ExamOpsPractice free

Cisco Certified Network Associate (CCNA) 200-301 · Free study guide

Objective 6.4 — Explain AI and machine learning in operations

Artificial intelligence and machine learning can help network teams summarize, classify, predict, generate, and prioritize. They do not replace authoritative telemetry, change control, or accountable engineering. The safest use starts by defining the decision being supported, the evidence available, and the human or automated boundary for action.

Separate predictive and generative uses

Predictive systems use patterns in data to estimate a class, probability, or future value. Network examples include anomaly scoring, capacity forecasts, and probable incident grouping. A prediction is not certainty. Base rates, thresholds, false positives, false negatives, and changing traffic patterns all affect usefulness.

Generative systems produce new text, code, configuration, queries, or summaries from prompts and context. They can accelerate drafting and exploration, but a plausible output may contain nonexistent commands, wrong interfaces, unsafe assumptions, or fabricated evidence. Generated material must enter the same review, validation, and approval process as human-authored material.

Understand data and drift

Models reflect their training data, features, objectives, and deployment environment. Missing telemetry or biased historical incidents can distort results. Drift occurs when operational patterns change and prior relationships no longer hold. Monitor quality over time with labeled outcomes where possible, not only the number of alerts produced.

Sensitive configurations, credentials, packet contents, and customer data need explicit handling rules. Do not send protected operational material to an unapproved service. Minimize and redact data while retaining enough context for the task.

Worked scenario

An anomaly model flags a branch for unusually high DNS traffic and a generative assistant suggests blocking all outbound UDP/53. Before action, the operator checks that the branch just enabled a legitimate resolver migration, validates destinations and timing, and compares client behavior. A blanket block would break service and could miss encrypted or TCP DNS. The output is a hypothesis, not a change authorization.

Keep humans accountable

Low-impact summarization may be safe with review. High-impact configuration changes require authoritative source data, bounded scope, deterministic validation, approval, rollback, and postchecks. Record which evidence came from the network and which content was inferred or generated. Operators remain responsible for understanding the intended and possible effects.

Verification evidence

Evaluate a system against known cases, inspect false-positive and false-negative rates, test data gaps, monitor drift, and review access to model inputs and outputs. For generated configuration, use syntax checks, policy validation, diffs, lab tests, canaries, and service verification. Never cite generated text as proof that a device changed.

Common traps

Readiness checklist

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free