Sign In
Home/Cisco/Automating Cisco Data Center Solutions (DCAUTO)/Free questions

Automating Cisco Data Center Solutions (DCAUTO) — Free Practice Questions

10 free sample questions from a bank of 69, with the correct answers and explanations. No signup required — start practising right now.

1Refer to the exhibit. Which two statements are true about this API GET request to the ACI APIC?(Choose two.)
  • The API response is encoded in JSON.
  • The API call reads information from a managed object.
  • The API call creates a new 10G interface in the APIC.
  • The API call reads information from an object class.
  • The API response is encoded in XML.
Answer: D, E

The short version

D and E — The call is a class query returning XML. The request reads an object class, and the payload encoding is XML rather than JSON.

Key concepts in this question

  • Managed object versus class: a distinguished-name query reads one instance, while a class query reads all instances of a type.
  • APIC REST encoding: the URI suffix selects XML or JSON representation of the same model data.
  • GET semantics: GET retrieves model information and never creates interfaces or policies.

Why D and E are correct

The exhibit URI targets a class path rather than a specific distinguished name, so the operation enumerates members of that object class. The request and response use XML encoding, which matches the XML suffix and body format rather than JSON. Together those two facts identify the call as a read of an object class with an XML response.

Why the others are wrong

  • A. JSON would require a JSON suffix and JSON body, which the exhibit does not use.
  • B. A managed-object read addresses one instance by distinguished name, not the class collection queried here.
  • C. GET never provisions a 10G interface; interface creation requires a POST with a configuration payload.

300-635 exam tip — memory hook

APIC URI with class means all objects of that type; suffix decides XML versus JSON.

2Refer to the exhibit. The exhibit shows a Cisco NX-OS switch configuration, an Ansible playbook, and the output of running this playbook. The playbook failed due to error "msg' 'Request failed<urlopen error [Errno 61] Connection refused>', 'status' -1, "url" "http://192.168.251.129:80/ins".Which Cisco NX-OS configuration command resolves this failure?
  • feature nxapi
  • http-server enabled
  • interface mgmt0; ip access-group allow_http_traffic in
  • feature http
Answer: C

The short version

C — The switch refuses HTTP because mgmt0 filtering blocks it. Correcting the management access-group to permit the automation host lets the Ansible NX-API call reach the switch.

Key concepts in this question

  • NX-API transport: Ansible nxos modules post to http or https on the switch management interface.
  • Connection refused: means TCP to port 80 was actively rejected or filtered before NX-API processing.
  • mgmt0 ACLs: an inbound access-group can silently block controller and automation traffic.

Why C is correct

The playbook posts to port 80 and receives connection refused with status minus one, which is a transport reachability failure rather than a command syntax failure. The exhibit configuration applies a restrictive access-group on mgmt0 that denies the automation source. Adjusting the interface access-group to allow HTTP traffic from that host restores TCP connectivity so the same playbook succeeds without changing NX-API features.

Why the others are wrong

  • A. Enabling the NX-API feature helps only after TCP reaches the switch; refused TCP points to filtering first.
  • B. NX-OS does not use a generic http-server enabled command for this path; management access is governed by NX-API and mgmt ACLs.
  • D. There is no standalone feature http fix for NX-API transport; the exhibited blocker is the mgmt0 policy.

300-635 exam tip — memory hook

Ansible connection refused on port 80: check mgmt0 ACLs before re-installing features.

3Which two methods can you use to implement in-band management access to a Cisco APIC?(Choose two.)
  • POAP
  • GUI
  • REST API
  • ZTP
  • FTP
Answer: B, C

The short version

B and C — In-band APIC access is GUI and REST API. Both ride the configured in-band network to manage the controller without using the out-of-band ports.

Key concepts in this question

  • In-band versus out-of-band: in-band management travels through the fabric; out-of-band uses dedicated APIC CIMC ports.
  • APIC GUI: browser access to the controller cluster over its in-band address.
  • REST API: programmatic access to the same MIT objects exposed by the GUI.

