Courseiva

CCNA Automation Questions

47 of 122 questions · Page 2/2 · Automation topic · Answers revealed

76
MCQmedium

A network engineer is using the ncclient Python library to send NETCONF RPCs to a Cisco IOS XE device. The engineer wants to lock the running configuration datastore before making changes to prevent other NETCONF sessions from modifying it concurrently. Which NETCONF operation should be used?

A.<lock> with <target><candidate/></target>
B.<commit> with <confirmed/>
C.<edit-config> with <default-operation>replace</default-operation>
D.<lock> with <target><running/></target>
AnswerD

The <lock> operation is used to lock a datastore, preventing other sessions from modifying it. The <target> element specifies which datastore to lock, in this case <running/>. This ensures exclusive access for the session. The lock must be released with <unlock> after changes are made. This is the correct operation to prevent concurrent modifications.

Why this answer

NETCONF provides a <lock> operation to lock a datastore, preventing other sessions from modifying it. The <target> element specifies the datastore to lock. On Cisco IOS XE, only the running datastore is supported, so the correct target is <running/>.

Locking ensures that no other NETCONF session can edit the configuration until the lock is released with <unlock>. This is essential for maintaining configuration integrity during automation.

Exam trap

The trap here is assuming that Cisco IOS XE supports the candidate datastore like some other vendors; IOS XE only supports the running datastore.

77
MCQmedium

A company has a large network of 500 Cisco IOS XE routers and switches spread across multiple sites. The network team wants to automate the collection of interface statistics every hour and store them in a central database for historical analysis. The team has a Linux server with Python 3 and access to all devices via SSH with key-based authentication. They have written a Python script using Netmiko to connect to each device, run 'show interfaces', and parse the output to extract key metrics (e.g., input/output errors, packets per second). The script works correctly when tested on a small subset of devices, but when run against all 500 devices, it takes too long (over 2 hours) and sometimes fails due to SSH connection timeouts. The team needs to reduce the execution time and improve reliability. Which approach should they take?

A.Reduce the collection frequency to every 4 hours
B.Implement multiprocessing or multithreading in the Python script to connect to devices concurrently
C.Replace Netmiko with SNMP polling using the pysnmp library
D.Use Ansible playbooks instead of a custom Python script
AnswerB

Implementing multiprocessing or multithreading allows the Python script to open SSH sessions to multiple routers simultaneously, dividing the 500-device workload across parallel workers. This dramatically reduces total wall-clock time, because network latency and device response delays overlap rather than accumulate. Using a ThreadPoolExecutor or multiprocessing pool with appropriate concurrency limits (e.g., 20-50 workers) can bring total runtime well under the timeout while preserving Netmiko's robust CLI interactions.

Why this answer

The primary bottleneck is sequential SSH connections to 500 devices. By using Python's multiprocessing or multithreading (e.g., concurrent.futures.ThreadPoolExecutor), the script can open multiple SSH sessions in parallel, drastically reducing total wall-clock time. Netmiko itself is not the issue; the serial execution pattern causes the 2-hour runtime and timeouts, which concurrent connections resolve by overlapping I/O wait times.

Exam trap

Cisco often tests the misconception that switching protocols (SNMP) or tools (Ansible) automatically solves performance issues, when the real root cause is lack of concurrency in the execution model.

How to eliminate wrong answers

Option A is wrong because reducing collection frequency to every 4 hours does not solve the underlying performance or reliability problem; it merely masks the symptom by collecting data less often, which may miss hourly trends and still fail when run. Option C is wrong because replacing Netmiko with SNMP polling (pysnmp) introduces a different protocol (UDP-based, community strings) that may require re-engineering the parsing logic and does not inherently improve concurrency; the bottleneck is serial execution, not the library or protocol. Option D is wrong because using Ansible playbooks instead of a custom Python script does not automatically parallelize connections unless explicitly configured with a strategy like 'free' or 'mitogen', and Ansible's default linear strategy still serializes per-batch; the team already has a working script, so switching to Ansible adds complexity without guaranteeing speedup.

78
MCQmedium

A network engineer is building a Python script to retrieve the operational status of all GigabitEthernet interfaces from a Cisco IOS XE device. The script uses the requests library and sends a GET request to the RESTCONF URL https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state. The device returns HTTP 401 Unauthorized. The engineer has verified that the RESTCONF service is enabled and the URL is correct. Which action should be taken to resolve the issue?

A.Change the HTTP method from GET to POST to retrieve operational data.
B.Include HTTP Basic Authentication credentials in the request using the auth parameter of the requests library.
C.Add an Accept header with the value application/yang-data+json to the request.
D.Enable the NETCONF protocol on the device and use it instead of RESTCONF.
AnswerB

RESTCONF on Cisco IOS XE requires authentication for all requests. HTTP 401 Unauthorized explicitly means the request lacks valid credentials. Providing a username and password via HTTP Basic Authentication (e.g., requests.get(url, auth=('admin', 'password'))) supplies the necessary authentication, allowing the request to succeed if the credentials are correct and the user has sufficient privileges.

Why this answer

The HTTP 401 Unauthorized response indicates that the RESTCONF request lacked valid authentication. Cisco IOS XE devices require authentication for RESTCONF operations, typically using HTTP Basic Authentication. Adding the appropriate credentials via the requests library's auth parameter will allow the request to proceed.

Other changes, such as modifying headers or HTTP methods, do not address the authentication requirement.

Exam trap

The trap here is assuming that a 401 error is caused by an incorrect URL or missing header, rather than recognizing it as a clear indication of missing or invalid authentication credentials.

79
MCQhard

A network engineer is using Cisco DNA Center's Intent API to automate the configuration of a new branch site. The engineer needs to create a new site hierarchy, assign devices to the site, and apply a template that configures VLANs and QoS. The engineer writes a Python script that calls the DNA Center APIs in sequence. After running the script, the site is created, and devices are assigned, but the template application fails with an error indicating that the device is not provisioned. What is the most likely missing step in the automation workflow?

A.The engineer must provision the devices to the site using the DNA Center provisioning API before applying templates.
B.The engineer must create a network profile that includes the template before assigning devices to the site.
C.The engineer must synchronize the devices with DNA Center by triggering a discovery job after site assignment.
D.The engineer must first add the devices to a fabric domain before applying templates.
AnswerA

In Cisco DNA Center, before a template can be applied to a device, the device must be provisioned to a site. Provisioning involves assigning the device to a site and configuring management IP, credentials, and other parameters. The Intent API has a provisioning endpoint that must be called after device assignment. Without provisioning, template application fails with an error indicating the device is not provisioned. This is the missing step.

Why this answer

Cisco DNA Center requires devices to be provisioned to a site before templates can be applied. Provisioning configures the device with the necessary management settings and associates it with the site. The Intent API provides a provisioning endpoint that must be called after assigning devices to the site.

Without this step, template application fails. The other options are either for different workflows (fabric, discovery) or not prerequisites.

Exam trap

The trap here is assuming that assigning a device to a site is sufficient for template application, when provisioning is a separate required step.

80
Multi-Selecthard

A network automation team is using the NETCONF protocol to manage a fleet of Cisco IOS XE devices. They need to ensure that configuration changes are applied atomically and that they can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities must be supported and used to achieve these requirements? (Choose two.)

Select 2 answers
A.:validate
B.:startup
C.:rollback-on-error
D.:writable-running
E.:candidate
AnswersC, E

The :rollback-on-error capability ensures that if any operation within a <commit> fails, the server automatically rolls back the entire transaction to the previous state. This provides automatic error recovery and guarantees atomicity. Without it, a partial commit could leave the device in an inconsistent state. This capability is crucial for the team's requirement to roll back on error.

Why this answer

To achieve atomic configuration changes and rollback, the :candidate and :rollback-on-error capabilities are required. The :candidate capability enables editing a candidate datastore and committing changes atomically. The :rollback-on-error capability ensures that if any part of the commit fails, the entire transaction is rolled back.

Together, they provide the transactional integrity and error recovery the team needs.

