Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps

 

Question 281.

Which Cisco NX-OS capability provides an isolated Linux environment that can be used for on-box automation and scripting?

  1. Guest Shell
    2. HSRP
    3. VTP
    4. FabricPath

Correct Answer: 1

Explanation:

Guest Shell provides a Linux-based environment on supported Cisco Nexus platforms where administrators can run Python scripts and other Linux utilities. It is useful for local automation, data collection, event processing, and integration tasks that do not need to depend entirely on an external automation host. Guest Shell does not replace NX-OS and should be used with appropriate resource and security controls. HSRP provides first-hop redundancy, VTP handles VLAN-related information in supported environments, and FabricPath is a network forwarding technology rather than an on-box scripting environment.

Question 282.

Which Cisco NX-OS automation feature is best suited for executing actions automatically when a specified syslog message appears?

  1. Guest Shell only
    2. Embedded Event Manager
    3. RESTCONF only
    4. LACP

Correct Answer: 2

Explanation:

Embedded Event Manager, or EEM, can monitor events such as syslog messages, interface transitions, timers, and other supported conditions. When a matching event occurs, EEM can execute configured actions such as CLI commands, diagnostics, notifications, or scripts. This makes it useful for local event-driven automation and rapid troubleshooting. Guest Shell provides a scripting environment but does not itself define the event trigger. RESTCONF provides model-driven API access, while LACP manages link aggregation.

Question 283.

Which part of an EEM policy determines what condition causes the policy to execute?

  1. Action list only
    2. CLI output
    3. Event detector
    4. Inventory group

Correct Answer: 3

Explanation:

The event detector defines the condition that causes an EEM policy to run. This condition may be based on a syslog message, timer, interface state, threshold, or another supported event source. After the event is detected, the configured actions are executed. Separating triggers from actions allows EEM to support many different event-driven workflows. The action list describes what happens after the trigger, while inventory groups are associated with external automation tools such as Ansible rather than EEM.

Question 284.

Which practice is most appropriate before deploying an EEM policy that automatically changes production configuration?

  1. Disable logging
    2. Make the trigger as broad as possible
    3. Skip testing because EEM is local
    4. Test the trigger and actions carefully in a controlled environment

Correct Answer: 4

Explanation:

EEM policies can make changes immediately when an event occurs, so they should be tested carefully before production deployment. Engineers should confirm that the event detector matches only the intended condition, that actions are safe, and that repeated events will not create an unintended loop. Logging and rollback planning are also important. Broad triggers or untested actions can result in repeated or disruptive configuration changes. Local execution does not reduce the need for change control and validation.

Question 285.

Which API interface is most appropriate when a script needs to execute supported Nexus CLI commands over HTTPS and receive structured output?

  1. NX-API
    2. CDP
    3. STP
    4. HSRP

Correct Answer: 1

Explanation:

NX-API allows automation software to send supported CLI commands to Cisco Nexus devices over HTTP or HTTPS and receive machine-readable responses, commonly JSON or XML. This is useful when existing operational workflows are already based on familiar CLI commands but need to be automated. CDP, STP, and HSRP serve networking functions and do not provide general programmable CLI execution. Secure use of NX-API should include HTTPS, authentication, authorization, and careful validation of commands before execution.

Question 286.

Which advantage does structured NX-API output provide compared with parsing normal terminal output?

  1. It removes authentication requirements
    2. It gives the script predictable fields that are easier to process
    3. It guarantees software versions never change
    4. It prevents every configuration error

Correct Answer: 2

Explanation:

Structured output provides named fields and predictable nesting, making it easier for software to extract the exact values it needs. By contrast, normal CLI output is designed for human readability and may change spacing, headings, or formatting between releases. JSON or XML reduces reliance on fragile regular expressions and screen-scraping logic. It does not remove authentication or guarantee that schemas will never evolve, but it generally makes automation more reliable and maintainable.

Question 287.

Which model-driven data modeling language is commonly used with NETCONF and RESTCONF?