Why B and C are correct

Once in-band management connectivity to the APIC is provisioned, administrators can reach the controller through its normal management services. The GUI provides interactive in-band access and the REST API provides the programmatic equivalent, so both are valid in-band methods using the same network path and credentials.

Why the others are wrong

  • A. POAP automates switch day-zero provisioning and is not a method for managing an APIC in-band.
  • D. ZTP provisions endpoints and nodes, but it does not constitute APIC management access.
  • E. FTP transfers files and cannot browse, configure, or query the APIC object model.

300-635 exam tip — memory hook

APIC in-band equals normal GUI plus API over fabric ports; POAP, ZTP, and FTP are not management logins.

4Refer to the exhibit. When Cisco UCS is configured, which filter must be added to the str_filter string to retrieve all discovered compute blades with two CPUs?
  • (num_of_cpus eq 2) and (discovery eq complete)
  • (num_of_cpus. 'x2\ type-sum") and (discovery, 'complete1, type='sum')
  • (num_of_cpus eq <2) and (discovery eq more)
  • (num_of_cpus. '2', type-eq') and (discovery, 'complete', type-'eq')
Answer: A

The short version

A — The filter must state two CPUs and completed discovery. The expression with num_of_cpus eq 2 and discovery eq complete returns exactly the wanted blades.

Key concepts in this question

  • UCS object properties: compute blades expose CPU count and discovery state as queryable fields.
  • Filter syntax: UCS queries use property, operator, and value triples joined by logical operators.
  • Discovery state: only blades with complete discovery are fully inventoried and usable.

Why A is correct

The requirement combines two independent conditions: hardware with two CPUs and successful discovery. Option A expresses both with valid equality operators joined by and, matching the documented UCS filter grammar. It therefore retrieves all discovered two-CPU blades and excludes incomplete or differently sized inventory.

Why the others are wrong

  • B. The garbled type-sum quoting does not form valid UCS filter syntax and will not parse.
  • C. Using less-than-two and a discovery value of more inverts both conditions and returns the wrong set.
  • D. The comma-separated type-eq fragments are malformed syntax, not valid UCS query filters.

300-635 exam tip — memory hook

UCS filters read like sentences: property, operator, value — keep the grammar clean.

5When the Cisco bigmuddy-network-telemetry-collector from GitHub is used, which command displays only the message headers?
  • --all
  • --print-all
  • --brief
  • --print
Answer: C

The short version

C — Brief mode shows only message headers. Running the collector with the brief flag suppresses full payloads for high-level monitoring.

Key concepts in this question

  • bigmuddy collector: open tool for receiving and decoding network telemetry streams.
  • Header versus payload: headers identify the message while payloads carry the full sensor data.
  • Display flags: output verbosity is controlled by explicit command-line options.

Why C is correct

The documented behavior of the collector reserves the brief option for header-only display, which is useful when checking stream liveness without flooding the terminal. Selecting that flag therefore satisfies the requirement to view only headers while continuing to receive the underlying telemetry stream.

Why the others are wrong

  • A. The all flag widens output rather than narrowing it to headers alone.
  • B. Print-all expands decoding to full messages, the opposite of header-only viewing.
  • D. Print enables message output but does not by itself restrict display to headers.

300-635 exam tip — memory hook

Collector verbosity: brief for headers, print-all when you need full payloads.

6An engineer configures streaming telemetry using gRPC dial-out mode from an NX-OS device to a collector, but no data arrives at the collector despite the subscription being marked "Active" on the switch. TCP capture shows no SYN packets leaving the switch toward the collector. What is the most likely cause?
  • The collector's IP is unreachable from the switch's management or data VRF used for the telemetry destination, or the destination-group is bound to the wrong VRF
  • gRPC dial-out mode requires the collector to initiate the connection, not the switch
  • Model-driven telemetry cannot use gRPC, only NETCONF
  • The sensor-group YANG path is case-sensitive and telemetry silently drops all data if paths are miscased
Answer: A

The short version

A — No SYNs means the switch cannot route to the collector. An unreachable destination or wrong telemetry VRF stops dial-out before TCP even starts.

