10 free sample questions from a bank of 692, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit.Refer to the exhibit. A developer is using cURL to test connectivity to a webpage. The request times out after 10 seconds. The developer tested connectivity by using Ping and can open a socket to the remote server by using Telnet. Other users confirm that they can access the webpage from their device. The developer has SSH access to the remote server and runs commands to troubleshoot. What causes the issue?
Connectivity from the remote server back to the client is down.
Firewall rules on the remote server block the client on port 443.
Application-layer security features on the remote server block the connection.
HTTPS proxy configured on the remote server blocks the connection.
Answer: C
The short version
C — Lower layers work but HTTP fails for one client, so the block is at the application layer. Ping proves L3, a Telnet-opened socket proves L4, and other users succeed, leaving server-side L7 filtering of this client as the cause.
Key concepts in this question
Layered isolation: ping tests reachability, TCP connect tests the port, HTTP tests the app.
Client-specific vs global failure: others succeeding rules out a dead service or path.
Application-layer security: WAF rules, allowlists, or request filtering can drop one client's HTTP while TCP succeeds.
Why C is correct
The developer's ping and Telnet checks show packets reach the server and TCP handshakes complete, so routing and the listening port are fine. Because everyone else loads the page, the service itself is up; only this developer's HTTP request times out. That pattern matches an application-layer policy (such as a WAF or app ACL) discarding that client's requests after the connection is accepted.
Why the others are wrong
A. Return-path failure would break the TCP handshake Telnet already completed; Telnet success proves return traffic flows.
B. A port 443 firewall block would prevent opening the socket at all, yet Telnet to the server succeeded.
D. A server-side HTTPS proxy does not selectively time out one client's request while others browse fine; the evidence points to L7 request filtering.
200-901 exam tip
Ping plus TCP open but HTTP dead for one user means look up the stack at L7.
2What is the benefit of edge computing?
It reduces network latency by moving processing closer to the data source.
It simplifies security as devices and processing are brought closer together
It removes the need for centralized data processing.
It reduces data velocity from devices or other data sources.
Answer: A
The short version
A — Edge computing cuts latency by processing near the data source. Running compute at or near the device avoids the round trip to a distant cloud or data center.
Key concepts in this question
Latency vs bandwidth: edge shortens the path, so responses return faster.
Local preprocessing: filtering and acting on data near its origin reduces backhaul.
Centralized processing remains: the cloud still aggregates; edge complements it.
Why A is correct
Placing processing adjacent to sensors, cameras, or users removes WAN propagation and queuing delay from the critical path, which is the defining benefit of edge architectures. Time-sensitive decisions happen locally while only summaries or exceptions travel upstream.
Why the others are wrong
B. Spreading processing across many edge sites complicates security posture rather than simplifying it.
C. Centralized processing is still needed for aggregation, training, and global view; edge reduces dependence on it, not the need.
D. Edge deals with high-velocity device data; it does not reduce that velocity, it handles it locally.
3Which action does the Git command git merge allow the development to perform?
Combine multiple sequence of commits into one unified history.
Push changes to the remote repository
Switch between branches
Create, list, rename, and delete branches
Answer: A
The short version
A — git merge joins commit sequences into one unified history. It takes two lines of development and combines them, preserving both ancestries in the resulting graph.
Key concepts in this question
Merge vs push vs branch commands: combining, publishing, and managing lines of work are separate operations.
Unified history: a merge commit has two parents, tying the branches together.
Switching branches: checkout/switch moves HEAD without combining anything.
Why A is correct
Running git merge on a branch integrates its commits with the current branch, producing a shared history that contains both sequences (with a merge commit in the default no-fast-forward case). That combining action is exactly what the option describes.
Why the others are wrong
B. Pushing to a remote is git push; merge works locally between branches.
C. Switching branches is git checkout or git switch, which only moves the working context.
D. Creating, listing, renaming, and deleting branches is git branch; merge consumes branches rather than administering them.
4Refer to the exhibit.A network engineer must manage the network devices. The engineer prepares a Python scripts to authenticate to the Cisco to DNA Center API and request a device list. The device request fails and returns errors code 401. Which action solves the problem?
Update the API URL. which matched the API endpoint for device list.
Send the request to another network in case there are reachability Issues.
Send the Authentication header In the request with a valid configuration.
