View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps
Question 161.
Which Cisco NX-OS feature allows a switch to expose a programmable interface for executing supported CLI commands over HTTP or HTTPS?
- NX-API
2. HSRP
3. LACP
4. UDLD
Correct Answer: 1
Explanation:
NX-API provides programmatic access to supported Cisco Nexus devices by allowing software to send commands over HTTP or HTTPS instead of relying exclusively on an interactive CLI session. Responses can be returned in structured forms such as JSON or XML, depending on the command and platform. This makes it easier for automation systems to parse output and integrate operational data into broader workflows. HSRP, LACP, and UDLD are networking features rather than general-purpose programmable management interfaces. NX-API is particularly useful when organizations want to transition existing CLI-based workflows into API-driven automation.
Question 162.
Which advantage does HTTPS provide when using NX-API?
- It guarantees every command succeeds
2. It encrypts the transport between the client and switch
3. It removes the need for authentication
4. It automatically converts CLI output into YANG
Correct Answer: 2
Explanation:
HTTPS protects communication between the automation client and the Nexus switch by encrypting the transport using TLS. This helps protect credentials, tokens, commands, and returned data from interception. HTTPS does not guarantee that an API command will succeed, and it does not eliminate authentication or authorization requirements. It also does not convert CLI output into YANG-modeled data. Transport security is one component of a secure automation design, which should also include strong credentials, certificate validation, least-privilege accounts, and secure secret storage.
Question 163.
A script needs to retrieve interface counters from a Nexus switch and parse them reliably. Which response format is preferable to raw CLI text?
- Plain terminal escape sequences
2. Screenshot output
3. Structured JSON
4. Audio output
Correct Answer: 3
Explanation:
Structured JSON is preferable because it provides predictable key-value structures and arrays that automation software can parse directly. Raw CLI text is designed primarily for human readers and may change formatting across software versions, commands, or platforms. JSON reduces dependence on fragile regular expressions and string parsing. A Python script can deserialize the response into dictionaries and lists, then extract specific counters or fields reliably. Screenshots and terminal formatting are unsuitable for scalable automation. Machine-readable output is one of the main benefits of API-driven management.
Question 164.
Which HTTP response code normally means the client request was valid but the server could not find the requested resource?
- 200
2. 201
3. 500
4. 404
Correct Answer: 4
Explanation:
HTTP status code 404 indicates that the requested resource could not be found. In automation, this can occur because the API path is incorrect, a referenced object does not exist, or a resource was removed. A 200 usually indicates success, while 201 commonly indicates successful resource creation. A 500 response points to an internal server error. Scripts should distinguish these conditions because they require different responses. For example, a missing object may need to be created, while a server error may justify a controlled retry.
Question 165.
Which Python method is commonly used to deserialize a JSON response returned by the requests library?
- response.json()
2. response.compile()
3. response.execute()
4. response.route()
Correct Answer: 1
Explanation:
The response.json() method parses a JSON response body into native Python data structures such as dictionaries and lists. This makes API results much easier to process programmatically. A robust script should first verify that the HTTP request succeeded and that a JSON response is expected. Invalid JSON can raise a parsing exception, so exception handling is useful. The other listed methods are not standard ways to deserialize a requests response. Structured response parsing is fundamental to Python-based infrastructure automation.
Question 166.
Which Python data structure is most appropriate for storing a mapping between switch hostnames and management IP addresses?
- Integer
2. Dictionary
3. Set only
4. String only
Correct Answer: 2
Explanation:
A dictionary is well suited for storing mappings between keys and values. In this case, each hostname can serve as a key and its management IP address as the corresponding value. Dictionaries make lookups simple and readable, for example by retrieving an IP address using the hostname. Sets contain unique values but do not provide key-value mappings, while strings and integers represent individual values. Dictionaries are frequently used in network automation to store device metadata, API configuration, credentials references, and parsed JSON objects.
Question 167.
Which Python feature is most appropriate for applying the same API query to every switch in a list?
