Courseiva
Using the Claude API →easyMultiple Choice

CCAO-F Using the Claude API Practice Question

An engineer is writing a first integration against the Claude Messages API and needs to select the correct endpoint and required authentication header. The application will send a messages array with user and assistant turns and read the response content blocks. Which configuration is correct?

⚠ Common exam trap

The trap here is carrying over an Authorization: Bearer plus chat completions pattern from another vendor's API instead of using the Claude messages endpoint and x-api-key header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

POST to /v1/messages with the API key in the x-api-key header and an anthropic-version header.

The Messages API is invoked by posting to /v1/messages, authenticating with the x-api-key header, and including an anthropic-version header to select the API version. The request body carries the model, max_tokens, and the messages array, and the reply is returned as content blocks. Other paths or query-string credentials do not match the supported interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    POST to /v1/chat/completions with the API key in an Authorization: Bearer header.

    Why it's wrong here

    The chat completions style path is associated with a different vendor's API surface, not the Claude Messages API, so the request shape and response format would not match what this integration expects. Sending Claude-formatted messages there would fail. The correct resource for Claude is the messages endpoint with the x-api-key header.

  • ✗

    POST to /v1/complete with the API key in an Authorization: Bearer header.

    Why it's wrong here

    The /v1/complete path belongs to the older text completion style rather than the Messages API, and it does not accept the messages array of user and assistant turns described here. Using it would require a different request shape and would not yield the content block response the engineer expects. The path is simply the wrong resource for this integration.

  • ✓

    POST to /v1/messages with the API key in the x-api-key header and an anthropic-version header.

    Why this is correct

    The Messages API is reached by posting to /v1/messages with the API key supplied in the x-api-key header, and requests include an anthropic-version header that pins the API version. The body carries the model, max_tokens, and the messages array, and the response returns content blocks. This matches the described integration exactly.

  • ✗

    POST to /v1/messages with the API key as a query string parameter named api_key.

    Why it's wrong here

    Passing credentials in the query string is not the supported authentication mechanism for the Claude API, and it exposes the secret in logs, proxies, and browser history. The correct path is a header-based credential. Even though the endpoint path itself is right, the authentication method described here would be rejected and is a poor security practice.

About these practice questions

Courseiva writes every CCAO-F question from scratch — 259 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAO-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAO-F exam.