Mental model
Cisco objective 5.7 says “Identify the workflow being automated by a Python script that uses Cisco APIs including ACI, Meraki, Cisco Catalyst Center, and RESTCONF”.
The exam shows you a script. You tell it what the script does. Four questions get you to the answer every time.
1. Which API is it talking to?
Look for the base URL or SDK import.
| Pattern | API |
|---|---|
https://api.meraki.com/api/v1/... or import meraki | Meraki Dashboard |
/dna/intent/api/v1/... or import dnacentersdk | Catalyst Center (ex-DNA Center) |
/api/aaaLogin.json or apic.example.com | ACI APIC |
/restconf/data/... with yang-data+json | Device-level RESTCONF (IOS XE / NX-OS) |
webexapis.com or import webexteamssdk | Webex |
nso.example.com/restconf/ | Cisco NSO |
2. What shape of call?
Count HTTP verbs:
- All
requests.get(...)→ read-only. Reporting, inventory, dashboard. requests.post(...)orrequests.put/patch(...)→ write. Creating / updating.requests.delete(...)→ cleanup.- Mix → workflow (fetch, decide, change).
3. Loop or one-shot?
for device in devices: ...→ fan-out over many targets.- No loop → single resource.
4. What happens with the result?
print(...)→ inventory report / diagnostic.- Writing to a file (
open(..., "w")) → saving a backup / generating a report. - Comparing or asserting → auditing / drift detection.
- Feeding into another API call → migration / sync.
Worked example 1
import os, requests
BASE = "https://api.meraki.com/api/v1"
HEADERS = {"X-Cisco-Meraki-API-Key": os.environ["MERAKI_KEY"]}
orgs = requests.get(f"{BASE}/organizations", headers=HEADERS).json()
for o in orgs:
nets = requests.get(f"{BASE}/organizations/{o['id']}/networks", headers=HEADERS).json()
for n in nets:
print(f"{o['name']} / {n['name']} productTypes={n['productTypes']}")
Answer
- API: Meraki Dashboard.
- All GETs → read-only.
- Two nested loops → fan-out over orgs then networks.
- Prints to stdout → reporting / inventory.
Verdict: “List every network in every organisation, showing its product types”. An inventory script.
Worked example 2
import requests, json
BASE = "https://10.0.0.1/restconf/data/ietf-interfaces:interfaces"
AUTH = ("admin", "cisco123")
HEADERS = {"Content-Type": "application/yang-data+json", "Accept": "application/yang-data+json"}
for intf in ["GigabitEthernet0/0", "GigabitEthernet0/1"]:
path = f"{BASE}/interface={intf.replace('/', '%2F')}"
body = {"ietf-interfaces:interface": {"name": intf, "enabled": True}}
r = requests.patch(path, auth=AUTH, headers=HEADERS, json=body, verify=False)
print(f"{intf}: HTTP {r.status_code}")
Answer
- API: RESTCONF on a Cisco device (10.0.0.1,
ietf-interfaces,yang-data+json). PATCH→ write, partial update.- Loop over two interfaces → fan-out across interfaces.
- Each sets
enabled: True.
Verdict: “Bring GigabitEthernet0/0 and GigabitEthernet0/1 up (no shutdown)”. A targeted enable script.
Worked example 3
import requests
TOKEN = "<fetched elsewhere>"
HEADERS = {"X-Auth-Token": TOKEN}
r = requests.get("https://dnac.example.com/dna/intent/api/v1/network-device",
headers=HEADERS, verify=False)
devices = r.json()["response"]
for d in devices:
if d["reachabilityStatus"] != "Reachable":
print(f"UNREACHABLE: {d['hostname']} ({d['managementIpAddress']})")
Answer
- API: Catalyst Center (DNA Center base URL +
X-Auth-Token). - One GET then filter + print.
- No writes.
Verdict: “List any Catalyst Center-managed device that is currently unreachable”. An alerting / health report.
Patterns you will see on the exam
| Pattern | Reads | Writes | Loops | Likely workflow |
|---|---|---|---|---|
| GET → print | 1 | 0 | 0 | One-off query |
| GET → filter → print | 1 | 0 | 0 | Report / check |
| Loop(GET → print) | N | 0 | 1 | Inventory report |
| Loop(GET → POST/PATCH) | N | N | 1 | Fan-out change |
| GET → POST | 1 | 1 | 0 | Copy / migrate |
| Loop(GET → compare → log) | N | 0 | 1 | Audit / drift detection |
Reading tips
- Skim top-down. First read: identify API, note HTTP methods.
- Second read: find the loops.
- Third read: name the end result.
- Ignore the auth boilerplate until you need it; the business logic is what the exam wants.
FAQ
What if the script uses an SDK instead of raw requests? Same logic. dashboard.networks.getOrganizationNetworks(...) is GET /networks. SDK method names mirror the URL.
Does the exam ask about specific line numbers? No. It asks what the script DOES. One-sentence answers.
What if there is error handling / retries? Usually noise around the business logic. Ignore try/except and time.sleep() to find the real intent.