Exam trap

The trap here is assuming that :validate or :writable-running alone can provide atomicity and rollback, when they only offer validation or direct editing without transactional guarantees.

81
MCQmedium

A network engineer is using a Python script with the ncclient library to retrieve interface statistics from a Cisco IOS XE router. The script connects successfully, but when it sends a <get> RPC, the router returns an error stating that the requested data model is not supported. The engineer verifies that the YANG model is present on the device. What is the most likely cause of this error?

A.The script is using the wrong NETCONF port; it should use port 830 instead of 22.
B.The NETCONF session is using the default namespace urn:ietf:params:xml:ns:netconf:base:1.0 instead of the correct YANG namespace.
C.The ncclient library version is incompatible with the router's NETCONF implementation.
D.The YANG model is present but not enabled in the NETCONF capability set on the device.
AnswerD

For a YANG model to be accessible via NETCONF, it must be advertised in the device's NETCONF capabilities. Even if the model file exists, if it is not enabled or supported by the NETCONF server, requests will fail. The engineer should check the <hello> message for the model's namespace and revision. This is the most likely cause of the error.

Why this answer

The error indicates that the NETCONF server does not support the requested YANG model, even though the model file exists. In NETCONF, capabilities are advertised in the initial <hello> exchange. If a model is not listed there, it is not enabled for NETCONF access.

The engineer must verify the device's NETCONF capabilities and ensure the model is supported and enabled.

Exam trap

The trap here is assuming that the presence of a YANG file on the device automatically makes it available via NETCONF, when in fact it must be advertised as a capability.

82
MCQmedium

A network engineer is using the Cisco SD-WAN vManage API to automate the creation of a new VPN template. The engineer sends a POST request to /dataservice/template/feature with a JSON body and receives an HTTP 400 Bad Request error. The JSON payload is syntactically valid. What is the most likely cause of this error?

A.The API endpoint URL is incorrect and should include the '/template/feature' path without '/dataservice'.
B.The request must use HTTP instead of HTTPS because vManage does not support TLS for API calls.
C.The JSON payload contains a field value that violates the template schema, such as an invalid IP address format.
D.The request is missing the 'X-XSRF-TOKEN' header required for CSRF protection.
AnswerC

An HTTP 400 Bad Request in vManage often indicates that the request body fails validation against the expected schema. Even if JSON syntax is correct, semantic errors like invalid IP addresses, missing required fields, or incorrect data types cause the API to reject the payload. Correcting the field values to match the template schema resolves the issue.

Why this answer

An HTTP 400 Bad Request from the vManage API indicates that the server cannot process the request due to client error, often because the JSON payload fails schema validation. Even with valid JSON syntax, incorrect field values or missing required attributes cause rejection. The engineer should validate the payload against the template schema and correct any semantic errors.

Exam trap

The trap here is assuming that a 400 error always means malformed JSON syntax, when it can also result from valid JSON that violates the API's schema requirements.

83
MCQeasy

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices in the overlay network. The engineer writes a Python script that sends a GET request to https://vmanage-ip/dataservice/device but receives a 401 Unauthorized error. What is the most likely reason for this error?

A.The script is missing the X-XSRF-TOKEN header.
B.The script has not obtained a valid session token via the /j_security_check endpoint.
C.The script is using the wrong HTTP method; it should use POST instead of GET.
D.The script is using HTTP instead of HTTPS.
AnswerB

The vManage REST API requires authentication using a session token. The client must first POST credentials to /j_security_check to obtain a JSESSIONID cookie, which is then included in subsequent requests. Without this token, the server returns 401 Unauthorized. The script must authenticate before accessing /dataservice/device. This is the most likely cause of the error.

Why this answer

The Cisco SD-WAN vManage REST API requires authentication via a session token. The client must POST credentials to /j_security_check to obtain a JSESSIONID cookie, which is then used in subsequent requests. Without this token, any request to protected endpoints like /dataservice/device returns 401 Unauthorized.

The engineer must implement the authentication step before retrieving device data.

Exam trap

The trap here is assuming that basic authentication or a simple API key is sufficient, when vManage requires a session-based token obtained from /j_security_check.

84
MCQmedium

A network team is using Ansible to manage a fleet of Cisco IOS XE switches. The team wants to ensure that the Ansible playbook can connect to the switches without prompting for passwords and without storing passwords in plaintext. The team has generated an SSH key pair and copied the public key to the switches. Which Ansible connection method and authentication mechanism should the team use?

A.Use the local connection with SSH key-based authentication.
B.Use the network_cli connection with SSH key-based authentication.
C.Use the ssh connection with password authentication stored in an Ansible vault.
D.Use the netconf connection with SSH key-based authentication.
AnswerB

The network_cli connection plugin is designed for network devices and supports SSH key-based authentication. By copying the public key to the switches, Ansible can authenticate using the private key without passwords. This meets the requirement of no password prompts and no plaintext passwords. The network_cli plugin handles the SSH session and CLI interaction.

Why this answer

For Cisco IOS XE switches, Ansible uses the network_cli connection plugin to establish SSH sessions and send CLI commands. SSH key-based authentication allows passwordless login by using the private key on the control node, with the public key installed on the switches. This avoids plaintext passwords and interactive prompts.

Other connection plugins like ssh or local are not suitable for network device CLI management.

Exam trap

The trap here is choosing the generic ssh connection plugin for network devices, which is incorrect because network devices require the network_cli plugin for proper CLI interaction.

85
MCQmedium

A network engineer is implementing a CI/CD pipeline for network configuration changes. The pipeline uses Git for version control and Jenkins for orchestration. The engineer wants to ensure that configuration changes are validated before deployment to production devices. Which approach best integrates validation into the pipeline?

A.Run a syntax check using a YANG model validator against the proposed configuration before merging.
B.Use SNMP traps to detect configuration errors after deployment.
C.Manually review the configuration changes in a change advisory board meeting.
D.Apply the configuration directly to production devices and monitor for errors.
AnswerA

Using a YANG model validator ensures the configuration adheres to the device's data model, catching syntax and semantic errors early. This validation can be automated in the CI pipeline, preventing invalid configurations from being deployed. It aligns with infrastructure-as-code best practices.

Why this answer

Integrating YANG model validation into the CI pipeline allows automated checks against device data models, ensuring configurations are syntactically and semantically correct before deployment. This proactive approach reduces errors and aligns with CI/CD best practices for network automation.

Exam trap

The trap here is thinking that post-deployment monitoring or manual review is sufficient, when CI/CD emphasizes automated pre-deployment validation to catch issues early.

86
Multi-Selectmedium

A network engineer is comparing the characteristics of agent-based and agentless automation tools for managing Cisco IOS XE devices. Which two statements accurately describe agentless automation? (Choose two.)

Select 2 answers
A.Agentless tools often rely on APIs or CLI scraping to push configuration changes.
B.Agentless tools provide real-time telemetry streaming from devices without additional configuration.
C.Agentless tools are unable to manage devices from multiple vendors.
D.Agentless tools require a persistent agent to be installed on each managed device.
E.Agentless tools typically use SSH or HTTPS to communicate with network devices.
AnswersA, E

Agentless tools interact with devices using existing interfaces like RESTCONF, NETCONF, or SSH CLI. They may parse CLI output or use structured APIs to apply changes. This approach avoids installing software on devices. This statement is correct and highlights how agentless tools operate.

Why this answer

Agentless automation tools, such as Ansible, do not require software on the managed devices. They communicate over standard protocols like SSH or HTTPS and use APIs or CLI to push changes. This makes them easy to deploy and suitable for multi-vendor environments.

The other statements incorrectly attribute agent-based characteristics or overstate capabilities. The correct answers are the ones that accurately reflect how agentless tools operate.

Exam trap

The trap here is conflating agentless with agent-based tools, or assuming agentless tools provide advanced features like telemetry streaming without extra configuration.

