Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps

 

Question 381.

Which Cisco NX-OS capability is most appropriate when an external application needs to execute supported CLI commands programmatically and receive structured output?

  1. NX-API CLI
    2. HSRP
    3. LACP
    4. UDLD

Correct Answer: 1

Explanation:

NX-API CLI provides programmatic access to supported Cisco Nexus CLI commands through HTTP or HTTPS. Instead of opening an interactive terminal session, an application can submit commands and receive responses in structured formats such as JSON or XML when supported. This makes it easier to integrate existing CLI-oriented workflows into automation systems. HSRP provides first-hop redundancy, LACP manages link aggregation, and UDLD detects certain unidirectional links. Secure deployments should use HTTPS, appropriate authentication, role-based access, and input validation so automation cannot execute unintended commands.

Question 382.

Which benefit does NX-API provide over traditional CLI screen scraping?

  1. It eliminates the need for authentication
    2. It can provide machine-readable structured output
    3. It guarantees that all operations are idempotent
    4. It removes the need for error handling

Correct Answer: 2

Explanation:

Structured NX-API output is significantly easier and safer for software to process than human-oriented terminal text. JSON or XML responses expose predictable fields that scripts can access directly rather than depending on spacing, headings, or regular expressions. This reduces the likelihood that minor display-format changes will break automation. NX-API does not remove authentication requirements, guarantee idempotency, or eliminate the need to handle errors. Scripts should still inspect response status, validate returned data, and confirm that the requested operation achieved the expected result.

Question 383.

A Python application receives a nested JSON response containing a collection of Nexus interfaces. Which combination of Python data structures is most likely to represent the response?

  1. Integers and Boolean values only
    2. Sets only
    3. Dictionaries containing lists and other dictionaries
    4. Tuples only

Correct Answer: 3

Explanation:

Nested JSON commonly maps to combinations of Python dictionaries and lists. JSON objects become dictionaries, while JSON arrays become lists. For example, an interface response might be a dictionary containing a list of interface dictionaries, with each interface containing keys such as name, administrative state, and counters. This structure allows scripts to navigate returned data systematically. Scalars such as strings, numbers, and Boolean values may appear inside the structure, but complex API responses are typically represented using nested dictionaries and lists.

Question 384.

Which HTTP response code should an automation script commonly interpret as a successful request with no response body?

  1. 401
    2. 404
    3. 500
    4. 204

Correct Answer: 4

Explanation:

HTTP 204 No Content indicates that the request was successfully processed but the server has no response body to return. Depending on the API, this can occur after successful updates or deletions. A script should recognize 204 as success and avoid trying to parse an empty body as JSON. A 401 typically indicates an authentication issue, 404 means that a requested resource was not found, and 500 represents an internal server error. Correct status-code handling is necessary for dependable infrastructure automation.

Question 385.

Which Cisco ACI API query is most appropriate when an engineer needs to retrieve one specific managed object whose Distinguished Name is already known?

  1. DN query
    2. Broad class query
    3. ARP query
    4. DNS query

Correct Answer: 1

Explanation:

A Distinguished Name query precisely targets a specific managed object in the ACI Management Information Tree. Because the DN represents the object’s complete hierarchical path, the script can retrieve or modify that object without searching through unrelated objects. A class query is better when multiple objects of the same class must be retrieved. ARP and DNS queries are networking functions and do not interact with the APIC managed-object model. DN queries are especially useful for validation before a targeted update or deletion.

Question 386.

Which Cisco ACI API method is most efficient when an automation workflow needs to inventory all objects belonging to the same managed-object class?

  1. Repeated terminal sessions
    2. Class query
    3. ICMP scanning
    4. Packet capture

Correct Answer: 2

Explanation:

A class query retrieves multiple instances of a specified managed-object class in a single APIC API operation. For example, an automation workflow might retrieve all Bridge Domains, EPGs, or contracts to perform a compliance assessment. Filters can be added to reduce the returned set further. Repeated terminal sessions are less scalable and more difficult to parse reliably. ICMP and packet capture do not provide structured access to the APIC object hierarchy.

Question 387.

Which field commonly contains the returned managed objects in a Cisco APIC REST API response?

