Courseiva

350-401 · topic practice

Automation practice questions

This domain covers network automation and programmability on Cisco IOS XE and related platforms: controller-based and agent-based tools, data formats, APIs, and Python scripting. Questions present operational scenarios and ask you to select the correct tool, protocol, or command, or to interpret JSON/YAML/XML payloads and RESTCONF/NETCONF responses.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Automation

What the exam tests

What to know about Automation

Be able to choose the right automation tool for a scenario and explain its transport and data format. The single most important thing is mapping Ansible to agentless SSH/YAML, NETCONF to SSH/XML, and RESTCONF to HTTP/JSON on IOS XE.

Ansible agentless playbooks over SSH versus Puppet, Chef, and SaltStack agent-based models

NETCONF and RESTCONF APIs using YANG models on Cisco IOS XE devices

Data serialization formats JSON, XML, and YAML and their syntax rules

Python scripting with Cisco SDKs, NETCONF libraries, and REST API calls

Watch out for

Common Automation exam traps

  • ▸Assuming Ansible needs an agent on managed devices; it is agentless and relies on SSH or API transport.
  • ▸Confusing NETCONF, which uses SSH and XML, with RESTCONF, which uses HTTP methods and JSON or XML.
  • ▸Treating YANG as a data format rather than a modeling language that defines the structure exposed by NETCONF and RESTCONF.

Practice set

Automation questions

20 questions · select your answer, then reveal the explanation

A network engineer needs to automate the backup of running configurations from multiple Cisco IOS XE devices to a central TFTP server. Which tool is best suited for this task in a Python-based automation framework?

Question 2mediummultiple choice
Study the full Python automation breakdown →

A network engineer is creating a Python script using the Cisco IOS XE RESTCONF API to configure a loopback interface. The script sends a PUT request to the URI /restconf/data/Cisco-IOS-XE-native:native/interface/Loopback=100 with a JSON body that includes the IP address. The API returns a 201 Created status, but the loopback interface does not appear in the running configuration. What is the most likely issue?

Question 3mediummultiple choice
Study the full ACL explanation →

A network engineer is troubleshooting an Ansible playbook that uses the ios_config module to apply ACLs. The playbook runs without errors, but the ACLs are not applied to the device. The engineer verifies that the device is reachable and the credentials are correct. What is the most likely cause?

Which THREE are valid methods for automating network device configuration using Cisco IOS XE? (Choose three.)

Question 5mediummultiple choice
Read the full Ansible explanation →

Refer to the exhibit. A network engineer wants to use Ansible to change the IP address of Loopback100 from 10.1.100.1/24 to 10.1.200.1/24. The playbook uses the ios_config module. The playbook runs successfully, but the IP address remains unchanged. What is the most likely reason?

Exhibit

R1#show ip interface brief | include Loopback
Loopback0        10.1.1.1       YES manual up                    up
Loopback100      10.1.100.1     YES manual up                    up

R1#show run interface Loopback100
Building configuration...
Current configuration : 67 bytes
!
interface Loopback100
 ip address 10.1.100.1 255.255.255.0
end

R1#show run | include snmp-server
snmp-server community public RO
snmp-server community private RW

Refer to the exhibit. A Python script sends the JSON payload shown via a POST request to the RESTCONF URI /restconf/data/ietf-interfaces:interfaces on a Cisco IOS XE device. The API returns 201 Created, but the interface GigabitEthernet1 is not configured. What is the most likely cause?

Exhibit

{
  "ietf-interfaces:interface": {
    "name": "GigabitEthernet1",
    "type": "iana-if-type:ethernetCsmacd",
    "enabled": true,
    "ietf-ip:ipv4": {
      "address": [
        {
          "ip": "192.168.1.1",
          "netmask": "255.255.255.0"
        }
      ]
    }
  }
}
Question 7hardmultiple choice
Read the full REST/YANG explanation →

A service provider uses Cisco IOS XE routers with NETCONF/YANG for configuration management. They have a centralized automation system that pushes configuration changes via NETCONF. Recently, after a maintenance window, several routers lost connectivity to the NETCONF server. The automation system can still SSH to the routers and execute CLI commands. The engineer suspects that the NETCONF server's SSH key changed, causing the routers to reject the connection. However, checking the routers' configuration, the engineer finds that the 'netconf ssh' command is present and the SSH server is enabled. The engineer also notices that the routers have an 'ip ssh server algorithm publickey' configuration specifying a list of allowed public keys. What is the most likely cause of the NETCONF connectivity loss?

