CCNP Automation Practice Question
A network automation engineer is using the Cisco DNA Center Intent API to retrieve a list of all network devices. The engineer sends a GET request to the URL https://dnac.example.com/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token. What is the most likely cause of the error?
⚠ Common exam trap
The trap here is assuming the token can be passed as a query parameter or that HTTP is acceptable, when DNA Center strictly requires the token in the X-Auth-Token header over HTTPS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The token was not included in the request header as an X-Auth-Token.
The Cisco DNA Center Intent API uses token-based authentication. After obtaining a token via the authentication API, the token must be included in every subsequent request as an HTTP header named 'X-Auth-Token'. Omitting this header causes a 401 Unauthorized response. The engineer should add the header with the valid token to successfully retrieve the device list. Other methods like query parameters or different HTTP methods are not used for authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The request must use HTTP instead of HTTPS.
Why it's wrong here
Cisco DNA Center APIs always require HTTPS for secure communication. Using HTTP would not resolve the 401 error and would likely be rejected or redirected. The 401 indicates an authentication issue, not a protocol issue. HTTPS is mandatory for all API calls to DNA Center.
- ✗
The API endpoint /api/v1/network-device requires a POST request.
Why it's wrong here
The endpoint /api/v1/network-device supports GET to retrieve device lists. A POST request is used for creating resources or other actions, not for retrieving a list of devices. Using POST would not fix the authentication error; the 401 is due to missing or incorrect authentication header.
- ✗
The token must be passed as a query parameter named 'token'.
Why it's wrong here
Cisco DNA Center does not accept the authentication token as a query parameter. The token must be sent in the HTTP header 'X-Auth-Token'. Using a query parameter would not authenticate the request and would result in a 401 Unauthorized error. The API documentation specifies the header method.
- ✓
The token was not included in the request header as an X-Auth-Token.
Why this is correct
The Cisco DNA Center Intent API requires the authentication token to be included in the HTTP header with the key 'X-Auth-Token'. Without this header, the API returns 401 Unauthorized even if the token is valid. The engineer must add the header 'X-Auth-Token: <token>' to the GET request to authenticate successfully.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.