300-635 Sample Questions

300-635 Sample Questions & Answers

Three areas tie for the heaviest weight: programming the ACI REST API, model-driven telemetry alongside Day 0 provisioning, and Intersight-based automation across UCS and NDFC APIs, with Git fundamentals and general API styles filling out the rest.

Launch the full 300-635 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Network Programmability Foundation · Describe the challenges encountered and patterns used when consuming APIs synchronously and asynchronously

    A developer is writing a Python script to interact with a REST API. The API can sometimes take several seconds to respond, and the script must perform other tasks while waiting for the API response to avoid blocking. Which Python library and approach should be used to achieve this non-blocking, asynchronous behavior?

    Show answer & explanation

    Correct answer: B

    The asyncio library is Python's standard framework for writing single-threaded concurrent code using coroutines. Paired with the aiohttp library, which provides an asynchronous HTTP client, it allows the script to make an API call, await the response without blocking, and yield control to the event loop to perform other tasks. This is the ideal pattern for non-blocking I/O operations.

  2. Question 2Beginner

    Data Center Device-centric Networking · Implement On-Box Programmability and Automation with NX-OS

    An administrator is attempting to run a Python script inside the NX-OS guest shell on a Nexus 9000 switch. The script fails because it depends on an external library that is not installed. What is the correct command to install the required library within the guest shell environment?

    Show answer & explanation

    Correct answer: B

    The NX-OS guest shell is a Linux environment where Python packages are managed using pip. To install packages system-wide within the shell, you need root privileges, which are obtained using sudo. Therefore, sudo pip install is the correct command.

  3. Question 3Intermediate

    Controller Based Data Center Networking · Construct a Terraform plan to use an ACI

    A financial services company is using Terraform to manage its Cisco ACI fabric. The security team mandates that all infrastructure changes must be reviewed and approved before being applied. The DevOps team uses a Git-based workflow. How can the team ensure that proposed ACI configuration changes are reviewed before they are implemented?

    flowchart TD A[Developer creates TF plan] --> B{Push to Git Repo}; B --> C[CI Server runs 'terraform plan']; C --> D{Review & Approve Plan Output}; D -- Approved --> E[CI Server runs 'terraform apply']; D -- Rejected --> F[Developer revises code]; F --> A; E --> G([End]);

    Show answer & explanation

    Correct answer: B

    This is the standard GitOps workflow for Terraform. When a developer submits a pull request, the CI/CD pipeline automatically runs terraform plan. The output of the plan, showing the exact changes to be made, is posted to the pull request for review. The changes are only applied (terraform apply) after the pull request is approved and merged, satisfying the security requirement for review and approval.

  4. Question 4Beginner

    Network Programmability Foundation · Describe the benefits of Python virtual environments

    A developer needs to ensure their Python automation project and its specific library dependencies can be reliably replicated on a different machine. The project uses the requests library version 2.25.1 and netmiko version 3.4.0. What is the best practice for managing and documenting these dependencies?

    Show answer & explanation

    Correct answer: B

    This is the standard best practice. A virtual environment isolates the project's dependencies from the system and other projects. The pip freeze > requirements.txt command creates a file listing the exact packages and versions, which can then be used on another machine with pip install -r requirements.txt to perfectly replicate the environment.

  5. Question 5IntermediateSelect 2

    Data Center Compute · Describe the capabilities of the Nexus Dashboard Fabric Controller API

    Which two authentication mechanisms are commonly required when making programmatic calls to the Nexus Dashboard Fabric Controller (NDFC) REST API? (Choose two.)

    Show answer & explanation

    Correct answers: B, C

    The standard workflow for NDFC API authentication involves sending a POST request with user credentials to a login endpoint. The response contains a session token (e.g., Dcnm-Token) that must be included in the headers of all subsequent API calls.

    The initial login request to obtain the session token requires the user's username and password to be sent in the body of the POST request. This is the first step of the authentication process.

  6. Question 6Intermediate

    Data Center Device-centric Networking · Implement Off-Box Programmability and Automation with NX-OS

    An engineer needs to automate the configuration of BGP on a fleet of Nexus switches using NETCONF. They want to use a standardized, vendor-neutral data model to ensure their automation script is portable. Which YANG model should they use?

    Show answer & explanation

    Correct answer: B

    OpenConfig is a collaborative effort by network operators to create vendor-neutral YANG data models for network configuration and management. Using the OpenConfig BGP model allows the engineer to write automation scripts that can, in principle, configure BGP on devices from any vendor that supports the model, thus meeting the portability requirement.

