DevNet Associate (DEVASC) v1.0 practice questions

200 free questions with answers and explanations.

Practice test
  1. 101.A network administrator is configuring a real-time monitoring system. This system needs to be notified immediately whenever a critical event (e.g., interface status change, high CPU utilization) occurs on a Cisco router. The existing API on the router supports a mechanism where the router can proactively send HTTP POST requests to a pre-configured URL whenever such an event happens. What is this mechanism called?Understanding and Using APIs
  2. 102.A network operations team is developing an automation script to provision VLANs on multiple Cisco switches using a REST API. The script needs to create a new VLAN by sending a POST request to a `/vlan` endpoint with a JSON payload containing the VLAN ID and name. Which `Content-Type` header value should be included in the HTTP request to correctly inform the API about the payload format?Understanding and Using APIs
  3. 103.A developer is performing API testing using Postman. They have successfully created a collection of requests to a Cisco API and want to automate the execution of these requests in a specific order, including handling environment variables and testing assertions for each response. Which Postman feature is designed for this exact purpose?Understanding and Using APIs
  4. 104.A developer is documenting a new internal REST API using OpenAPI Specification (OAS). The API has an endpoint `/api/v1/devices/{deviceId}` that supports a `GET` operation to retrieve device details and a `PUT` operation to update device details. Which OpenAPI component would be used to define the structure of the `deviceId` in the URL path for both operations?Understanding and Using APIs
  5. 105.A developer is performing API testing and needs to send a series of HTTP requests to a REST API. Each request requires a different set of query parameters and occasionally a different request body, but the base URL and authentication headers remain constant. Which cURL command line feature is best suited for reusing common request parts while varying others?Understanding and Using APIs
  6. 106.A network automation developer is using Postman to test a new REST API endpoint on a Cisco router. The API documentation specifies that the endpoint `/restconf/data/interfaces/interface=GigabitEthernet1` expects a `PUT` request with a JSON payload to modify the interface configuration. The developer constructs the request in Postman, but the router consistently returns a `400 Bad Request` error, even though the JSON payload appears correct. Which of the following is the MOST likely cause of the `400 Bad Request` error in this scenario?Understanding and Using APIs
  7. 107.A developer is designing an application that needs to receive real-time notifications about changes to a device's configuration without continuously polling the API. Which API-related mechanism would best achieve this requirement?Understanding and Using APIs
  8. 108.A DevOps team is setting up a Kubernetes cluster and needs to implement role-based access control (RBAC) for their developers. They want to define roles that grant specific permissions within a single namespace, such as deploying pods or viewing logs, but not cluster-wide administrative privileges. Which Kubernetes RBAC object should they use to define these namespace-scoped permissions?Application Deployment and Security
  9. 109.A developer is designing a RESTful API that will be consumed by both internal and external client applications. To protect against common web vulnerabilities, they need to implement measures to prevent attackers from injecting malicious scripts into the application's user interface via input fields. Which security best practice directly addresses this concern?Application Deployment and Security
  10. 110.A development team is deploying a new microservice that requires a consistent runtime environment across development, testing, and production. They also need to ensure isolation between the application and the host operating system. Which technology is best suited for this requirement?Application Deployment and Security
  11. 111.A DevOps team is implementing a new CI/CD pipeline for a critical microservice. They need to ensure that every code change undergoes automated testing and static code analysis before being deployed to a staging environment. Which CI/CD practice directly addresses this requirement?Application Deployment and Security
  12. 112.A security team is auditing an application's data handling practices. The application processes sensitive user data, and regulations require that this data be protected against unauthorized access, even if the underlying storage infrastructure is compromised. Which security best practice specifically addresses the protection of data when it is stored on disk or in a database?Application Deployment and Security
  13. 113.A company is developing a highly sensitive financial application that will store customer account details. Due to strict regulatory compliance requirements, all data must be encrypted both when stored and when transmitted over the network. Which two cryptographic methods, when combined, would best meet these requirements?Application Deployment and Security
  14. 114.A developer is building a RESTful API that will be consumed by various client applications. To ensure that only authorized clients can access specific resources, the API needs to implement a robust authorization mechanism. After a client has been authenticated, what is the most appropriate method for the API to determine if the client has the necessary permissions to perform a requested action on a given resource?Application Deployment and Security
  15. 115.A development team is deploying a new microservice that needs to communicate securely with an existing database. The database credentials, including the username and password, must be protected both during deployment and at runtime. Which of the following is the most secure approach for storing and injecting these credentials into the microservice in a Kubernetes environment?Application Deployment and Security
  16. 116.A client application needs to interact with a secure backend API that is hosted within a Kubernetes cluster. The API requires mutual TLS (mTLS) for all incoming connections to ensure both the client and server authenticate each other. Which of the following is the correct sequence of TLS handshake steps that establishes this mutual authentication?Application Deployment and Security
