Cisco CCNA (200-301) — All Questions

← Back to practiceRead the Cisco CCNA (200-301) study guide →

The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →

58 questions

Automation & Programmability

In a controller-based (SDN) network architecture, which plane does the centralized controller primarily assume from the individual network devices?

  • a.Control plane✓
  • b.Physical layer
  • c.Management plane only
  • d.Data (forwarding) plane

SDN separates the control plane from the data plane, centralizing control-plane decisions such as routing and topology in a controller. The controller programs the devices, which continue to forward traffic in their data plane. A southbound interface (for example, OpenFlow or NETCONF) carries instructions from the controller down to the devices.

Automation & Programmability

A configuration management tool applies a desired state to network devices without requiring an agent installed on each device, connecting over SSH and using YAML playbooks. Which tool is described?

  • a.Puppet
  • b.SNMP
  • c.Chef
  • d.Ansible✓

Ansible is agentless, pushing configuration over SSH and defining desired state in human-readable YAML playbooks, which makes it popular for network automation. Puppet and Chef traditionally use an agent-based, pull model with their own domain-specific languages. All three enforce consistent, repeatable configuration across many devices.

Automation & Programmability

Which REST API method is used to retrieve data from a resource without modifying it?

  • a.PUT
  • b.GET✓
  • c.DELETE
  • d.POST

GET requests read/retrieve a resource and are considered safe and idempotent because they do not change server state. POST creates new resources, PUT updates/replaces a resource, and DELETE removes one. Knowing the CRUD-to-HTTP mapping (Create=POST, Read=GET, Update=PUT/PATCH, Delete=DELETE) is fundamental to using network controller APIs.

Automation & Programmability

Which description best fits JSON as used in network automation?

  • a.A programming language for writing scripts
  • b.A physical cabling standard
  • c.A text-based data format using key-value pairs, arrays, and nested objects✓
  • d.A dynamic routing protocol

JSON (JavaScript Object Notation) is a lightweight, human-readable data-interchange format built from key-value pairs, arrays, and nested objects. REST APIs commonly exchange JSON payloads, so being able to read its curly-brace and bracket structure is essential for parsing controller responses. YAML and XML are alternative data formats.

Automation & Programmability

In an SDN architecture, what does the controller's southbound interface communicate with?

  • a.External DNS servers
  • b.End users browsing the web
  • c.The network devices the controller programs✓
  • d.Business applications requesting services

The southbound interface (using protocols like OpenFlow, NETCONF, or vendor APIs) connects the controller down to the network devices it manages, pushing forwarding and policy instructions. The northbound interface, by contrast, faces up toward applications and orchestration tools that request network behavior. This separation abstracts the underlying hardware.

Automation & Programmability

Compared with traditional per-device management, what is a key benefit of controller-based networking?

  • a.It eliminates the need for any security
  • b.Each device must still be configured individually by hand
  • c.It removes the need for IP addressing
  • d.Centralized, consistent policy can be pushed to many devices, reducing manual error✓

Controller-based networking centralizes intelligence so administrators define policy once and the controller programs it across many devices, improving consistency and speed while cutting the human errors common in box-by-box CLI configuration. Devices still forward traffic, but their control decisions are coordinated centrally, enabling automation and rapid change.

Automation & Programmability

What is the primary responsibility of the data (forwarding) plane on a network device?

  • a.Running the SPF algorithm
  • b.Actually forwarding packets based on the control plane's decisions✓
  • c.Deciding the overall network topology
  • d.Managing user accounts and logins

The data plane (forwarding plane) moves packets through the device as fast as possible, consulting forwarding tables built by the control plane. The control plane makes the decisions (routing protocols, topology), and the management plane handles administration and monitoring. SDN centralizes the control plane while leaving forwarding on the devices.

Automation & Programmability

In which human-readable language are Ansible playbooks written to define desired configuration state?

  • a.YAML✓
  • b.Compiled binary
  • c.HTML
  • d.C++

Ansible playbooks are written in YAML, a readable, indentation-based format that describes the desired end state of devices. Ansible is agentless and connects over SSH, applying tasks idempotently so re-running a playbook does not cause unintended changes. YAML's simplicity is a major reason Ansible is popular for network automation.

Automation & Programmability

What is Cisco DNA Center?

  • a.A Layer 2 access switch for wiring closets
  • b.A dedicated DHCP and DNS appliance for assigning client addresses
  • c.A handheld cable-certification tester
  • d.A central controller for intent-based network management and automation✓

Cisco DNA Center is the central controller and dashboard for intent-based networking, providing design, provisioning, policy, and assurance across the enterprise. It abstracts device-by-device CLI into centralized, automated workflows and telemetry.