Update the credentials that are already supplied and retry the request
Answer: D
The short version
D — Send the auth token header on the device-list request. The script fetched a token but never used it.
Key concepts in this question
DNA Center token flow: POST /dna/system/api/v1/auth/token with Basic auth returns a Token valid about an hour.
X-Auth-Token header: every subsequent Intent API call must carry the token; without it the API returns 401.
Exhibit bug: token is retrieved into data but the GET to /dna/intent/api/v1/network-device reuses only Content-Type headers.
Why D is correct
Cisco documents that the token obtained from the auth endpoint must be set as X-Auth-Token on all API calls, and an expired or missing token surfaces as 401 UNAUTHORIZED. The exhibit follows the correct auth URL and credentials, then drops the token on the device-list GET, so the fix is attaching the authentication header with the valid token, not changing URLs, credentials, or networks.
Why the others are wrong
A. The auth and device URLs match the documented endpoints; a wrong URL would typically 404, not 401.
B. Credentials already succeeded at the auth POST that returned a token; retrying them without sending the token repeats the 401.
C. Reachability problems produce connection or timeout errors, not an application-level 401.
200-901 exam tip
DNA Center 401 after a good auth call means the X-Auth-Token header is missing on the next request.
5A new application is being developed that requires the ability to be copied and moved from one location to another. The existing infrastructure is already heavily utilized, so the new application must have a low resource footprint. The application includes a small PostgreSQL database component. Which application deployment type meets the requirements?
Virtual machine
Bare metal
Container
Python virtual environment
Answer: C
The short version
C — A container gives portability with a small footprint. It packages the app plus its PostgreSQL component into a movable image sharing the host kernel, far lighter than a VM.
Key concepts in this question
Containers vs VMs: shared kernel and layered images versus full guest OS per instance.
Portability: images move between hosts and registries with their dependencies.
Bare metal and venvs: dedicated hardware and Python-only isolation do not meet both goals.
Why C is correct
The requirements are copy-and-move portability plus low overhead on busy infrastructure, including a database piece. A container image bundles app and database with minimal extra OS weight and runs consistently wherever a container runtime exists, satisfying both constraints at once.
Why the others are wrong
A. A virtual machine carries a full guest OS, giving the heaviest footprint of the choices.
B. Bare metal pins the app to specific hardware with no portability and poor density.
D. A Python virtual environment isolates packages only; it cannot package PostgreSQL or ship a whole app image.
200-901 exam tip
Portable plus lightweight with a database inside means container.
6Which line is an example of the start of a chunk from a unified diff?
@@ -90,88 +20191008T1349@@
@@ -20191007T1200 +88,90 @@
@@ -20191007T1200 +20191008T1349@@
@@ -88,10 +88,6 @@
Answer: D
The short version
D — A unified-diff hunk header looks like @@ -88,10 +88,6 @@. The @@ markers wrap old-file then new-file start,count ranges, with nothing else on the line.
Key concepts in this question
Hunk header syntax: @@ -l,c +l,c @@ with line numbers and counts.
Timestamps vs ranges: dates belong in file-header lines, never in hunk headers.
@@ -88,10 +88,6 @@ has both required range specs: old file starting at line 88 for 10 lines, new file starting at 88 for 6 lines. That numeric range-pair form is exactly how diff marks where each chunk begins.
Why the others are wrong
A. It appends a timestamp (20191008T1349) where a line count belongs, which is not hunk syntax.
B. Its ranges are replaced by timestamps on both sides, resembling log output rather than a diff.
C. Both sides are pure timestamps with no start,count ranges, so it cannot locate any chunk.
200-901 exam tip
Hunk headers count lines (-l,c +l,c); timestamps never appear between @@ marks.
7A developer creates an application that must provide an encrypted connection or API keys. The keys will be used to communicate with a REST API. Which command must be used for the secure connection?
curl -X GET 'https://username.app.com/endpoint/?api_key=12345abcdef'
curl -X GET 'http://username.app.com/endpoint/?api_key=12345abcdef'
Answer: C
The short version
C — Use HTTPS with GET so the API key travels over an encrypted read. The https:// scheme provides TLS, and GET is the correct verb for retrieving from an endpoint.
Key concepts in this question
HTTPS vs HTTP: TLS encrypts the request line and query string on the wire.
Correct method: GET reads; PUSH is not an HTTP method at all.
