Courseiva
mediumMultiple Choice

CCNP Practice Question: A Python script uses the requests library to…

A Python script uses the requests library to interact with Cisco DNA Center's REST API:

import requests

url = "https://dna-center/api/v1/network-device" headers = {

"X-Auth-Token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9..."
}

response = requests.get(url, headers=headers, verify=False)

print(response.json())

What is a security concern with this script?

⚠ Common exam trap

Cisco often tests the distinction between authentication token management (hardcoding) and transport security (SSL verification), leading candidates to incorrectly focus on the hardcoded token as the primary risk when the disabled certificate validation is the more critical security flaw in this specific context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The script disables SSL certificate verification, making it vulnerable to man-in-the-middle attacks.

Setting `verify=False` in the `requests.get()` call disables SSL/TLS certificate validation. This means the client will not verify the identity of the Cisco DNA Center server, making the connection vulnerable to man-in-the-middle (MITM) attacks where an attacker could intercept or modify the API traffic. In production environments, certificate validation should always be enabled to ensure the authenticity of the server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The script uses a hardcoded token, which is a security risk.

    Why it's wrong here

    Hardcoded credentials or API tokens are indeed a security weakness because anyone with access to the script source can extract and reuse the token, and rotating it requires editing code. However, in this particular script the token is present and functional, so the script will operate; the more immediate and catastrophic flaw is that SSL verification is disabled, allowing an attacker to intercept the token and the entire session. Thus, although hardcoded tokens are a valid concern, the question specifically targets the most severe vulnerability shown.

  • ✓

    The script disables SSL certificate verification, making it vulnerable to man-in-the-middle attacks.

    Why this is correct

    Disabling SSL certificate verification with verify=False means the client accepts any certificate presented, including a forged one from a man-in-the-middle. This allows an attacker to intercept, decrypt, and modify traffic between the script and the DNA Center API, exposing credentials and data. In production, certificates should be validated against a trusted CA or internal enterprise CA. This is the most direct and exploitable security flaw in the script as written.

  • ✗

    The script does not handle HTTP errors, which could expose sensitive information.

    Why it's wrong here

    While adding try/except or checking status codes is good practice, the absence of error handling does not directly make the script vulnerable to an attacker; it may cause crashes or unclear diagnostics, but it does not expose data to interception on the wire. The question asks for a security risk, and an SSL verification failure is the more concrete and severe vulnerability. Unhandled HTTP errors typically only affect the script's own output, not an attacker's ability to compromise the session.

  • ✗

    The script uses an incorrect URL; the path should be /dna/intent/api/v1/network-device.

    Why it's wrong here

    The URL path /dna/intent/api/v1/network-device is actually the correct endpoint for retrieving network devices in the Catalyst Center (DNA Center) REST API. The script's issue is not a typo or wrong path but the disabled transport security; even if the path were wrong, that would cause a functional failure rather than a security vulnerability. Therefore this option misidentifies the actual problem in the script.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.