Automation & Programmability

What does the northbound interface of an SDN controller do?

  • a.Connects the controller down to the managed switches and routers
  • b.Lets applications and orchestration tools request services from the controller✓
  • c.Carries end-user data packets across the fabric
  • d.Is the physical console cable attached to the controller

The northbound interface (typically REST APIs) faces upward toward applications and automation tools, letting them request network behavior from the controller. The southbound interface faces down to program the network devices themselves.

Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Automation & Programmability

In a REST API, which action does the POST method typically perform?

  • a.Create a new resource✓
  • b.Delete an existing resource
  • c.Replace an entire existing resource in place
  • d.Retrieve an existing resource

POST is used to create a new resource on the server, mapping to the 'Create' operation in CRUD. GET reads, PUT replaces/updates, and DELETE removes. Unlike GET, POST changes server state and is not considered idempotent.

Automation & Programmability

In a REST API, what does the PUT method generally do?

  • a.Only read data without changing it
  • b.Permanently delete the whole collection of resources
  • c.Update or replace an existing resource✓
  • d.Open a persistent TCP session to the server

PUT updates or replaces a resource at a known URI and is idempotent, meaning repeating the same request yields the same result. GET reads, POST creates, and PATCH applies a partial update rather than replacing the whole resource.

Automation & Programmability

In a REST API, what does the DELETE method do?

  • a.Create a new resource on the server
  • b.Duplicate the resource into a backup collection
  • c.Read a resource without modifying it
  • d.Remove the specified resource✓

DELETE removes the resource identified by the URI, completing the CRUD set alongside POST (create), GET (read), and PUT/PATCH (update). It is idempotent because deleting an already-deleted resource leaves the same end state.

Automation & Programmability

What does the HTTP PATCH method do in a REST API?

  • a.Applies a partial update to a resource✓
  • b.Fully replaces the entire resource
  • c.Creates an entirely new nested resource tree
  • d.Reads the resource without changes

PATCH modifies part of a resource, sending only the fields to change, whereas PUT typically replaces the whole resource. PATCH is efficient when you need to update just one attribute of a large configuration object.

Automation & Programmability

What does an HTTP 200 status code indicate in a REST API response?

  • a.The request succeeded (OK)✓
  • b.The request was redirected elsewhere
  • c.A server-side error occurred
  • d.The client sent a malformed, unauthorized request

HTTP 200 (OK) means the request succeeded and the response contains the expected data. 2xx codes indicate success, 3xx redirection, 4xx client errors, and 5xx server errors. Reading status codes is essential when working with controller APIs.

Automation & Programmability

What does an HTTP 401 status code indicate?

  • a.Unauthorized: authentication is required or has failed✓
  • b.A server-side failure occurred while processing
  • c.The requested resource does not exist on the server
  • d.The request succeeded and the resource was returned to the caller

HTTP 401 Unauthorized means the request lacks valid authentication credentials, so the client must authenticate (for example with a token) before access is granted. It differs from 403 Forbidden, where the identity is known but lacks permission.

Automation & Programmability

What does an HTTP 404 status code mean?

  • a.The client is unauthorized to access the resource
  • b.The gateway timed out waiting for an upstream server
  • c.The requested resource was not found✓
  • d.The request completed successfully

HTTP 404 Not Found means the server could not locate the requested resource at that URI, often due to a wrong endpoint path. As a 4xx code it points to a client-side issue such as a typo in the request URL.

Automation & Programmability

What does an HTTP 500 status code indicate?

  • a.A server-side error prevented fulfilling a valid request✓
  • b.A fully successful response with data
  • c.The resource was created successfully
  • d.The client is unauthorized and must provide valid credentials first

HTTP 500 Internal Server Error is a 5xx code indicating the server encountered an unexpected condition and could not complete an otherwise valid request. The fix usually lies on the server side, not with the client's request format.

Automation & Programmability

What does it mean that REST is stateless?

  • a.Each request is self-contained; no session is stored between calls✓
  • b.It requires a permanent encrypted tunnel to remain open
  • c.The server stores and tracks every client's ongoing session state
  • d.It works only between devices inside the same VLAN

Statelessness means each REST request carries all the information the server needs (such as an auth token), and the server keeps no client session between requests. This makes REST APIs scalable and easy to load-balance across servers.

Automation & Programmability

How is a client commonly authenticated to a REST API?

  • a.Only through a directly attached serial console
  • b.By exchanging OSPF hello packets between the two peers
  • c.It never requires any form of authentication
  • d.With a token or API key supplied in the request header✓

REST APIs typically authenticate clients using a token or API key (often a bearer token in the HTTP Authorization header), sometimes obtained via a prior login call. This proves identity on each stateless request without a persistent session.

