Choosing a Good Prompt for Network Operations
CCNA v2.0 objective 5.2: judge prompts to a generative AI tool by data classification, output format, persona and instructions, with worked network examples.
- Objective 5.2 says select a prompt, so expect several prompts on screen and one question: which is best? Judge each on four components: data classification, output format, persona, instructions.
- Data classification is a pass or fail gate. A prompt that pastes a password, SNMP community, key or public IP is wrong even if the rest of it is perfect.
- A good network prompt names the platform and version, gives the relevant facts, asks for a specific output shape, and asks for commands you can use to verify the answer.
Mental model
A generative AI tool answers the question you asked, not the one you meant. Ask “why is OSPF broken?” and you get ten generic causes. Give it the platform, the neighbor state and the interface facts, and you get a short list you can test.
Treat a prompt like a work order for a contractor you have never met: say what role they fill, what the job is and what done looks like, and never hand over the keys.
The official wording of CCNA v2.0 objective 5.2 is: “Select a prompt to send to a generative AI system to support network operations considering prompt components such as data classification, output format, persona, and instructions.” The verb is select: compare prompts, pick the safe, useful one. The CCNA v2.0 AI domain guide covers all six objectives; this page goes deeper on 5.2.
The four components
| Component | Plain definition | Network example |
|---|---|---|
| Data classification | What information may leave your network and go into this tool | Write “enable secret is set” in place of the real line; use 10.x addresses in place of your public block |
| Output format | The shape of the answer | ”A table with columns: cause, verification command, fix” |
| Persona | The role the model answers as | ”Act as a senior network engineer reviewing a change” |
| Instructions | The task, the facts, the limits | ”IOS XE 17.x. Do not suggest a reload. Give show commands to confirm each step” |
Output format choices you will see: a table to compare causes or devices, numbered steps for a procedure, a single command when you only need syntax, a YAML playbook for Ansible, and JSON when a script will read the result.
Persona sets depth and attitude. “Senior network engineer reviewing a change” pushes toward risk and rollback; “NOC analyst” pushes toward short, safe checks. A persona alone does nothing without a task.
Instructions carry most of the weight. A strong set covers:
- Task: “find the likely cause”, “write a playbook”.
- Platform and version: IOS XE 17.x or NX-OS 10.x. Syntax differs.
- Constraints: read only, no reload, 30 minute window.
- What not to do: “do not remove existing VLANs from the trunk”.
- Verification: “give the show commands that prove each step worked”.
Data classification: what never goes in
Your company sorts data into levels such as public, internal, confidential and restricted; network configs sit near the top. Before you type, ask: is this tool approved for this data, and does the prompt need this detail at all?
Never paste these into a public AI tool:
- Passwords and
enable secretlines, even hashed - SNMP community strings and SNMPv3 keys
- TACACS+ and RADIUS keys, IPsec pre-shared keys, private keys, API tokens
- Public IP addresses and real domain names
- Customer names, circuit IDs, device serial numbers
Mask or summarize. The model almost never needs the secret. “SNMPv2c community configured with RW access” says everything that matters. Swap public addresses for documentation ranges (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24) or private 10.x space. An OSPF question needs the OSPF process and two interfaces, not the whole running config.
Use the approved tool. Many companies provide an internal assistant approved for internal data. If policy says internal tool only, the best prompt on a public tool is the one you do not send. More in don’t paste configs into ChatGPT.
A checklist for comparing prompts
Run each option through these checks in order. The first one is a gate: fail it and the prompt is out.
| # | Check | Pass looks like |
|---|---|---|
| 1 | Data classification | No secrets, keys, public IPs, customer names or serials |
| 2 | Task | One clear job, not “tell me about OSPF” |
| 3 | Context | Platform, version and the facts that matter |
| 4 | Output format | A named shape: table, steps, command, YAML, JSON |
| 5 | Constraints | What not to change or suggest |
| 6 | Verification | Asks for commands to confirm the answer |
| 7 | Persona | Fits the task (rarely the deciding factor) |
Among options that pass the gate, the one that hits more of checks 2 to 6 wins.
Worked examples: pick the best prompt
Example 1: OSPF stuck in EXSTART on two IOS XE routers sharing an Ethernet link.
- A. “OSPF is stuck. Help.”
- B. “Act as a senior network engineer. Two Cisco IOS XE 17.x routers on one Ethernet segment stay in EXSTART. MTU is 1500 on R1 Gi0/0 and 1400 on R2 Gi0/0. List likely causes as a table: cause, verification command, fix. Do not suggest clearing the OSPF process as the fix.”
- C. “Here is R1’s full running config with the enable secret, TACACS key and our public WAN block. Act as a senior engineer, fix OSPF, answer as a table.”
- D. “Act as a senior network engineer and explain every OSPF neighbor state in detail.”
Answer: B. It has the platform, the state and the MTU mismatch, which is the classic EXSTART cause: Database Description packets carry the interface MTU, and a router rejects a neighbor’s DBD with a larger MTU. It also names a format and a limit. C fails data classification. A has no context. D is a textbook task.
Example 2: VLAN 30 not passing a trunk. Hosts in VLAN 30 on SW2 cannot reach their gateway on SW1.
