1. A network administrator is troubleshooting an automation script that interacts with a network device's REST API. The script consistently receives an HTTP status code 403. What does this code most likely indicate?
Automation and Programmability
A.The request was successful, and the server is returning the requested data.
B.The requested resource could not be found on the server.
C.The server understands the request but refuses to authorize it.
D.The server encountered an unexpected condition that prevented it from fulfilling the request.
Show answerAnswer
C. The server understands the request but refuses to authorize it.
An HTTP 403 Forbidden status code means the server understood the request but refuses to fulfill it due to insufficient permissions or authorization. This is distinct from a 401 Unauthorized, which typically means authentication failed.
2. A network engineer is using a script to configure VLANs on multiple switches through a network controller's REST API. The script sends JSON payloads containing the desired VLAN configurations. Which data format is commonly used for representing structured data when interacting with REST APIs?
Automation and Programmability
A.HTML
B.YAML
C.XML
D.JSON
Show answerAnswer
D. JSON
JSON (JavaScript Object Notation) is the most widely adopted data format for representing structured data in modern web APIs, including RESTful APIs, due to its lightweight nature and ease of parsing by both humans and machines.
3. A company implements a new security policy requiring all employees to use multi-factor authentication (MFA) for accessing internal systems. Which security concept is primarily strengthened by this policy?
Security Fundamentals
A.Authentication
B.Confidentiality
C.Integrity
D.Availability
Show answerAnswer
A. Authentication
Multi-factor authentication (MFA) requires users to provide two or more verification factors to gain access, directly strengthening the authentication process and making it harder for unauthorized users to log in even if they have a password.
4. A small business wants to protect its internal network from unauthorized access while allowing employees to securely access company resources when working remotely. Which network security technology is primarily designed to create a secure, encrypted connection over a public network?
Security Fundamentals
A.Intrusion Detection System (IDS)
B.Virtual Private Network (VPN)
C.Demilitarized Zone (DMZ)
D.Firewall
Show answerAnswer
B. Virtual Private Network (VPN)
A Virtual Private Network (VPN) creates a secure, encrypted tunnel over an unsecure network like the internet, allowing remote users to access internal resources as if they were physically present on the local network.
5. A network operations team is implementing an automation script to regularly check the status of network device interfaces. The script needs to fetch current operational data from a device's API without making any changes. Which API interaction type is being performed?
Automation and Programmability
A.Idempotent
B.Declarative
C.Imperative
D.Query
Show answerAnswer
D. Query
Fetching current operational data from an API without making changes is a 'query' operation. This falls under the general category of retrieving information, which is a common function of APIs.
6. A network automation engineer is deploying a new service that provides network telemetry data to an analytics platform. This service needs to expose an API that allows the analytics platform to subscribe to real-time events and receive data pushes whenever a significant network event occurs (e.g., interface status change, high utilization). Which type of API interaction model is best suited for this real-time, event-driven data pushing?
Automation and Programmability
A.RESTful API (Request/Response)
B.Batch Processing API
C.Polling API
D.Webhook/Callback API
Show answerAnswer
D. Webhook/Callback API
A Webhook/Callback API is ideal for real-time event-driven data pushing. Instead of the client constantly polling, the server (network device/service) proactively sends an HTTP POST request to a pre-registered URL (the webhook) on the client whenever a specified event occurs.
7. A network administrator is designing a new campus network and wants to implement a solution that centralizes network configuration and management, allowing for programmatic control and automation. The administrator specifically wants to decouple the control plane from the data plane. Which networking concept best fits these requirements?
Automation and Programmability
A.Virtual Local Area Network (VLAN)
B.Quality of Service (QoS)
C.Software-Defined Networking (SDN)
D.Network Address Translation (NAT)
Show answerAnswer
C. Software-Defined Networking (SDN)
Software-Defined Networking (SDN) is an architectural approach that decouples the network control and forwarding functions, enabling network programmability and abstracting underlying infrastructure from applications and network services. This allows for centralized management and automation.
8. A cybersecurity team is investigating a potential data breach where an attacker gained unauthorized access to sensitive customer records. The team discovers that the attacker exploited a vulnerability in the web application's input validation, allowing them to execute malicious commands on the database server. Which type of attack was most likely used?
Security Fundamentals
A.Distributed Denial of Service (DDoS)
B.SQL Injection
C.Phishing
D.Cross-Site Scripting (XSS)
Show answerAnswer
B. SQL Injection
The scenario describes an attacker exploiting 'input validation' vulnerability to 'execute malicious commands on the database server' to access 'sensitive customer records'. This is a classic description of an SQL injection attack, where malicious SQL code is inserted into input fields to manipulate database queries.