- Exception handler only
2. Decorator only
3. for loop
4. Class inheritance only
Correct Answer: 3
Explanation:
A for loop allows the script to iterate through each switch in a list and execute the same logic for every item. This is a core automation pattern because infrastructure workflows often need to perform identical checks across many devices. Functions can be combined with loops to keep the code reusable and readable. Exception handling should also be included so one failed device does not necessarily terminate the entire operation. Decorators and inheritance serve other programming purposes and are not the basic mechanism for sequential device processing.
Question 168.
Which Python mechanism should be used when a script must always close an API session even if an exception occurs?
- break
2. continue
3. lambda
4. finally
Correct Answer: 4
Explanation:
A finally block executes whether or not an exception occurs in the corresponding try block. This makes it appropriate for cleanup operations such as closing API sessions, releasing locks, or closing files. Infrastructure automation should account for failure paths because network requests can time out, authentication can fail, and responses may be malformed. If cleanup is omitted, a failed script may leave sessions or resources open. break and continue affect loop control, while lambda creates an anonymous function.
Question 169.
Which Ansible component defines the systems that a playbook will manage?
- Inventory
2. Handler
3. Template only
4. Vault password file only
Correct Answer: 1
Explanation:
An Ansible inventory defines the hosts and groups targeted by automation. It can include connection information and variables and may be static or generated dynamically. Playbooks reference inventory hosts or groups when deciding where tasks should run. Handlers execute follow-up actions after notifications, templates generate content dynamically, and Vault protects sensitive information. A well-organized inventory makes it easier to target different environments, device roles, or locations without duplicating playbook logic.
Question 170.
Which Ansible keyword allows a task to execute only if a certain condition evaluates as true?
- notify
2. when
3. import_playbook only
4. gather_facts only
Correct Answer: 2
Explanation:
The when keyword provides conditional execution in Ansible. It allows a task to run only if a variable, registered result, or expression meets a specified condition. For example, a playbook might configure a feature only on Nexus leaf switches or create a resource only when it is missing. Conditional execution makes playbooks more flexible and reduces unnecessary changes. notify triggers handlers after task changes, while other keywords serve different purposes. Conditions are especially useful in idempotent workflows.
Question 171.
Which Ansible feature is used to save the output of a task into a variable for later use?
- register
2. roles
3. handlers
4. collections only
Correct Answer: 1
Explanation:
The register keyword stores the result of an Ansible task in a variable. Later tasks can inspect that result, use it in conditionals, or extract returned data. For example, a playbook can query current interface state, register the result, and make a change only if the current value differs from the desired configuration. Roles organize reusable automation, while handlers respond to notifications. Registered task results allow playbooks to respond dynamically to the actual state of managed infrastructure.
Question 172.
Which Ansible mechanism should be used when a task must repeat for each VLAN in a predefined list?
- Vault
2. loop
3. handler
4. callback plugin
Correct Answer: 2
Explanation:
An Ansible loop repeats a task for each item in a sequence. If a list contains multiple VLAN IDs, the same configuration task can be executed once per VLAN without writing duplicate YAML. This improves maintainability and makes the playbook easier to extend. Vault protects secrets, handlers are triggered by notifications, and callback plugins affect output or execution reporting. Loops are widely used when deploying repeated data center constructs such as VLANs, interfaces, EPGs, or server policies.
Question 173.
Which infrastructure-as-code tool commonly uses HCL configuration files and maintains state about managed resources?
- Terraform
2. Wireshark
3. Syslog
4. TFTP
Correct Answer: 1
Explanation:
Terraform uses HashiCorp Configuration Language, or HCL, to define desired infrastructure state. It maintains state information so it can understand the relationship between configuration declarations and actual resources. Providers connect Terraform to external APIs and services. Wireshark is a packet analyzer, Syslog transports event information, and TFTP transfers files. Terraform is commonly used when teams want declarative, version-controlled infrastructure definitions and repeatable deployment workflows.
Question 174.
Which Terraform command shows the changes that would occur without immediately applying them?
- terraform destroy
2. terraform plan
3. terraform state rm
4. terraform output
Correct Answer: 2
Explanation:
terraform plan compares the declared desired state with the current known state and produces a preview of proposed infrastructure changes. It shows which resources would be created, updated, replaced, or destroyed. Reviewing this output before deployment is an important safety measure, especially in production. terraform destroy removes resources, while state-management commands and output commands serve different purposes. Plans help teams identify unexpected changes before they become operational impact.