Key concepts in this question

  • gRPC dial-out: the switch initiates telemetry TCP sessions toward the collector.
  • Destination-group VRF: NX-OS binds the telemetry destination to a specific VRF for reachability.
  • Active subscription: only reflects local configuration validity, not end-to-end TCP success.

Why A is correct

Dial-out requires the switch to originate SYNs, so absent SYNs prove packets never left or had no route. If the collector address is unreachable from the configured management or data VRF, or the destination-group references the wrong VRF, the switch has no forwarding path and emits nothing. Fixing reachability or correcting the VRF binding restores SYN transmission and data flow.

Why the others are wrong

  • B. Dial-out by definition has the switch initiate; requiring the collector to initiate describes dial-in, not this mode.
  • C. Model-driven telemetry commonly uses gRPC as a transport alongside NETCONF, so transport choice is not the blocker.
  • D. YANG path casing affects subscription content, not whether TCP SYNs leave the switch toward the collector.

300-635 exam tip — memory hook

Telemetry Active but silent on the wire: verify VRF, routing, and destination-group first.

7Refer to the exhibit above and click on the resource tabs in the top left corner to view resources to help with this question. An engineer is creating a Python script to update the firmware on a specific Cisco UCS rack server that is managed by Cisco Intersight. The script uses the Cisco Intersight REST API. The value of the 'resource_path' key in the rackunitJson_body Python dictionary retrieves the server with the AssetTag DMZ-R-L2- ADJM. The AssetTag is assigned to only one server. The value of the 'Server' key must be set in the firm ware Json_body Python dictionary with a value from the query result.Which two Python statements, a GET request and a dictionary update, are required to complete the code? (Choose two.)
  • query_result = intersight_api_call('GET', "/api/v1/compute/RackUnits?$filter=Serial eq 'DMZ-R-L2-ADJM'")
  • query_result = intersight_api_call('GET', "/api/v1/compute/RackUnits?$filter=AssetTag eq 'DMZ-R-L2-ADJM'")
  • firmwareJson_body['Server'] = rackunitJson_body['resource_path']
  • firmwareJson_body['Server'] = query_result['Results'][0]['Moid']
  • rackunitJson_body['resource_path'] = firmwareJson_body['Server']
Answer: B, D

The short version

BD — GET filtered by AssetTag then set firmware Server to returned Moid. B performs the correct filtered RackUnits query and D links the firmware payload to that server MOID.

Key concepts in this question

  • Intersight REST resource: compute/RackUnits objects carry AssetTag and Moid identity.
  • $filter query: AssetTag eq value returns only the matching server.
  • Firmware reference: HCL firmware / Server Profile update requires Server Moid, not a path string.

Why BD is correct

B issues GET /api/v1/compute/RackUnits?$filter=AssetTag eq 'DMZ-R-L2-ADJM', which retrieves exactly the one server with that AssetTag. D then sets firmwareJson_body['Server'] from query_result['Results'][0]['Moid'], satisfying the required Server reference for the firmware update call.

Why the others are wrong

  • A. Filters on Serial, not AssetTag, so it will not match DMZ-R-L2-ADJM.
  • C. Copies the local resource_path string instead of the queried server Moid.
  • E. Reverses the assignment and overwrites the query path instead of populating the firmware body.

300-635 exam tip

Remember: Intersight filter = AssetTag eq, then use Results[0].Moid as the Server reference.

8An engineer needs to run a custom Python script directly on an NX-OS switch (on-box) to react to a locally detected condition, without needing external connectivity to a controller. Which NX-OS feature provides an isolated, persistent Linux container environment for running such scripts, separate from the base OS?
  • Bash-shell (native NX-OS Linux shell)
  • Guestshell (a secure, resource-isolated Linux container based on LXC, with its own package management via guestshell CLI and yum/pip)
  • EEM applet action cli
  • Python interpreter invoked directly from BIOS
Answer: B

The short version

B — Guestshell is the on-box Linux container for custom scripts. It provides an isolated, persistent Python environment directly on NX-OS without external connectivity.

Key concepts in this question

  • On-box automation: scripts execute locally on the switch rather than from a controller.
  • Guestshell: LXC-based secure container with its own CentOS user space, yum and pip, and guestshell CLI controls.
  • Persistence: container contents and scripts survive across sessions unlike ad hoc shells.