  1. YAML only
    2. HCL
    3. YANG
    4. CSV

Correct Answer: 3

Explanation:

YANG is a data modeling language used to define the structure of network configuration and operational data. NETCONF and RESTCONF commonly use YANG models to provide predictable schemas for network automation. YANG defines constructs such as containers, lists, leaves, data types, and constraints. YAML and HCL are useful in other automation contexts, while CSV is a simple tabular format. Model-driven automation is valuable because clients can interact with structured data rather than parsing device-specific CLI output.

Question 288.

Which YANG construct is best suited to represent a single scalar value such as an interface description?

  1. list
    2. container
    3. module only
    4. leaf

Correct Answer: 4

Explanation:

A YANG leaf represents a single scalar value, such as an interface description, MTU, administrative state, or IP-related attribute. A container groups related child nodes, while a list represents repeated structured entries. Understanding these model elements helps developers navigate and manipulate data exposed through NETCONF or RESTCONF. A leaf also has a defined data type and may include constraints, which provides stronger validation than unstructured CLI text.

Question 289.

Which YANG construct is typically used to represent multiple interfaces, each containing several child attributes?

  1. list
    2. leaf only
    3. typedef only
    4. revision only

Correct Answer: 1

Explanation:

A YANG list represents multiple instances of a structured object. For example, an interface list can contain many interface entries, each with child leaves for name, MTU, description, status, and other attributes. Lists commonly use one or more keys to uniquely identify each entry. A single leaf cannot represent multiple structured interface records. Typedefs define reusable data types, while revision statements track model history.

Question 290.

Which NETCONF operation retrieves both configuration and operational state data?

  1. <commit>
    2. <get>
    3. <lock>
    4. <edit-config>

Correct Answer: 2

Explanation:

The NETCONF <get> operation retrieves both configuration and operational state data from the device. Filters can be used to reduce the response to a relevant subtree or portion of the model. <get-config> is used when only configuration from a selected datastore is needed. <edit-config> modifies configuration, <lock> reserves a datastore, and <commit> activates candidate configuration when that capability is supported. Structured retrieval makes NETCONF well suited for model-driven automation.

Question 291.

Which NETCONF operation should an automation client use when it needs only configuration data from the running datastore?

  1. <get-config>
    2. <hello>
    3. <close-session>
    4. <kill-session>

Correct Answer: 1

Explanation:

The <get-config> operation retrieves configuration data from a selected NETCONF datastore such as running or candidate, depending on platform capabilities. This is preferable to <get> when operational state is not needed. Filters can narrow the response further. <hello> participates in initial capability exchange, while <close-session> and <kill-session> terminate sessions. Choosing the appropriate operation reduces unnecessary data transfer and makes automation logic clearer.

Question 292.

Which NETCONF operation is used to modify configuration in a target datastore?

  1. <get>
    2. <edit-config>
    3. <hello>
    4. <close-session>

Correct Answer: 2

Explanation:

The <edit-config> operation changes configuration in a specified NETCONF datastore. The payload is structured according to the YANG data model and can include instructions for operations such as merge, replace, create, or delete. The exact supported capabilities depend on the device. <get> retrieves data, <hello> participates in session negotiation, and <close-session> ends the connection. Automation should validate the intended target datastore before applying changes.

Question 293.

Which NETCONF capability allows configuration changes to be staged before they become active?

  1. Candidate datastore
    2. Syslog buffer
    3. ARP table
    4. Routing cache only

Correct Answer: 1

Explanation:

When supported, the candidate datastore allows automation to prepare configuration changes separately from the running configuration. The client can edit the candidate, review or validate it, and then commit the changes as a coordinated set. This is useful for reducing risk when several dependent changes should become active together. Not every device supports candidate configuration, so the automation client should inspect the device’s advertised NETCONF capabilities rather than making assumptions.

Question 294.

Which NETCONF operation normally activates configuration stored in the candidate datastore?

