Courseiva
mediumMultiple Choice

200-901 Practice Question: A developer is building a chatbot that retrieves…

A developer is building a chatbot that retrieves interface status from a Cisco Catalyst 9000 switch using RESTCONF. Which authentication method is most appropriate for programmatic access?

⚠ Common exam trap

Cisco often tests the misconception that RESTCONF requires OAuth or API keys because it is a RESTful API, but in reality, IOS XE devices rely on traditional AAA and HTTP Basic Auth over HTTPS for programmatic access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTP Basic Authentication over HTTPS.

RESTCONF on Cisco Catalyst 9000 switches supports HTTP Basic Authentication over HTTPS as a straightforward, standards-based method for programmatic access. Basic authentication sends the username and password in the HTTP Authorization header, and when combined with HTTPS, the credentials are encrypted in transit, providing adequate security for device management without requiring additional infrastructure like an OAuth provider or certificate authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HTTP Basic Authentication over HTTPS.

    Why this is correct

    HTTP Basic Authentication over HTTPS supplies credentials in the request header, which RESTCONF accepts for programmatic access, satisfying the stem's chatbot requirement. HTTPS encrypts the base64-encoded credentials in transit, preventing interception, and the method needs no browser-based interactive login flow.

  • ✗

    API key passed in the HTTP header.

    Why it's wrong here

    API keys authenticate against an API gateway's own key store, not against the switch's local user database or AAA, so RESTCONF's HTTP Basic or token-based authentication would reject them. They suit third-party SaaS APIs issuing keys to consumers; a Catalyst 9000 running RESTCONF expects credentials validated by its configured authentication source instead.

  • ✗

    OAuth 2.0 with client credentials grant.

    Why it's wrong here

    OAuth 2.0 client credentials require an authorisation server issuing tokens, which IOS XE RESTCONF does not provide natively. It fits cloud APIs with an identity provider, not direct switch authentication, where HTTP Basic over HTTPS is used.

  • ✗

    Client certificate authentication.

    Why it's wrong here

    Client certificates authenticate the device rather than a user or application identity, and RESTCONF on Catalyst 9000 expects HTTP Basic or token credentials. Certificate authentication suits mutual TLS between infrastructure components, not a chatbot retrieving interface status.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.