9. A network engineer needs to retrieve the current running configuration from a Cisco switch using a RESTful API. Which HTTP method is most appropriate for this read-only operation?
Automation and Programmability
A.PUT
B.POST
C.GET
D.DELETE
Show answerAnswer
C. GET
The GET method is specifically designed for retrieving data from a specified resource without altering it. This makes it ideal for read-only operations like fetching a configuration.
10. A network security engineer is tasked with automating the process of blocking malicious IP addresses on perimeter firewalls. The automation involves a script that receives a list of suspicious IPs and sends an API call to each firewall's controller to add these IPs to a blocklist. The engineer wants to ensure that if the script is run multiple times with the same list of IPs, it does not create duplicate entries or cause unintended side effects beyond ensuring the IPs are blocked. Which API property is the engineer seeking?
Automation and Programmability
A.Idempotent
B.Atomic
C.Stateless
D.Asynchronous
Show answerAnswer
A. Idempotent
An 'idempotent' API operation is one that produces the same result whether it is executed once or multiple times with the same input. In this scenario, running the script multiple times to block the same IPs should ensure they are blocked without creating duplicates or errors if they are already blocked, which is the definition of idempotency.
11. A network administrator is implementing a security measure to prevent unauthorized devices from connecting to the wired network by ensuring that only devices with specific, pre-approved hardware addresses are allowed. Which network security technology is being utilized?
Security Fundamentals
A.Access Control List (ACL)
B.Port security
C.802.1X authentication
D.MAC address filtering
Show answerAnswer
D. MAC address filtering
MAC address filtering (or MAC whitelisting) is the specific technology that allows or denies network access based on the unique MAC (Media Access Control) address of a network interface card. This directly addresses the requirement of allowing 'only devices with specific, pre-approved hardware addresses'. Port security can incorporate MAC address filtering, but MAC filtering itself is the core mechanism described.
12. A network automation engineer is writing a Python script to interact with a network device's API. The device's API documentation specifies that all API calls require an API key to be included in the 'Authorization' header of every HTTP request. Which API concept does this requirement fall under?
Automation and Programmability
A.Authentication
B.Rate Limiting
C.Version Control
D.Error Handling
Show answerAnswer
A. Authentication
Requiring an API key in the 'Authorization' header is a fundamental mechanism for 'authentication'. Authentication verifies the identity of the client making the API request, ensuring that only authorized entities can access the API's resources.
13. A network operations team is implementing a new network automation solution. They want to use a standard data format for exchanging configuration and operational data between different network devices and automation scripts. Which of the following formats is widely adopted and human-readable for this purpose?
Automation and Programmability
A.Encrypted ZIP Archive
B.Binary Large Object (BLOB)
C.Extensible Markup Language (XML)
D.Proprietary Binary Format
Show answerAnswer
C. Extensible Markup Language (XML)
XML is a widely adopted, human-readable, and machine-parsable data format commonly used for data exchange in network automation, especially with older or enterprise-grade network devices and APIs.
14. A security analyst is reviewing logs and identifies multiple failed login attempts from a single IP address targeting various user accounts on the company's external web server. The attempts are spaced out over several hours. Which common security threat does this activity most closely represent?
Security Fundamentals
A.Cross-Site Scripting (XSS)
B.Brute-force attack
C.Man-in-the-Middle (MitM) attack
D.Distributed Denial of Service (DDoS) attack
Show answerAnswer
B. Brute-force attack
Multiple failed login attempts from a single source targeting various user accounts is characteristic of a brute-force attack, where an attacker systematically tries different password combinations until a correct one is found. The spacing over hours suggests an attempt to evade rapid detection.
15. A network architect is designing a new solution that uses a centralized controller to manage both wired and wireless network infrastructure across multiple sites. The goal is to simplify policy enforcement, automate provisioning, and provide a single point of management. Which type of SDN solution is best suited for this comprehensive, enterprise-wide approach?
Automation and Programmability
A.OpenFlow-based SDN
B.Controller-based Overlay SDN
C.Intent-Based Networking (IBN)
D.SD-WAN (Software-Defined Wide Area Network)
Show answerAnswer
C. Intent-Based Networking (IBN)
Intent-Based Networking (IBN) represents an advanced evolution of SDN, focusing on translating business intent into network policies and automatically configuring the network to achieve that intent, constantly verifying compliance. It's ideal for a comprehensive, enterprise-wide approach to policy enforcement and automation across various infrastructure types.
16. A network engineer is designing a network segment for public-facing web servers that need to be accessible from the internet but must be isolated from the internal corporate network to limit potential damage from external attacks. Which network security technology best provides this isolation?