  1. objectsOnly
    2. returnData
    3. imdata
    4. classList

Correct Answer: 3

Explanation:

Cisco APIC REST responses commonly place managed-object records within the imdata array. Each entry identifies an object class and includes its attributes, and child objects can also be included depending on query options. Python automation frequently accesses this array when evaluating existing configuration or operational state. Scripts should validate that imdata exists and contains the expected objects before using the response to drive configuration changes. This reduces the chance of acting on empty or malformed results.

Question 388.

Which APIC response field can help an automation script determine how many managed objects matched a query?

  1. httpCount
    2. objectSize
    3. rowTotal
    4. totalCount

Correct Answer: 4

Explanation:

The totalCount value in an APIC response provides information about the number of objects associated with the query result. This can be used as a validation safeguard. For example, if a script expects exactly one object before performing an update but receives a larger count, it can stop rather than risk modifying the wrong resources. Validation of returned object counts, Distinguished Names, and attributes is particularly important before destructive operations. Automation should verify scope instead of assuming a query returned only the intended target.

Question 389.

Which Cisco UCS construct allows policies and identity information to be associated with a server independently of the physical hardware?

  1. Service Profile
    2. ACI Filter
    3. Nexus Port Channel
    4. Bridge Domain

Correct Answer: 1

Explanation:

A Cisco UCS Service Profile abstracts server identity and configuration from the underlying physical server. It can define network identities, boot settings, storage connectivity, firmware policies, BIOS policies, and other operational characteristics. This abstraction allows a profile to be associated with another compatible physical server when needed. ACI filters and Bridge Domains are networking constructs, while a Nexus port channel aggregates interfaces. Service Profiles are particularly useful in automated provisioning because they support consistent, policy-based server configuration.

Question 390.

Which Cisco UCS feature is most useful for creating many Service Profiles that follow the same approved baseline?

  1. VLAN trunk
    2. Service Profile template
    3. Static route
    4. ARP entry

Correct Answer: 2

Explanation:

A Service Profile template allows administrators and automation tools to create multiple Service Profiles from a common standardized configuration. Templates can reference boot, firmware, BIOS, network, and other policies, reducing repetitive manual work and improving consistency. Depending on the template model, derived profiles may remain linked to the template or be independently instantiated. VLAN trunks, static routes, and ARP entries do not provide this server-policy templating capability.

Question 391.

Which Cisco automation tool is most appropriate for managing UCS infrastructure from Python code through object-oriented abstractions?

  1. Cisco UCS Python SDK
    2. EEM
    3. CDP
    4. Wireshark

Correct Answer: 1

Explanation:

The Cisco UCS Python SDK provides Python objects and methods that simplify interaction with UCS Manager’s managed-object model. It can be used to retrieve inventory, manage policies, work with Service Profiles, and automate other UCS tasks without manually constructing each XML request. EEM provides event-driven automation on supported network devices, CDP performs neighbor discovery, and Wireshark analyzes packets. SDK-based automation is particularly useful when workflows require repeated programmatic interaction with many UCS objects.

Question 392.

Which Cisco automation tool provides PowerShell cmdlets for querying and configuring UCS infrastructure?

  1. Cobra SDK
    2. Cisco UCS PowerTool
    3. Guest Shell
    4. RESTCONF

Correct Answer: 2

Explanation:

Cisco UCS PowerTool provides PowerShell cmdlets designed specifically for Cisco UCS management. Administrators can use it to query inventory, configure Service Profiles, work with policies, and automate repetitive management operations. This is useful for teams that already use PowerShell for operational automation. The Cobra SDK is associated with Cisco ACI, Guest Shell provides a Linux-based environment on supported Nexus switches, and RESTCONF is a model-driven HTTP protocol rather than a UCS-specific PowerShell toolkit.

Question 393.

Which Ansible keyword is most appropriate when a network task should be considered failed based on a custom condition in its returned data?

  1. failed_when
    2. notify
    3. serial
    4. loop

Correct Answer: 1

Explanation:

The failed_when directive allows the playbook author to define custom logic that determines whether a task should be treated as failed. This is useful when an API or command technically executes successfully but returns data indicating an unacceptable operational condition. For example, an interface query may succeed but reveal that a critical link is down. notify triggers handlers, serial controls batch size, and loop repeats a task. Custom failure conditions help automation validate outcomes instead of relying only on command execution status.

Question 394.

Which Ansible directive allows a play to update production devices in small batches rather than all at once?

