Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Designing, Deploying and Managing Network Automation Systems 350-901 Exam Questions

Page: 1 / 36 Total 535 questions

Want more questions? Get Premium Access.

Question 1

During the final step in the OAuth2 authorization process, what must the client send to the OAuth authorization server to obtain a data access token?

Correct Answer: D. short-lived access code
Explanation:

During the final step of the OAuth2 authorization process, the client must send the following to the OAuth authorization server to obtain a data access token:

  • Authorization Code: The code received from the authorization server in the previous step.
  • Client ID: The unique identifier for the client application registered with the authorization server.
  • Client Secret: A confidential credential known only to the client and authorization server (sent securely, typically in the request body or HTTP Basic Auth header).
  • Redirect URI: The callback URL where the authorization code was delivered, must match the registered redirect URI.
  • Grant Type: Set to authorization_code to specify the OAuth2 flow being used.

Method: This request is made directly from the client's backend server to the authorization server's token endpoint using HTTPS POST, ensuring the client secret is transmitted securely and never exposed to the user's browser.

Upon validation of these parameters, the authorization server returns the access token, which the client can then use to access protected resources on behalf of the user.

Question 2

Refer to the exhibit.

An application is created to serve the needs of an enterprise. Slow performance now impacts certain API calls, and the application design lacks observability. Which two commands improve observability and provide an output that is similar to the sample output? (Choose two.)

A)

B)

C)

D)

E)

Correct Answer: C. Option C; E. Option E

Question 3

What is a benefit of running multiple instances of a back-end service and using load balancing to distribute the communication between the front-end and back-end services?

Correct Answer: B. High availability is provided for the back-end services.

Question 4

What is a characteristic of a monolithic architecture?

Correct Answer: C. A service failure can bring down the whole application.
Explanation:

A monolitic app can be platform-agnostic but it's not mandatory. But is the app is monolitic, a service failure (such as storage or network) will bring down the whole app/service. This is unlike the distributed application architecture where failure of one microcomponent can be detected and fixed dynamically.


Question 5

A developer is working on a live project and must apply a new feature. After the commit,the manager informs the team that the wrong file was applied. The developer must undo the single commit and apply the file with the name feature-App-UXU1411841916ADD. Which command must the developer use?

Correct Answer: C. git clean

Question 6

Refer to the exhibit.

A Python script has these requirements

* Retrieve a list of Bluetooth clients seen by the access pants on a network.

* Print the content of the response

* Retrieve the next page only if it is available in the response headers

What must be added where the code is missing to get the remaining pages by using the next link from the link response header of the last request?

A)

B)

C)

D)

Correct Answer: A. Option A
Explanation:

To retrieve remaining pages using pagination with the Link header response field, the missing code must:

  • Parse the Link header - Extract the URL from the Link header of the current response
  • Check for next link availability - Verify that a 'next' link exists in the header before attempting to follow it
  • Follow the next link - Use the URL from the Link header to fetch the next page of results

Implementation pattern:

while True:
    response = requests.get(url, headers=headers)
    print(response.json())
    
    # Parse Link header for next URL
    if 'link' in response.headers:
        links = response.headers['link']
        # Extract next link from format: ; rel='next'
        next_url = extract_next_link(links)
        if next_url:
            url = next_url
        else:
            break
    else:
        break

Why this approach:

  • Follows REST best practices for pagination
  • Only requests additional pages if they exist (as required)
  • The Link header provides the server-side pagination cursor, avoiding manual offset/limit calculations
  • Continues until no 'next' link is provided, indicating the last page

Question 7

Which database type should be used with highly structured data and provides support for ACID transactions?

Correct Answer: D. relational
Explanation:

For highly structured data with ACID transaction support, a relational database (SQL database) should be used, such as:

  • PostgreSQL
  • MySQL
  • Oracle Database
  • SQL Server

Relational databases provide:

  • ACID properties: Atomicity, Consistency, Isolation, Durability ensure reliable transactions
  • Structured schemas: Enforce data structure and relationships
  • SQL queries: Powerful querying and joins across structured data

NoSQL databases sacrifice some ACID guarantees for scalability and flexibility, making them unsuitable when ACID compliance and structure are requirements.

Question 8

Refer to the exhibit.

This script uses ciscoyang to configure two VRF instances on a Cisco IOS-XR device using the Yang NETCONF type.