Security Fundamentals
A.Network Address Translation (NAT)
B.Demilitarized Zone (DMZ)
C.Virtual Local Area Network (VLAN)
D.Intrusion Detection System (IDS)
Show answerAnswer
B. Demilitarized Zone (DMZ)
A Demilitarized Zone (DMZ) is a separate network segment that provides an additional layer of security between a company's internal network and an untrusted network (like the internet). It's specifically designed to host public-facing services while isolating them from the private network.
17. An IT manager wants to ensure that all data transmitted from the company's web server to client browsers is encrypted to protect sensitive customer information. Which security protocol, commonly used with HTTP, achieves this goal?
Security Fundamentals
A.SMTP
B.DNS
C.TLS
D.FTP
Show answerAnswer
C. TLS
Transport Layer Security (TLS), often seen as HTTPS (HTTP Secure), encrypts communication between a web server and a client browser, ensuring the confidentiality and integrity of data transmitted over the internet. SSL is its predecessor.
18. A network engineer is writing a Python script to gather operational data from a large number of network devices. The script needs to parse the received data, which is structured in a human-readable format with key-value pairs, nested objects, and arrays. Which Python module is most suitable for handling this data format?
Automation and Programmability
A.re
B.json
C.xml.etree.ElementTree
D.csv
Show answerAnswer
B. json
The 'json' module in Python is specifically designed to work with JSON (JavaScript Object Notation) data, which matches the description of human-readable data with key-value pairs, nested objects, and arrays commonly used in network APIs.
19. A network administrator is troubleshooting an issue where a new automation script fails to connect to a network device's API. The script is attempting to establish a secure connection using HTTPS, but it consistently receives an SSL/TLS certificate error. Which of the following is the MOST likely cause of this error?
Automation and Programmability
A.The network firewall is blocking TCP port 80.
B.The script is sending an incorrect JSON payload format.
C.The API endpoint uses an unsupported HTTP method.
D.The device's clock is significantly out of sync, causing certificate validation issues.
Show answerAnswer
D. The device's clock is significantly out of sync, causing certificate validation issues.
SSL/TLS certificate errors, especially 'certificate not yet valid' or 'certificate expired', are frequently caused by a significant time drift on either the client or server device. Certificates have validity periods, and if the device's clock is outside this period, validation will fail. Other options are less likely to cause a specific SSL/TLS certificate error.
20. A network administrator is designing an automation workflow where a script needs to determine if a network device is reachable before attempting to configure it via an API. Which command-line utility is commonly used to test the reachability of a host on an IP network?
Automation and Programmability
A.ipconfig
B.ping
C.netstat
D.traceroute
Show answerAnswer
B. ping
The 'ping' utility sends ICMP echo request packets to a target host and listens for echo replies, making it the most common and straightforward tool to test network reachability.
21. A network security team observes an unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously. This traffic is overwhelming the server's resources, making it unresponsive to legitimate requests. Which type of attack is most likely occurring?
Security Fundamentals
A.Port scanning
B.Zero-day exploit
C.Distributed Denial of Service (DDoS) attack
D.Man-in-the-Middle (MitM) attack
Show answerAnswer
C. Distributed Denial of Service (DDoS) attack
An 'unusually high volume of traffic flooding a specific server from numerous disparate IP addresses simultaneously', resulting in the server being 'unresponsive to legitimate requests', is the textbook definition of a Distributed Denial of Service (DDoS) attack.
22. A network administrator notices unusual outbound traffic patterns originating from several internal workstations, including connections to unknown IP addresses on high-numbered ports. The traffic volume is low but persistent. Users report no issues with their applications. Which of the following best describes the most likely type of security threat occurring?
Security Fundamentals
A.Malware infection (e.g., botnet activity)
B.SQL injection
C.Denial of Service (DoS) attack
D.Phishing attempt
Show answerAnswer
A. Malware infection (e.g., botnet activity)
Unusual outbound traffic to unknown IP addresses on high-numbered ports, especially when users report no issues, is a classic indicator of malware, often part of a botnet. The infected machines are likely communicating with a command-and-control server.
23. A network administrator is evaluating different network automation tools. One tool advertises its ability to manage network configurations by simply defining the desired state of the network (e.g., 'interface GigabitEthernet0/1 should be up with IP address 192.168.1.1/24'). The tool then automatically figures out and executes the necessary commands to achieve and maintain that state. Which network automation approach does this tool primarily utilize?
Automation and Programmability
A.Event-driven automation
B.Imperative automation
C.Scripted automation
D.Declarative automation
Show answerAnswer
D. Declarative automation
Declarative automation focuses on defining the desired end state of the network. The automation engine then determines the steps needed to reach that state and continuously works to maintain it. This contrasts with imperative automation, which specifies the exact sequence of commands to execute.
