Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps

 

Question 321.

Which authentication approach is commonly used by Cisco Intersight APIs for programmatic access?

  1. API key-based request signing
    2. Anonymous HTTP access
    3. SNMP community strings
    4. Telnet password exchange

Correct Answer: 1

Explanation:

Cisco Intersight APIs commonly use API keys together with cryptographic request signing to authenticate programmatic clients. The client typically uses a key identifier and associated private key material to prove its identity when making API requests. This is more appropriate for automation than embedding normal interactive credentials in every request. API key material should be stored securely and protected with least-privilege access controls. Anonymous access, SNMP community strings, and Telnet authentication are not the normal mechanisms for authenticating Intersight REST API requests.

Question 322.

Which practice best protects an Intersight private API key used by a Python automation script?

  1. Store it directly in the source code
    2. Retrieve it from a secure secret-management system at runtime
    3. Place it in a public Git repository
    4. Print it to the console before each request

Correct Answer: 2

Explanation:

Sensitive API key material should be stored outside application source code and retrieved securely at runtime. A dedicated secret-management platform, protected environment mechanism, or approved credential vault provides better access control and reduces the chance of accidental exposure. Hardcoding keys in scripts or storing them in Git can expose them through repository history, backups, or code sharing. Printing keys to logs or consoles also creates unnecessary risk. Automation credentials should use only the privileges required for their intended tasks and should be rotated according to organizational policy.

Question 323.

An Intersight inventory API returns thousands of server objects, but an automation workflow needs only servers from one organization. Which technique should be used?

  1. Retrieve all objects and restart the controller
    2. Disable pagination
    3. Apply server-side filtering
    4. Convert the request to ICMP

Correct Answer: 3

Explanation:

Server-side filtering allows the client to request only objects matching the required organization or other attributes. This reduces network traffic, response size, memory usage, and processing time. Filtering is especially useful in large environments where retrieving every managed object would be inefficient. Pagination may still be required if many filtered objects remain. Disabling pagination or using unrelated protocols does not improve the query. Efficient API design generally combines filtering, field selection, and pagination when supported.

Question 324.

Which HTTP response code most commonly indicates that an API request was accepted and a resource was successfully created?

  1. 401
    2. 403
    3. 500
    4. 201

Correct Answer: 4

Explanation:

HTTP 201 Created normally indicates that the server successfully processed a request that resulted in creation of a new resource. A 401 response typically indicates missing or invalid authentication, while 403 indicates insufficient authorization. A 500 response represents an internal server error. Automation should check both the status code and the returned body or resource identifier before assuming the new object is ready for later operations. Different APIs may have platform-specific behavior, so developers should still consult the relevant API documentation.

Question 325.

Which Python programming technique allows a developer to generate a new list by transforming or filtering items from another iterable in a concise expression?

  1. List comprehension
    2. Exception chaining
    3. Class inheritance only
    4. Module import

Correct Answer: 1

Explanation:

A list comprehension provides a compact way to build a new Python list by iterating over an existing iterable and optionally applying filtering conditions. In infrastructure automation, it can be useful for extracting hostnames from API records, selecting interfaces in a particular state, or transforming returned objects into a simpler structure. Although concise, comprehensions should remain readable; complex logic is often better placed in a normal loop or function. Exception handling, inheritance, and imports serve different purposes.

Question 326.

Which Python data structure is most appropriate for removing duplicate VLAN IDs from a collection automatically?

  1. String
    2. Set
    3. Integer
    4. Tuple only

Correct Answer: 2

Explanation:

A Python set stores unique values, making it useful when duplicate VLAN IDs, hostnames, addresses, or other identifiers must be removed. Converting a list to a set can eliminate duplicates without requiring manual comparison logic. Sets also support useful operations such as union, intersection, and difference. They are not the best choice when element order or duplicate preservation is important. Lists and tuples preserve sequence behavior, while a string and integer represent different data types entirely.

Question 327.

Which Python mechanism should be used when an automation script wants to catch a timeout separately from other exceptions?