87
MCQhard

A network automation team is using Cisco NSO (Network Services Orchestrator) to manage a multi-vendor network. They have created a service model in YANG and deployed it. A network engineer notices that when a device configuration is changed manually outside of NSO, NSO does not automatically correct it. Which NSO feature should be configured to ensure that NSO re-applies the intended configuration when a device drifts from the service model?

A.Set up a periodic 'sync-from' operation to pull the device configuration into NSO.
B.Configure NSO to use the 'commit dry-run' option when deploying services.
C.Configure the device to use NETCONF Call Home to notify NSO of changes.
D.Enable the 'reconcile' action on the device or service in NSO.
AnswerD

NSO provides a reconcile action that compares the actual device configuration with the intended configuration from the service model and re-applies any missing or altered settings. This action can be triggered manually or scheduled. By enabling reconcile, the engineer ensures that drift is corrected according to the service model. This is the correct feature for enforcing configuration compliance in NSO.

Why this answer

To correct configuration drift in Cisco NSO, the reconcile action is used. It compares the device's actual configuration with the intended configuration defined by the service model and re-applies any discrepancies. This ensures that the device remains compliant with the service intent.

Other options either do not address drift correction or would worsen the situation by syncing the wrong state. Reconcile is the standard mechanism for enforcing compliance in NSO.

Exam trap

The trap here is confusing sync-from with reconcile; sync-from pulls device config into NSO, while reconcile pushes the intended config to the device.

88
MCQhard

A network engineer is using Ansible to manage a fleet of Cisco IOS XE devices. The playbook uses the 'ios_config' module to push a set of configuration lines. After running the playbook, the engineer notices that the configuration changes are not being saved to the startup configuration, and the devices revert to the previous configuration after a reboot. Which parameter should be added to the 'ios_config' task to ensure the running configuration is saved to the startup configuration?

A.diff_against: startup
B.replace: config
C.backup: yes
D.save_when: always
AnswerD

The 'save_when' parameter in the ios_config module controls when the running configuration is saved to the startup configuration. Setting it to 'always' ensures that after any configuration change, the running config is saved. This directly addresses the issue of changes not persisting after reboot. It is the correct parameter to use.

Why this answer

The 'save_when' parameter with the value 'always' forces the ios_config module to save the running configuration to the startup configuration after every change. This ensures that configuration persists across reboots. Other parameters like 'backup', 'diff_against', and 'replace' serve different purposes and do not save the configuration.

Thus, 'save_when: always' is the correct solution.

Exam trap

The trap here is assuming that any configuration change automatically saves to startup, or confusing backup and diff parameters with saving the configuration.

89
MCQhard

A network automation team is using the Cisco SD-WAN vManage REST API to monitor the status of WAN Edge devices. The team writes a Python script that authenticates using basic authentication and then sends a GET request to /dataservice/device. The script receives a 401 Unauthorized error even though the credentials are correct. The team verifies that the user account has the 'admin' role. What is the most likely cause of the authentication failure?

A.The vManage API requires the use of a session token obtained via /j_security_check instead of basic authentication.
B.The vManage API requires TLS client certificate authentication for all API calls.
C.The script must include the header 'Content-Type: application/json' in the GET request to authenticate.
D.The user account must be assigned the 'api' role in addition to the 'admin' role to access the REST API.
AnswerA

The Cisco SD-WAN vManage REST API does not support basic authentication for most endpoints. Instead, clients must authenticate by sending a POST request to /j_security_check with username and password, which returns a JSESSIONID cookie. Subsequent requests must include this cookie. Using basic authentication results in a 401 error even with valid credentials.

Why this answer

The Cisco SD-WAN vManage REST API uses session-based authentication. Clients must first POST to /j_security_check with credentials to obtain a JSESSIONID cookie, which is then included in subsequent requests. Basic authentication is not supported, leading to a 401 error even with valid credentials.

Exam trap

The trap here is assuming that the vManage API supports basic authentication like many REST APIs, when it actually requires a session cookie obtained via a specific login endpoint.

90
MCQmedium

A network engineer is developing a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. The script sends a GET request to the URI https://10.1.1.1/restconf/data/ietf-interfaces:interfaces. The device returns a 401 Unauthorized error. The engineer verifies that the RESTCONF API is enabled and the URI is correct. Which action should the engineer take to resolve this issue?

A.Configure the HTTP client to use Basic authentication with valid user credentials.
B.Enable the NETCONF protocol on the device using the netconf-yang command.
C.Change the request method from GET to POST to retrieve interface statistics.
D.Add the header 'Content-Type: application/yang-data+json' to the request.
AnswerA

RESTCONF requires authentication, and a 401 Unauthorized indicates missing or invalid credentials. Cisco IOS XE supports Basic authentication over HTTPS, so the engineer must include a valid username and password in the request headers. This directly addresses the authentication failure without altering device configuration.

Why this answer

A 401 Unauthorized response from a RESTCONF API indicates that the request lacks valid authentication credentials. Cisco IOS XE RESTCONF uses HTTP Basic authentication, so the client must include an Authorization header with a base64-encoded username and password. Without this, the device rejects the request regardless of the URI or method.

Therefore, configuring Basic authentication is the correct solution.

Exam trap

The trap here is assuming that enabling NETCONF or adjusting headers will fix an authentication error, when the real issue is missing credentials.

91
MCQeasy

A company uses Chef to automate network device configuration. The network devices are Cisco IOS XE running in a brownfield environment. Which Chef component is used to manage the state of the devices?

A.Ohai
B.Chef client
C.Chef workstation
D.Chef server
AnswerB

The Chef client is the enforcement agent that runs directly on each managed device, including network infrastructure such as IOS XE, NX-OS, or IOS XR when Cisco devices are integrated with Chef. It performs the convergence loop by querying the Chef server for the node's run list, evaluating the current state using Ohai, and then executing resources to bring the device to the desired configuration. This on-device agent is precisely the component that applies the automated configuration, making it the correct answer.

Why this answer

In a Chef-managed brownfield environment with Cisco IOS XE devices, the Chef client is the agent that runs on each device (or on a proxy like a guest shell) and applies the desired state defined in cookbooks. It is responsible for converging the device's configuration to match the policy, making it the correct component for state management.

Exam trap

Cisco often tests the distinction between the Chef client (the agent that enforces state) and the Chef server (the repository), leading candidates to mistakenly select the server as the component that manages device state.

How to eliminate wrong answers

Option A is wrong because Ohai is a tool that collects system metadata (e.g., platform, interfaces) on the node and makes it available as attributes, but it does not manage state or apply configurations. Option C is wrong because the Chef workstation is where cookbooks are authored and uploaded to the Chef server; it does not run on the network devices or directly manage their state. Option D is wrong because the Chef server stores cookbooks, node data, and policies, but it does not execute configuration changes on devices; it acts as a central repository and API endpoint.

92
MCQhard

A network engineer is implementing a Python script to interact with a Cisco IOS XE device using RESTCONF. The script must authenticate using basic authentication over HTTPS and retrieve the configured hostname. Which Python code snippet correctly performs this task using the requests library?

A.import requests url = 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['name']
B.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, verify=False) hostname = response.json()['Cisco-IOS-XE-native:hostname']
C.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Content-Type': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['hostname']
D.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['Cisco-IOS-XE-native:hostname']
AnswerD

This snippet uses the correct RESTCONF URL for the hostname, sets the Accept header to 'application/yang-data+json', provides basic authentication credentials, and disables SSL verification. The JSON response for this leaf is a dictionary with the key 'Cisco-IOS-XE-native:hostname'. This correctly retrieves the hostname.

Why this answer

The correct RESTCONF request must use the proper URL for the hostname leaf, set the Accept header to 'application/yang-data+json', provide basic authentication, and parse the response using the fully qualified key 'Cisco-IOS-XE-native:hostname'. The other options use the wrong URL, wrong header, wrong JSON key, or omit authentication.

Exam trap

The trap here is using Content-Type instead of Accept for a GET request, or forgetting the namespace prefix in the JSON key, both of which cause failures.

