Courseiva
Network Fundamentals →mediumMultiple Choice

200-901 Network Fundamentals Practice Question

A developer is creating a REST API client that needs to authenticate using credentials passed in the HTTP header. Which header should be used?

⚠ Common exam trap

Watch out — candidates often confuse the Cookie header with the Authorization header because both can carry tokens, but Cisco tests the specific RFC-defined purpose of the Authorization header for direct credential transmission in REST APIs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization

The Authorization header is the standard HTTP header used to transmit credentials (such as Basic, Bearer, or Digest tokens) to authenticate a REST API client. RFC 7235 defines this header as the mechanism for carrying authentication information from the client to the server, making it the correct choice for passing credentials in the HTTP header.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authorization

    Why this is correct

    The Authorization header carries credentials, typically as a Bearer token or Basic scheme, in the HTTP request. It satisfies the stem's requirement for passing credentials in the header, unlike Content-Type or Accept, which describe payload format and response preferences.

  • ✗

    Host

    Why it's wrong here

    Host identifies the target server for HTTP/1.1 routing, carrying no credentials. It is tempting because it is a mandatory request header, but it belongs in requests for virtual-host routing, whereas authentication credentials belong in the Authorization header.

  • ✗

    Content-Type

    Why it's wrong here

    Content-Type declares the media type of the request body, such as application/json, and carries no credentials. It is tempting because it is a standard request header, but authentication uses the Authorization header with the scheme and token, which this scenario requires.

  • ✗

    Cookie

    Why it's wrong here

    The Cookie header carries session state previously set by the server, not credentials supplied directly by the client. It is tempting because cookies often hold session tokens, but the scenario passes credentials in the header, which is the Authorization header's role.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.