Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps

 

Question 361.

Which Cisco Nexus capability can automatically provision a new switch by downloading configuration and software information during initial deployment?

  1. POAP
    2. HSRP
    3. LACP
    4. UDLD

Correct Answer: 1

Explanation:

PowerOn Auto Provisioning, or POAP, allows supported Cisco Nexus switches to automate initial provisioning when they boot without a startup configuration. The switch can obtain network information, locate a provisioning script, download configuration or software, and complete deployment with minimal manual interaction. This is useful when deploying many switches consistently. HSRP provides first-hop redundancy, LACP negotiates link aggregation, and UDLD detects certain unidirectional link conditions. POAP is especially valuable in large data centers where repeatable zero-touch provisioning reduces deployment time and minimizes configuration inconsistencies.

Question 362.

What is a primary benefit of using POAP when deploying a large number of Nexus switches?

  1. It removes the need for network connectivity
    2. It enables repeatable zero-touch initial provisioning
    3. It automatically creates ACI contracts
    4. It replaces all configuration management tools permanently

Correct Answer: 2

Explanation:

POAP helps automate the initial deployment of supported Nexus switches by obtaining provisioning information and applying configuration or software automatically. This reduces repetitive manual CLI work and improves consistency across large deployments. POAP still depends on appropriate connectivity and supporting services during provisioning. It does not create ACI application policy by itself and does not replace ongoing configuration management tools such as Ansible, APIs, or infrastructure-as-code systems. Its strongest use case is accelerating and standardizing initial switch provisioning.

Question 363.

Which practice best reduces the risk of deploying an incorrect configuration through POAP?

  1. Use the same unvalidated script for every environment
    2. Disable provisioning logs
    3. Validate provisioning scripts and configuration in a lab before production use
    4. Avoid source control

Correct Answer: 3

Explanation:

POAP can apply configuration automatically at scale, so a mistake in a provisioning script can affect many devices quickly. Scripts, image references, configuration templates, and environment-specific variables should therefore be tested in a controlled environment before production rollout. Source control should be used to track changes and enable review. Logging should remain enabled so failed or unexpected provisioning can be investigated. Automated deployment increases speed, but it also increases potential blast radius, making validation and staged testing essential.

Question 364.

Which Cisco NX-OS capability provides a Bash shell environment on supported platforms for advanced local scripting and Linux-style commands?

  1. NX-API only
    2. EEM only
    3. POAP only
    4. Bash shell or Guest Shell environment

Correct Answer: 4

Explanation:

Supported Cisco Nexus platforms provide Linux-oriented environments such as Bash access or Guest Shell that allow administrators to use common Linux commands and scripting tools locally. Guest Shell offers an isolated environment suitable for Python and other utilities. NX-API is a programmable interface rather than a local shell, EEM provides event-driven automation, and POAP focuses on initial provisioning. Local scripting can be powerful, but scripts should be tested carefully because excessive CPU, memory, storage, or process usage could affect production switch operations.

Question 365.

Which security practice is most important when enabling local shell access on a production Nexus switch?

  1. Restrict access using role-based permissions and least privilege
    2. Give every user unrestricted shell access
    3. Disable command logging
    4. Share one administrative password among all automation users

Correct Answer: 1

Explanation:

Local shell access can provide powerful capabilities, so it should be restricted to authorized users with only the permissions they require. Role-based access control, strong authentication, logging, and separation of duties help reduce risk. Shared credentials make accountability difficult, while unrestricted access unnecessarily increases the impact of credential compromise. Command and session logging should remain enabled where supported. Automation identities should also be distinct from human administrator accounts so actions can be traced and privileges can be managed independently.

Question 366.

Which Cisco Nexus feature can trigger a local action when a threshold such as CPU utilization or interface errors exceeds a defined condition?

  1. CDP
    2. Embedded Event Manager
    3. HSRP
    4. VRRP only

Correct Answer: 2

Explanation:

Embedded Event Manager can react to supported operational events, including threshold-based conditions, syslog messages, timers, and interface changes. An EEM policy can then execute commands, collect diagnostics, or generate notifications. This makes it suitable for local event-driven remediation or troubleshooting. CDP discovers neighboring Cisco devices, while HSRP and VRRP provide first-hop redundancy. EEM actions should be carefully scoped because repeatedly triggered remediation can create unexpected behavior if the underlying event remains active.

