Be able to choose the right API call for a scenario: pick NETCONF/RESTCONF operations that match the datastore and intent, register and handle Webex webhooks, and read HTTP status codes and JSON payloads. Getting the operation-to-datastore mapping right is the key skill.
Start practicing
Understanding and Using APIs — choose a session length
Free · No account required
Domain overview
This domain covers consuming and building APIs on Cisco platforms: REST basics, HTTP methods and status codes, authentication, JSON/XML parsing, and model-driven programmability. It is tested through scenario questions on Cisco DevNet tooling such as Webex APIs, NETCONF/RESTCONF operations, webhooks, and Python requests code that calls real endpoints.
Exam objectives
NETCONF operations: <get>, <get-config>, <edit-config>, and which retrieves the running datastore
Webex API webhooks for real-time event notifications and their registration, payload, and delivery behavior
REST fundamentals: HTTP verbs, status codes, headers, authentication, and JSON/XML response parsing
RESTCONF and YANG model-driven programmability using HTTP methods against Cisco device datastores
Confusing NETCONF <get> with <get-config>: <get> returns state plus config, while <get-config> targets a specific datastore like running.
Assuming Webex webhooks stream messages directly; webhooks only POST event metadata, so the bot must call the API to fetch details.
Mixing RESTCONF and NETCONF transports, or using the wrong HTTP verb (PUT vs PATCH vs POST) when editing YANG-modeled configuration.
Click any question to see the full explanation and answer options, or start a focused practice session above.
What HTTP method should be used to update only the description field of a network device resource via a REST API?
2A developer is building a script to retrieve a list of network devices from Cisco DNA Center. The API response includes a 'nextToken' field in the body to indicate more results. What pagination method is being used?
3Which HTTP header is used to specify the format of the request body (e.g., application/json) when sending a POST request to a REST API?
4A developer is using the Meraki Dashboard API and receives a 429 Too Many Requests error. The API documentation states a rate limit of 5 calls per second. What is the best practice to handle this?
5Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required, such as a backend service calling Cisco API?
6A developer wants to use Postman to test a REST API that requires a Bearer token. Where should the token be placed in the request?
7What is the correct URL path for retrieving the configuration of a network interface using RESTCONF on a Cisco device?
8A network engineer wants to stream telemetry data from a Cisco router using gRPC. Which gRPC service model is typically used for the router to push data to a collector?
9Which NETCONF operation is used to retrieve the entire configuration datastore from a network device?
10What is the purpose of the 'Authorization' header in a REST API request?
11A developer is using the Webex API to create a webhook that triggers when a new message is posted in a room. What information is typically included in the webhook payload sent by Webex to the callback URL?
12In Cisco DNA Center's intent API, which endpoint would you use to retrieve the list of all network devices?
13A developer needs to use Postman to test an API that uses Basic authentication. How should the credentials be configured in Postman?
14Which authentication flow is most appropriate for a native mobile app that needs to access the Webex API on behalf of a user?
15What is the correct Content-Type header value for a RESTCONF request using JSON encoding?
16Which THREE of the following are characteristics of NETCONF? (Select THREE)
17Which TWO of the following are commonly used when implementing pagination in REST APIs? (Select TWO)
18An application needs to retrieve a list of network devices from Cisco DNA Center. Which HTTP method should be used against the /dna/intent/api/v1/network-device endpoint?
19In a RESTCONF API call to retrieve a specific interface configuration on a Cisco device, an engineer sends a GET request to /restconf/data/interfaces/interface=GigabitEthernet0/1. What Content-Type should be specified in the Accept header to receive YANG-defined JSON?
20A Webex bot needs to receive real-time notifications when a new message is posted in a Webex space. Which Webex API feature should the bot implement?
21A network automation script uses the Python ncclient library to modify a device configuration. Which NETCONF operation should be used to apply configuration changes?
22A Cisco Catalyst Center API uses OAuth 2.0 with the client credentials grant for server-to-server communication. Which token endpoint parameter should the client include to identify itself?
