Courseiva

200-901 Cisco Platforms and Development Practice Question

A developer is building a Python application that interacts with Cisco Meraki Dashboard API. The application needs to retrieve the list of organizations. Which HTTP header must be included in the request to authenticate?

⚠ Common exam trap

The trap here is assuming that all Cisco APIs use the same authentication header, when in fact each platform has its own specific header name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

X-Cisco-Meraki-API-Key: <API_KEY>

The Meraki Dashboard API authenticates requests using the X-Cisco-Meraki-API-Key header. The API key is generated in the Meraki Dashboard and must be included in every API call. Other headers like Authorization: Bearer or X-Auth-Token are used by different Cisco platforms and will not work with Meraki.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authorization: Bearer <API_KEY>

    Why it's wrong here

    Meraki Dashboard API does not use OAuth 2.0 Bearer tokens for API key authentication. While Bearer is common in other APIs, Meraki expects the API key in a custom header. Using Bearer would result in a 401 Unauthorized error because the server does not recognize that scheme.

  • ✓

    X-Cisco-Meraki-API-Key: <API_KEY>

    Why this is correct

    The Meraki Dashboard API requires the API key to be passed in the X-Cisco-Meraki-API-Key header. This is the standard authentication method for all Meraki API calls. Without this header, the API returns a 401 Unauthorized response. The developer must include it in every request to access organization data.

  • ✗

    X-Auth-Token: <API_KEY>

    Why it's wrong here

    The X-Auth-Token header is used by Cisco DNA Center, not Meraki. Meraki uses a specific header name that includes 'Cisco-Meraki'. Using X-Auth-Token would not authenticate and would result in an error. This option confuses authentication mechanisms between different Cisco platforms.

  • ✗

    api-key: <API_KEY>

    Why it's wrong here

    The generic 'api-key' header is not recognized by Meraki Dashboard API. While some APIs use a simple 'api-key' header, Meraki requires the fully qualified header name. Using this would cause authentication failure. The developer must use the exact header specified in Meraki documentation.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.