Automating and Programming Cisco Enterprise Solutions — Free Practice Questions
10 free sample questions from a bank of 220, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit. End users cannot connect to the circular network, and the signal strength is poor. A missing or unknown APN status message is present and the modern status remains in low-power mode. Which addresses the issue?
Use the device/celluiar/status vManage resource URI to ensure sufficient radio signal strength.
Use the systen/device/controllers vManage resource URI to set the platform temperature.
Use the device/tools'ping vManage resource URI to allow network device reachability.
Use the device/app-route/statistics vManage resource URI to allow packets reachability to hosts.
Answer: A
The short version
A — Cellular status check is the fix. Poor signal plus APN unknown and modem low-power points to the cellular radio path, not ping.
Key concepts in this question
vManage cellular status API: GET /device/cellular/status, radio, network and modem expose signal, APN and modem state.
Symptom-to-URI mapping: signal/APN/modem symptoms require the cellular status resource before reachability tools.
Why A is correct
Exhibit lists GET /device/cellular/status, GET /device/cellular/radio, GET /device/cellular/network and GET /device/cellular/modem. Option A uses the device/cellular/status resource to verify sufficient radio signal strength, which directly addresses poor signal, missing/unknown APN and modem low-power mode.
Why the others are wrong
B. Controllers/temperature URI does not check radio signal or APN/modem state.
C. device/tools/ping tests reachability but does not diagnose signal strength, APN status or modem power mode.
D. app-route statistics covers packet reachability to hosts, not cellular radio/APN status.
300-435 exam tip
Poor signal plus APN plus modem low-power means check cellular status first.
2Refer to the exhibit. A RESTCONF GET request is sent to a Cisco IOS XE device. A portion of the response is shown in the exhibit.Which module name corresponds to the YANG model referenced in the request?
ietf-interfaces:ietf-ipv4
iana-if-type:ethernetCsmacd
ietf-interfaces
ietf-interfaces:interfaces
Answer: C
The short version
C — The module is ietf-interfaces. The top-level JSON key prefix before the colon names the YANG module.
Key concepts in this question
YANG module vs container: in "ietf-interfaces:interfaces", ietf-interfaces is the module and interfaces is the top container.
RESTCONF JSON encoding: response keys use module-name:container-name form.
Why C is correct
Exhibit response opens with "ietf-interfaces:interfaces": { "interface": [ { "name": "GigabitEthernet1" with "type": "iana-if-type:ethernetCsmacd" and "ietf-ip-ipv4". The prefix on the top-level container identifies the referenced YANG module as ietf-interfaces.
Why the others are wrong
A. ietf-interfaces:ietf-ipv4 is not a module name; it mixes module and IPv4 augmentation labels.
B. iana-if-type:ethernetCsmacd is only the interface type identity value, not the requested module.
D. ietf-interfaces:interfaces is the module-plus-container path, not the module name itself.
300-435 exam tip
Prefix before the colon on the top key equals the YANG module.
3Drag and Drop QuestionAn engineer must monitor device health across a Meraki organization. The engineer must retrieve device statuses via the organizations devices/statuses endpoint and archive the JSON. Drag and drop the code snippets from the bottom onto the boxes in the code to construct the artifact. Not all options are used.
Answer:
Answer
Correct mapping — MATCH
Box 1 → import requests; Box 2 → GET /devices/statuses; Box 3 → response.json(); Box 4 → json.dump to file.
Why this mapping is correct
Meraki device-status archival flow
Import client, GET organizations devices/statuses, parse JSON, then archive with json.dump; claim endpoint is the distractor.
300-435 exam tip
Meraki monitoring pattern
Remember: headers carry X-Cisco-Meraki-API-Key, statuses is a GET, and json.dump archives the artifact.
4Refer to the exhibit. The lab group consists of four Cisco IOS XE routers named pod-11,pod-12, and pod-22. What is the result of running the Ansible playbook to reset the lab?
The Loopback1 interface is removed from the pod-11 and pod-12 routers.
The IPv4 and IPv6 addresses for the Loopback2 interface are removed from all routers.
The changes will occur on pod-21 and pod-22 If the loopback2 Interface is absent.
The IPv4 and IPv6 addresses for the Loopback1 interface are removed from pod-11 and pod-12.
Answer: A
The short version
A — Loopback1 is removed from pod-11 and pod-12. The "pod-1" substring matches exactly those two hostnames.
Key concepts in this question
Ansible when condition with substring: when: '"pod-1" in ansible_net_hostname' matches pod-11 and pod-12.
ios_l3_interface state absent: removes the named Loopback interface L3 state on matched hosts.
Why A is correct
Exhibit task2 sets ios_l3_interface name Loopback1 state absent when "pod-1" in ansible_net_hostname, and task3 targets Loopback2 only when "pod-2" in hostname. Among pod-11, pod-12 and pod-22 class hosts, only pod-11 and pod-12 contain "pod-1", so Loopback1 is removed from pod-11 and pod-12.
Why the others are wrong
B. Nothing removes Loopback2 IPv4/IPv6 from all routers; task3 is gated to "pod-2" hosts only.
C. pod-21/pod-22 Loopback2 handling is conditional on absence logic for Loopback2, not the stated Loopback1 result.
D. The playbook removes Loopback1 per task2, not specifically only its IPv4/IPv6 addresses on pod-11/pod-12.
300-435 exam tip
Read the when substring literally: pod-1 hits pod-11 and pod-12 only.