Automation & Programmability

In JSON, what does a pair of square brackets [ ] denote?

  • a.A key that maps directly to one boolean value
  • b.A comment block ignored by parsers
  • c.A single string value
  • d.An array, an ordered list of values✓

Square brackets define a JSON array, an ordered list that can hold strings, numbers, objects, or other arrays. Curly braces define objects (key-value collections). Recognizing this structure is essential when parsing API responses.

Automation & Programmability

Which of the following correctly lists valid JSON value types?

  • a.Only string values are permitted
  • b.Tags and attributes wrapped in angle brackets as in XML
  • c.String, number, boolean, null, object, array✓
  • d.Only integers and floating-point numbers

JSON values may be a string, number, boolean (true/false), null, object, or array, and objects and arrays can nest. This small, well-defined type set is what makes JSON simple to parse across programming languages.

Automation & Programmability

How does JSON generally compare with XML as a data-interchange format?

  • a.JSON is unable to represent nested or hierarchical data
  • b.JSON is more lightweight and less verbose than XML✓
  • c.XML is always smaller and simpler than the equivalent JSON document
  • d.JSON and XML are byte-for-byte identical in structure

JSON's minimal syntax (braces, brackets, and key-value pairs) makes it more compact and easier to read than XML's opening and closing tags. Both can represent nested data, but JSON is now the more common choice for REST APIs.

Automation & Programmability

What is the basic syntax style of YAML?

  • a.Indentation with key: value pairs and dashes for lists✓
  • b.A compact binary encoding that humans cannot read
  • c.Curly braces and commas only, exactly like JSON
  • d.Angle-bracket opening and closing tags

YAML uses indentation to show structure, with 'key: value' pairs and leading dashes for list items, making it very human-readable. This readability is a major reason Ansible playbooks are written in YAML.

Automation & Programmability

How does XML structure its data?

  • a.Using opening and closing angle-bracket tags around each element✓
  • b.Using indentation levels only, with no delimiters around values
  • c.Using square brackets to wrap each element
  • d.Using key: value pairs separated by colons

XML wraps each piece of data in matching opening and closing tags (for example <name>R1</name>) and supports attributes within tags. This verbose, hierarchical markup is used by NETCONF, though JSON and YAML are often preferred for readability.

Automation & Programmability

Which statement best describes Puppet as a configuration management tool?

  • a.It is a dynamic routing protocol for enterprise cores
  • b.It is agent-based, uses a pull model, and defines state in manifests✓
  • c.It is agentless and pushes over SSH, like Ansible
  • d.It is a REST verb used to update device configuration files

Puppet traditionally uses an agent installed on each managed node that periodically pulls its desired state (written in Puppet's declarative language) from a master. This contrasts with Ansible's agentless push model over SSH.

Automation & Programmability

Which statement best describes the Chef configuration management tool?

  • a.It uses Ruby-based recipes and cookbooks with an agent-based model✓
  • b.It is a wireless controller feature for onboarding access points
  • c.It uses YAML playbooks pushed over SSH with no agent
  • d.It is a Layer 2 switching protocol

Chef organizes configuration into recipes and cookbooks written in a Ruby-based DSL, applied by an agent (chef-client) that pulls policy from a Chef server. Like Puppet, it is agent-based, whereas Ansible is agentless.

Automation & Programmability

How does Ansible's delivery model differ from Puppet's and Chef's?

  • a.All three require a compiled agent installed on every device
  • b.Ansible pushes configuration, while Puppet and Chef typically pull✓
  • c.All three are strictly pull-based with mandatory agents
  • d.Ansible needs a compiled binary agent installed on every device

Ansible is agentless and pushes configuration to devices over SSH, whereas Puppet and Chef usually rely on an installed agent that pulls policy from a central server. Ansible's push, agentless approach simplifies network device automation.

Automation & Programmability

What does idempotency mean in configuration automation?

  • a.It requires a device reboot after every single task
  • b.It automatically encrypts the playbook before running
  • c.Re-running the same task yields the same end state with no extra changes✓
  • d.Each run doubles the configuration already present

An idempotent operation produces the same result no matter how many times it runs, so applying an already-correct configuration causes no additional change. This safety property lets automation tools re-run reliably without unintended side effects.

Automation & Programmability

What is a CI/CD pipeline in the context of network automation?

  • a.An automated pipeline that tests and deploys configuration changes✓
  • b.A variant of Network Address Translation
  • c.A method of manually copying configs device by device at night
  • d.A spanning-tree redundancy feature

CI/CD (continuous integration/continuous delivery) automates testing and deployment so configuration changes are validated and pushed consistently. Applied to networks, it reduces manual error and speeds safe rollout of changes across many devices.