93
MCQeasy

A network engineer is new to network automation and wants to use a declarative, agentless tool that uses YAML playbooks to push configuration to Cisco IOS devices over SSH. Which tool should the engineer choose?

A.Puppet
B.SaltStack
C.Ansible
D.Chef
AnswerC

Ansible is a declarative, agentless automation tool that uses YAML playbooks and connects to devices over SSH. It does not require an agent on the managed device, making it ideal for network automation. The scenario describes exactly these characteristics.

Why this answer

Ansible is known for being agentless, using YAML playbooks, and connecting over SSH. These features align perfectly with the engineer's requirements. Puppet and Chef typically require agents and use different configuration languages, while SaltStack, though YAML-based, uses a different architecture and terminology.

Exam trap

The trap here is assuming that any declarative automation tool uses YAML playbooks and is agentless, when in fact Ansible is uniquely characterized by these traits in common network automation contexts.

94
Multi-Selectmedium

A network engineer is designing a Python script to interact with a Cisco IOS XE device using RESTCONF. The engineer needs to perform a partial modification of the interface description without affecting other configured parameters. Which two HTTP methods and payload considerations are appropriate for this task? (Choose two.)

Select 2 answers
A.Use the PATCH method with a JSON payload containing only the fields to be changed.
B.Use the POST method to create a new data node for the description under the interface.
C.Use the DELETE method to remove the existing description and then POST a new one.
D.Use the PATCH method with an XML payload and set the Content-Type header to application/yang-data+xml.
E.Use the PUT method with a JSON payload containing only the fields to be changed.
AnswersA, D

RESTCONF supports the PATCH method to apply partial modifications to a resource. When using PATCH with a JSON payload, only the specified fields are altered, leaving other existing configuration intact. This is ideal for changing a single interface description without overwriting the entire interface configuration. The payload must be structured according to the YANG model, targeting the specific leaf to be modified.

Why this answer

Partial modification of a RESTCONF resource is achieved with the PATCH method, which updates only the specified fields. Both JSON and XML payloads are supported, provided the Content-Type header matches the encoding. Using PUT would replace the entire resource, and POST or DELETE are not appropriate for modifying an existing leaf.

Therefore, the two correct approaches are PATCH with JSON and PATCH with XML.

Exam trap

The trap here is assuming that PUT can be used for partial updates like PATCH, when PUT actually replaces the entire resource and can inadvertently erase other configuration.

95
Multi-Selectmedium

A network engineer is designing an automation solution that uses Python with the ncclient library to manage Cisco IOS XE devices via NETCONF. The engineer needs to ensure that the solution can retrieve interface configurations, modify them, and verify the changes. Which two NETCONF operations should the engineer use to accomplish these tasks? (Choose two.)

Select 2 answers
A.<delete-config>
B.<get>
C.<edit-config>
D.<copy-config>
E.<get-config>
AnswersC, E

The <edit-config> operation is used to modify the configuration in a target datastore. It supports operations like merge, replace, create, and delete. The engineer would use this to apply changes to interface configurations. It is the core operation for making configuration changes via NETCONF and is required to fulfill the modification requirement.

Why this answer

To retrieve interface configurations, the engineer should use <get-config>, which fetches configuration data from a datastore. To modify those configurations, <edit-config> is the correct operation, allowing targeted changes. Together, these operations enable reading the current state, applying changes, and then verifying by re-reading the configuration.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both state and config, while <get-config> is specifically for configuration data, which is what the engineer needs for precise editing.

96
MCQhard

A network team uses Ansible to automate VLAN configuration on Cisco IOS devices. The playbook fails with the error 'Failed to connect to the host via ssh: Permission denied (publickey)'. The control node runs Ubuntu, and the network devices are configured with SSH key authentication. Which solution should the engineer implement?

A.Set ansible_ssh_private_key_file in the inventory but omit the passphrase
B.Set ansible_user to the correct username in the inventory
C.Run ssh-add on the control node to add the private key to the SSH agent
D.Enable keyboard-interactive authentication on the IOS devices
AnswerC

Running ssh-add on the control node is the correct solution because it loads the passphrase-protected private key into the running SSH agent, where its decrypted form is retained for the duration of the agent session. Once the key is in the agent, Ansible's SSH connections can use it transparently without prompting for the passphrase, since the agent responds to authentication requests. This directly addresses the root cause: the key must be pre-authenticated to the SSH agent before Ansible attempts to connect, and ssh-add is the standard way to do that in an automated, non-interactive workflow.

Why this answer

The error 'Permission denied (publickey)' indicates that the SSH key is not being presented to the IOS device. Running ssh-add on the control node loads the private key into the SSH agent, which Ansible uses by default when connecting via SSH. This resolves the authentication failure without requiring a passphrase or changing the inventory.

Exam trap

Cisco often tests the misconception that setting inventory variables like ansible_ssh_private_key_file or ansible_user alone fixes SSH key issues, when the real problem is that the key is not loaded into the SSH agent on the control node.

How to eliminate wrong answers

Option A is wrong because setting ansible_ssh_private_key_file without a passphrase does not help if the key is not loaded into the agent or if the key file is encrypted; Ansible will still fail to authenticate if the key is not accessible. Option B is wrong because setting ansible_user to the correct username addresses only the username, not the missing private key authentication; the error is about key-based authentication, not user identity. Option D is wrong because enabling keyboard-interactive authentication on IOS devices would allow password-based methods, but the issue is that the private key is not being presented; keyboard-interactive does not solve the missing key problem and may introduce security risks.

97
MCQhard

A network engineer is developing a Python script to configure OSPF on a Cisco IOS XE device using the NETCONF protocol. The script establishes an SSH session and sends a <edit-config> RPC with the target datastore set to 'running'. The configuration is applied successfully, but after a device reload, the OSPF configuration is missing. The engineer verifies that the <edit-config> operation included the 'default-operation' parameter set to 'merge'. What is the most likely reason for the configuration loss?

A.The <edit-config> operation was applied to the 'candidate' datastore instead of the 'running' datastore, and the candidate was not committed.
B.The 'default-operation' parameter should have been set to 'replace' instead of 'merge' to ensure the configuration is saved to NVRAM.
C.The NETCONF session was not closed properly, causing the device to roll back the configuration upon session termination.
D.The NETCONF <edit-config> operation modifies the running configuration but does not automatically save it to the startup configuration; a separate <copy-config> or <commit> to startup is required.
AnswerD

NETCONF <edit-config> on Cisco IOS XE modifies the running configuration. To persist changes across a reload, the running configuration must be copied to the startup configuration. This can be done with a <copy-config> RPC targeting the 'startup' datastore or by using the 'copy running-config startup-config' command. Without this step, the configuration is lost on reload, which matches the scenario.

Why this answer

NETCONF <edit-config> operations on Cisco IOS XE modify the running configuration. To persist changes across a reload, the running configuration must be explicitly saved to the startup configuration using a <copy-config> RPC or equivalent. The scenario describes a classic case where the configuration is applied but not saved, leading to loss after reload.

The other options incorrectly attribute the loss to datastore targeting, merge behavior, or session handling.

Exam trap

The trap here is assuming that NETCONF automatically saves changes to startup, when it only modifies the running configuration.

98
Multi-Selecteasy

Which TWO statements are true about Cisco DNA Center automation? (Choose two.)

Select 2 answers
A.DNA Center primarily uses SNMP to manage devices.
B.DNA Center only supports greenfield deployments.
C.DNA Center uses a declarative model for network configuration.
D.DNA Center provides a single dashboard for network management.
E.DNA Center uses an imperative model for network configuration.
AnswersC, D

DNA Center's intent-based declarative model lets engineers define the desired end state, and the controller computes and applies device configuration to reach it. This contrasts with imperative per-device CLI configuration, and is a defining characteristic of DNA Center automation.

