300-635 Sample Questions & Answers
Three areas tie for the heaviest weight: programming the ACI REST API, model-driven telemetry alongside Day 0 provisioning, and Intersight-based automation across UCS and NDFC APIs, with Git fundamentals and general API styles filling out the rest.
Launch the full 300-635 simulator →Free 300-635 Sample Questions with Answers
Real questions from the Automating Cisco Data Center Networking Solutions (DCNAUTO) practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Intermediate
Network Programmability Foundation · Describe the challenges encountered and patterns used when consuming APIs synchronously and asynchronously
A developer is writing a Python script to interact with a REST API. The API can sometimes take several seconds to respond, and the script must perform other tasks while waiting for the API response to avoid blocking. Which Python library and approach should be used to achieve this non-blocking, asynchronous behavior?
Show answer & explanation
Correct answer: B
The
asynciolibrary is Python's standard framework for writing single-threaded concurrent code using coroutines. Paired with theaiohttplibrary, which provides an asynchronous HTTP client, it allows the script to make an API call,awaitthe response without blocking, and yield control to the event loop to perform other tasks. This is the ideal pattern for non-blocking I/O operations. - Question 2Beginner
Data Center Device-centric Networking · Implement On-Box Programmability and Automation with NX-OS
An administrator is attempting to run a Python script inside the NX-OS guest shell on a Nexus 9000 switch. The script fails because it depends on an external library that is not installed. What is the correct command to install the required library within the guest shell environment?
Show answer & explanation
Correct answer: B
The NX-OS guest shell is a Linux environment where Python packages are managed using
pip. To install packages system-wide within the shell, you need root privileges, which are obtained usingsudo. Therefore,sudo pip installis the correct command. - Question 3Intermediate
Controller Based Data Center Networking · Construct a Terraform plan to use an ACI
A financial services company is using Terraform to manage its Cisco ACI fabric. The security team mandates that all infrastructure changes must be reviewed and approved before being applied. The DevOps team uses a Git-based workflow. How can the team ensure that proposed ACI configuration changes are reviewed before they are implemented?
flowchart TD A[Developer creates TF plan] --> B{Push to Git Repo}; B --> C[CI Server runs 'terraform plan']; C --> D{Review & Approve Plan Output}; D -- Approved --> E[CI Server runs 'terraform apply']; D -- Rejected --> F[Developer revises code]; F --> A; E --> G([End]);Show answer & explanation
Correct answer: B
This is the standard GitOps workflow for Terraform. When a developer submits a pull request, the CI/CD pipeline automatically runs
terraform plan. The output of the plan, showing the exact changes to be made, is posted to the pull request for review. The changes are only applied (terraform apply) after the pull request is approved and merged, satisfying the security requirement for review and approval. - Question 4Beginner
Network Programmability Foundation · Describe the benefits of Python virtual environments
A developer needs to ensure their Python automation project and its specific library dependencies can be reliably replicated on a different machine. The project uses the
requestslibrary version2.25.1andnetmikoversion3.4.0. What is the best practice for managing and documenting these dependencies?Show answer & explanation
Correct answer: B
This is the standard best practice. A virtual environment isolates the project's dependencies from the system and other projects. The
pip freeze > requirements.txtcommand creates a file listing the exact packages and versions, which can then be used on another machine withpip install -r requirements.txtto perfectly replicate the environment. - Question 5IntermediateSelect 2
Data Center Compute · Describe the capabilities of the Nexus Dashboard Fabric Controller API
Which two authentication mechanisms are commonly required when making programmatic calls to the Nexus Dashboard Fabric Controller (NDFC) REST API? (Choose two.)
Show answer & explanation
Correct answers: B, C
The standard workflow for NDFC API authentication involves sending a POST request with user credentials to a login endpoint. The response contains a session token (e.g.,
Dcnm-Token) that must be included in the headers of all subsequent API calls.The initial login request to obtain the session token requires the user's username and password to be sent in the body of the POST request. This is the first step of the authentication process.
- Question 6Intermediate
Data Center Device-centric Networking · Implement Off-Box Programmability and Automation with NX-OS
An engineer needs to automate the configuration of BGP on a fleet of Nexus switches using NETCONF. They want to use a standardized, vendor-neutral data model to ensure their automation script is portable. Which YANG model should they use?
Show answer & explanation
Correct answer: B
OpenConfig is a collaborative effort by network operators to create vendor-neutral YANG data models for network configuration and management. Using the OpenConfig BGP model allows the engineer to write automation scripts that can, in principle, configure BGP on devices from any vendor that supports the model, thus meeting the portability requirement.
