View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps
Question 81.
A network automation engineer wants to retrieve interface information from a Cisco Nexus switch in a machine-readable format. Which approach is most appropriate?
- Use NX-API and request structured JSON or XML output
2. Copy and paste CLI output manually
3. Use only CDP advertisements
4. Disable HTTPS on the switch
Correct Answer: 1
Explanation:
NX-API allows supported Cisco Nexus platforms to expose CLI and operational information through programmable HTTP or HTTPS requests. When structured output such as JSON or XML is available, automation scripts can parse fields reliably instead of using fragile text-matching techniques. Manual copy-and-paste workflows do not scale and are difficult to validate consistently. CDP provides neighbor-discovery information but is not a general automation interface. Disabling HTTPS would weaken transport security. Structured programmatic access is preferable because the script can validate responses, process multiple devices, and integrate the results into larger orchestration or compliance workflows.
Question 82.
Which HTTP header commonly tells a REST API that the client expects JSON data in the response?
- Hostname
2. Accept
3. Retry-After
4. Location only
Correct Answer: 2
Explanation:
The HTTP Accept header tells the server which media type the client prefers in the response. For JSON, a client commonly specifies application/json. The Content-Type header instead describes the format of the body being sent by the client. Retry-After can indicate how long a client should wait before retrying a request, while Location may identify a newly created or redirected resource. Understanding HTTP headers is important when automating Cisco APIs because authentication, content negotiation, caching, and error handling can depend on correctly formed request metadata.
Question 83.
Which HTTP header identifies the format of the request payload being sent to an API?
- Server
2. Accept-Encoding
3. Content-Type
4. User-Agent only
Correct Answer: 3
Explanation:
The Content-Type header identifies the media type of the request body. For a JSON payload, the value is commonly application/json; for XML it may be application/xml or another platform-specific type. This helps the API correctly parse the submitted data. Accept describes the response format desired by the client, while the other headers serve different purposes. If the Content-Type value does not match the actual payload format, the API may reject the request or fail to interpret it correctly. Automation engineers should explicitly set and validate request headers rather than relying on assumptions.
Question 84.
A REST API request returns HTTP status code 204. What does this usually indicate?
- Authentication failed
2. The server crashed
3. The object was not found
4. The request succeeded but there is no response body
Correct Answer: 4
Explanation:
HTTP status code 204 means the request was successfully processed and the server has no content to return in the response body. This may occur after a successful update or deletion, depending on the API design. A 401 response is commonly associated with authentication failure, 404 indicates that a resource was not found, and 500-series responses indicate server-side errors. Automation scripts should treat 204 as success when documented by the API and avoid attempting to parse an empty response body as JSON. Correct status-code handling prevents false failures in production workflows.
Question 85.
Which Python technique is most appropriate for ensuring that an HTTP request does not wait indefinitely for an unreachable Cisco controller?
- Configure a timeout in the request
2. Remove exception handling
3. Use an infinite loop
4. Disable authentication
Correct Answer: 1
Explanation:
A timeout limits how long the script waits for a connection or response before raising an exception. This is important when automating infrastructure because a controller or device may be unreachable, overloaded, or experiencing network problems. Without a timeout, one failed request can cause a workflow to hang indefinitely and block processing of other systems. The script should catch timeout exceptions and decide whether to retry, skip the device, or escalate the failure. Infinite loops and missing exception handling increase operational risk, while authentication settings do not solve connectivity delays.
Question 86.
Which Python statement is commonly used to ensure that cleanup code executes whether an exception occurs or not?
- elif
2. finally
3. lambda
4. yield only
Correct Answer: 2
Explanation:
The finally block executes after a try statement regardless of whether an exception occurred. This is useful for cleanup actions such as closing files, releasing resources, terminating sessions, or performing final logging. In infrastructure automation, predictable cleanup can prevent stale sessions or partially open resources. An except block handles specific exceptions, while finally ensures that designated cleanup logic still runs. elif, lambda, and yield serve different purposes. Good exception handling helps scripts fail safely rather than leaving infrastructure workflows in an uncertain state.
Question 87.
Which Python mechanism allows code to explicitly generate an exception when an invalid condition is detected?