Why this answer

Option C is correct because Cisco DNA Center is built around intent-based networking, where administrators define the desired end state (intent) declaratively and DNA Center translates that intent into device-level configurations, rather than requiring per-device imperative command sequences. Option D is correct because DNA Center offers a centralized, single-pane-of-glass dashboard that unifies assurance, monitoring, automation, and policy management across the fabric, giving one management view for the network. Options A, B, and E are not correct: DNA Center does not primarily rely on SNMP for management (it uses APIs such as REST, NETCONF, and SSH/CLI for automation and telemetry), it supports both greenfield and brownfield deployments rather than only greenfield, and it does not use an imperative model as its core configuration approach.

Exam trap

Cisco often tests the distinction between declarative and imperative models, and the trap here is that candidates mistakenly associate DNA Center's automation with imperative scripting (like Python or Ansible playbooks) rather than recognizing its intent-based, declarative nature.

99
Multi-Selectmedium

A network automation team is evaluating YANG as the data modeling language underpinning its Cisco IOS XE automation. Which two statements accurately describe YANG in this context? (Choose two.)

Select 2 answers
A.YANG replaces the need for underlying transport protocols by embedding its own session and encryption layer for device communication.
B.YANG modules can include constraints such as type, range, and pattern on leaves, and devices enforce these during configuration validation.
C.YANG data can only be serialized as XML, so JSON payloads are invalid for any NETCONF or RESTCONF operation.
D.YANG models are proprietary to Cisco and cannot be extended or reused across different vendors' network operating systems.
E.YANG defines a hierarchical, tree-structured schema for configuration and state data that protocols such as NETCONF and RESTCONF can transport.
AnswersB, E

YANG leaves carry built-in types and restriction statements like range, length, pattern, and mandatory. When a NETCONF or RESTCONF write arrives, the device validates the value against these constraints, producing errors such as 'invalid-value' if violated. This enforcement is central to why model-driven interfaces are more reliable than CLI screen-scraping, and it directly reflects how YANG behaves on IOS XE.

Why this answer

YANG is a hierarchical data modeling language that defines configuration and state schemas transported by NETCONF and RESTCONF. Its leaves carry constraints such as type, range, and pattern that devices validate on write, which is why model-driven automation is more robust than CLI scraping. YANG is an open standard, is not a transport itself, and its data can be encoded in XML or JSON depending on the protocol and media type.

Exam trap

The trap here is confusing YANG, a modeling language, with the transport protocols that actually carry its data.

100
MCQhard

A network engineer is using a Python script with the 'requests' library to interact with a Cisco IOS XE device via RESTCONF. The script sends a GET request to the URI 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1' but receives a 401 Unauthorized error. The engineer has verified that the RESTCONF service is enabled and the URI is correct. What is the most likely cause of the error?

A.The RESTCONF request must include an Accept header specifying 'application/yang-data+json'.
B.The RESTCONF URI is incorrect because it should use 'config' instead of 'data'.
C.The device requires authentication, and the script did not provide valid credentials.
D.The device's HTTP server is not enabled, so it is rejecting the connection.
AnswerC

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication or token-based methods. If the Python script did not include the 'auth' parameter with a valid username and password, or if the credentials are incorrect, the device will return 401. The engineer must configure the script to send proper authentication headers.

Why this answer

The 401 Unauthorized status code specifically means that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, and the Python script must include a valid username and password, typically using HTTP Basic Auth. Without it, the device rejects the request.

The other options would produce different error codes, such as 406 for missing Accept header or 404 for incorrect URI.

Exam trap

The trap here is assuming that a missing Accept header or incorrect URI causes a 401 error; in reality, 401 is solely about authentication, while other issues yield different status codes.

101
MCQmedium

A network automation engineer is using the Cisco DNA Center Intent API to retrieve a list of all network devices. The engineer sends a GET request to the URL https://dnac.example.com/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token. What is the most likely cause of the error?

A.The request must use HTTP instead of HTTPS.
B.The API endpoint /api/v1/network-device requires a POST request.
C.The token must be passed as a query parameter named 'token'.
D.The token was not included in the request header as an X-Auth-Token.
AnswerD

The Cisco DNA Center Intent API requires the authentication token to be included in the HTTP header with the key 'X-Auth-Token'. Without this header, the API returns 401 Unauthorized even if the token is valid. The engineer must add the header 'X-Auth-Token: <token>' to the GET request to authenticate successfully.

Why this answer

The Cisco DNA Center Intent API uses token-based authentication. After obtaining a token via the authentication API, the token must be included in every subsequent request as an HTTP header named 'X-Auth-Token'. Omitting this header causes a 401 Unauthorized response.

The engineer should add the header with the valid token to successfully retrieve the device list. Other methods like query parameters or different HTTP methods are not used for authentication.

Exam trap

The trap here is assuming the token can be passed as a query parameter or that HTTP is acceptable, when DNA Center strictly requires the token in the X-Auth-Token header over HTTPS.

102
MCQmedium

A network engineer wants to automate configuration backups for a fleet of Cisco IOS XE devices using Ansible. The engineer uses the ios_config module with the backup: yes option and sets the backup directory via the ANSIBLE_BACKUP_DIR environment variable. After running the playbook, the engineer finds that no backup files are created on the control node. What is the most likely cause?

A.The ios_config module does not support the backup option; the ios_command module must be used instead.
B.The ios_config module requires the backup option to be set to a file path, not a boolean value.
C.The ANSIBLE_BACKUP_DIR environment variable is not recognized by Ansible; the backup directory must be specified using the backup_options parameter in the task.
D.The Ansible control node must have the paramiko library installed for backups to work; otherwise, backups are silently skipped.
AnswerC

Ansible does not use an environment variable named ANSIBLE_BACKUP_DIR to set the backup directory. Instead, the ios_config module provides the backup_options parameter, which includes a dir_path sub-option to specify where backups are stored. Without this, backups may be saved to a default location or not at all, depending on the Ansible version.

Why this answer

The ios_config module's backup feature saves the device configuration to the Ansible control node. The directory for these backups is not controlled by an environment variable like ANSIBLE_BACKUP_DIR; instead, it is set using the backup_options parameter, specifically the dir_path sub-option. Without specifying this, backups may go to a default location or fail to be created, leading to the observed issue.

Exam trap

The trap here is assuming that Ansible uses environment variables to configure module-specific options like backup directories, when in fact such options are defined within the playbook task itself.

103
MCQhard

A network engineer is using the RESTCONF API on a Cisco IOS XE device to configure an interface. The engineer sends a PATCH request to the URL https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 with the following JSON payload: {"ietf-interfaces:interface": {"description": "Uplink to Core"}}. The request returns a 400 Bad Request error. What is the most likely reason for this error?

A.The URL should use the data store 'running' instead of 'data'.
B.The Content-Type header is missing or incorrect; it should be application/yang-data+json.
C.The PATCH method is not supported by RESTCONF; PUT should be used instead.
D.The interface name must be URL-encoded, so GigabitEthernet1 should be GigabitEthernet%31.
AnswerB

RESTCONF requires the Content-Type header to be set to 'application/yang-data+json' when sending JSON payloads. If the header is missing or set to 'application/json', the server may reject the request with a 400 Bad Request. The engineer must include the correct media type to ensure the server parses the payload correctly.

Why this answer

RESTCONF requires the Content-Type header to be 'application/yang-data+json' for JSON payloads. Without this header, the server cannot interpret the payload and returns a 400 Bad Request. The PATCH method is supported, the URL path is correct, and the interface name does not need encoding.

Ensuring the correct media type resolves the error.

Exam trap

The trap here is focusing on the HTTP method or URL structure while overlooking the mandatory Content-Type header required by RESTCONF for JSON payloads.

104
MCQhard

A network engineer is using the YANG Suite tool to explore YANG models on a Cisco IOS XE device. The engineer wants to retrieve the operational state of all interfaces using NETCONF. The engineer sends a <get> RPC with a filter that selects the 'interfaces-state' container from the ietf-interfaces YANG module. The device returns an empty response. The engineer confirms that interfaces are up and running. What is the most likely reason for the empty response?

