CCNA AI and Network Operations Practice Question
A network automation team is designing a workflow that uses a controller's REST API to retrieve device inventory and then push configuration changes. The API requires an authentication token obtained from a login endpoint. Which two practices should the team follow to securely and efficiently manage the token? (Choose two.)
⚠ Common exam trap
The trap here is treating the token like a permanent password; tokens expire and must be sent in headers, not embedded in URLs or scripts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include the token in the HTTP Authorization header for subsequent API calls.
Token-based API sessions require sending the token in the Authorization header for each request. Because tokens expire, automation should refresh or re-authenticate before expiration to avoid failures. Storing tokens in plaintext or URLs, or reusing them indefinitely, introduces security and reliability risks. These two practices balance security with operational continuity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cache the token and reuse it indefinitely without checking expiration.
Why it's wrong here
Tokens have limited lifetimes for security reasons. Reusing an expired token results in 401 Unauthorized errors and failed automation. The team should handle expiration by re-authenticating or using refresh tokens if supported. Indefinite caching ignores security controls and can cause operational failures when the token is revoked or times out.
- ✓
Include the token in the HTTP Authorization header for subsequent API calls.
Why this is correct
After a successful login, the token is typically sent in the Authorization header, often as a Bearer token. This allows the server to authenticate and authorize each request without re-sending credentials. It is the standard method for token-based API sessions and aligns with RESTful design. The header must be included in every protected request until the token expires.
- ✗
Store the token in plaintext in the script for easy reuse across runs.
Why it's wrong here
Storing a token in plaintext in a script exposes it to anyone with read access to the file or repository. If the script is committed to version control, the token leaks. This practice violates security best practices and can lead to unauthorized access. Tokens should be stored securely, such as in an encrypted vault or environment variable with restricted permissions.
- ✓
Implement token refresh or re-authentication before expiration to maintain session continuity.
Why this is correct
Proactively refreshing or re-authenticating before the token expires ensures uninterrupted automation. Many APIs provide a refresh endpoint or allow generating a new token. This practice avoids mid-workflow failures due to expired credentials. It also supports least privilege by allowing short token lifetimes while maintaining operational reliability.
- ✗
Embed the token in the URL query string to simplify logging.
Why it's wrong here
Placing a token in a URL query string is insecure because URLs are often logged by proxies, servers, and browsers. It can also be exposed in referrer headers. The token should be sent in the Authorization header instead. Query strings are not encrypted by default and can persist in logs, increasing the risk of credential leakage.
Go deeper
Related to this question
Learn chapter
REST APIs for Networking
Key term
REST API
A REST API is a set of rules that allows different software applications to communicate with each other over the internet using standard HTTP methods.
Key term
API
An API is a set of rules that allows software applications to communicate and exchange data with each other.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.