Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is building a script that authenticates to the Cisco DNA Center API. The documentation states that the authentication endpoint returns a token that must be included in subsequent API calls. Which authentication scheme does Cisco DNA Center expect for those subsequent calls?

⚠ Common exam trap

The trap here is assuming that any token obtained from an authentication endpoint can be placed in an arbitrary custom header, when the platform expects the standard Bearer scheme.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An Authorization header with the Bearer scheme followed by the token

Cisco DNA Center authenticates clients through a dedicated endpoint that returns a token, and that token is then presented in the Authorization header using the Bearer scheme. This keeps credentials off subsequent requests and allows the token to expire on a schedule. Basic auth, custom token headers, and session cookies do not match the documented mechanism and would not authenticate successfully.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A custom X-Auth-Token header containing the token returned by the authentication endpoint

    Why it's wrong here

    Some platforms use a custom token header, but Cisco DNA Center documents a standard bearer token in the Authorization header. Using a non-standard header name would cause the platform to treat the request as unauthenticated. Because the scenario follows DNA Center's documented behavior, a custom header is not the expected scheme and would fail against the real API.

  • ✓

    An Authorization header with the Bearer scheme followed by the token

    Why this is correct

    Cisco DNA Center's authentication endpoint returns a token that clients present in the Authorization header using the Bearer scheme, for example 'Authorization: Bearer <token>'. This is the documented mechanism for authenticating subsequent API calls, and the token expires after a set period, prompting re-authentication. It is the correct scheme for the scenario.

  • ✗

    A Cookie header containing the session identifier issued at login

    Why it's wrong here

    Cookie-based sessions are used by some web applications, but Cisco DNA Center's API is designed around a bearer token returned by its authentication endpoint. Relying on a session cookie would not match the documented flow and would likely be rejected by the API gateway. Therefore this option does not describe how DNA Center expects subsequent calls to be authenticated.

  • ✗

    HTTP Basic authentication using the username and password on every request

    Why it's wrong here

    Cisco DNA Center uses its authentication endpoint to issue a time-limited token rather than requiring credentials on each call. Sending Basic credentials on every request would ignore the documented token flow and would repeatedly transmit the password. While some APIs accept Basic auth, it is not the scheme described for DNA Center's token-based access, so this option does not match the scenario.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.