  1. <get-config>
    2. <commit>
    3. <lock>
    4. <delete-config>

Correct Answer: 2

Explanation:

The <commit> operation activates configuration staged in the candidate datastore by applying it to the running configuration, when the platform supports that capability. This allows multiple edits to be prepared before becoming active. <get-config> retrieves configuration, <lock> prevents conflicting edits, and <delete-config> removes configuration from an eligible datastore in supported scenarios. Production automation should validate candidate changes before committing them whenever possible.

Question 295.

Which RESTCONF method is generally used to retrieve YANG-modeled configuration or operational data?

  1. GET
    2. DELETE
    3. POST only
    4. PATCH only

Correct Answer: 1

Explanation:

RESTCONF uses HTTP methods, and GET is normally used to retrieve YANG-modeled configuration or operational data. The returned content is commonly represented in JSON or XML. Other methods such as POST, PUT, PATCH, and DELETE can be used for modification depending on the resource and supported semantics. RESTCONF combines familiar web API concepts with structured YANG models, making it attractive to developers who already work with REST-style interfaces.

Question 296.

Which development practice best verifies that a configuration-rendering function produces the correct result from known input values?

  1. Manual production testing only
    2. Disable validation
    3. Skip source control
    4. Unit testing

Correct Answer: 4

Explanation:

Unit testing verifies a small piece of code in isolation. For a configuration-rendering function, a unit test can provide known inputs and compare the generated output with an expected result. This helps identify logic errors, incorrect formatting, and regressions before the code reaches production. Unit tests can run automatically in continuous integration and provide fast feedback. They do not replace integration testing, but they are highly effective for validating reusable functions and templates.

Question 297.

Which test type is most appropriate for verifying that an automation script can authenticate to a test controller, call its API, and correctly process the response?

  1. Integration test
    2. Spell check
    3. Unit test only with no external interaction
    4. Static formatting check

Correct Answer: 1

Explanation:

An integration test checks whether multiple components work together correctly. In this case, the test verifies the interaction among authentication logic, the controller API, response parsing, and application behavior. It may use a lab system, simulator, or controlled mock service. Unit tests focus on smaller isolated pieces of code, while formatting checks do not validate API interaction. Integration tests are important because code that works correctly in isolation can still fail when interacting with real systems and external dependencies.

Question 298.

Which CI pipeline stage is best suited to identifying Python style violations and common coding mistakes before merge?

  1. Production deployment
    2. Linting
    3. Resource destruction
    4. State import

Correct Answer: 2

Explanation:

Linting analyzes source code for style issues, suspicious constructs, undefined variables, unused imports, and other common problems. It is fast and therefore well suited to early CI pipeline stages. Linting does not replace unit or integration testing, but it helps enforce consistent code quality and catches many simple defects before they reach peer review or production. Production deployment and infrastructure state operations serve completely different purposes.

Question 299.

Which source-control workflow best reduces the risk of unreviewed automation code reaching production?

  1. Use feature branches and pull requests with peer review
    2. Allow direct edits to the production branch by everyone
    3. Remove all repository history after each deployment
    4. Store secrets in commit messages

Correct Answer: 1

Explanation:

Feature branches and pull requests allow engineers to develop changes independently and then submit them for review before merging into a production branch. Reviewers can inspect the diff, validate logic, confirm testing, and identify security or operational risks. CI checks can also run automatically against the proposed change. Direct unrestricted changes reduce oversight, while removing history weakens auditability. Secrets should never be placed in commit messages because repository history can preserve them permanently.

Question 300.

A CI/CD pipeline passes all automated tests, but a Terraform plan shows that a critical production resource will be destroyed. What should the pipeline do?

  1. Apply immediately because the tests passed
    2. Ignore the plan output
    3. Block deployment and require explicit review or approval
    4. Disable logging and continue

Correct Answer: 3

Explanation:

Automated tests do not prove that every planned infrastructure change is acceptable. A Terraform plan showing destruction of a critical production resource should trigger a policy or approval gate. The deployment should stop until the change is reviewed and confirmed as intentional. This illustrates why mature CI/CD combines testing with plan inspection, policy enforcement, change control, and human approval for high-impact operations. Ignoring destructive plan output defeats one of the most important safeguards in infrastructure-as-code workflows.