  1. Catch a specific exception type in an except clause
    2. Use only pass
    3. Remove the try block
    4. Catch every condition with continue

Correct Answer: 1

Explanation:

Catching specific exception types allows an automation script to respond differently to different failures. A timeout might justify a limited retry with backoff, while an authentication failure might require credential review rather than another immediate attempt. Broad exception handling can hide the true cause of a failure and make troubleshooting difficult. Specific except clauses improve clarity and make error handling more intentional. Infrastructure automation should distinguish temporary network failures, invalid responses, authentication problems, and logical validation failures whenever practical.

Question 328.

Which Python feature is best for ensuring that a file containing generated configuration is automatically closed after use?

  1. break
    2. continue
    3. lambda
    4. A with context manager

Correct Answer: 4

Explanation:

The with statement provides context management and is commonly used when working with files and other resources that need reliable cleanup. When a file is opened inside a with block, Python closes it automatically when execution leaves the block, even if an exception occurs. This reduces the chance of leaked file handles or incomplete cleanup. Similar context-manager patterns can be used with locks, sessions, and temporary resources when supported. Loop-control and lambda constructs do not provide automatic resource cleanup.

Question 329.

Which Ansible capability packages modules, roles, and plugins into a distributable namespace for reuse?

  1. Collection
    2. Handler
    3. Inventory host
    4. Registered variable

Correct Answer: 1

Explanation:

An Ansible collection is a distribution format that can package modules, roles, plugins, and related automation content under a namespace. Collections make it easier to organize and distribute vendor-specific or function-specific automation components. Cisco networking content is commonly delivered through collections that provide modules designed for particular platforms. Handlers run after notifications, inventory identifies managed hosts, and registered variables store task results. Collections help teams maintain reusable automation while avoiding large amounts of custom one-off scripting.

Question 330.

Which Ansible feature allows variables to be defined once for every host in a logical inventory group?

  1. Callback plugin
    2. Group variables
    3. Handler notification
    4. Loop control only

Correct Answer: 2

Explanation:

Group variables allow common values to be assigned to all hosts belonging to an inventory group. For example, every Nexus leaf switch might share connection parameters, NTP servers, or baseline configuration values. This reduces duplicated variable definitions and makes playbooks easier to reuse. Host-specific values can still override group values when necessary. Callback plugins affect output, handlers respond to changes, and loop controls affect task iteration. Proper variable organization is important in larger automation inventories.

Question 331.

Which Ansible practice best supports idempotent configuration management?

  1. Use modules that compare current and desired state before changing resources
    2. Execute raw configuration commands repeatedly without state checks
    3. Delete and recreate every object during each run
    4. Disable change reporting

Correct Answer: 1

Explanation:

Modules that understand current and desired state can determine whether a configuration change is actually required. When the system already matches the requested state, the module can report no change. This is the essence of idempotent automation. Repeated raw commands may create duplicates or unnecessary changes unless carefully designed. Deleting and recreating objects can introduce downtime and unintended side effects. Accurate change reporting is valuable because it allows operators and CI/CD systems to understand what the automation actually modified.

Question 332.

Which Terraform construct can expose a value, such as a newly created resource identifier, for use by operators or other modules?

  1. Provider block
    2. Output value
    3. Backend block
    4. State lock

Correct Answer: 2

Explanation:

Terraform outputs expose selected values after configuration evaluation or deployment. They can provide information such as resource identifiers, addresses, names, or values needed by another module or automation stage. Outputs improve module usability by defining a clear interface for information that callers need. Provider blocks configure API integrations, backends control state storage, and state locking prevents concurrent updates. Sensitive outputs should be treated carefully because even values hidden from normal terminal display may still exist in Terraform state.

Question 333.

Which Terraform concept allows one resource to use an attribute exported by another resource, creating an implicit dependency?

  1. Resource reference
    2. Packet filter
    3. State deletion
    4. CLI alias

Correct Answer: 1

Explanation:

Terraform resource references allow one resource to consume an attribute produced by another. Terraform uses these references to infer dependencies and determine the correct operation order automatically. For example, a resource may reference the identifier of another object that must exist first. This is preferable to manually sequencing independent commands because Terraform can build a dependency graph. Explicit depends_on may be used when a dependency exists but cannot be inferred from attribute references.

Question 334.

Which Terraform meta-argument can be used when a dependency exists but Terraform cannot infer it from resource references?