Scheme fitness: FTP cannot invoke a REST endpoint.
Why C is correct
curl -X GET 'https://...' opens a TLS session before sending anything, so the api_key in the request is encrypted in transit, and GET matches a REST read against the endpoint. It is the only option combining a valid REST verb with a secure transport.
Why the others are wrong
A.PUSH is not an HTTP method, and plain http:// would expose the key in cleartext.
B.ftp:// addresses a file-transfer service, not a REST API, and -v only adds verbosity, not security.
D. GET is right but http:// sends the key unencrypted, failing the secure-connection requirement.
200-901 exam tip
API key in the URL demands HTTPS; check the scheme first, then the verb.
8Refer to the exhibit.A developer creates a Python script that queries Cisco Webex. When the script is executed, a 401 code is returned. After troubleshooting, the developer discovers that the service is missing privileges. Which change to the header in line 4 of the script results in the code 200?
Answer:
The short version
A — Use Authorization: Bearer <token>. That is the only valid Webex header form.
Key concepts in this question
Webex OAuth: calls carry the access token in the Authorization header with the Bearer scheme.
Exact spelling: header name Authorization, value Bearer plus one space plus token.
Exhibit bug: line 4 uses a placeholder Key/Value pair, so the API sees missing privileges and returns 401.
Why A is correct
Webex developer docs require Authorization: Bearer YOUR_ACCESS_TOKEN on every REST call. Option A is the only choice with the correct header name and the Bearer scheme in the value, so it is the single change to line 4 that turns the 401 into a 200.
Why the others are wrong
B. Merges the scheme into the key as Authentication Bearer and drops Bearer from the value; never a valid header.
C. Uses Authentication instead of the required Authorization header name.
D. Merges the scheme into the key as Authorization Bearer and omits Bearer from the value.
200-901 exam tip
Webex 401 on headers always resolves to Authorization colon Bearer space token.
9Refer to the exhibit.Which JSON is equivalent to the XML -encoded data?
Option B
Option A
Option C
Option D
Answer: B
The short version
B — Plain nested objects mirror the XML one-to-one. Single elements become objects, not arrays.
Key concepts in this question
XML-to-JSON rule: an element appearing once maps to an object member; arrays are only for repeated sibling tags.
Exhibit XML: books holds one science (biology, geology, chemistry) and one math (calculus, algebra), no attributes.
Correct shape: books as object containing science and math objects with string values.
Why B is correct
Only B preserves the hierarchy without adding wrappers: books object, science object with its three leaves, math object with its two leaves. That is the exact structural equivalent of the XML tree.
Why the others are wrong
A. Wraps the whole document in an outer array; the root occurs once and must be an object.
C. Makes books an array holding key-value pairs, which is invalid JSON structure and breaks single-occurrence mapping.
D. Splits names from content into alternating strings and objects inside an array, destroying the parent-child relationships.
200-901 exam tip
No repeated tags means no square brackets — one XML element equals one JSON object.
10A company wants to automate the orders processed on its website using API. The network device that supports the solution must:support XML encodingsupport distributed transactionssupport YANG data modelsbe support software redundancyWhich requirement prevents the use of RESTCONF for the solution?
software redundancy
YANG data models
distributed transactions
XML encoding
Answer: C
The short version
C — Distributed transactions rule out RESTCONF. Multi-device atomic commit is a NETCONF capability; RESTCONF's stateless CRUD has no transaction support.
Key concepts in this question
NETCONF transactions: candidate datastore with commit, rollback, and locking across operations.
RESTCONF limits: REST-mapped YANG operations without candidate/commit semantics.
Shared ground: both use YANG models, and XML/encoding plus redundancy are device features.
Why C is correct
Requirements demanding that changes across systems succeed or fail together need the transaction machinery (candidate, validate, commit, rollback) defined for NETCONF. RESTCONF deliberately omits that model, offering per-resource HTTP verbs instead, so a distributed-transaction mandate cannot be met with RESTCONF.
Why the others are wrong
A. Software redundancy is a platform feature independent of the management protocol chosen.
B. RESTCONF natively serves YANG data models, so YANG support is no obstacle.
D. RESTCONF supports both XML and JSON encodings of YANG data, so XML is fully compatible.
200-901 exam tip
Transactions and candidate/commit mean NETCONF; RESTCONF is transaction-free CRUD.