation scripts, and could trigger interactive paging or require additional parsing. It also relies on the command actually being executed successfully; if the device is slow or congested, the command itself might fail and defeat the purpose.
- ✓
Set the 'keepalive' parameter in the paramiko Transport object to send keepalive packets every 30 seconds.
Why this is correct
Setting the 'keepalive' parameter in the Paramiko Transport object is the correct approach because it tells the SSH transport layer to send keepalive packets on its own at the specified interval, without interfering with any running shell commands. Paramiko's `set_keepalive()` method works by transmitting a simple SSH protocol message (e.g., an SSH2_MSG_IGNORE or global request) whenever no data has been sent for that interval. These lightweight packets reset the idle timers on firewalls and the remote SSH server, keeping the session open cleanly and automatically.
- ✗
Use the netmiko library instead, which automatically handles keepalives.
Why it's wrong here
Netmiko does not automatically enable keepalives; it is a higher-level library that uses Paramiko for the underlying SSH connection. Netmiko does expose a `keepalive` parameter in its device connection dictionaries, but it must be explicitly set by the user to pass the interval to Paramiko's `set_keepalive()` method. Without that explicit configuration, Netmiko behaves exactly like raw Paramiko and will let an idle connection eventually time out.
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.