- import
2. pass
3. raise
4. continue
Correct Answer: 3
Explanation:
The raise statement explicitly generates an exception. An automation script can use it when input validation fails, an API response contains unexpected data, or a safety check determines that execution should stop. For example, a script could raise an exception if a production environment identifier does not match the expected value before making a destructive change. pass performs no action, continue advances to the next loop iteration, and import loads modules. Deliberately raising clear exceptions can make automation safer and easier to troubleshoot.
Question 88.
Which Python keyword creates an anonymous function that can be useful for simple inline operations?
- def only
2. with
3. async only
4. lambda
Correct Answer: 4
Explanation:
The lambda keyword creates a small anonymous function in Python. Lambdas are often used for simple transformations, sorting keys, or short callback-style operations where defining a separate named function would be unnecessary. For complex logic, normal functions created with def are generally clearer and easier to test. In automation code, readability and maintainability are important because scripts may later be modified by other engineers. with provides context management, while async relates to asynchronous programming.
Question 89.
Which Ansible construct is most appropriate when a task must execute once for every VLAN ID in a list?
- loop
2. handler only
3. inventory plugin only
4. callback plugin only
Correct Answer: 1
Explanation:
An Ansible loop allows a task to run repeatedly for each item in a list. For example, the same module can be invoked once for every VLAN ID while the current value is referenced through a loop variable. This reduces duplicated YAML and makes the playbook easier to maintain. Handlers are generally triggered after changes, inventory identifies managed hosts, and callback plugins influence output or execution behavior. Loops are particularly useful in data center automation because many configuration elements follow repetitive patterns.
Question 90.
Which Ansible feature allows a task to run only when a specified expression evaluates as true?
- vars_files
2. when
3. notify
4. gather_facts only
Correct Answer: 2
Explanation:
The Ansible when conditional controls whether a task executes based on an expression. For example, a playbook can apply one configuration only to leaf switches or create a resource only when a required variable is defined. Conditionals help make playbooks reusable across different devices and environments. notify triggers handlers when a task changes state, while vars_files loads variables from external files. Proper use of conditionals reduces unnecessary changes and supports idempotent automation by applying actions only when relevant conditions are met.
Question 91.
Which Ansible keyword can store the output from one task so later tasks can reference it?
- register
2. become only
3. hosts
4. serial only
Correct Answer: 1
Explanation:
The register keyword stores the result of an Ansible task in a variable. Later tasks can inspect fields such as success status, returned data, or module-specific values and make decisions based on them. For example, a playbook might query a Cisco device, register the result, and then use a when statement to apply a configuration only if the current state differs from the desired state. hosts selects play targets, while become and serial serve other execution functions. Registering results is a useful technique for building dynamic workflows.
Question 92.
What is the primary purpose of Ansible Vault?
- Store switch forwarding tables
2. Encrypt sensitive variables and files
3. Replace Git entirely
4. Perform packet capture
Correct Answer: 2
Explanation:
Ansible Vault encrypts sensitive content such as passwords, API tokens, or other secrets stored in Ansible variable files. This reduces the risk of exposing credentials when playbooks are stored in a repository or shared among engineers. Vault does not replace broader secret-management requirements, and organizations may also use dedicated secret stores with stronger centralized controls and auditing. Git remains useful for version control, while packet capture and forwarding-table functions are unrelated. Secrets should still be granted minimum required privileges and rotated according to policy.
Question 93.
Which Terraform command actually performs the infrastructure changes described by a reviewed configuration?
- terraform apply
2. terraform fmt only
3. terraform validate only
4. terraform show only
Correct Answer: 1
Explanation:
terraform apply executes the changes required to move infrastructure toward the declared desired state. Before using it in production, engineers should normally review the output of terraform plan so they understand which resources will be created, modified, replaced, or destroyed. terraform validate checks configuration validity, while terraform fmt normalizes formatting and terraform show displays state or plan information. Applying infrastructure changes without reviewing the plan can create unexpected impact, particularly when provider behavior or dependencies cause resource replacement.
Question 94.
Which Terraform command checks whether configuration files are syntactically valid and internally consistent without applying changes?
- terraform destroy
2. terraform validate
3. terraform import
4. terraform taint only
Correct Answer: 2
Explanation:
terraform validate checks whether Terraform configuration is syntactically valid and internally consistent. It can identify malformed references, invalid arguments, and other configuration problems before an apply operation. Validation does not contact every external API or guarantee that deployment will succeed, but it is an important early quality check. terraform plan provides a more detailed preview of infrastructure changes, while apply performs those changes. Combining formatting, validation, planning, review, and testing creates a safer infrastructure-as-code workflow.
