mediumMultiple Select
350-401 Practice Question: Which two statements about using Python for…
Which two statements about using Python for network automation with Cisco devices are true? (Choose two.)
⚠ Common exam trap
Many candidates confuse the layering of Paramiko, Netmiko, and NAPALM, and assuming Netmiko is Cisco-IOS-only when it is actually multi-vendor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Netmiko is a Python library that simplifies SSH connections to network devices by handling authentication and session establishment.
Option A is correct because Netmiko is a Python library built on top of Paramiko that abstracts SSH connection details—handling authentication, session establishment, and device prompts—so scripts can interact with Cisco devices without manually managing low-level SSH. Option B is correct because NAPALM provides a vendor-agnostic API with methods such as get_facts(), get_interfaces(), and get_config() that retrieve operational state and configuration data across multiple vendors, including Cisco IOS, IOS-XR, NX-OS, and Junos. Option C is incorrect because Python is an interpreted language; scripts are executed by the Python interpreter and are not compiled into native machine code. Option D is incorrect because Netmiko supports many platforms beyond Cisco IOS, including Cisco IOS-XE, IOS-XR, NX-OS, ASA, Juniper, Arista, and others via its platform-specific drivers. Option E is incorrect because Paramiko is a lower-level SSH library, while Netmiko is the higher-level abstraction that adds network-device-specific automation features on top of Paramiko.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Netmiko is a Python library that simplifies SSH connections to network devices by handling authentication and session establishment.
Why this is correct
Netmiko wraps Paramiko to abstract per-vendor SSH prompts, handling login credentials, enable mode and prompt detection so scripts need not manage raw channels. This satisfies the stem's requirement for simplified SSH session establishment and authentication against Cisco devices.
- ✓
NAPALM can be used to retrieve operational state data from network devices using a vendor-agnostic API.
Why this is correct
NAPALM exposes uniform methods like get_facts and get_interfaces across vendors, translating each platform's native commands into consistent Python structures. This satisfies the vendor-agnostic requirement, letting one script retrieve operational state from multivendor devices without per-OS parsing.
- ✗
Python scripts for network automation are compiled into native machine code for faster execution.
Why it's wrong here
Python is interpreted at runtime by CPython, not compiled to native machine code; only optional tools such as Cython or Nuitka do that. The claim is tempting because compiled languages do execute faster, but Python's appeal for automation is rapid scripting, not native compilation.
- ✗
The netmiko library can only be used with Cisco IOS devices.
Why it's wrong here
Netmiko supports many vendors beyond Cisco, including Juniper, Arista and HP, through platform-specific drivers. The claim tempts because Netmiko originated with Cisco IOS, yet its multi-vendor device_type parameter is precisely what makes it useful in heterogeneous networks.
- ✗
Paramiko is a higher-level library than Netmiko and provides additional automation features.
Why it's wrong here
Paramiko is a lower-level SSH library implementing the transport and channel layers; Netmiko wraps it with device-aware methods such as send_config_set. The reversed hierarchy is tempting because Paramiko predates Netmiko, but Netmiko adds the automation abstractions Paramiko lacks.
Visual reference
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Cisco DNA Center Automation
Cisco DNA Center Automation is a centralized software platform that simplifies network management by automatically configuring, monitoring, and troubleshooting Cisco devices using policy-driven intent and software tools.
Key term
Python for Network Engineers
Python for Network Engineers is the use of the Python programming language to automate, configure, monitor, and troubleshoot network devices like routers and switches.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two statements about using Python for network automation are true? (Choose two.)
medium- ✓ A.The netmiko library is commonly used to automate SSH connections to Cisco devices.
- B.The paramiko library provides a high-level API for network automation tasks.
- ✓ C.The requests library can be used to send HTTP requests to REST APIs on network devices.
- D.The telnetlib library is recommended for secure network automation.
- E.The scapy library is used to send configuration commands to network devices.
Why A: Option A is correct because netmiko is a multi-vendor Python library built on top of Paramiko that simplifies establishing SSH (and Telnet) sessions to network devices such as Cisco IOS, IOS-XE, and NX-OS, handling prompts, paging, and enable mode automatically. Option C is correct because the requests library is the standard Python HTTP client used to send GET, POST, PUT, PATCH, and DELETE requests to REST APIs (for example, Cisco DNA Center, Meraki, or NX-API), typically with JSON payloads and authentication headers. Option B is incorrect because Paramiko is a low-level SSHv2 implementation, not a high-level network-automation API; netmiko provides that higher-level abstraction. Option D is incorrect because telnetlib sends credentials and data in cleartext, so it is not recommended for secure automation—SSH-based tools like netmiko or Paramiko should be used instead. Option E is incorrect because Scapy is a packet crafting, sending, and sniffing library, not a tool for pushing configuration commands to network devices.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.