Courseiva

200-901 Cisco DNA Center API Authentication Practice Question

A developer is building an automation script to retrieve network device details from Cisco DNA Center. The script needs to authenticate and then call the device list API. Which THREE steps are required in the correct sequence?

⚠ Common exam trap

The exam often tests the correct order of steps for Cisco DNA Center API authentication. Candidates may forget that the GET request to retrieve devices is a distinct step in the sequence and may incorrectly assume that steps C and D are sufficient. Additionally, they may confuse token-based authentication with cookie-based or query parameter authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send a GET request to /dna/intent/api/v1/network-device

The correct sequence begins with D: the script must POST to /dna/system/api/v1/auth/token using HTTP Basic Auth (base64-encoded username:password) to obtain a JWT token from Cisco DNA Center. Next, C is required because that token must be presented on every subsequent API call in the Authorization header using the Bearer scheme (Authorization: Bearer <token>), which is how DNA Center validates the caller. Finally, A is required because the device inventory is retrieved with a GET request to /dna/intent/api/v1/network-device, the Intent API endpoint that returns the network device list. Option B is incorrect because DNA Center's token-based authentication does not rely on HTTP cookies. Option E is incorrect because the token must be sent in the Authorization header, not as a query parameter, which would be insecure and unsupported.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Send a GET request to /dna/intent/api/v1/network-device

    Why this is correct

    Correct. After authenticating and obtaining the token, the GET request to /dna/intent/api/v1/network-device is the step that retrieves the device list. It must include the Bearer token in the Authorization header, which is established in the previous step (option C).

  • ✗

    Enable cookie-based authentication in the HTTP client

    Why it's wrong here

    DNA Center issues a time-limited token via its authentication API; the script must capture and resend that token, so enabling cookie-based authentication in the HTTP client does not satisfy the flow. Cookies suit session-based web applications that maintain server-side login state.

  • ✓

    Use the token in the Authorization header as Bearer token for subsequent requests

    Why this is correct

    After obtaining the token from the authentication endpoint, the script must include it in the Authorization header as a Bearer token on each subsequent API call. This satisfies the authentication requirement for calling the device list API.

  • ✓

    Send a POST request to /dna/system/api/v1/auth/token with Basic Auth

    Why this is correct

    Basic Auth credentials are exchanged at the token endpoint, returning a time-limited JWT that must accompany subsequent DNA Center API calls. This satisfies the stem's authentication requirement, since the device list API rejects unauthenticated requests and expects the token in the X-Auth-Token header.

  • ✗

    Include the token as a query parameter in the device list request

    Why it's wrong here

    Cisco DNA Center's token-based authentication expects the token in the X-Auth-Token HTTP header, not as a query parameter, so the device list call would be rejected as unauthenticated. Query parameters suit filtering or pagination on API requests, not credential transport.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.