24. A developer accidentally hardcodes sensitive credentials directly into the source code of a public-facing application. Which fundamental security concept is most directly violated by this action?
Security Fundamentals
A.Integrity
B.Availability
C.Confidentiality
D.Non-repudiation
Show answerAnswer
C. Confidentiality
Hardcoding sensitive credentials into public-facing code directly exposes them to anyone who can view the code, violating the principle of Confidentiality by allowing unauthorized disclosure of information. If these credentials are then used, it can lead to further breaches.
25. A network architect is designing a new solution where applications need to interact directly with network devices to provision services and retrieve operational state. The solution requires a standardized, programmatic interface that is independent of vendor-specific CLI commands. Which protocol is specifically designed for managing network devices with structured data models and supports both XML and JSON encoding?
Automation and Programmability
A.SNMP (Simple Network Management Protocol)
B.SSH (Secure Shell)
C.Telnet
D.NETCONF (Network Configuration Protocol)
Show answerAnswer
D. NETCONF (Network Configuration Protocol)
NETCONF is a network management protocol specifically designed to provide mechanisms for installing, manipulating, and deleting configuration data on network devices. It uses XML for data encoding (and often JSON with RESTCONF) and is built around structured data models (YANG), making it vendor-agnostic and programmatic.
The HTTP 403 Forbidden status code indicates that the server understood the request but refuses to authorize it. This often means the client does not have the necessary permissions to access the resource.
Server understood the request.
Access is denied due to authorization issues.
Different from 401 Unauthorized (authentication failure).
A lightweight data-interchange format that is easy for humans to read and write and easy for machines to parse and generate. It is widely used for transmitting data in web applications.
A technology that creates a secure, encrypted connection (a 'tunnel') over a less secure network, such as the internet, to provide remote access to private network resources.
A Webhook (also known as a web callback or HTTP push API) is a method of augmenting or altering the behavior of a web page or web application with custom callbacks. These callbacks are triggered by specific events and send data to a URI specified by the client, enabling real-time, event-driven communication.
Server-initiated communication.
Real-time event notification.
Client registers a URL (endpoint) to receive data.
An architecture that decouples the network control and forwarding functions, enabling network programmability and abstracting underlying infrastructure from applications and network services.
A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It allows an attacker to view, modify, or delete data, or even execute administrative operations on the database server.
An API operation that, when executed multiple times with the same input, produces the same result as if it had been executed only once, without causing unintended side effects.
Safe to repeat multiple times
Prevents unintended side effects (e.g., duplicates)
The process by which an API verifies the identity of a client (user or application) attempting to access its resources, often using API keys, tokens, or credentials.
Verifies client identity
Ensures only authorized access
Commonly uses API keys, OAuth tokens, or basic auth
XML is a markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable. It is widely used for data exchange, especially in older web services and network APIs.
Uses tags to define elements and attributes.
Platform-independent and extensible.
Often used in SOAP-based web services and NetConf.
An advanced networking approach that captures business intent and translates it into network policies, automatically configuring and continuously verifying the network to achieve and maintain that desired state.
Focuses on business intent, not low-level configurations
A physical or logical subnetwork that contains and exposes an organization's external-facing services to a larger and untrusted network, usually the internet, while isolating the internal local-area network (LAN).
A cryptographic protocol designed to provide communication security over a computer network. It is the successor to SSL and is widely used for securing web browsing (HTTPS), email, instant messaging, and other data transfers.
The Python 'json' module provides an API to encode and decode JSON objects. It allows Python data structures (like dictionaries and lists) to be converted to JSON strings and vice-versa, facilitating data exchange with web services and APIs.
Used to serialize Python objects to JSON strings (json.dumps()).
Used to deserialize JSON strings to Python objects (json.loads()).
Handles nested structures like dictionaries and lists.
Issues arising during the process of verifying the authenticity and validity of an SSL/TLS certificate, often preventing a secure connection from being established.
Can be caused by expired/invalid certificates
Mismatched hostnames are a common cause
Incorrect system time can lead to validation failures
Ping is a network utility used to test the reachability of a host on an Internet Protocol (IP) network. It measures the round-trip time for messages sent from the originating host to a destination computer and reports errors.
Uses ICMP (Internet Control Message Protocol) echo request/reply messages.
Determines if a host is alive and reachable.
Measures latency (round-trip time) and packet loss.
A malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
Uses multiple sources (botnet)
Aims to exhaust resources (bandwidth, CPU, memory)
An automation approach where the desired end state of a system or network is defined, and the automation engine is responsible for executing the necessary actions to achieve and maintain that state.
Focuses on 'what' the state should be, not 'how' to get there
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.