Automation & Programmability

What is configuration drift?

  • a.A routing loop caused by a missing default route
  • b.Cabling that slowly comes loose from the patch panel over time
  • c.Signal attenuation over a long fiber run between buildings
  • d.Devices diverging from their intended configuration baseline✓

Configuration drift is the gradual divergence of a device's running configuration from its documented, intended baseline, often from ad-hoc manual changes. Automation and infrastructure-as-code detect and correct drift to keep devices consistent.

Automation & Programmability

What is infrastructure as code (IaC)?

  • a.A special wireless AP operating mode
  • b.Running each configuration command by hand on every device nightly
  • c.Defining and version-controlling infrastructure configuration in code files✓
  • d.A cabling standard for structured wiring closets

IaC manages network and system configuration through machine-readable definition files kept under version control, so infrastructure is provisioned consistently and repeatably. This brings software practices like review, testing, and rollback to network changes.

Automation & Programmability

How do NETCONF and RESTCONF differ in transport and encoding?

  • a.NETCONF is a spanning-tree extension for faster convergence
  • b.Both use Telnet exclusively for transport
  • c.Both are wireless roaming protocols
  • d.NETCONF uses XML over SSH; RESTCONF uses HTTP with JSON or XML✓

NETCONF exchanges XML-encoded data over an SSH session, while RESTCONF uses REST-style HTTP methods with JSON or XML payloads. Both let tools programmatically configure devices using structured data models such as YANG.

Automation & Programmability

What is YANG in the context of network automation?

  • a.A data-modeling language describing device configuration and state✓
  • b.A routing metric used by link-state protocols
  • c.A shielded twisted-pair cable rated for 10-gigabit Ethernet
  • d.A symmetric encryption cipher for management traffic

YANG is a data-modeling language that defines the structure of configuration and operational data used by NETCONF and RESTCONF. Standardized models let automation tools interact with devices in a consistent, vendor-neutral way.

Automation & Programmability

What is OpenFlow in a software-defined networking architecture?

  • a.A southbound protocol that programs the forwarding tables of network devices✓
  • b.A structured cabling specification for data centers
  • c.A northbound application programming interface used by orchestration tools
  • d.A wireless client roaming standard for large campuses

OpenFlow is a southbound protocol that lets an SDN controller directly program the flow (forwarding) tables in switches. Southbound interfaces face the devices, while northbound interfaces face the applications requesting network services.

Automation & Programmability

What is an overlay network?

  • a.A virtual network tunneled on top of the physical underlay✓
  • b.A single VLAN spanning one access switch
  • c.The out-of-band management console port on a router
  • d.The physical cabling and switches that carry the underlying transport

An overlay is a virtual network (often using tunnels such as VXLAN) built logically on top of the physical underlay that provides basic IP connectivity. Overlays enable flexible segmentation and mobility independent of the underlying topology.

Automation & Programmability

What is intent-based networking?

  • a.A physical Layer 1 cabling standard
  • b.A backup power supply system for core switches
  • c.The administrator declares the desired outcome and the controller implements it✓
  • d.Manually typing the same CLI commands on each device one at a time

Intent-based networking lets administrators express what they want (business intent), and the controller translates that into device configuration, then continuously verifies it. It shifts effort from box-by-box CLI to declarative, automated policy.

Automation & Programmability

What is a key benefit of software-defined networking (SDN)?

  • a.It eliminates the need for IP addressing entirely
  • b.It removes all need for network security controls
  • c.Centralized automation enabling faster, more consistent changes✓
  • d.Every device must still be touched by hand for each change

SDN centralizes control so policy is defined once and pushed programmatically, improving speed, consistency, and agility while reducing manual errors. Security remains essential and devices still forward traffic; only the control decisions are centralized.

Automation & Programmability

What is a major drawback of traditional per-device CLI management?

  • a.It requires no engineers to operate or maintain
  • b.It scales instantly to thousands of devices without effort
  • c.It is slow and error-prone because each device is configured by hand✓
  • d.It is fully automated and applies every change across all devices at once

Configuring devices one at a time via CLI is time-consuming and prone to inconsistent, human-introduced errors, especially at scale. Automation and controller-based approaches address this by applying consistent configuration programmatically.

Automation & Programmability

What advantage do structured data models provide for network configuration?

  • a.They make configuration structured and machine-readable for automation✓
  • b.They are readable only by humans, never by machines
  • c.They physically replace the need for network cabling
  • d.They are a type of spanning-tree BPDU exchanged between switches

Data models such as those written in YANG give configuration a consistent, machine-readable structure, so tools can reliably generate, validate, and apply it. This structure is the foundation that lets APIs automate devices predictably.

Showing 40 of 58

Report