Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Automating Networks Using Cisco Platforms 200-901 Exam Questions

Page: 1 / 33 Total 481 questions

Want more questions? Get Premium Access.

Question 1

What is a capability of the AXL API?

Correct Answer: C. It authenticates users who exist in Cisco Unified Communications Manager.
Explanation:

The Administrative XML Layer (AXL) API in Cisco Unified Communications Manager (CUCM) allows for various administrative tasks, including the ability to authenticate users. It enables applications to interact with CUCM, retrieving user information, and authenticating users based on their credentials stored in CUCM.


Question 2

Which tool provides a testing environment to run tests on network devices and perform network automation scenarios?

Correct Answer: C. pyATS
Explanation:

pyATS (Python Automated Test Systems) is a comprehensive testing framework developed by Cisco, designed specifically for automating the testing of network devices. It provides a robust and flexible environment for creating and running tests on network devices and simulating network automation scenarios.

pyATS enables the creation of reusable test scripts and workflows that can be applied across different network environments and devices.

It supports various protocols and devices, allowing for extensive testing coverage.

It integrates well with other Cisco network automation tools and frameworks, making it a versatile choice for network engineers and developers.


Cisco DevNet pyATS documentation

Cisco DevNet Associate Certification Guide

Question 3

Refer to the exhibit.

The IT team deployed a new Linux virtual machine for a software engineer to use. but the engineer is not comfortable configuring services using Bash. Which workflow is automated by the Ansible playbook?

Correct Answer: A. Restart the network on the ethO interlace and start the httpd service if it is not already started.
Explanation:

The Ansible playbook in the exhibit consists of two stages:

Stage 1: Restarts the network service on the eth0 interface.

Stage 2: Starts the httpd service.

Stage 1:

- name: stage1

ansible.builtin.service:

name: network

state: restarted

args: eth0

This stage ensures that the network service on the eth0 interface is restarted.

Stage 2:

- name: stage2

ansible.builtin.service:

name: httpd

state: started

This stage ensures that the httpd service is started if it is not already running.


Ansible Playbook Documentation: Ansible Service Module

Question 4

Refer to the exhibit.

A company recently acquired new IP-based security cameras. After discussion with the engineering team, they decide to segment the security camera traffic m the rest...The engineer assigns the new VLAN 10 for the security camera traffic. After all the devices are configured, it seems as if the cameras cannot access the Internet, .. a few minutes of debugging, the engineer restricts the problem to the router configuration. What is the cause of the issue?

Correct Answer: C. A specific permit statement for the 192.168.10.0/24 subnet is missing from the access list.
Explanation:

The exhibit shows the router configuration for NAT (Network Address Translation). To allow traffic from the security cameras to access the Internet, the access list needs to include a permit statement for the 192.168.10.0/24 subnet.

Access List Configuration: The access list (ACL) should permit traffic from the security camera VLAN (192.168.10.0/24).

NAT Configuration: The NAT configuration uses an ACL to determine which internal IP addresses are translated to the public IP address pool.

Missing Permit Statement: Without a specific permit statement for the 192.168.10.0/24 subnet, the router does not translate the IP addresses from this subnet, resulting in a lack of Internet access for the security cameras.


Cisco NAT Configuration Guide: NAT Configuration

Question 5

Refer to the exhibit.

OR

An administrator attempts to perform a GET using the Cisco IOS XE RESTOCNF API to return the hostname of a device. The sequence diagram illustrated the HTTP message observed. Which change to the API request resolves the issue?

Correct Answer: B. Use -u cisco: cisco instead of -u 'cisco: cisco'.
Explanation:

The issue shown in the sequence diagram is an HTTP 401 Unauthorized response. This suggests that the authentication credentials provided are incorrect or improperly formatted. The correct format for the credentials in a cURL command should be without quotes around the username and password. Hence, changing -u 'cisco

' to -u cisco

resolves the issue.


Question 6

What are two characteristics of Bare Metal environments that are related to application deployment? (Choose two.)

Correct Answer: C. Provides workloads with access to hardware features; D. Suitable for legacy application that do not support virtualization
Explanation:

Bare Metal environments refer to physical servers that run directly on the hardware without a hypervisor. They offer several characteristics related to application deployment:

Provide workloads with access to hardware features: Bare Metal environments allow applications to directly access hardware resources, which can be critical for performance-sensitive applications.

Suitable for legacy applications that do not support virtualization: Some older applications may not be compatible with virtualized environments or may require direct access to physical hardware, making Bare Metal servers an ideal choice.

Bare Metal environments: Offer direct hardware access and are suitable for certain legacy applications.

Not specifically designed for container-based workloads: While containers can run on Bare Metal, these environments are not specifically tailored for containers.

Not providing hypervisors: Bare Metal environments do not include a hypervisor layer, which is a feature of virtualized environments.


Question 7

A developer creates a web application that receives a username and password and uses them to sync the credentials to other services through HTTPS. API keys to services are part of the configuration files of the application, but the credentials to the database that stores the synchronization logs are obtained through an external vault service. What is the security issue in this scenario?

Correct Answer: C. The API keys are stored in the configuration files but should be stored in the vault service.
Explanation:

The primary security issue in this scenario is that API keys are stored in the configuration files. It is a best practice to store sensitive information such as API keys in a secure vault service rather than in configuration files.

A . Communication between the application and the services is not encrypted - Incorrect. The communication is through HTTPS, which is encrypted. B. The database credentials should be stored in the configuration files so that they are secured on the same server - Incorrect. Database credentials should be securely obtained, as mentioned, through a vault service. C. The API keys are stored in the configuration files but should be stored in the vault service - Correct. Storing API keys in configuration files poses a security risk. They should be stored in a secure vault service. D. The synchronization logs should be encrypted and not stored in a relational database - Incorrect. The issue is not about storing logs in a relational database, but rather the storage of API keys in configuration files.