23A developer needs to partially update a Meraki network's configuration, changing only the time zone. Which HTTP method should be used on the network resource?
24When using the Cisco DNA Center intent API to retrieve issues, the response includes a Link header with rel="next" and a URL. What type of pagination is this?
25A developer is implementing gRPC telemetry with dial-out streaming from a Cisco IOS XE device. Which component initiates the TCP connection to the collector?
26A Webex API request returns a 401 Unauthorized error. The developer has already obtained an access token. What is the most likely cause?
27In a Postman collection, a developer stores the base URL of a Meraki API as a variable. Which Postman feature allows this?
28Which THREE of the following are valid NETCONF operations? (Choose three.)
29Which HTTP method should be used to partially update an existing resource in a REST API?
30A developer wants to retrieve a list of network devices from Cisco DNA Center. Which HTTP method and URL structure should be used?
31An application uses OAuth 2.0 client credentials grant to authenticate with a Cisco API. Which of the following best describes this flow?
32A developer is using the Meraki Dashboard API and notices that some requests return a 429 status code. What is the most likely cause?
33When using RESTCONF to configure a network device, which URL path prefix and content-type header should be used?
34In Postman, you want to run a collection of API requests automatically and test responses. Which feature should you use?
35Which header is used to pass an API key in Meraki Dashboard API requests?
36A network engineer wants to use NETCONF to change the hostname of a Cisco device. Which operation should be used?
37In Cisco DNA Center, which API endpoint is used to retrieve the site hierarchy?
38Which three statements about Webex API webhooks are true? (Choose three.)
39A network automation engineer wants to retrieve a list of all network devices from Cisco DNA Center. Which HTTP method and URL path should be used with the DNAC intent API?
40An application uses the Meraki Dashboard API and receives a 429 Too Many Requests error. What is the most likely cause, and how should the application adjust?
41When using RESTCONF to configure a network device, what Content-Type header should be set in the HTTP request to indicate YANG data in JSON format?
42What is the purpose of the Authorization header in a REST API call?
43Which HTTP method is used to partially update an existing resource in a RESTful API?
44When using the Cisco Meraki Dashboard API with pagination, the Link header in the response contains <https://api.meraki.com/api/v1/organizations?perPage=10&startingAfter=123>; rel="next". What does this indicate?
45A developer is using gRPC/gNMI for model-driven telemetry from a Cisco device. Which of the following best describes the difference between dial-in and dial-out streaming?
46Which header is used in an HTTP request to tell the server the format of the request body?
47A Cisco Webex bot needs to receive real-time notifications when new messages are posted in a space. Which API feature should the bot use?
48When using OAuth 2.0 client credentials flow with a Cisco API, what is the typical purpose of the access token?
49In the Cisco DNA Center intent API, which HTTP method should be used to update a specific site's information?
50Which THREE of the following are characteristics of RESTCONF compared to NETCONF? (Select three.)
51Which TWO of the following HTTP methods are considered safe (idempotent and not modifying server state)? (Select two.)
52A developer is designing a Cisco Catalyst Center integration that uses the intent API. Which THREE of the following are available via the intent API? (Select three.)
53Which HTTP method is used to partially update a resource in a RESTful API?
54A developer needs to retrieve a list of network devices from Cisco DNA Center. Which API endpoint should be used?
55In the context of Cisco Webex APIs, which mechanism allows an application to receive real-time notifications when a message is created in a space?
56A developer uses RESTCONF to configure a network device. What is the correct content-type header to send in the request?
57Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required?
58In Postman, what feature allows you to reuse a value like a base URL or token across multiple requests?
59A developer is using NETCONF to retrieve the running configuration of a network device. Which operation should be used?
60When using the Meraki Dashboard API, how should the API key be included in a request?
61In gNMI, what is the difference between dial-in and dial-out streaming?
62Which Cisco platform provides an Intent API for network automation, including endpoints for network-device, topology, and site hierarchy?