Which two words are required to complete the script? (Choose two.)

Correct Answer: C. false; D. replace

Question 9

What are two benefits of using a centralized logging service? (Choose two.)

Correct Answer: A. reduces the time required to query log data across multiple hosts; E. provides compression and layout of log data

Question 10

Refer to the exhibit.

A developer runs the docker service scale command to increase the number of replicas for the cisco_devnet service. The swarm cluster is using a private IP address subnet. The service has these design requirements:

It must be hosted behind a virtual IP address that is reachable from the Internet.

For security reasons, the Docker swarm cluster subnet must not be reachable from the Internet.

Which design approach is used to fulfill the requirements?

Correct Answer: A. Create an overlay network by using a globally roulable subnet and enable a routing mesh within the swarm cluster.
Explanation:

To meet these requirements, an Ingress Controller or reverse proxy/load balancer with Network Address Translation (NAT) must be implemented. This design approach:

  • Exposes a public virtual IP address that is reachable from the Internet
  • Shields the private subnet by not exposing Docker swarm internal IPs to the Internet
  • Routes traffic from the public IP to the internal services running on private IPs

The load balancer/ingress acts as an intermediary, translating external requests to internal service addresses while keeping the swarm cluster subnet isolated from direct Internet exposure.

Question 11

An application uses OAuth to get access to several API resources on behalf of an end user. What are two valid parameters to send to the authorization server as part of the first step of an authorization code grant flow? (Choose two.)

Correct Answer: A. URI to which the authorization server will send the user-agent back when access is granted or denied; C. secret that was generated by the authorization server when the application registered as an OAuth integration

Question 12

Which configuration stop must be performed on a Cisco IOS XE device to present collected data in Cisco DNA Center?

Correct Answer: B. Apply a telemetry profile.
Explanation:

To present collected data in Cisco DNA Center from a Cisco IOS XE device, the configuration step that must be performed is to enable telemetry (Model-Driven Telemetry/MDT).

Specifically:

  • Enable Netconf/Yang models - configure the device to expose data via NETCONF/YANG for model-driven telemetry
  • Configure telemetry subscriptions - set up subscriptions to specific data models (interfaces, CPU, memory, etc.)
  • Specify collector destination - point telemetry streams to the DNA Center collector IP and port

Example configuration:

telemetry ietf subscription 100
  encoding yang-json
  source-address 10.1.1.1
  filter-type xpath /native/interface/GigabitEthernet[*]
  stream yang-push
  update-policy on-change
  receiver ip address 10.2.2.2 port 5432

This enables DNA Center to receive real-time device state and performance data for visibility and analytics.

Question 13

How does the use of release packaging allow dependencies to be effectively managed during deployments?

Correct Answer: B. designed to prevent any dependencies between release units
Explanation:

Release packaging manages dependencies effectively during deployments through:

  • Version pinning - specifying exact versions of dependencies in package manifests (requirements.txt, package.json, etc.)
  • Dependency lockfiles - creating lock files (package-lock.json, Pipfile.lock, etc.) that freeze transitive dependencies
  • Containerization - packaging the application with all dependencies in a Docker image ensures consistency across environments
  • Reproducibility - the same package deployed multiple times will have identical dependencies
  • Avoiding version drift - preventing environments from diverging due to automatic minor/patch updates

This approach ensures that the exact same versions are deployed consistently across development, staging, and production environments.

Question 14

Which Puppet manifest changes the NTP server and generates the traffic from VLAN 15?

A)

B)

C)

D)

Correct Answer: C. Option C
Explanation:

A Puppet manifest that changes the NTP server and generates traffic from VLAN 15 would need to:

  • Use a resource type to configure NTP (like ntp::server)
  • Configure the NTP server IP address
  • Ensure traffic originates from VLAN 15 (set source interface or IP)

The manifest might use:

  • ntp::server resource for NTP configuration
  • network_interface resource or class parameter to specify VLAN 15
  • Proper class declarations and resource ordering

The correct answer shows Puppet syntax properly configuring NTP and ensuring VLAN 15 as the source for management traffic.

Question 15

A team of developers created their own CA and started signing certificates for all of their loT devices, Which action will make the browser

accept these certificates?

Correct Answer: B. Preload the developer CA on the trusted CA list of the browser.