Question 367.

Which design choice helps prevent an EEM policy from entering a repeated action loop after the same event is generated by its own remediation command?

  1. Make the trigger broader
    2. Disable all logging
    3. Add trigger conditions and safeguards that prevent recursive execution
    4. Increase the number of remediation commands

Correct Answer: 3

Explanation:

Event-driven automation should include safeguards against recursive or repeated execution. If an action generates the same syslog message or condition that triggered the policy, the EEM applet could repeatedly run. Engineers can reduce this risk with carefully defined trigger patterns, state checks, counters, timers, or conditions that suppress repeated execution. Broad triggers increase risk rather than reducing it. Logging is valuable for understanding what happened and should not be disabled simply to hide repeated actions.

Question 368.

Which RESTCONF response format is commonly used because it maps naturally to dictionaries and lists in Python?

  1. BMP
    2. WAV
    3. MPEG
    4. JSON

Correct Answer: 4

Explanation:

JSON is commonly used with RESTCONF because it provides a lightweight structured representation of YANG-modeled data. Python can parse JSON into dictionaries, lists, strings, numbers, and Boolean values, which makes automation straightforward. XML may also be supported, but JSON is often preferred by developers familiar with REST APIs. BMP, WAV, and MPEG are media formats and are unrelated to model-driven configuration payloads. Structured data helps automation avoid the fragility associated with parsing human-oriented CLI output.

Question 369.

Which RESTCONF characteristic allows the client to identify a specific modeled resource directly through the request URI?

  1. The URI maps to the YANG-modeled data hierarchy
    2. Every request must contain CLI commands
    3. RESTCONF ignores the underlying data model
    4. All resources share the same URI

Correct Answer: 1

Explanation:

RESTCONF exposes YANG-modeled data through hierarchical URIs. The URI identifies the targeted container, list entry, leaf, or other modeled resource, allowing the client to retrieve or modify specific data programmatically. This structured mapping is one of the major advantages of model-driven APIs. RESTCONF does not require CLI commands and does not ignore the data model. Precise resource addressing makes automation more deterministic and reduces dependence on screen scraping.

Question 370.

Which RESTCONF operation is most appropriate when an automation client wants to create a new child resource within an existing parent resource?

  1. GET
    2. POST
    3. HEAD
    4. OPTIONS

Correct Answer: 2

Explanation:

POST is commonly used in RESTCONF to create a new child resource beneath an existing data resource, depending on the modeled structure and implementation. GET retrieves data, while HEAD and OPTIONS provide other HTTP functions. PUT may also be used in some circumstances to create or replace a resource at a known URI. Automation engineers should follow the exact RESTCONF and platform semantics because creation behavior depends on the targeted YANG data node and supported operations.

Question 371.

Which NETCONF operation can be used to replace the entire contents of a supported configuration datastore with another configuration?

  1. <copy-config>
    2. <get>
    3. <lock>
    4. <hello>

Correct Answer: 1

Explanation:

The <copy-config> operation copies a complete configuration from a source to a target datastore when the device supports the requested datastores. This can be useful for backup restoration, initialization, or synchronized configuration workflows. <get> retrieves data, <lock> reserves a datastore, and <hello> exchanges capabilities when establishing a NETCONF session. Because <copy-config> can affect large amounts of configuration, automation should verify source and target carefully before executing it.

Question 372.

Which NETCONF operation is most appropriate when a client wants to remove a supported configuration datastore such as a candidate or startup datastore?

  1. <commit>
    2. <delete-config>
    3. <get-config>
    4. <unlock>

Correct Answer: 2

Explanation:

The <delete-config> operation deletes the contents of a supported configuration datastore, subject to server capabilities and protocol restrictions. It cannot be assumed to apply to every datastore, and the running datastore typically has different constraints. <commit> activates candidate changes, <get-config> retrieves configuration, and <unlock> releases a datastore lock. Because deletion is destructive, clients should verify capabilities, target datastore, and operational intent before issuing the request.

Question 373.

Which YANG statement is used to identify the field or fields that uniquely identify entries in a list?

  1. leafref only
    2. namespace only
    3. key
    4. revision

Correct Answer: 3

Explanation:

A YANG list can define one or more key leaves that uniquely identify each entry. For an interface list, the interface name might serve as the key. Keys are important because RESTCONF and NETCONF clients often need them to address a specific list entry. The revision statement documents model history, while namespace declarations identify module naming information. Understanding list keys helps automation construct correct resource paths and precisely target modeled objects.