63A developer needs to retrieve a list of network devices from Cisco DNA Center with pagination. Which TWO URL components are typically used for offset/limit pagination?
64Which THREE statements about NETCONF are correct?
65Which HTTP method should be used to replace an entire existing resource in a RESTful API?
66A developer is making a GET request to a REST API and needs to specify that the response should be in JSON format. Which HTTP header should be set?
67A network automation engineer is using the Cisco DNA Center intent API to retrieve a list of network devices. Which API endpoint should be used?
68When using the Meraki Dashboard API, what is the correct method to authenticate requests?
69An application needs to receive real-time notifications when a new message is posted in a Webex space. Which Webex API feature should be used?
70A developer is using the ncclient library in Python to connect to a network device via NETCONF. Which operation should be used to modify the running configuration and commit the changes?
71A REST API uses offset and limit parameters for pagination. If the first request returns items 0-49 with limit=50 and offset=0, how should the next request be constructed to get the next page?
72In the OAuth 2.0 authorization code flow, what does the client receive after the user grants authorization?
73Which HTTP method is idempotent and safe?
74A developer needs to create a Postman collection that uses a variable for the base URL and a token variable for authentication. The token is obtained from a login request and must be reused across requests. Where should the token variable be defined to persist across all requests in the collection?
75When using gRPC/gNMI for model-driven telemetry, which mode allows the network device to push telemetry data to a collector without the collector initiating the connection?
76Which three statements are true about the Cisco Catalyst Center (formerly DNA Center) intent API? (Choose three.)
77A developer is integrating a Python script with Cisco Webex Teams. The script must create a new space and then immediately post a message to that space. After the POST to /v1/rooms, the API returns HTTP 200 with a JSON body containing the new room's id. The script then needs to send a message. Which approach correctly uses the API response to post the message to the newly created room?
78A network automation engineer is writing a Python script that calls the Cisco DNA Center API to retrieve device health scores. The API enforces rate limiting and returns HTTP 429 with a 'Retry-After' header when the limit is exceeded. The script must handle this gracefully without crashing. Which code pattern correctly implements the retry logic?
79A developer is building a Python script that calls the Cisco Webex Teams API to fetch a list of rooms. The API returns a response with a Link header containing a URL with a 'pageToken' parameter. What should the developer do to retrieve the next page of results?
80A developer is building a Python script that calls the Cisco Webex REST API. The API requires an OAuth 2.0 access token that expires after 14 days. The script will run unattended on a server every hour. Which OAuth 2.0 grant type should the developer use to obtain tokens without user interaction?
81A network engineer is writing a script to interact with a Cisco DNA Center controller. They need to authenticate and obtain a token to include in subsequent API requests. Which HTTP header should they use to send the token?
82A developer is building a Python script that calls the Cisco Webex Rooms API. The API returns a JSON error response with HTTP status code 429. The script currently retries immediately in a tight loop, but the errors persist. What should the developer implement to correctly handle this response?
83A developer is writing a Python script to interact with a REST API that returns JSON. The script must handle rate limiting gracefully. The API returns a 429 status code with a Retry-After header when the limit is exceeded. Which approach should the developer take to ensure the script continues to function without being blocked?
84A developer is writing a Python script that calls the Cisco Webex Rooms API to create a new team room. The script must send JSON data in the request body and receive JSON responses. Which HTTP header should be set to ensure the API interprets the request body as JSON and returns JSON?
85A developer is writing a Python script that calls the Cisco Webex Teams API to create a new space. The API returns the new space object, including a Location header pointing to the newly created resource. Which HTTP status code should the developer expect from a successful space creation?
86A developer is integrating a Python script with the Cisco Webex API to create a new team. The script sends a POST request to https://webexapis.com/v1/teams with a JSON body containing the team name. The API returns HTTP 401 Unauthorized. The developer confirms the request body and URL are correct. Which of the following is the most likely cause of the 401 response?
87A network engineer wants to retrieve the list of organizations associated with their API key from the Cisco Meraki Dashboard API. The API base URL is https://api.meraki.com/api/v1. Which HTTP request should the engineer send?