- Question 7Beginner
Controller Based Data Center Networking · Leverage the API inspector to explore the REST API calls made by the ACI GUI
What is the primary function of the API Inspector in the Cisco APIC GUI?
Show answer & explanation
Correct answer: B
The API Inspector's main purpose is to serve as a learning and development tool. It records actions taken in the graphical user interface and displays the corresponding REST API calls (including the URL, method, and JSON payload) that the GUI made to the APIC. This allows developers to easily learn how to perform tasks programmatically.
- Question 8Advanced
Controller Based Data Center Networking · Construct an Ansible playbook to create an application policy
Case Study: A large e-commerce company, 'ShopFast', is automating its data center infrastructure hosted on a Cisco ACI fabric and UCS servers. Their goal is to achieve a full GitOps workflow for both network and compute provisioning.
Current Environment & Team: The infrastructure team is highly skilled in Python and Ansible. All infrastructure definitions are intended to be stored in a central Git repository. A Jenkins CI/CD pipeline is used to orchestrate deployments. The ACI fabric spans two data centers, and UCS is managed by UCS Manager in a multi-domain setup.
Requirements:
- Network Policy: ACI Tenants, VRFs, Bridge Domains, and EPGs must be defined in a declarative format in Git.
- Compute Policy: UCS Service Profile Templates, vNIC/vHBA templates, and server pool policies must also be defined declaratively in Git.
- Automation Engine: The CI/CD pipeline must trigger a tool that can interact with both APIC and UCS Manager idempotently.
- Auditability: All changes applied to the infrastructure must be traceable back to a specific commit in Git.
Problem: The team needs to choose the primary automation tool to be executed by their Jenkins pipeline to manage both ACI and UCS. The chosen tool must align with their declarative, idempotent, and Git-centric philosophy.
Which automation strategy best fulfills all of ShopFast's requirements?
Show answer & explanation
Correct answer: C
This is the optimal solution. Ansible is declarative, idempotent, and uses YAML, which fits perfectly with GitOps. The
cisco.aciandcisco.ucscollections provide comprehensive modules for managing both ACI and UCS Manager. This approach leverages the team's existing Ansible skills and meets all the requirements for declarative definitions, idempotency, and a unified toolchain for network and compute. - Question 9Advanced
Data Center Device-centric Networking · Implement Off-Box Programmability and Automation with NX-OS
An engineer has written an Ansible playbook to configure a new VLAN on a Nexus switch. The playbook fails with an authentication error. The playbook uses
ansible_userandansible_passwordfor credentials. The engineer has confirmed the credentials are correct and work via SSH. The switch is configured for RADIUS authentication. What is the most likely reason for the playbook's failure?Show answer & explanation
Correct answer: D
When using external AAA servers like RADIUS with NX-OS, programmatic access (like that used by Ansible) often requires the user to be assigned a specific role with sufficient privileges (e.g.,
network-admin). Even if the credentials are correct for interactive SSH login, if the RADIUS server does not return the correct role authorization attributes for a non-interactive session, the login will be rejected, resulting in an authentication failure from Ansible's perspective. - Question 10Intermediate
Data Center Compute · Identify the steps in the Cisco Intersight API authentication method
The signature for a Cisco Intersight API request is generated by creating a string that includes the HTTP method, host, date, request target, and a digest of the request body. This entire string is then signed using a private key. What hashing algorithm is used to create the digest and the final signature?
sequenceDiagram participant Client participant Intersight API Client->>Client: Create Digest from request body (SHA-256) Client->>Client: Construct Signature String Client->>Client: Sign the string with Private Key (RSA-SHA256) Client->>Intersight API: Send Request with Signature Header Intersight API->>Intersight API: Re-create signature string Intersight API->>Intersight API: Verify signature with Public Key alt Signature Valid Intersight API-->>Client: 200 OK else Signature Invalid Intersight API-->>Client: 401 Unauthorized endShow answer & explanation
Correct answer: B
The Cisco Intersight API authentication method uses the HTTP Signature scheme. It requires creating a SHA-256 hash of the request body to generate a digest. The final signature string is then signed using the RSA-SHA256 algorithm with the user's private key. This ensures both the integrity of the request body and the authenticity of the caller.
Ready for the real thing?
The full 300-635 simulator has every exam-style question, timed mode, and instant scoring.