200-901 Understanding and Using APIs Practice Question
A developer is building a Python script that calls the Cisco Webex Rooms API. The script must handle rate limiting gracefully by reading the response headers when the API returns HTTP 429. Which response header should the script inspect to determine how long to wait before retrying?
⚠ Common exam trap
The trap here is assuming that a custom header like X-RateLimit-Reset is always used for rate limiting, when the Webex API specifically relies on the standard Retry-After header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retry-After
When the Webex API throttles a client with HTTP 429, it includes the Retry-After header to specify the number of seconds to wait. Reading this header allows the script to implement an appropriate backoff, respecting the service's limits and avoiding further penalties. The other headers serve different purposes and do not provide rate-limit timing information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
X-RateLimit-Reset
Why it's wrong here
While some APIs use X-RateLimit-Reset to indicate when the rate limit window resets, the Cisco Webex API specifically uses the standard Retry-After header for 429 responses. Relying on X-RateLimit-Reset would be incorrect here because the Webex API does not include that header in its throttling responses, leading the script to misjudge the wait time.
- ✓
Retry-After
Why this is correct
The Retry-After header is a standard HTTP response header that indicates how many seconds the client should wait before making a follow-up request. When the Webex API returns 429 Too Many Requests, it includes Retry-After so the client can pause accordingly, avoiding further throttling and ensuring the script respects the service's rate limits.
- ✗
Location
Why it's wrong here
The Location header is used in HTTP responses to redirect the client to a different URL, such as after a 201 Created or 3xx redirect. It has no role in rate limiting. Inspecting Location on a 429 response would yield no useful information and would not help the script determine an appropriate backoff interval, causing repeated failed requests.
- ✗
WWW-Authenticate
Why it's wrong here
The WWW-Authenticate header is returned with a 401 Unauthorized response to indicate the authentication scheme required. It is unrelated to rate limiting. A script checking this header on a 429 response would not find timing guidance and would likely retry too quickly, compounding the throttling issue and potentially leading to longer blocks from the Webex API.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.