88A developer is building a Python script that calls the Cisco Webex Rooms API. The script must handle rate limiting gracefully by reading the response headers when the API returns HTTP 429. Which response header should the script inspect to determine how long to wait before retrying?
89A developer is building an application that needs to retrieve information from a REST API that uses cursor-based pagination. The response includes a 'next_cursor' field when more results are available. How should the developer structure the requests to retrieve all pages of data?
90A network engineer is using the Cisco DNA Center API to retrieve a list of all sites. The API returns a large number of records, and the response includes a header indicating the total count and a limit on the number of records per page. Which HTTP response header should the engineer inspect to find the URL for the next page of results?
91A network engineer is using the Cisco Meraki Dashboard API to retrieve a list of organizations. The API returns a JSON array. Which HTTP method should be used to fetch this list?
92A network engineer is using the Cisco DNA Center API to retrieve a list of all sites. The API response is a JSON object with a 'response' array containing site objects. The engineer wants to extract the name of each site. Which Python code snippet correctly parses the JSON response and prints each site name?
93A developer is testing a REST API endpoint using curl. The API requires an API key to be sent in the HTTP header 'X-API-Key'. Which curl command correctly includes the API key?
94A network engineer is writing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) REST API. They need to authenticate and obtain a token that will be used in subsequent API calls. Which HTTP header should be included in the authentication request to specify the expected response format?
95A developer is designing a Python application that consumes several Cisco REST APIs. To make the code maintainable and secure, the developer wants to implement reusable API request handling. Which two practices should be applied? (Choose two.)
96A developer is integrating with the Cisco Meraki Dashboard API. They need to update the name of an existing network. Which HTTP method should they use to modify only the name attribute without affecting other attributes?
97A developer is building a Python script that calls the Cisco Webex Teams API to list all memberships in a room. The API returns a maximum of 100 items per page and includes a 'Link' header in the response. The developer needs to retrieve all memberships across multiple pages. What is the correct approach to handle pagination using the Link header?
98A developer is testing a custom REST API that returns a JSON error object with an HTTP 400 status when an invalid query parameter is sent. They want to confirm that the API is behaving correctly according to REST conventions. Which HTTP status code class indicates that the client's request contains an error that the client can potentially fix?
99A developer is writing a Python script that calls the Cisco Webex API. The script must handle the case where the API returns a 429 Too Many Requests response. Which HTTP response header should the script inspect to determine how long to wait before retrying the request?
100A developer is building a Python application that integrates with Cisco DNA Center. The application needs to authenticate and then retrieve a list of network devices. The developer decides to use the DNA Center Intent API. Which two steps are required to successfully authenticate and make an API call? (Choose two.)
101A developer is building a Python script that calls the Cisco Webex API to retrieve a list of rooms. The API returns a maximum of 100 items per page and includes a 'Link' response header with a rel="next" URL. The script must automatically fetch all pages until no 'next' link remains. Which approach should the developer implement?
102A developer is using the Cisco Meraki Dashboard API to update the configuration of a wireless SSID. The API requires a PUT request to /networks/{networkId}/wireless/ssids/{number}. Which HTTP header is mandatory to include the API key for authentication?
103A developer is designing a Python application that will consume multiple REST APIs from different Cisco platforms. The application must handle common API behaviors such as authentication, rate limiting, and error responses. Which TWO of the following are best practices for making the application robust and maintainable? (Choose two.)
104A developer is integrating with Cisco DNA Center. After a successful POST to create a new site, the API returns HTTP 202 Accepted with a task ID in the response body. The developer needs to confirm when the site creation completes. What should the developer do next?
105A developer is building a Python application that consumes the Cisco Webex Teams API. The application needs to handle rate limiting gracefully. Which TWO of the following are appropriate strategies when the API returns a 429 Too Many Requests status code? (Choose two.)