Question 8mediummultiple choice
Read the full Ansible explanation →

A network engineer is automating configuration backups using Ansible. The playbook uses the ios_config module to retrieve running configurations from Cisco IOS XE devices. However, the playbook fails with a timeout error on a specific device. Other devices respond correctly. What is the most likely cause of the failure?

Question 9easymultiple choice
Read the full REST/YANG explanation →

Refer to the exhibit. A network engineer sends a RESTCONF PATCH request with the above JSON payload to the URL https://192.168.1.100/restconf/data/ietf-interfaces:interface=GigabitEthernet0/0/0. What is the expected outcome?

Exhibit

Refer to the exhibit.
{
  "ietf-interfaces:interface": {
    "name": "GigabitEthernet0/0/0",
    "description": "Link to Core",
    "enabled": true,
    "ietf-ip:ipv4": {
      "address": [
        {
          "ip": "192.168.1.1",
          "netmask": "255.255.255.0"
        }
      ]
    }
  }
}
Question 10mediumdrag order
Read the full Automation explanation →

Drag and drop the steps for the three-way TCP handshake into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 11mediumdrag order
Study the full ACL explanation →

Which of the following represents the correct order of steps to configure an extended access control list (ACL) on a Cisco router?

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 12mediummultiple choice
Study the full Python automation breakdown →

A network engineer is using the Python ncclient library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The script connects successfully, but the <get-config> RPC returns an empty <data> element even though the requested configuration clearly exists on the device. The engineer confirms the correct datastore is targeted. Which action should the engineer take to resolve this?

A network engineer is writing a Python script that uses the requests library to interact with a Cisco IOS XE device via RESTCONF. The script authenticates with basic authentication and sends a GET request to retrieve interface statistics. The device returns a 401 Unauthorized error even though the username and password are correct and have privilege level 15. Which configuration is most likely missing on the device?

Question 14mediummultiple choice
Study the full Python automation breakdown →

A network engineer is building a Python script to retrieve interface statistics from a Cisco IOS XE device using the RESTCONF API. The device is configured with the 'restconf' and 'netconf-yang' commands. The engineer sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state/interface=GigabitEthernet1 and receives a 404 Not Found error. The interface GigabitEthernet1 exists and is up. What is the most likely cause of the error?

A network automation team is using a Python script with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script sends an <edit-config> RPC with a candidate datastore and then commits the configuration. After running the script, the team notices that the configuration changes are not present in the running configuration. The script completes without errors. Which is the most likely cause?

Question 16mediummultiple choice
Study the full Python automation breakdown →

A network engineer is using the Python ncclient library to retrieve interface statistics from a Cisco IOS XE device. The script connects successfully but the returned data is a large XML document that is difficult to parse. The engineer wants to work with data in a structured, vendor-neutral format that can be validated against a model. Which action should be taken to achieve this?

Question 17mediummultiple choice
Study the full SD-WAN breakdown →

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of devices. The API requires authentication via a session token. The engineer successfully obtains a token using the /j_security_check endpoint but then receives a 403 Forbidden error when calling /dataservice/device. What is the most likely cause?

Question 18mediummultiple choice
Study the full SD-WAN breakdown →

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices managed by the controller. The engineer sends a GET request to https://vmanage.example.com:8443/dataservice/device with the header 'Accept: application/json' and receives an HTTP 200 OK response containing a JSON payload. The engineer now needs to extract only the device IDs of the devices that are in a 'reachable' state. Which Python code snippet correctly parses the response and filters the devices?

A network engineer is designing a Python script to interact with a Cisco IOS XE device using RESTCONF. The engineer wants to ensure the script can perform both read and write operations on the device's configuration. Which two actions must be taken to enable RESTCONF and allow the script to authenticate? (Choose two.)

Question 20hardmultiple choice
Study the full ACL explanation →

A network engineer is using Ansible to configure a Cisco IOS XE device. The playbook uses the 'ios_config' module to apply an ACL. The playbook runs successfully, but the ACL is not present on the device. The engineer verifies that the device is reachable and credentials are correct. Which action should the engineer take to troubleshoot the issue?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Automation sessions

Start a Automation only practice session

Every question in these sessions is drawn from the Automation domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Automation?
Be able to choose the right automation tool for a scenario and explain its transport and data format. The single most important thing is mapping Ansible to agentless SSH/YAML, NETCONF to SSH/XML, and RESTCONF to HTTP/JSON on IOS XE.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Automation questions in a focused session?
Yes — the session launcher on this page draws every question from the Automation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.