Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is building a Python application that integrates with Cisco DNA Center. The application needs to authenticate and then retrieve a list of network devices. The developer decides to use the DNA Center Intent API. Which two steps are required to successfully authenticate and make an API call? (Choose two.)

⚠ Common exam trap

The trap here is assuming DNA Center uses OAuth 2.0 or JWT, when it actually uses a simple token-based system with Basic Auth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send a POST request to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.

To authenticate with the DNA Center Intent API, the developer must first obtain a token by sending a POST request with Basic Auth credentials to the token endpoint. Then, that token must be included in the 'X-Auth-Token' header for all subsequent API calls. This two-step process ensures secure authentication and authorization. The other options describe incorrect or insecure methods that are not supported by DNA Center.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a JWT token using the DNA Center certificate and sign each request with it.

    Why it's wrong here

    DNA Center does not use JWT tokens signed with certificates for API authentication. The Intent API uses a simple token obtained via Basic Auth. While JWT is used in other contexts, it is not part of the DNA Center authentication flow. Attempting to generate and use a JWT would not work and would result in unauthorized errors. The correct method is to use the token endpoint as described.

  • ✓

    Send a POST request to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.

    Why this is correct

    The DNA Center Intent API requires obtaining an authentication token by sending a POST request to the /dna/system/api/v1/auth/token endpoint. The request must include Basic Auth headers with the username and password. The response contains a token that must be used in subsequent API calls. This step is essential for authentication and is documented in the Cisco DNA Center Platform API guide.

  • ✗

    Use OAuth 2.0 with the client credentials grant to obtain an access token from the /token endpoint.

    Why it's wrong here

    DNA Center does not use OAuth 2.0 client credentials for its Intent API authentication. Instead, it uses a token-based system with Basic Auth to obtain a token. While OAuth 2.0 is used in some Cisco platforms, such as Webex, it is not the method for DNA Center. Using OAuth 2.0 would result in authentication failure because the endpoint and flow are different.

  • ✓

    Include the obtained token in the 'X-Auth-Token' header for subsequent API requests.

    Why this is correct

    After obtaining the token, all subsequent API calls must include it in the 'X-Auth-Token' HTTP header. This header authenticates the request. Without it, the API returns a 401 Unauthorized error. The token is typically valid for a limited time, so the application must handle token refresh. This is a standard requirement for DNA Center Intent API calls.

  • ✗

    Pass the username and password as query parameters in each API request.

    Why it's wrong here

    Passing credentials as query parameters is insecure and not supported by DNA Center. Credentials must be sent in the Authorization header using Basic Auth only for the token request. For subsequent requests, the token is used. Query parameters are visible in logs and URLs, posing a security risk. DNA Center does not accept credentials this way, so this approach would fail authentication.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.