A.The 'interfaces-state' container is deprecated in favor of the 'interfaces' container with 'config false' nodes.
B.The ietf-interfaces YANG module is not supported by the device.
C.The NETCONF session is using the 'candidate' datastore, which does not contain operational data.
D.The filter is using the wrong namespace for the ietf-interfaces module.
AnswerA

In newer revisions of the ietf-interfaces YANG module (RFC 8343), the 'interfaces-state' container was removed and replaced by the 'interfaces' container containing both configuration and state data, with state nodes marked as 'config false'. If the device implements the newer model, a filter targeting 'interfaces-state' will return no data. The engineer should query the 'interfaces' container instead.

Why this answer

The ietf-interfaces YANG module has evolved. In RFC 8343, the 'interfaces-state' container was deprecated and its contents merged into the 'interfaces' container. State data is now represented as 'config false' nodes within the same tree.

If a device implements the newer revision, a filter for 'interfaces-state' will not match any data, resulting in an empty response. The engineer should adjust the filter to target the 'interfaces' container and look for state nodes.

Exam trap

The trap here is assuming that the 'interfaces-state' container still exists in all implementations, when it has been deprecated in newer YANG models.

105
MCQeasy

A network automation team wants to programmatically configure a Cisco Catalyst 9300 switch using RESTCONF. The switch is running Cisco IOS XE 17.x. Which HTTP method should be used to create a new VLAN by sending a JSON payload to the RESTCONF URI /restconf/data/Cisco-IOS-XE-vlan:vlan?

A.GET
B.PUT
C.PATCH
D.POST
AnswerD

RESTCONF uses POST to create a new resource in a data tree. Sending a JSON body to the VLAN list URI creates the specified VLAN. The device responds with 201 Created and a Location header. This is the correct method when the target resource does not yet exist and you are adding a new list entry.

Why this answer

RESTCONF maps CRUD operations to HTTP methods: POST creates a new resource within a collection. To add a new VLAN to the VLAN list, the correct method is POST to the list URI. PUT would require the full resource URI and replaces content, PATCH modifies existing resources, and GET only reads.

Thus POST is the correct choice for creating a new VLAN.

Exam trap

The trap here is confusing POST with PUT; POST creates a subordinate resource in a collection, while PUT creates or replaces a resource at a specific URI.

106
MCQmedium

An organization uses Chef to manage network device configurations. A cookbook that configures SNMP community strings is applied to a group of routers. After the run, one router loses SNMP access. The cookbook uses the following resource: snmp_community 'public' do action :remove end. What is the most likely cause of the issue?

A.The router's Chef client encountered a syntax error and stopped mid-execution
B.The cookbook accidentally applied a 'private' community string instead of 'public'
C.The cookbook removed the only configured SNMP community string
D.The cookbook is not idempotent and reapplied the change multiple times
AnswerC

The cookbook likely contains a resource that declares the desired set of SNMP community strings and uses Chef's convergence model to delete any string not in that set. If 'public' was the only community configured on the router, removing it leaves zero valid SNMP communities, causing management stations to lose all SNMP access. This is a classic configuration-drift accident where a declarative resource accidentally omits an existing credential.

Why this answer

The `snmp_community 'public' do action :remove end` resource explicitly removes the SNMP community string named 'public'. If 'public' was the only SNMP community string configured on the router, its removal would leave the router with no valid SNMP community, causing all SNMP access to be lost. Chef applies the resource as defined; the issue is not a syntax error or misapplication of a different string, but the direct consequence of removing the sole community.

Exam trap

The trap here is that candidates may assume the issue is a syntax error or a misapplied community string, but Cisco tests the understanding that Chef resources execute exactly as written, and removing the only SNMP community string will break SNMP access regardless of other factors.

How to eliminate wrong answers

Option A is wrong because a syntax error in the Chef client would typically cause the entire run to fail or produce an error in the Chef logs, not silently remove a community string and then stop mid-execution; the resource shown is syntactically correct. Option B is wrong because the cookbook explicitly targets the 'public' community string with the `:remove` action; there is no mention or evidence of a 'private' string being applied, and the issue is removal, not misapplication. Option D is wrong because idempotency is not the problem; the `:remove` action is inherently idempotent (removing an already-removed community does nothing), and reapplying the change multiple times would not cause the initial loss of access—the first removal alone is sufficient.

107
Matchingmedium

Match each QoS feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Identifying traffic based on specific fields

Setting the DSCP or CoS value in a packet

Dropping packets that exceed a configured rate

Buffering packets to maintain a configured rate

Managing packet order during congestion

Why these pairings

Correct matches: Classification (A), Marking (B), Policing (C), Queuing (F). Common confusions: Shaping vs. Congestion Avoidance (WRED), where Shaping buffers and WRED drops early.

108
MCQmedium

A network engineer is writing a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces but receives an HTTP 406 Not Acceptable response. The engineer verifies that the device has RESTCONF enabled and the credentials are correct. Which action should the engineer take to resolve this issue?

A.Enable NETCONF on the device and use it instead of RESTCONF.
B.Change the HTTP method from GET to POST.
C.Add a Content-Type header of application/yang-data+json to the request.
D.Add an Accept header of application/yang-data+json to the request.
AnswerD

RESTCONF requires the client to specify the desired media type via the Accept header. Without it, the server may return 406 Not Acceptable. Setting Accept: application/yang-data+json tells the server to return data in JSON format, which is the standard for RESTCONF. This directly resolves the 406 error by indicating the client's supported response format.

Why this answer

The 406 Not Acceptable status code indicates that the server cannot produce a response matching the client's Accept header. In RESTCONF, the client must specify the desired media type, such as application/yang-data+json. Without it, the server may reject the request.

Adding the Accept header tells the server to return JSON-encoded YANG data, which is the expected format.

Exam trap

The trap here is confusing the Accept header with the Content-Type header, assuming that any media type header will fix the 406 error.

109
MCQeasy

A network engineer is writing a Python script to query interface statistics from a Cisco IOS XE device using NETCONF. The script must establish a secure session that supports configuration and state data retrieval. Which transport protocol and port should the engineer use for the NETCONF session?

A.SSH over TCP port 22
B.HTTPS over TCP port 443
C.TLS over TCP port 6513
D.HTTP over TCP port 80
AnswerA

NETCONF uses SSH as its transport protocol, and the standard port for SSH is TCP 22. This provides a secure, encrypted channel for NETCONF messages. The engineer should connect to port 22 to establish the NETCONF session, which supports both configuration and state data retrieval via RPCs.

Why this answer

NETCONF is transported over SSH, which by default listens on TCP port 22. This provides a secure, encrypted connection suitable for configuration and state data retrieval. Other protocols like TLS or HTTP are either not supported on Cisco IOS XE for NETCONF or are used for different APIs such as RESTCONF.

The engineer must use SSH on port 22 to establish a NETCONF session.

Exam trap

The trap here is confusing NETCONF with RESTCONF, which uses HTTPS on port 443, or assuming NETCONF over TLS is the default on Cisco IOS XE.

110
MCQmedium

A network engineer is writing a Python script to retrieve the operational state of a GigabitEthernet interface from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 but receives a 406 Not Acceptable response. The device supports RESTCONF and the interface exists. Which HTTP header should the engineer add to the request to resolve this error?

A.Accept: application/xml
B.Accept: application/yang-data+json
C.Authorization: Basic YWRtaW46YWRtaW4=
D.Content-Type: application/yang-data+json
AnswerB

RESTCONF requires the client to specify the desired media type for the response. The 406 Not Acceptable error occurs when the Accept header is missing or does not match a media type the server can produce. Adding Accept: application/yang-data+json tells the server to return the data in JSON format, which IOS XE supports, resolving the error.

Why this answer

The 406 Not Acceptable status code indicates that the server cannot produce a response matching the Accept header. In RESTCONF, the client must specify the desired media type, such as application/yang-data+json, to retrieve data in JSON. Without it, the server may reject the request.

Adding the correct Accept header resolves the negotiation issue.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which specifies the format of the request body, leading to an incorrect fix.