Question 175.
Which Terraform command should be used to check whether the configuration is syntactically valid and internally consistent?
- terraform validate
2. terraform destroy
3. terraform taint only
4. terraform import only
Correct Answer: 1
Explanation:
terraform validate checks Terraform configuration for syntax and internal consistency without applying changes. It can detect malformed expressions, incorrect references, and other configuration problems. Validation is typically combined with terraform fmt, automated testing, and plan review in a mature workflow. Validation does not guarantee that external APIs will accept the configuration, but it catches many issues early. Destroy and import commands serve operational state-management functions and are not general syntax-validation tools.
Question 176.
Why is remote Terraform state useful for a team environment?
- It removes all API authentication
2. It automatically fixes configuration errors
3. It replaces source control
4. It provides a shared authoritative state location and may support locking
Correct Answer: 4
Explanation:
Remote state allows multiple engineers or automation pipelines to use a common authoritative copy of Terraform state. Depending on the backend, it can also support locking, access control, encryption, and version history. This reduces the risk of conflicting local state files and helps coordinate team workflows. Remote state does not replace Git or other source-control systems and does not eliminate authentication or configuration mistakes. Because state can contain sensitive infrastructure details, the backend should be protected appropriately.
Question 177.
Which model-driven protocol typically uses XML-encoded RPC messages over SSH?
- NETCONF
2. RESTCONF
3. CDP
4. LLDP
Correct Answer: 1
Explanation:
NETCONF is a model-driven management protocol commonly transported over SSH and typically uses XML-encoded RPC operations. It works with YANG data models and supports structured configuration and state retrieval. RESTCONF also uses YANG models but exposes them through HTTP-based methods. CDP and LLDP are neighbor-discovery protocols and do not provide general configuration management. NETCONF is particularly useful when automation needs structured operations such as retrieving configuration, editing datastores, locking them, or committing candidate changes where supported.
Question 178.
Which protocol provides REST-style access to YANG-modeled data using HTTP methods?
- FTP
2. RESTCONF
3. TFTP
4. SNMP trap only
Correct Answer: 2
Explanation:
RESTCONF exposes YANG-modeled configuration and operational data using HTTP methods such as GET, POST, PUT, PATCH, and DELETE as supported by the implementation. Data is commonly represented as JSON or XML. This makes RESTCONF familiar to developers experienced with web APIs while retaining structured network data models. NETCONF provides similar model-driven functionality through XML RPC operations over SSH. File-transfer protocols and SNMP traps do not provide equivalent YANG-based configuration capabilities.
Question 179.
Which Cisco NX-OS feature is most appropriate for triggering an automated response when a specific syslog message occurs?
- Embedded Event Manager
2. STP
3. HSRP
4. LACP
Correct Answer: 1
Explanation:
Embedded Event Manager can monitor for specified events, including syslog messages, and trigger predefined actions. Those actions might collect troubleshooting information, issue CLI commands, create notifications, or invoke scripts. This makes EEM useful for event-driven local automation. STP prevents Layer 2 loops, HSRP provides gateway redundancy, and LACP manages link aggregation. EEM policies should be tested carefully because poorly designed triggers or actions can execute repeatedly or produce unintended operational effects.
Question 180.
A team wants automation changes to be tested automatically, reviewed, and blocked from production if validation fails. Which workflow best meets this requirement?
- Direct manual changes on production devices
2. Disable source control and testing
3. CI/CD pipeline with quality gates and approval controls
4. Store production credentials inside the code repository
Correct Answer: 3
Explanation:
A CI/CD pipeline can automatically run syntax checks, unit tests, linting, policy validation, and other controls whenever automation code changes. Quality gates stop promotion when required checks fail, while approval controls can ensure that high-impact production changes receive human review. This produces a repeatable and auditable deployment process. Direct manual changes bypass these controls, and embedding credentials in source code creates serious security risk. Mature infrastructure automation combines version control, testing, peer review, secure secrets management, staged deployment, and controlled production promotion.