Secure Secrets Management

Best Practices for Storing API Keys

Question 8

What are two functions of a routing table on a network device? (Choose two.)

Correct Answer: B. It lists the routes to a particular destination.; E. It lists the static and dynamic entries.
Explanation:

A routing table on a network device serves as a map for determining the best path to route packets to their destinations. It lists all the routes to particular destinations, including both the next-hop addresses and the associated metrics. The routing table also includes static entries (manually configured routes) and dynamic entries (routes learned through routing protocols).


Cisco DevNet Associate Study Guide: Understanding Routing Tables (Chapter 4, Section: Routing and Switching Fundamentals).

Question 9

Refer to the exhibit.

An engineer must add new users and set privileges for executing a few Python scripts. The engineer prepares a Bash script to automate this task. The script ds a user and a group from the command-line arguments, creates a directory, and copies the Python scripts to it. The script then changes to the directory and lists the scripts, used on the script workflow, which process is being automated within the loop by using the list of Python scripts?

Correct Answer: C. assigning execution privileges to the owner, setting the user and group owner to the scripts that were initially created, and storing the script names in a file.
Explanation:

The provided Bash script performs the following steps:

Adds a new user with useradd.

Adds a new group with groupadd.

Creates a directory /opt/scripts.

Copies all Python scripts (*.py) to the /opt/scripts directory.

Changes to the /opt/scripts directory.

Lists the Python scripts and processes each script in a loop.

Within the loop, the script:

Appends the script name to a file content.txt.

Assigns execution privileges to the script (chmod u+x).

Changes the ownership of the script to the newly created user and group (chown $1:$2).

This workflow automates the process of setting execution permissions for the owner (the newly created user) and assigning the user and group ownership to the scripts. It also stores the script names in content.txt.


Cisco DevNet Associate Certification Guide

Bash Scripting Documentation

Question 10

What is a capability of Ansible playbooks?

Correct Answer: B. They define the state for a device configuration.
Explanation:

Ansible playbooks are used to define the desired state of a device configuration. Playbooks contain a series of tasks that describe the configuration management, deployment, and orchestration tasks. They are written in YAML and are designed to be simple yet powerful, allowing users to define the state and ensure that devices are configured accordingly.


Question 11

An engineer prepares a set of Python scripts to interact with network devices. To avoid network performance issues, the engineer wants to run them in a test environment. Which resource must be used to monitor the

live execution of code in an always-available environment?

Correct Answer: C. sandbox
Explanation:

Comprehensive Detailed Step by Step Explanation with Reference A sandbox environment is an isolated testing environment that mimics a live network. It allows engineers and developers to run scripts and test code without affecting the production network. Cisco provides sandboxes through the DevNet portal, which are always available for testing and experimentation with network automation and programmability. Using a sandbox helps monitor the live execution of code in a controlled and safe manner, ensuring that any potential issues do not impact the actual network.


Cisco DevNet Sandboxes

Cisco DevNet Associate Certification Guide

Question 12

Refer to the exhibit.

A network engineer uses model-driven programmability to monitor and perform changes on the network. The network engineer decides to use the NETCONF RPC message to complete one of their tasks. What is accomplished by sending the RPC message?

Correct Answer: A. The running-config of the device is returned.
Explanation:

The NETCONF RPC message shown in the exhibit requests the running configuration of the device filtered to show only interface names.

A . The running-config of the device is returned - Correct. The RPC message with the <get-config> operation retrieves the running configuration filtered to include only the interface names. B. The name of each interface is reset to a default name - Incorrect. The RPC message is a read operation, not a configuration change. C. All the YANG capabilities supported by the device are returned - Incorrect. The RPC message specifically targets the running configuration, not the YANG capabilities. D . A list of interface names is returned - Incorrect. While the filter is for interface names, the context is that the running configuration containing these interface names is returned.

Top of Form

Bottom of Form


NETCONF Protocol Operations

YANG Data Modeling Language

Question 13

Which HTTP error code series relates to redirection?

Correct Answer: D. 300
Explanation:

HTTP status codes in the 300 range are related to redirection. These codes indicate that the requested resource has been moved to a different URL, and the client should use the new URL provided in the response. Common examples include 301 (Moved Permanently) and 302 (Found).


Question 14

Which model-driven programmability protocol does Cisco IOS XE Software support?

Correct Answer: C. gNMI
Explanation:

Cisco IOS XE supports model-driven programmability using protocols such as gNMI (gRPC Network Management Interface). gNMI is a protocol that provides a way to manage and configure network devices using a standardized approach to data models and APIs.

Model-Driven Telemetry: gNMI is used for streaming telemetry data from network devices.

Configuration Management: It allows for the configuration of network devices using standardized YANG models.


Question 15

What is the purpose of a MAC address on a network device?

Correct Answer: C. unique hardware address that identifies the network interface of a device
Explanation:

A MAC address (Media Access Control address) is a unique hardware address assigned to the network interface of a device. It is used for network communication at the data link layer of the OSI model.

A . unique network address that identifies the network interface of a device - Incorrect. This describes an IP address. B. unique network interface address that is provided by the DHCP server - Incorrect. MAC addresses are hardware-based, not provided by DHCP. C. unique hardware address that identifies the network interface of a device - Correct. This is the correct definition of a MAC address. D. unique hardware interface address that is provided by the central switch - Incorrect. MAC addresses are not provided by switches.


Cisco MAC Address Basics