111
MCQeasy

A network engineer is new to automation and wants to start by writing a simple Python script to interact with a Cisco IOS XE device using RESTCONF. Which Python library is specifically designed to simplify sending HTTP requests to RESTCONF APIs?

A.Netmiko
B.Ncclient
C.Paramiko
D.Requests
AnswerD

The Requests library is a popular Python HTTP library that simplifies sending HTTP requests. It is commonly used with RESTCONF to interact with Cisco devices because it handles HTTP methods like GET, POST, PUT, PATCH, and DELETE, and supports authentication and JSON/XML payloads. It is an excellent choice for beginners.

Why this answer

The Requests library is designed for making HTTP requests in Python, which is exactly what RESTCONF uses. It abstracts the complexities of HTTP and allows easy interaction with RESTCONF APIs, including authentication and data formatting. Other libraries like Netmiko and Ncclient are for SSH and NETCONF, respectively, and are not suited for RESTCONF.

Paramiko is for SSH and not HTTP.

Exam trap

The trap here is confusing RESTCONF with NETCONF or CLI automation, leading to the selection of libraries like Ncclient or Netmiko, which are not HTTP-based.

112
MCQhard

A network engineer is using a Python script with the ncclient library to retrieve configuration from a Cisco IOS XE device via NETCONF. The script uses the <get-config> RPC with a source of <running/> and a filter of <native xmlns="http://cisco.com/ns/yang/Cisco-IOS-XE-native"/>. The script successfully retrieves the configuration but the output is in XML format. The engineer wants to convert this XML into a Python dictionary for easier manipulation. Which Python library is specifically designed to parse XML into a dictionary structure?

A.ElementTree
B.lxml
C.BeautifulSoup
D.xmltodict
AnswerD

xmltodict is a Python library that converts XML into a dictionary, making it easy to work with XML data in Python. It preserves attributes and nested structures, and is commonly used with NETCONF responses. It directly addresses the need to transform XML into a dictionary for manipulation.

Why this answer

xmltodict is specifically designed to convert XML into a Python dictionary, making it the ideal choice for transforming NETCONF XML responses into a manipulable dictionary format.

Exam trap

The trap here is confusing general XML parsing libraries with a library that specifically outputs a dictionary.

113
MCQeasy

A network engineer is troubleshooting an automated configuration change that caused a routing loop. The change was pushed via an Ansible playbook that modified OSPF cost values on multiple routers simultaneously. What is the most likely reason for the loop?

A.OSPF does not support changing costs on multiple routers at the same time
B.OSPF uses hop count as a metric, and the changes caused a count-to-infinity issue
C.The changes were applied simultaneously without allowing OSPF to converge between updates
D.The OSPF cost values were changed to non-standard values that OSPF cannot process
AnswerC

When OSPF cost changes are deployed simultaneously across multiple routers without a convergence interval, each router temporarily holds a different version of the link-state database (LSDB). This inconsistency causes the Shortest Path First (SPF) calculations on different routers to produce divergent, potentially looping paths until LSAs are fully flooded and SPF re-runs on all nodes. The correct practice is to stage changes incrementally, allowing each LSA to propagate and the SPF recalculation to complete before the next cost modification is applied.

Why this answer

Applying OSPF cost changes simultaneously on multiple routers without allowing convergence between updates can cause transient routing loops. OSPF relies on the SPF algorithm to calculate loop-free paths based on consistent link-state databases across the network. When costs are changed on multiple routers at once, some routers may have outdated LSAs, leading to inconsistent forwarding tables and temporary loops until all routers reconverge.

Exam trap

Cisco often tests the misconception that OSPF can handle simultaneous changes without issue, but the trap here is that candidates overlook the need for convergence between updates, confusing protocol capability with operational best practices.

How to eliminate wrong answers

Option A is wrong because OSPF fully supports changing costs on multiple routers simultaneously; the issue is not a protocol limitation but the lack of convergence between updates. Option B is wrong because OSPF uses cost (based on bandwidth) as its metric, not hop count; hop count is used by RIP, and count-to-infinity is a RIP-specific problem. Option D is wrong because OSPF can process any positive integer cost value (1 to 65535) as defined in RFC 2328; non-standard values are not a cause of loops.

114
Multi-Selecthard

Which TWO statements about NETCONF and YANG are true?

Select 2 answers
A.NETCONF sessions are stateless
B.YANG defines both the data model and the RPC operations for network devices
C.NETCONF uses TLS as the mandatory transport protocol
D.YANG is a data modeling language used to define the structure of configuration and state data
E.NETCONF uses XML as the data encoding format
AnswersD, E

YANG is a data modeling language used to define the hierarchical structure of configuration and state data in a device. It describes nodes, types, and constraints, allowing controllers and applications to understand the data that NETCONF retrieves and modifies. This is the core purpose of YANG, separate from transport or encoding details, and it is correct because YANG models the data, not the protocol messages.

Why this answer

YANG (RFC 7950) is a data modeling language specifically designed to define the structure of configuration and state data, as well as notifications and RPCs, for network devices. It provides a hierarchical, schema-based representation of data that can be serialized into XML or JSON, making it the standard for modeling NETCONF and RESTCONF datastores.

Exam trap

The trap here is confusing YANG's role in defining data models with NETCONF's role in defining transport and RPC operations, leading candidates to incorrectly select Option B, while also mistaking NETCONF's mandatory SSH transport for TLS.

115
MCQeasy

A network engineer is learning about data models used in network automation. The engineer needs to choose a data modeling language that is human-readable, supports hierarchical data structures, and is used by NETCONF and RESTCONF to define the structure of configuration and state data. Which data modeling language should the engineer choose?

B.YANG
C.XML
D.SNMP MIB
AnswerB

YANG is a data modeling language used to model configuration and state data manipulated by NETCONF, RESTCONF, and other protocols. It is human-readable, hierarchical, and defines the structure, syntax, and semantics of data. YANG models are used by Cisco IOS XE and other vendors to expose their APIs. The engineer should choose YANG because it is specifically designed for this purpose and is the standard for model-driven programmability.

Why this answer

YANG is the data modeling language standardized by IETF for NETCONF and RESTCONF. It provides a hierarchical, human-readable way to model configuration and state data. JSON and XML are serialization formats used to encode data, but they do not define the data model.

SNMP MIBs are for SNMP and not used by NETCONF/RESTCONF. Therefore, YANG is the correct choice for modeling data in modern network automation.

Exam trap

The trap here is confusing data serialization formats like JSON or XML with data modeling languages like YANG.

116
MCQmedium

A network architect is designing a Python script that will retrieve interface statistics from a Cisco IOS XE device using the RESTCONF API. The script must authenticate with a username and password, and all communication must be encrypted. The device is configured with the 'restconf' and 'ip http secure-server' commands. Which HTTP method and authentication mechanism should the script use to retrieve the data?

A.PATCH with Basic Authentication over HTTPS
B.PUT with Token Authentication over HTTPS
C.POST with OAuth 2.0 over HTTP
D.GET with Basic Authentication over HTTPS
AnswerD

GET is the correct HTTP method for retrieving data from a RESTCONF resource. Basic Authentication over HTTPS encodes the username and password in the Authorization header, and the TLS encryption of HTTPS protects the credentials in transit. This satisfies the requirement for encrypted communication and authentication, making it the appropriate choice for this scenario.

Why this answer

RESTCONF uses HTTP methods that align with CRUD operations: GET for read, POST for create, PUT/PATCH for update, and DELETE for delete. To retrieve interface statistics, the script must use GET. Basic Authentication over HTTPS ensures that credentials are encrypted during transmission.

The combination of GET and Basic Auth over HTTPS meets both the functional and security requirements of the scenario.

Exam trap

The trap here is confusing the HTTP methods used for different CRUD operations, such as using POST or PATCH when a GET is required for retrieval.

117
MCQmedium

A network engineer is using the YANG Suite tool to explore YANG models supported by a Cisco IOS XE device. The engineer wants to retrieve the list of available YANG modules from the device using NETCONF. Which NETCONF operation should be used to obtain this information?