  1. output
    2. depends_on
    3. backend
    4. provider only

Correct Answer: 2

Explanation:

The depends_on meta-argument explicitly declares that one resource or module depends on another when the dependency is not already visible through attribute references. Terraform normally infers dependencies automatically, so depends_on should be used only when necessary. Correct dependencies help Terraform order creation, modification, and destruction operations safely. Output, backend, and provider configuration serve other purposes. Overusing explicit dependencies can make configurations harder to understand, so natural references are generally preferred when possible.

Question 335.

Which Terraform lifecycle behavior is most appropriate when replacing a production resource must create the new instance before destroying the old one?

  1. create_before_destroy
    2. ignore_changes only
    3. prevent_destroy only
    4. count = 0

Correct Answer: 1

Explanation:

The create_before_destroy lifecycle behavior instructs Terraform to create the replacement resource before removing the existing one when the provider and resource relationships permit it. This can reduce disruption during replacement operations. It should still be tested because naming constraints, dependencies, or platform behavior may prevent both resources from existing simultaneously. prevent_destroy blocks destruction, while ignore_changes tells Terraform to disregard selected drift. Lifecycle settings can have significant operational effects and should be used deliberately.

Question 336.

Which Terraform lifecycle setting can protect a critical resource from accidental destruction through a normal plan and apply?

  1. replace_triggered_by
    2. create_before_destroy
    3. ignore_changes
    4. prevent_destroy

Correct Answer: 4

Explanation:

The prevent_destroy lifecycle setting causes Terraform to reject plans that would destroy the protected resource through normal configuration changes. This provides an additional safeguard for critical infrastructure. It is not an absolute security boundary because an engineer with sufficient access can remove the setting or manipulate state, but it helps prevent accidental deletion. create_before_destroy changes replacement ordering, while ignore_changes suppresses selected drift handling. Critical resources should also be protected through access controls, review, and CI/CD policy gates.

Question 337.

Which NETCONF message is exchanged at the beginning of a session to advertise supported capabilities?

  1. <hello>
    2. <commit>
    3. <edit-config>
    4. <close-session>

Correct Answer: 1

Explanation:

NETCONF peers exchange <hello> messages when a session begins. These messages advertise the capabilities each side supports, such as candidate configuration, writable-running behavior, validation, notification capabilities, or other extensions. Automation clients should examine these advertised capabilities before assuming a particular workflow is supported. <edit-config> changes configuration, <commit> activates candidate changes where supported, and <close-session> terminates the session. Capability discovery helps automation adapt safely to different network platforms.

Question 338.

Which NETCONF operation can prevent another NETCONF session from modifying a datastore while a coordinated change is being prepared?

  1. <get>
    2. <lock>
    3. <hello>
    4. <close-session>

Correct Answer: 2

Explanation:

The <lock> operation can reserve a supported NETCONF datastore so other sessions cannot make conflicting modifications while a coordinated update is underway. This is valuable when several related configuration changes need to be applied consistently. After the operation is complete, the client should release the datastore with the corresponding unlock operation. Locking does not replace change control and should not be held longer than necessary because it can block other legitimate automation or administrators.

Question 339.

Which Git workflow is most appropriate when an engineer wants to combine an approved feature branch into the main branch?

  1. Merge
    2. Clone only
    3. Tag only
    4. Reinitialize the repository

Correct Answer: 1

Explanation:

A merge combines changes from one Git branch into another. In an infrastructure automation workflow, an engineer may develop changes on a feature branch, submit them for peer review and CI validation, and then merge the approved branch into the main or production branch. A clone creates a local copy of a repository, while a tag marks a specific revision. Branch-and-merge workflows provide separation between development and production code and support controlled review before deployment.

Question 340.

A CI/CD pipeline detects that an automation change passes unit tests but fails an integration test against a lab controller. What should the pipeline do?

  1. Deploy to production because unit tests passed
    2. Ignore the failed integration test
    3. Stop promotion until the failure is corrected or explicitly handled according to policy
    4. Disable integration testing for future runs

Correct Answer: 3

Explanation:

An integration-test failure means the complete workflow does not behave as expected when interacting with another component or platform, even if individual functions passed unit tests. A controlled CI/CD pipeline should therefore stop promotion until the problem is understood and corrected or handled through an approved exception process. Deploying anyway could introduce failures into production infrastructure. Mature automation uses layered testing because syntax checks, unit tests, integration tests, plan reviews, and policy checks each detect different classes of problems.