5Drag and Drop QuestionAn engineer must provide subnet intelligence to an AI agent so it can reason about addressing during change planning. The engineer must implement a FastMCP tool that accepts a CIDR and returns network, broadcast, and host counts, then start the server over stdio. Drag and drop the code snippets from the bottom onto the boxes in the code to construct the artifact. Not all options are used.
Imports enable parsing, the @mcp.tool computes network/broadcast/num_addresses via ip_network, server instantiation names it, and stdio transport starts it; SSE is the distractor.
300-435 exam tip
FastMCP tool pattern
Remember: @mcp.tool() exposes the function, ipaddress.ip_network does the math, and transport='stdio' is required for agent stdio launch.
6What is a benefit of using Terraform with Cisco IOS XE platforms?
GUI-based
requires a master server
real-time monitoring
agentless
Answer: D
The short version
D — Terraform's edge with IOS XE is that it is agentless. Nothing installs on the device; the provider drives NETCONF, RESTCONF, or SSH remotely from wherever Terraform runs.
Key concepts in this question
Agentless: no software footprint on the managed device.
Declarative providers: declare end state and Terraform computes the changes.
Monitoring vs provisioning: configuration tools versus telemetry pipelines.
Why D is correct
IOS XE exposes programmatic interfaces that Terraform providers consume remotely, so there is no agent to install, upgrade, or secure on each box. That zero-footprint model is precisely what agentless means, and it is the listed benefit that actually distinguishes Terraform's operating model, making D correct.
Why the others are wrong
A. Terraform is CLI- and code-driven, not GUI-based.
B. A master server describes Puppet or Chef architectures, not Terraform's local runs.
C. Real-time monitoring belongs to telemetry and assurance tools, not a provisioning tool.
300-435 exam tip
Terraform phones it in: no agent on the box, everything driven remotely.
7Refer to the exhibit. A Cisco Catalyst SD-WAN Fabric Policy must be created in a non-production environment. To implement this, a Python script that pulls the existing policy and updates the preferred route to be over MPLS must run during the maintenance window. Which code snippet must be added to the box in the code to complete the Python script? The initial part of the Python script is not shown.
Answer A is correct - PUT the updated policy with preferred route over MPLS.
Key concepts in this question
SD-WAN fabric policy, vManage REST API, GET then PUT, preferred-color MPLS.
Why A is correct
A retrieves the policy then PUTs preferredColor mpls with correct JSON and headers.
Why the others are wrong
GET POST and DELETE do not update the policy and wrong keys miss preferredColor.
300-435 exam tip
For vManage updates GET the object then PUT the full modified payload.
8Refer to exhibit. A network engineer creates an Ansible playbook execution task that automates the removal of unnecessary IP addresses from the loopback interfaces of Cisco IOS XE devices.Which code snippet must be added to the box in the code?
ios_l3_interfaces
ios_command
ios_config
ios_vrf
Answer: A
The short version
A — Removing loopback addresses idempotently calls for ios_l3_interfaces. That resource module owns Layer 3 addressing state, while the other modules run raw commands, raw config, or VRF tasks.
Key concepts in this question
ios_l3_interfaces: declarative IPv4 and IPv6 addressing per interface.
ios_command vs ios_config: operational commands versus free-form config lines.
ios_vrf: VRF definitions and membership, not host addresses.
Why A is correct
Stripping unwanted IPs from loopbacks is a desired-state addressing task: with ios_l3_interfaces the playbook declares which addresses must be absent and the module renders the exact removal idempotently. That structured, state-aware handling is why the automation uses the L3 interfaces module rather than blind command or config pushes, so A is correct.
Why the others are wrong
B. ios_command executes show and operational commands; it does not manage configuration state.
C. ios_config pushes raw lines without the address-aware state model the task needs.
D. ios_vrf manages VRF tables, not the interface addresses being removed.
300-435 exam tip
Addresses as state means l3_interfaces; raw lines mean ios_config; show commands mean ios_command.
9Drag and Drop QuestionDrag and drop the code from the bottom onto the box where the code is missing to construct a Python script to automate the process of updating the site-to-site VPN settings of the network.Not all options are used.
Authenticate, build hub-mode payload with hubs/useDefaultRoute, call the site-to-site VPN update for the network, then verify; third-party-peers call is the distractor.
300-435 exam tip
Meraki VPN endpoint
Remember: site-to-site VPN uses updateNetworkApplianceVpnSiteToSiteVpn with mode hub/spoke, not the third-party peers endpoint.
10Refer to the exhibit. What is a valid XML instances of this YANG module?
Option B
Option A
Option C
Option D
Answer: B
The short version
B — Option A is the only fully valid instance. It supplies every mandatory leaf with dotted-quad values and omits only the optional leaf.
Key concepts in this question
Mandatory leaves: name, address and subnet-mask are mandatory true; enabled is optional with default false.
dotted-quad pattern: address and subnet-mask must be four decimal octets, so IPv6 values fail.
Why B is correct
Exhibit YANG module requires name, address and subnet-mask and defines address/subnet-mask as dotted-quad. Option A provides GigabitEthernet 0/0/0 and 0/0/1 each with name, dotted-quad address 10.10.10.1/192.168.1.1 and dotted-quad mask 255.255.255.0, with no invalid values and no missing mandatory leaf.
Why the others are wrong
A. Option B is invalid because its first interface has address plus enabled but no mandatory subnet-mask.
C. Option C is invalid because 2001:db8::2:1 addresses violate the dotted-quad pattern.
D. Option D is invalid because its interfaces omit the mandatory name leaf.
300-435 exam tip
Mandatory true means missing equals invalid; optional enabled may be omitted.