A.<get-schema>
B.<get> with a filter for ietf-yang-library:modules-state
C.<get-config> with a filter for ietf-netconf-monitoring:netconf-state
D.<edit-config> to add a new module
AnswerB

The ietf-yang-library YANG module defines a data model for listing YANG modules supported by a device. By using the <get> operation with a subtree filter targeting 'ietf-yang-library:modules-state', the engineer can retrieve the list of all available YANG modules. This is the standard method for discovering YANG models via NETCONF.

Why this answer

To retrieve the list of YANG modules supported by a Cisco IOS XE device, the engineer should use the <get> operation with a filter for 'ietf-yang-library:modules-state'. This data is operational and provided by the ietf-yang-library module. The <get-schema> operation retrieves a specific schema, while <get-config> and <edit-config> are for configuration data.

Thus, the correct operation is <get> with the appropriate filter.

Exam trap

The trap here is confusing the retrieval of a specific YANG schema with listing all available modules, or using <get-config> for operational data.

118
MCQhard

A network automation engineer is developing a Python script using the ncclient library to configure a Cisco IOS XE device via NETCONF. The engineer wants to lock the running datastore, apply a candidate configuration, validate it, and then commit it. Which sequence of ncclient operations correctly performs this workflow?

A.manager.lock('candidate') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
B.manager.lock('running') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('running')
C.manager.lock('candidate') manager.edit_config(target='running', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
D.manager.lock('running') manager.edit_config(target='running', config=config_payload) manager.validate('running') manager.commit() manager.unlock('running')
AnswerA

This sequence correctly locks the candidate datastore, edits it with the desired configuration, validates the candidate, commits the changes to running, and then unlocks the candidate. This follows the NETCONF confirmed-commit workflow and is the standard approach when using the candidate datastore with ncclient. It ensures atomicity and prevents conflicts.

Why this answer

The correct NETCONF workflow with a candidate datastore involves locking the candidate, editing it, validating it, committing to running, and unlocking. This ensures configuration changes are atomic and can be validated before application. The ncclient library maps these to lock, edit_config, validate, commit, and unlock methods.

Using the candidate datastore is essential for this sequence.

Exam trap

The trap here is mixing datastores—locking running while editing candidate, or editing running directly—which breaks the candidate-based transactional model.

119
MCQhard

A network automation team is using NETCONF to configure a Cisco IOS XE device. They send an <edit-config> RPC with the default-operation set to 'merge'. The target configuration already has an interface GigabitEthernet0/1 with an IP address of 10.1.1.1/24. The RPC payload includes a new IP address of 10.1.1.2/24 for the same interface. What will be the result on the device?

A.The interface will have both IP addresses configured as secondary addresses.
B.The device will ignore the new IP address and keep the existing one.
C.The existing IP address will be replaced with the new IP address.
D.The RPC will fail with a 'data-exists' error because the IP address is already configured.
AnswerC

In NETCONF, the 'merge' operation combines the configuration data in the RPC with the existing configuration. For a leaf node like the IP address, which is a single instance, the new value overwrites the existing value. The interface will end up with only the new IP address 10.1.1.2/24. This is because the merge operation updates the leaf with the provided value, effectively replacing the old one.

Why this answer

The NETCONF 'merge' operation (default-operation='merge') combines the RPC's configuration with the device's existing configuration. For a leaf node such as an IP address, which can only have one value, the merge results in the new value overwriting the old one. Therefore, the interface's IP address is replaced with 10.1.1.2/24.

This behavior is consistent with the NETCONF RFC 6241, where merge updates existing data and creates new data as needed.

Exam trap

The trap here is thinking that merge operation adds to existing configuration without overwriting, but for single-instance leaf nodes, it replaces the value.

120
MCQhard

A network engineer is using the Cisco Catalyst Center (formerly DNA Center) Intent API to retrieve a list of all network devices. The engineer sends a GET request to /dna/intent/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token from /dna/system/api/v1/auth/token. What is the most likely reason for the 401 error?

A.The token has expired and must be refreshed every 60 minutes.
B.The token must be URL-encoded before being placed in the header.
C.The token must be included in the request header as 'X-Auth-Token: <token>'.
D.The API endpoint requires the token to be sent as a Bearer token in the Authorization header.
AnswerC

The Cisco Catalyst Center Intent API requires the authentication token to be passed in the HTTP header 'X-Auth-Token'. If the token is included in the body or as a query parameter, the API will reject the request with 401 Unauthorized. The engineer must set the header correctly. This is a common mistake when first using the API.

Why this answer

The Cisco Catalyst Center Intent API uses a custom authentication header named 'X-Auth-Token' to pass the token obtained from the authentication endpoint. Failure to include this header, or using a different scheme like Bearer, results in a 401 Unauthorized error. The engineer must set 'X-Auth-Token' with the token value in all subsequent API calls.

Exam trap

The trap here is assuming that Catalyst Center uses standard OAuth Bearer tokens, when it actually requires a proprietary X-Auth-Token header.

121
MCQhard

A network automation team is using the ncclient Python library to configure a Cisco IOS XE router via NETCONF. The engineer wants to ensure the configuration changes are applied atomically and that the device automatically rolls back if any part of the change fails. Which NETCONF capability must the engineer verify is advertised by the device before relying on this behavior?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:writable-running:1.0
C.urn:ietf:params:netconf:capability:validate:1.0
D.urn:ietf:params:netconf:capability:confirmed-commit:1.0
AnswerD

The confirmed-commit capability enables a commit operation that must be confirmed within a specified timeout; if confirmation does not occur, the device automatically reverts to the previous configuration. This provides the automatic rollback behavior the engineer needs. Without this capability, a failed or unconfirmed commit would leave the device in the new configuration state, so verifying its advertisement is essential for atomic, safe changes.

Why this answer

To achieve atomic configuration with automatic rollback, the NETCONF confirmed-commit capability is required. It allows a commit to be provisional until explicitly confirmed; if confirmation is not received within the timeout, the device reverts to the prior configuration. Verifying that the device advertises this capability ensures the automation can rely on rollback semantics rather than leaving the device in an inconsistent state after a failure.

Exam trap

The trap here is confusing the candidate datastore capability with confirmed-commit, assuming that using a candidate automatically provides rollback when in fact only confirmed-commit does.

122
Multi-Selectmedium

Which THREE attributes are typically included in a YANG module for interface configuration? (Choose three.)

Select 3 answers
A.switchport mode
B.description
C.mtu
D.ip address
AnswersB, C, D

A YANG interface module carries a description leaf holding free-text administrative annotation for the interface. It is a standard configurable attribute alongside administrative state and addressing, making it one of the three expected interface attributes.

Why this answer

In a YANG module for interface configuration, the 'description' leaf (option B) is a standard attribute used to set a human-readable interface description via the CLI equivalent 'description <text>'. The 'mtu' leaf (option C) is also standard, representing the interface Maximum Transmission Unit, commonly configured with 'mtu <value>' and modeled in YANG as an unsigned integer. The 'ip address' node (option D) is included to assign an IPv4 address and subnet mask to an interface, typically modeled as a container or list with 'address' and 'prefix-length' leaves.

Option A, 'switchport mode', is a Layer 2 switching attribute found in vendor-specific or Cisco YANG models (e.g., Cisco IOS XE native model) but is not a generic interface configuration attribute in standard IETF YANG models like ietf-interfaces. Option E, 'mac address', is usually a read-only operational state or a hardware-assigned value, not a typical configurable attribute in a YANG interface configuration module.

Exam trap

Cisco often tests the distinction between configurable YANG leaves (like 'description', 'mtu', 'ip address') and operational state leaves (like 'mac address') or platform-specific extensions (like 'switchport mode') to see if candidates understand the standard IETF interface model versus proprietary additions.

← PreviousPage 2 of 2 · 122 questions total

Ready to test yourself?

Try a timed practice session using only Automation questions.