  1. register
    2. serial
    3. changed_when
    4. vars_files

Correct Answer: 2

Explanation:

The serial directive controls how many hosts are processed in each batch of an Ansible play. This enables staged deployments that reduce blast radius. For example, a change can first be applied to two switches, validated, and then continued to the next group. If a problem occurs, automation can stop before every production device is affected. register stores task results, changed_when customizes change reporting, and vars_files loads variables. Batch-based deployment is an important safety practice for production infrastructure.

Question 395.

Which Terraform construct should be used when a configuration needs information about an existing infrastructure object but should not create that object?

  1. Data source
    2. Resource replacement
    3. State lock
    4. Backend

Correct Answer: 1

Explanation:

A Terraform data source reads information about an existing object without declaring that Terraform should create that object. The returned values can then be referenced by managed resources or modules. For example, a configuration may look up an existing organization, network, or policy and use its identifier when creating something new. Resource blocks represent objects Terraform intends to manage, while backends and state locks support state management. Data sources are valuable when new automation must integrate with preexisting infrastructure.

Question 396.

Which Terraform meta-argument should be used when an infrastructure dependency exists but cannot be inferred automatically through resource references?

  1. count
    2. depends_on
    3. provider
    4. output

Correct Answer: 2

Explanation:

depends_on explicitly defines a dependency between Terraform resources or modules when the dependency is not visible through normal attribute references. Terraform usually builds its dependency graph automatically, so explicit dependencies are only needed in special cases. Correct dependency modeling helps ensure operations occur in a safe order. count controls the number of resource instances, while providers and outputs perform different functions. Overuse of explicit dependencies can make configurations harder to understand, so natural references are preferable when possible.

Question 397.

Which NETCONF operation is used to retrieve configuration information from a specific datastore without including operational state?

  1. <get-config>
    2. <get>
    3. <commit>
    4. <lock>

Correct Answer: 1

Explanation:

The <get-config> operation retrieves configuration data from a specified NETCONF datastore such as running or candidate. This differs from <get>, which can retrieve both configuration and operational state information. Filters can be included to return only relevant parts of the YANG model. <commit> activates candidate changes, while <lock> prevents competing edits to a datastore. Selecting the appropriate retrieval operation makes automation more efficient and ensures the returned data matches the workflow’s needs.

Question 398.

Which NETCONF operation should be used after a workflow has completed modifications to a datastore that it previously locked?

  1. <hello>
    2. <unlock>
    3. <get>
    4. <validate>

Correct Answer: 2

Explanation:

The <unlock> operation releases a NETCONF datastore that was previously locked. Locks should be held only for the time required to complete a coordinated change, because they may prevent other legitimate administrators or automation processes from modifying configuration. Well-designed code should release the lock even when an exception occurs, usually through reliable cleanup logic. <hello> is part of capability negotiation, <get> retrieves data, and <validate> checks configuration when that capability is supported.

Question 399.

Which Git practice best allows an infrastructure team to review proposed changes before they become part of the production branch?

  1. Feature branch with a pull request
    2. Direct commits to production without review
    3. Deleting commit history
    4. Sharing the repository through email attachments only

Correct Answer: 1

Explanation:

A feature-branch and pull-request workflow separates proposed changes from the production branch until they have been reviewed and validated. Automated CI checks can run against the branch, and reviewers can inspect the diff before approving the merge. This provides traceability and reduces the risk of unreviewed automation reaching production. Direct commits remove an important layer of oversight, while deleting history makes auditing and rollback more difficult. Source-control review is particularly valuable for infrastructure code because small errors can affect many systems rapidly.

Question 400.

A CI/CD pipeline successfully deploys a network change, but an automated post-change test detects loss of application reachability. What should the workflow do?

  1. Continue to the remaining production devices because deployment technically succeeded
    2. Ignore the application test
    3. Stop further deployment and initiate the defined remediation or rollback procedure
    4. Delete the test result and mark the deployment successful

Correct Answer: 3

Explanation:

A successful configuration transaction does not prove that the resulting infrastructure is operating correctly. Post-change validation should test the business or technical outcomes that matter, such as reachability, routing, interfaces, or application health. If validation fails, further rollout should stop so the problem does not spread. The workflow should preserve logs and initiate the predefined remediation or rollback procedure. Mature automation evaluates actual outcomes as well as command success, making post-deployment verification a critical component of safe infrastructure automation.