106A developer is integrating a Python script with the Cisco Webex API. The script needs to read the value of the HTTP status code returned by the API to decide whether to retry a request. Using the requests library, which attribute of the response object should the developer inspect?
107A network engineer is writing a Python script that uses the requests library to call a REST API. The API requires an API key to be passed in the header. Which HTTP header field is commonly used to transmit an API key for authentication?
108A developer is building a Python application that consumes the Cisco Meraki Dashboard API. The application must store the API key securely and include it on every request. Which HTTP request header should the application set to authenticate each call?
109A developer is integrating with Cisco DNA Center's Intent API. They need to retrieve a list of all network devices and then filter for devices with a specific software version. The API returns a paginated response with a 'nextPage' field in the JSON body. Which approach should the developer use to efficiently process all devices?
110A developer is writing a Python script that consumes a REST API. The API returns a large number of records and uses pagination via a 'next' link in the response body. The developer needs to automatically follow these links until all records are retrieved. Which Python library feature is most appropriate for making the HTTP requests and handling the pagination loop?
111A developer is using the Cisco DNA Center API to retrieve device details. The API requires authentication using a token obtained from the /dna/system/api/v1/auth/token endpoint. The token has an expiration time. Which HTTP status code indicates that the token has expired and a new one must be obtained?
112A developer is writing a Python script that calls the Cisco Webex Teams API. The script must handle the case where the access token has expired. Which HTTP status code should the script check for to detect an expired or invalid token?
113An engineer is writing a script that calls the Cisco DNA Center API to create a new site. The API requires the request body to be encoded as JSON. Which HTTP request header should the script set so the server interprets the payload correctly?
114A developer is integrating with the Cisco Webex API and wants to authenticate on behalf of users without ever handling their passwords. The integration is a web application hosted on a public server, and the developer needs a refresh token so the app can keep working after the user's access token expires. Which OAuth 2.0 grant type should be used?
115A developer is writing a Python script that uses the requests library to call a REST API. The API requires an API key in the header 'X-API-Key'. The developer wants to ensure the key is not hardcoded in the script and is instead read from an environment variable. Which code snippet correctly implements this?
116A developer is designing a Python application that interacts with multiple Cisco REST APIs. They need to implement robust error handling for common HTTP status codes. Which TWO of the following status codes indicate that the client should retry the request after a delay? (Choose two.)
117A developer is testing a REST API with curl and receives a response body containing JSON. They want to confirm that the payload is JSON before parsing it in code. Which HTTP response header should they check?
118A developer is troubleshooting a REST API integration that intermittently returns HTTP 429 responses. Which TWO practices help the client handle rate limiting correctly? (Choose two.)
119A developer sends a GET request to https://sandboxdnac.cisco.com/dna/system/api/v1/auth/token and receives an HTTP 401 Unauthorized response. The request included no Authorization header. Which HTTP request header must be added to obtain a token from Cisco DNA Center?
120A developer is integrating with a REST API that returns a 429 Too Many Requests status code along with a Retry-After header. The developer's script currently retries immediately upon receiving a 429. What should the developer do to correctly handle rate limiting?
121A developer is building a Python application that uses the Cisco Webex API to send messages. The application must authenticate on behalf of a user without storing the user's password. Which OAuth 2.0 grant type should be used to obtain an access token?
122A developer is integrating a Python application with the Cisco Webex API. The application must act on behalf of users to create messages in Webex spaces. The developer wants to avoid storing user credentials. Which OAuth 2.0 flow is most appropriate for this scenario?
123A developer is designing a REST API client that must handle rate limiting from a Cisco Webex API. The API returns HTTP 429 Too Many Requests with a 'Retry-After' header. Which two strategies should the developer implement to handle rate limiting gracefully? (Choose two.)
124A developer is building a Python script that calls the Cisco Webex API. The API returns JSON with a top-level key "items" containing a list of records, and a "link" object with a "next" URL when more records exist. The developer needs to iterate through all pages until every record is retrieved. Which approach correctly handles this pagination style?