  7. Question 7Beginner

    Controller Based Data Center Networking · Leverage the API inspector to explore the REST API calls made by the ACI GUI

    What is the primary function of the API Inspector in the Cisco APIC GUI?

    Show answer & explanation

    Correct answer: B

    The API Inspector's main purpose is to serve as a learning and development tool. It records actions taken in the graphical user interface and displays the corresponding REST API calls (including the URL, method, and JSON payload) that the GUI made to the APIC. This allows developers to easily learn how to perform tasks programmatically.

  8. Question 8Advanced

    Controller Based Data Center Networking · Construct an Ansible playbook to create an application policy

    Case Study: A large e-commerce company, 'ShopFast', is automating its data center infrastructure hosted on a Cisco ACI fabric and UCS servers. Their goal is to achieve a full GitOps workflow for both network and compute provisioning.

    Current Environment & Team: The infrastructure team is highly skilled in Python and Ansible. All infrastructure definitions are intended to be stored in a central Git repository. A Jenkins CI/CD pipeline is used to orchestrate deployments. The ACI fabric spans two data centers, and UCS is managed by UCS Manager in a multi-domain setup.

    Requirements:

    1. Network Policy: ACI Tenants, VRFs, Bridge Domains, and EPGs must be defined in a declarative format in Git.
    2. Compute Policy: UCS Service Profile Templates, vNIC/vHBA templates, and server pool policies must also be defined declaratively in Git.
    3. Automation Engine: The CI/CD pipeline must trigger a tool that can interact with both APIC and UCS Manager idempotently.
    4. Auditability: All changes applied to the infrastructure must be traceable back to a specific commit in Git.

    Problem: The team needs to choose the primary automation tool to be executed by their Jenkins pipeline to manage both ACI and UCS. The chosen tool must align with their declarative, idempotent, and Git-centric philosophy.

    Which automation strategy best fulfills all of ShopFast's requirements?

    Show answer & explanation

    Correct answer: C

    This is the optimal solution. Ansible is declarative, idempotent, and uses YAML, which fits perfectly with GitOps. The cisco.aci and cisco.ucs collections provide comprehensive modules for managing both ACI and UCS Manager. This approach leverages the team's existing Ansible skills and meets all the requirements for declarative definitions, idempotency, and a unified toolchain for network and compute.

  9. Question 9Advanced

    Data Center Device-centric Networking · Implement Off-Box Programmability and Automation with NX-OS

    An engineer has written an Ansible playbook to configure a new VLAN on a Nexus switch. The playbook fails with an authentication error. The playbook uses ansible_user and ansible_password for credentials. The engineer has confirmed the credentials are correct and work via SSH. The switch is configured for RADIUS authentication. What is the most likely reason for the playbook's failure?

    Show answer & explanation

    Correct answer: D

    When using external AAA servers like RADIUS with NX-OS, programmatic access (like that used by Ansible) often requires the user to be assigned a specific role with sufficient privileges (e.g., network-admin). Even if the credentials are correct for interactive SSH login, if the RADIUS server does not return the correct role authorization attributes for a non-interactive session, the login will be rejected, resulting in an authentication failure from Ansible's perspective.

  10. Question 10Intermediate

    Data Center Compute · Identify the steps in the Cisco Intersight API authentication method

    The signature for a Cisco Intersight API request is generated by creating a string that includes the HTTP method, host, date, request target, and a digest of the request body. This entire string is then signed using a private key. What hashing algorithm is used to create the digest and the final signature?

    sequenceDiagram participant Client participant Intersight API Client->>Client: Create Digest from request body (SHA-256) Client->>Client: Construct Signature String Client->>Client: Sign the string with Private Key (RSA-SHA256) Client->>Intersight API: Send Request with Signature Header Intersight API->>Intersight API: Re-create signature string Intersight API->>Intersight API: Verify signature with Public Key alt Signature Valid Intersight API-->>Client: 200 OK else Signature Invalid Intersight API-->>Client: 401 Unauthorized end
    Show answer & explanation

    Correct answer: B

    The Cisco Intersight API authentication method uses the HTTP Signature scheme. It requires creating a SHA-256 hash of the request body to generate a digest. The final signature string is then signed using the RSA-SHA256 algorithm with the user's private key. This ensures both the integrity of the request body and the authenticity of the caller.

Ready for the real thing?

The full 300-635 simulator has every exam-style question, timed mode, and instant scoring.