CCNP Automation Practice Question
A network engineer is using Cisco SD-WAN vManage APIs to automate the creation of a new VPN template. The engineer needs to authenticate to the vManage REST API using a Python script. Which authentication method is natively supported by the vManage API for programmatic access?
⚠ Common exam trap
The trap here is assuming that vManage supports OAuth or API keys like some other Cisco platforms, but it actually uses session cookies for API authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session-based authentication using a cookie obtained from /j_security_check
The vManage REST API uses session-based authentication. A client sends a POST request to /j_security_check with username and password, receives a JSESSIONID cookie, and includes it in subsequent requests. This method is standard for automating vManage operations. Other methods like OAuth or API keys are not natively supported for the vManage API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session-based authentication using a cookie obtained from /j_security_check
Why this is correct
The vManage REST API uses session-based authentication where the client posts credentials to /j_security_check and receives a JSESSIONID cookie. This cookie must be included in subsequent API requests. This is the standard method for programmatic access to vManage, allowing scripts to authenticate and perform operations.
- ✗
API key authentication using a static key generated in the vManage GUI
Why it's wrong here
vManage does not provide static API keys for authentication. The API requires a session cookie obtained after login. API keys are common in other platforms like Cisco DNA Center, but not in vManage. Therefore, this method is not supported natively.
- ✗
Certificate-based authentication using X.509 client certificates
Why it's wrong here
While vManage supports certificate-based authentication for some features, the REST API for automation typically uses session-based authentication. X.509 client certificates are not the standard method for programmatic API access. Using certificates would require additional configuration and is not the native method for API scripts.
- ✗
OAuth 2.0 with JWT tokens issued by vManage
Why it's wrong here
Cisco SD-WAN vManage does not natively support OAuth 2.0 for its REST API. While some Cisco platforms use OAuth, vManage relies on session-based authentication. Using OAuth would not work without additional gateways or custom integration, which is not natively supported.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.