Why B is correct

The requirement is local event reaction with no controller dependency plus isolation from the base OS. Guestshell meets all three: it runs on the switch, is resource-isolated from NX-OS processes, persists installed packages and scripts, and supports Python execution natively. That makes it the intended platform for the described custom monitoring script.

Why the others are wrong

  • A. Bash-shell exposes the underlying NX-OS Linux shell but lacks container isolation and package persistence guarantees.
  • C. EEM action cli runs CLI commands on events but is not a general Linux container for custom Python applications.
  • D. There is no supported Python-from-BIOS execution path on NX-OS for on-box automation.

300-635 exam tip — memory hook

Need isolated on-box Python: think Guestshell container, not bare bash or EEM.

9An engineer building a network CI/CD pipeline wants automated tests to validate not just "did the playbook run without errors" but also "does the resulting device state match the intended design" (e.g., correct BGP neighbor count, correct VLAN membership) after deployment. Which testing approach best fits this requirement?
  • Rely solely on Ansible's changed/failed task status
  • Post-deployment state validation using a tool like pyATS/Genie (or Ansible facts-gathering modules) to query live operational state and assert it against expected values, run as a distinct test stage after configuration deployment
  • Only check HTTP response codes from the APIC/NDFC API during deployment
  • Rely on visual inspection of the CLI output in the Jenkins console log
Answer: B

The short version

B — Validate live state after deployment, not just playbook status. Querying operational state with pyATS, Genie, or facts and asserting design values proves the network matches intent.

Key concepts in this question

  • Configuration versus state: a successful play run does not guarantee the intended forwarding state.
  • pyATS and Genie: Cisco test framework that parses show state and supports assertions.
  • Pipeline stages: deploy, validate-state, and report belong in separate automated steps.

Why B is correct

The pipeline must answer whether BGP counts, VLAN membership, and other design values are actually present after deployment. Post-deployment validation queries live operational state and compares it against expected variables as a distinct test stage. That directly detects partial applies and drift that task status alone would miss.

Why the others are wrong

  • A. Changed and failed flags report task execution only, not whether resulting state equals the design.
  • C. API HTTP codes confirm message delivery, not that device RIB, VLAN, or neighbor state is correct.
  • D. Manual log inspection is unscalable, non-assertive, and unsuitable for automated CI gates.

300-635 exam tip — memory hook

CI for networks: deploy with Ansible, prove it with pyATS state assertions.

10Refer to the exhibit. The code should create a new tenant named Cisco via the Cobra SDK, which shows up after the execution of this script in the APIC dashboard.Which code must he inserted into the red box to create this tenant?
  • fvTenant = Tenant(topMo, name='Cisco')
  • fvTenant = Tenant('Cisco')
  • tenant = Tenant(topMo. name='Cisco')
  • fvTenant = NewTenant(name='Cisco')
Answer: A

The short version

A — Cobra tenants attach to the top object with a name. Instantiating Tenant from topMo with name Cisco creates the tenant shown in the dashboard.

Key concepts in this question

  • Cobra SDK: Python binding for the ACI Management Information Tree.
  • topMo: handle for the root from which new managed objects are constructed.
  • fvTenant: tenant class requiring a parent and naming property.

Why A is correct

Cobra construction always needs the parent managed object plus class properties. Passing topMo as the parent places the new tenant at the fabric root, and name Cisco supplies the required naming property. Committing that object creates fvTenant Cisco, which then appears in the APIC dashboard as shown after execution.

Why the others are wrong

  • B. Omitting the topMo parent leaves the object unattached to the tree, so it cannot be committed correctly.
  • C. The lowercase form and spaced syntax do not match the Cobra class constructor for fvTenant.
  • D. There is no NewTenant constructor in Cobra; the class is Tenant under the fv package.

300-635 exam tip — memory hook

Cobra pattern: ClassName parent plus properties — Tenant needs topMo and name.

Want the full bank of 69 questions for Automating Cisco Data Center Solutions (DCAUTO)? See all practice exams.