125A developer's script calls a REST API and receives HTTP 429 Too Many Requests. The response includes a Retry-After header with a value of 30. What should the script do to behave correctly?
126A developer is building a Python script that calls the Cisco Webex API to create a new room. The API returns a JSON payload containing the room ID. The developer needs to extract the room ID from the response and use it in a subsequent API call to add a member to that room. Which Python code snippet correctly parses the JSON response and extracts the room ID, assuming the response object is stored in a variable named `response` and the JSON key is `id`?
127A developer is building a script that authenticates to the Cisco DNA Center API. The documentation states that the authentication endpoint returns a token that must be included in subsequent API calls. Which authentication scheme does Cisco DNA Center expect for those subsequent calls?
128A developer is testing a REST API that returns a JSON response with a 'Location' header when a new resource is created. The developer wants to capture the URL of the newly created resource from the response. Which HTTP status code and header should the developer look for?
129A developer is writing an integration that calls a REST API which returns a large collection of items across many pages. The API documentation states that the response includes a 'next' link when more results are available. Which approach correctly retrieves the complete collection?
130A developer is testing a REST API with curl and wants the response to include only the HTTP status code and response headers, discarding the body. Which curl option accomplishes this?
131A network engineer is using curl to test a REST API endpoint on a Cisco IOS XE device that supports RESTCONF. The engineer wants to retrieve the configuration of the GigabitEthernet1 interface. Which curl command correctly sends a GET request to the RESTCONF API with the appropriate headers to retrieve the interface configuration in JSON format?
132A developer calls a REST API with GET /api/v1/devices?limit=50 and receives the first page of results plus a body field named nextPageToken. The API documentation states that results are cursor-paginated. How should the script request the next page?
133A developer is integrating with a REST API that returns JSON error responses. The team needs to handle failures robustly in code. Which TWO practices are appropriate when processing API responses? (Choose two.)
134A developer is integrating a Python application with the Cisco DNA Center API. The application must handle rate limiting gracefully. The API returns HTTP 429 Too Many Requests with a 'Retry-After' header indicating the number of seconds to wait before retrying. Which approach best implements exponential backoff with jitter to respect the rate limit and avoid overwhelming the server?
135A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?
136A developer is designing a Python script that interacts with multiple Cisco APIs, including Cisco Webex and Cisco DNA Center. The script must authenticate to each API and handle tokens securely. Which TWO of the following practices are recommended for securely managing API credentials and tokens? (Choose two.)
137A developer needs to authenticate to a REST API using an API key that must be sent in a custom HTTP header named X-API-Key on every request. The team uses Python requests. Which code snippet correctly attaches the key to a GET request?
138A developer is testing a REST API using curl. The API returns a JSON response with a status code of 201. What does this status code indicate about the request?
139A developer is writing a Python script that consumes a REST API which returns JSON error bodies. The script must distinguish client mistakes from server-side problems and react accordingly. Which TWO HTTP status code ranges or codes indicate conditions the client should handle as errors caused by the request or by the server rather than success? (Choose two.)
140A developer is writing a script that calls a REST API returning JSON. The script uses the Python requests library and must detect when the server responds with a 429 Too Many Requests status. Which expression correctly evaluates the status code?
141A developer is integrating with a REST API that uses rate limiting. The API documentation states that clients can make 100 requests per minute. The developer's application needs to fetch data from multiple endpoints. Which HTTP status code should the application expect if it exceeds the rate limit, and what header might indicate when to retry?
142A developer is designing a Python script that interacts with a REST API. The script must handle common HTTP methods appropriately. Which TWO of the following statements correctly describe the use of HTTP methods in RESTful APIs? (Choose two.)
Be able to choose the right API call for a scenario: pick NETCONF/RESTCONF operations that match the datastore and intent, register and handle Webex webhooks, and read HTTP status codes and JSON payloads. Getting the operation-to-datastore mapping right is the key skill.
The Courseiva 200-901 question bank contains 142 questions in the Understanding and Using APIs domain, covering the 20% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Understanding and Using APIs domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included