Cisco Certified Support Technician (CCST) NetworkingAutomation and ProgrammabilityHard

A network automation engineer is deploying a new application that will programmatically provision virtual networks and firewall rules in a cloud environment. This application requires direct access to the cloud provider's network resources. Which type of API is the engineer MOST likely interacting with?

  1. AData Plane API
  2. BSouthbound API
  3. CManagement Plane API
  4. DNorthbound API
Show answer & explanation

Correct answer: D. Northbound API

In an SDN context, 'Northbound APIs' are interfaces exposed by the SDN controller to applications and orchestration systems. These APIs allow applications to request network services, provision resources (like virtual networks and firewall rules), and abstract the underlying network complexity. The application interacts with the controller via this API.

Why the other options are wrong

  • A. Data Plane APIs are less common and typically refer to direct programmatic control over packet forwarding, which is not the primary function for provisioning virtual networks and firewall rules.
  • B. Southbound APIs are used by the SDN controller to communicate with and control the underlying network devices (switches, routers).
  • C. Management Plane APIs are for managing the controller itself (e.g., configuration, monitoring), not for applications to provision network resources directly.

Northbound API (SDN)

An interface exposed by an SDN controller to applications and orchestration systems, allowing them to request network services and provision resources without needing to understand the underlying network infrastructure.

  • Controller to application/orchestration communication
  • Abstracts network complexity
  • Used for provisioning and service requests

Memory trick: North is for apps, South is for devices.

More Automation and Programmability questions