  17. 117.A company is developing a highly sensitive financial application. They need to ensure that data at rest (e.g., in databases, file storage) is protected from unauthorized access, even if the underlying storage is compromised. Which security best practice is specifically designed to address this requirement?Application Deployment and Security
  18. 118.A development team is designing a new microservice architecture where services need to communicate with each other over HTTP/HTTPS. They want to implement fine-grained access control and enforce policy-based routing between services without modifying the application code. Which architectural pattern or tool is best suited for this requirement?Application Deployment and Security
  19. 119.A team is developing a microservice that runs in a Docker container and needs to access a database. During development, they frequently rebuild the container image. To optimize rebuild times and reduce the final image size, while also improving security by limiting the attack surface, which Dockerfile feature should be utilized?Application Deployment and Security
  20. 120.A developer is designing an API that will be accessed by both internal and external clients. To protect against common web vulnerabilities, they decide to implement input validation for all incoming requests. Which security best practice does this directly address?Application Deployment and Security
  21. 121.A DevOps team is implementing a CI/CD pipeline for a new microservice. They want to ensure that code changes are automatically built, tested, and deployed to a staging environment whenever a developer pushes code to the main branch. Which CI/CD concept best describes this automated process that ensures the software is always in a releasable state?Application Deployment and Security
  22. 122.A team is deploying a new service to a Kubernetes cluster. This service needs to communicate with another existing service within the same cluster. They want to ensure that all communication between these services is encrypted by default without requiring application-level changes or manual certificate management for each service. Which Kubernetes-native solution or approach best facilitates this requirement?Application Deployment and Security
  23. 123.A developer is implementing a CI/CD pipeline for a new web application. After successful code commit and unit tests, the next stage involves automatically deploying the application to a staging environment for integration testing. Which CI/CD concept does this scenario best represent?Application Deployment and Security
  24. 124.A development team is implementing a new microservice that requires access to several external APIs. Each API uses a different authentication method and requires a unique set of credentials (API keys, client secrets). To avoid hardcoding these credentials and manage them effectively across different environments (dev, staging, prod), they decide to use a centralized secrets management solution. Which of the following is the primary benefit of using such a solution over environment variables for sensitive data?Application Deployment and Security
  25. 125.An organization is migrating its legacy monolithic application to a microservices architecture using Kubernetes. The application needs to securely store sensitive database credentials and API keys. Which Kubernetes object is specifically designed for managing and providing these secrets to pods?Application Deployment and Security
  26. 126.A developer wants to automate the process of building, testing, and deploying a new web application whenever code changes are pushed to the main branch of a Git repository. The goal is to frequently integrate changes and ensure they are always ready for deployment. Which CI/CD concept best describes this end-to-end automation goal?Application Deployment and Security
  27. 127.A security team is reviewing an application's authentication mechanism. The application uses JWTs (JSON Web Tokens) for session management. Which component of a JWT is used to verify the token's integrity and ensure it hasn't been tampered with?Application Deployment and Security
  28. 128.A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. They need to ensure that all network traffic between namespaces and to external services is strictly controlled based on defined policies, such as allowing only specific ports or protocols between certain application tiers. Which Kubernetes resource should be used to implement these network segmentation and access control policies?Application Deployment and Security
  29. 129.A development team is deploying a new web application to a Kubernetes cluster. They need to ensure that all sensitive configuration data, such as database passwords and API keys, are securely managed and injected into the application containers without exposing them in the Git repository or Docker images. Which Kubernetes resource should they use for this purpose?Application Deployment and Security
  30. 130.A developer is implementing a new API endpoint that will receive user-submitted data. To prevent common web vulnerabilities, such as Cross-Site Scripting (XSS) and SQL Injection, which security best practice should be applied to all incoming data before it is processed or stored?Application Deployment and Security
  31. 131.A development team is using Git for version control and a CI/CD pipeline. They have a repository containing application code, configuration files, and sensitive API keys. To prevent accidental exposure of these API keys in the repository or during the build process, which security measure should be implemented?Application Deployment and Security
  32. 132.A developer is writing a Python application that needs to interact with a secure REST API. The API uses OAuth 2.0 for authorization and requires an access token in the 'Authorization: Bearer' header for every request. The application successfully obtains an access token, but the API still returns a 401 Unauthorized error. Which of the following is the most likely reason for this error, assuming the token itself is valid and not expired?Application Deployment and Security
  33. 133.A web application is designed to handle user authentication and authorization. After a user successfully logs in, the application needs to issue a token that proves the user's identity and their allowed permissions for subsequent requests without re-authenticating. This token should be digitally signed to prevent tampering. Which standard protocol or token type is most appropriate for this scenario?Application Deployment and Security