- A. “Act as a NOC analyst. On IOS XE switches, VLAN 30 exists on SW1 and SW2 but does not cross the Gi1/0/48 trunk. VLANs 10 and 20 work. Give numbered steps with the show command for each. Any fix must add VLAN 30 without removing VLANs already allowed.”
- B. “Act as a NOC analyst. VLAN 30 does not work on the trunk. Answer in JSON.”
- C. “Why do VLANs fail on trunks? Tell me everything.”
- D. “Act as a NOC analyst. SW1 serial FOC1234X5YZ at Acme Bank’s Main Street branch drops VLAN 30 on the trunk. Give numbered steps.”
Answer: A. Saying what works and what does not points straight at the trunk allowed list, which show interfaces trunk confirms. The constraint matters: switchport trunk allowed vlan 30 replaces the list and drops VLANs 10 and 20, while switchport trunk allowed vlan add 30 is the safe fix. D leaks a serial number and a customer name. B has no facts and the wrong format for a person. C has no task.
Example 3: an Ansible playbook for show commands.
- A. “Write an Ansible playbook for my switches. Username admin, password Cisco123, hosts 203.0.113.10 and 203.0.113.11.”
- B. “Act as a network automation engineer. Write a YAML playbook for IOS XE switches in inventory group
switches, usingansible.netcommon.network_cliandcisco.ios.ios_commandto runshow versionandshow ip interface brief, register and print the output. Read only, no config modules, no credentials in the file. Return only the YAML and theansible-playbookcommand to run it.” - C. “Explain what Ansible is and how it compares to Python.”
- D. “Act as a network automation engineer. Write a playbook that configures all my switches.”
Answer: B. It names the connection, module, commands, output shape and limits. A leaks a password and addresses. D is vague and asks for changes with no scope. C is a study question.
Checking the answer you get back
A good prompt gets you a better draft, not a verified fix.
- Check every command on your platform and version. Models mix IOS, IOS XE and NX-OS syntax.
- Run show commands first (
show ip ospf neighbor,show interfaces trunk) to confirm the cause before changing anything. - Read config line by line for commands that replace lists or reset processes.
- Test playbooks in a lab or with
--checkwhere the module supports it. - Never paste output blindly into production.
When an AI tool runs those commands itself, you are into agentic AI: see agentic AI in network operations.
Common mistakes
A great prompt that leaks secrets. The #1 mistake on this objective. Perfect persona, format and instructions do not rescue a prompt containing an enable secret or a pre-shared key. It fails data classification, so it is the wrong answer.
Picking the prompt with only a persona. “Act as a CCIE” with no task is not a good prompt.
Choosing the longest prompt. A long prompt stuffed with a full config usually fails the gate.
Trusting the answer unchecked. Confirm on the device before any change.
Cheat strip
| Concept | Plain English |
|---|---|
| Objective 5.2 verb | Select: compare prompts, pick the best |
| Data classification | What may leave your network. Pass or fail gate |
| Never send | Passwords, secrets, SNMP communities, keys, PSKs, public IPs, customer names, serials |
| Output format | Table, numbered steps, single command, YAML, JSON |
| Persona | Senior engineer reviewing a change, NOC analyst |
| Instructions | Task, platform and version, constraints, what not to do, verification |
Frequently asked questions
Q: Is data classification more important than the other three components? A: Treat it as a gate. A prompt that leaks sensitive data is wrong however good the rest is. Among safe prompts, compare the other three.
Q: Is a hashed enable secret safe to paste? A: No. Type 7 passwords reverse in seconds, and type 5 or type 9 hashes of weak passwords can be cracked offline. Write “enable secret is configured” instead.
Q: Which output format should I ask for on an Ansible task? A: YAML, because playbooks are YAML files. Ask for the playbook only, with no credentials inside.
Q: Can I paste real configs into my company’s internal AI assistant? A: Only if your data policy approves that tool for that class of data.
Practice: quick check
Every question in the bank, once. No repeats. Missed ones cycle back at the end.
Agentic AI in Network Operations
What an AI agent actually does on a network, how it differs from a chatbot or a script, and how to check its recommendations before anything touches production.
Network Topologies: Bus, Ring, Star, Mesh, Hybrid, Hub-and-Spoke
Every physical and logical topology CompTIA Network+ (N10-009) tests: bus, ring, star, mesh, hybrid, point-to-point, hub-and-spoke, three-tier, spine-leaf. Diagrams, trade-offs, real-world use.
Want this drilled into reflex?
1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.
Related topics
AI & ML in Network Operations
Where machine learning really shows up in networks: anomaly detection, predictive maintenance and generative AI assistants, plus marketing AI vs the real thing.
Automation & ProgrammabilityAnsible for Network Engineers
Push configuration to dozens of Cisco devices from one YAML playbook. Covers inventory, modules, idempotency, and why Ansible became the default automation tool for network teams who don't want to write a custom Python script for every change.
Automation & ProgrammabilityNetwork Management Approaches
Device-based, cloud-based, controller-based, automation-based and infrastructure as code: how each one makes changes and where the source of truth lives.
Get the free CCNA 12-week roadmap
You're already reading up on Choosing a Good Prompt for Network Operations. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Choosing a Good Prompt for Network Operations fits. A written personal reply, not an autoresponder. Expect it within one business day.
Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.
