Courseiva

200-901 Software Development and Design Practice Question

A developer is building a Python client that calls a REST API returning JSON. The client must detect authentication failures, rate limiting, and server errors so it can retry or alert appropriately. Which coding practice should be applied?

⚠ Common exam trap

The trap here is treating a successful JSON parse as proof of success, when error responses such as 401 or 429 often return well-formed JSON bodies too.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inspect the response status code and branch on categories such as 401/403 for authentication, 429 for rate limiting, and 5xx for server errors before processing the body.

HTTP status codes carry the outcome of each request, so a robust client branches on them: refresh credentials on 401, respect Retry-After and back off on 429, and alert on 5xx. Parsing the body is meaningful only after the status indicates success. This ordering lets the client retry the conditions that are transient and escalate the ones that are not.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Call response.json() immediately after every request and catch only json.JSONDecodeError, since valid JSON indicates success.

    Why it's wrong here

    A response body can be valid JSON while the HTTP status code indicates failure, such as a 401 error object or a 429 rate-limit payload. Parsing JSON first and ignoring status codes means authentication failures and rate limiting are treated as successful responses. Error handling must branch on the HTTP status code before interpreting the body.

  • ✗

    Set a long socket timeout and retry indefinitely on any exception until the request succeeds.

    Why it's wrong here

    Retrying indefinitely on any exception can hammer a struggling service and never surface an unrecoverable authentication failure, which will not succeed no matter how many times it is retried. Without inspecting status codes, the client cannot apply backoff only to throttling or stop on client errors. Unbounded retries also delay alerts and consume resources.

  • ✗

    Wrap every request in a bare try/except that logs the exception and returns an empty list so the caller never fails.

    Why it's wrong here

    A bare except swallows programming errors and network faults alike, hiding the very conditions the client must detect. Returning an empty list makes a rate-limited or unauthorized call indistinguishable from a genuinely empty result set, so retries and alerts never trigger. Broad exception handling without inspecting status codes defeats the stated requirement.

  • ✓

    Inspect the response status code and branch on categories such as 401/403 for authentication, 429 for rate limiting, and 5xx for server errors before processing the body.

    Why this is correct

    HTTP status codes are the contract for request outcomes, so checking them first lets the client distinguish an expired token from throttling from an upstream fault. The client can then retry 429 responses with backoff, alert on persistent 5xx errors, and refresh credentials on 401. Reading the body only after confirming success avoids misinterpreting error payloads as data.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.