Question 95.
Why should Terraform state be treated as sensitive information?
- It may contain detailed infrastructure attributes and potentially sensitive values
2. It contains only comments
3. It is always publicly encrypted automatically
4. It cannot reveal resource information
Correct Answer: 1
Explanation:
Terraform state contains detailed information about managed resources and may include identifiers, addresses, configuration attributes, and sometimes sensitive values returned by providers. Even when variables are marked sensitive in normal output, state may still contain the underlying data. For this reason, state should be protected through access controls, encryption, controlled remote backends, and restricted distribution. It should not be committed casually to public repositories. Proper state protection is part of secure infrastructure-as-code practice because exposure can reveal valuable details about production environments.
Question 96.
Which Terraform capability helps prevent two engineers from modifying the same remote state simultaneously when the backend supports it?
- Packet filtering
2. VLAN pruning
3. API pagination
4. State locking
Correct Answer: 4
Explanation:
State locking prevents multiple Terraform processes from writing to the same state concurrently. Without locking, simultaneous changes could produce conflicting updates or corrupt state information. Supported remote backends can automatically acquire a lock before an operation and release it afterward. State locking does not replace source-control coordination or change review, but it adds an important protection at execution time. Packet filtering, VLAN pruning, and pagination are unrelated to Terraform state coordination.
Question 97.
Which protocol uses YANG models and typically exchanges XML-encoded RPC messages over SSH?
- NETCONF
2. TFTP
3. FTP
4. Syslog
Correct Answer: 1
Explanation:
NETCONF is a model-driven management protocol commonly transported over SSH. It uses RPC-style operations, typically encoded in XML, to retrieve and modify configuration and operational data defined by YANG models. NETCONF supports structured operations and can offer capabilities such as configuration locking and candidate datastores depending on the device. TFTP and FTP are file-transfer protocols, while Syslog transports event messages. NETCONF is important in automation because it avoids relying exclusively on unstructured CLI output.
Question 98.
Which protocol provides REST-like HTTP access to YANG-modeled network data?
- SNMPv1 only
2. RESTCONF
3. CDP
4. LLDP
Correct Answer: 2
Explanation:
RESTCONF provides HTTP-based access to configuration and operational data modeled with YANG. It uses REST-style methods and commonly represents data using JSON or XML. This makes RESTCONF familiar to developers who already work with web APIs while retaining the benefits of structured YANG models. NETCONF provides similar model-driven capabilities through an RPC-oriented interface, commonly over SSH. CDP and LLDP are neighbor-discovery protocols and do not provide general model-driven configuration APIs.
Question 99.
Which practice best helps ensure that a new automation feature does not break previously working Python functions?
- Maintain automated regression and unit tests
2. Remove all test code after deployment
3. Avoid version control
4. Test only in production
Correct Answer: 1
Explanation:
Automated unit and regression tests help verify that existing functionality continues to work after new code is introduced. Unit tests validate individual functions, while broader regression tests check that previously supported behavior has not been broken by a change. Running these tests in CI before code is merged provides early feedback and reduces production risk. Removing tests or testing exclusively in production defeats this safeguard. Infrastructure automation can affect large numbers of systems quickly, so repeatable automated testing is particularly important.
Question 100.
A CI pipeline validates syntax successfully but a proposed automation change would delete several production resources. Which additional control would provide the best protection before deployment?
- Disable all audit logs
2. Remove the plan output
3. Require review of the proposed changes and an approval gate before production execution
4. Hardcode production credentials into the pipeline
Correct Answer: 3
Explanation:
Syntax validation confirms only that code is structurally valid; it does not prove that the intended infrastructure changes are safe. A production workflow should therefore include change previews, plan review, policy checks, and approval gates for high-impact operations. For Terraform, reviewing the plan can expose unexpected deletions or replacements. Similar dry-run or diff mechanisms are useful with other automation tools. Audit logging should remain enabled, and credentials should be managed securely rather than embedded in pipeline code. Human approval for destructive production changes adds a valuable safeguard when automation has a large potential blast radius.