Question 374.

Which YANG construct allows a model to reuse an existing data type with a new locally meaningful name?

  1. container
    2. list
    3. notification
    4. typedef

Correct Answer: 4

Explanation:

A YANG typedef defines a reusable named data type. This can improve consistency by allowing multiple leaves to share the same type definition, restrictions, or semantic meaning. Containers group related data, lists represent repeated entries, and notifications define event information. Typedefs help model designers avoid duplicating type definitions and make large data models easier to maintain. Automation clients benefit indirectly because strong typing helps validate acceptable values.

Question 375.

Which Ansible keyword controls how many hosts in a play are processed at one time during a staged rollout?

  1. serial
    2. register
    3. notify
    4. vars_files

Correct Answer: 1

Explanation:

The serial keyword limits how many hosts are processed in each batch. This is useful for rolling or staged changes because automation can update a small subset of devices, validate results, and then continue with the next group. Limiting concurrency reduces blast radius when a change behaves unexpectedly. register stores task output, notify triggers handlers, and vars_files loads external variables. Staged execution is particularly valuable when modifying production data center infrastructure.

Question 376.

Which Ansible directive can stop execution when a required validation condition is not satisfied?

  1. loop
    2. failed_when
    3. notify
    4. register only

Correct Answer: 2

Explanation:

failed_when allows a task result to be treated as a failure when a custom condition evaluates as true. This enables playbooks to enforce operational validation beyond a module’s default success criteria. For example, a query might technically complete successfully but return an unexpected interface state; failed_when can stop the workflow in that case. Loops repeat tasks, notifications trigger handlers, and registration stores results. Custom failure conditions help make automation more aware of business and operational expectations.

Question 377.

Which Ansible directive can mark a task as changed only when a custom condition is met?

  1. changed_when
    2. serial
    3. delegate_to only
    4. become only

Correct Answer: 1

Explanation:

changed_when allows a playbook author to control whether Ansible reports that a task changed the target system. This is useful when using commands or custom modules whose default change reporting does not accurately reflect the real state transition. Correct change reporting matters because handlers and CI systems may rely on that status. serial controls batch size, while delegation and privilege escalation serve different purposes. Accurate change reporting improves idempotency and operational visibility.

Question 378.

Which Terraform command displays the current state or the contents of a saved plan in a human-readable form?

  1. terraform init
    2. terraform show
    3. terraform destroy
    4. terraform fmt

Correct Answer: 2

Explanation:

terraform show displays information from Terraform state or a saved plan in a readable form. This can help engineers inspect managed resource attributes or understand exactly what a saved plan contains before execution. It is useful during troubleshooting, review, and CI/CD workflows. terraform init initializes providers and backends, destroy removes resources, and fmt formats configuration files. Detailed plan and state visibility helps teams detect unexpected behavior before applying changes.

Question 379.

Which Terraform data construct reads information about infrastructure that already exists without declaring that Terraform should create that object?

  1. Data source
    2. Resource block only
    3. Backend only
    4. State lock

Correct Answer: 1

Explanation:

A Terraform data source retrieves information about existing infrastructure or external values without creating the referenced object itself. For example, a configuration may look up an existing network, policy, organization, or identifier and then use that value when creating another managed resource. Resource blocks represent objects Terraform intends to manage, while backends and state locks serve state-management functions. Data sources are valuable when automation must integrate new resources with infrastructure managed elsewhere.

Question 380.

A deployment pipeline completes successfully, but a post-change API validation shows that the actual infrastructure state does not match the intended configuration. What should the workflow do?

  1. Ignore the difference because deployment completed
    2. Delete validation logs
    3. Stop further promotion and trigger remediation or rollback according to policy
    4. Mark the deployment successful automatically

Correct Answer: 3

Explanation:

Successful execution does not guarantee that the final infrastructure state matches the intended design. Post-change validation should compare expected and actual state and treat meaningful differences as deployment failures. The workflow should stop further promotion, preserve logs, and initiate remediation or rollback according to defined policy. This is especially important when APIs accept a request but later reject part of the configuration or when dependencies produce unexpected results. Mature automation validates outcomes, not merely command execution.