  34. 134.A development team is building a containerized application using Docker. They need to create a Dockerfile that ensures the application has only the necessary permissions and resources, minimizing its attack surface. Which Dockerfile instruction or best practice directly contributes to this security goal?Application Deployment and Security
  35. 135.A developer is writing a Python script to interact with a network device's configuration. The device exposes its configuration via RESTCONF. The developer needs to retrieve the current running configuration of a specific interface. Which HTTP method should the script use for this operation?Infrastructure and Automation
  36. 136.A network automation script needs to check if a specific interface on a Cisco device is currently up and receiving packets. The most efficient way to retrieve this real-time operational status programmatically, without parsing CLI output, would be to use a protocol that can query structured data directly. Which protocol, often used with YANG data models, supports this type of operational state retrieval?Infrastructure and Automation
  37. 137.A network engineer is configuring a new Cisco router to allow programmatic access for configuration management. Which protocol is specifically designed to provide a programmatic and transaction-based configuration management interface over SSH or TLS, using XML-encoded data?Infrastructure and Automation
  38. 138.A network engineer is using a Python script with the 'ncclient' library to modify the running configuration of a Cisco IOS XE device via NETCONF. To ensure that the configuration change is atomic and either fully committed or fully rolled back in case of an error, which NETCONF operation should the engineer use after sending the configuration data?Infrastructure and Automation
  39. 139.A network automation script is designed to monitor a specific interface on a Cisco device for state changes (e.g., link up/down). When a change occurs, the script needs to be immediately notified without constantly polling the device. Which NETCONF mechanism should the script subscribe to for these event-driven notifications?Infrastructure and Automation
  40. 140.A network operations team is implementing an event-driven automation system. They want to react automatically to specific network events, such as an interface going down or high CPU utilization. The system needs to capture these events as they occur and trigger predefined actions. Which mechanism is most suitable for receiving real-time, push-based notifications from network devices about these events?Infrastructure and Automation
  41. 141.A network engineer is using the 'pyang' tool to validate a custom YANG module that defines new configuration parameters for a router. After writing the YANG file, the engineer runs 'pyang -f tree my-custom-module.yang'. What is the primary purpose of using the '-f tree' option in this command?Infrastructure and Automation
  42. 142.A development team is implementing a microservices architecture where services need to communicate efficiently with low latency, especially for streaming data and remote procedure calls. They are considering an open-source framework that supports multiple programming languages and uses Protocol Buffers for message serialization. Which technology best fits these requirements?Infrastructure and Automation
  43. 143.A network administrator is evaluating different configuration management tools for automating day-to-day tasks across a heterogeneous network environment. The requirements include agentless operation, push-based configuration, and strong community support for network automation modules. Which automation tool best fits these criteria?Infrastructure and Automation
  44. 144.A network engineer is troubleshooting a flapping interface on a router. To understand the sequence of events leading to the issue, the engineer needs to collect historical syslog messages from the device and correlate them with interface status changes. Which type of data model is primarily concerned with defining the format and content of network device events and logs?Infrastructure and Automation
  45. 145.A network automation script needs to retrieve the running configuration from a Cisco device using NETCONF. The script will then parse this configuration to extract specific interface details. Which Python library is commonly used for interacting with NETCONF-enabled devices and executing operations like retrieving configuration?Infrastructure and Automation
  46. 146.A development team is implementing an Infrastructure as Code (IaC) solution for their cloud deployments. They need a tool that can define infrastructure using a declarative language, manage state, and support a wide range of cloud providers. Which tool best fits these requirements?Infrastructure and Automation
  47. 147.A network automation engineer is designing a system to collect real-time performance metrics from thousands of network devices. The solution requires a high-performance, low-latency, and bi-directional streaming mechanism. Which protocol is best suited for this requirement?Infrastructure and Automation
  48. 148.A network architect is designing an Infrastructure as Code (IaC) solution for a hybrid cloud environment. The solution needs to provision and manage resources consistently across both on-premises virtualized infrastructure (VMware) and public cloud providers (AWS, Azure). Which IaC tool is best known for its multi-cloud and on-premises orchestration capabilities using a declarative approach?Infrastructure and Automation
  49. 149.A network automation engineer is designing a solution to deploy standardized network configurations to hundreds of devices in a highly dynamic environment. The solution must support idempotent operations, allow for templating of configuration files, and offer a simple, agentless approach for execution. Which tool is most appropriate for this scenario?Infrastructure and Automation
  50. 150.A network automation engineer is designing a system to automate the provisioning of new virtual machines (VMs) and their network configurations within a private cloud environment. The solution needs to define the desired state of both the VMs and the network infrastructure in a declarative manner, allowing for version control and automated deployment. Which of the following approaches is most suitable for this requirement?Infrastructure and Automation