200-901 Network Fundamentals Practice Question
A developer is creating a REST API client that needs to authenticate using credentials passed in the HTTP header. Which header should be used?
⚠ Common exam trap
Watch out — candidates often confuse the Cookie header with the Authorization header because both can carry tokens, but Cisco tests the specific RFC-defined purpose of the Authorization header for direct credential transmission in REST APIs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
The Authorization header is the standard HTTP header used to transmit credentials (such as Basic, Bearer, or Digest tokens) to authenticate a REST API client. RFC 7235 defines this header as the mechanism for carrying authentication information from the client to the server, making it the correct choice for passing credentials in the HTTP header.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization
Why this is correct
The Authorization header carries credentials, typically as a Bearer token or Basic scheme, in the HTTP request. It satisfies the stem's requirement for passing credentials in the header, unlike Content-Type or Accept, which describe payload format and response preferences.
- ✗
Host
Why it's wrong here
Host identifies the target server for HTTP/1.1 routing, carrying no credentials. It is tempting because it is a mandatory request header, but it belongs in requests for virtual-host routing, whereas authentication credentials belong in the Authorization header.
- ✗
Content-Type
Why it's wrong here
Content-Type declares the media type of the request body, such as application/json, and carries no credentials. It is tempting because it is a standard request header, but authentication uses the Authorization header with the scheme and token, which this scenario requires.
- ✗
Cookie
Why it's wrong here
The Cookie header carries session state previously set by the server, not credentials supplied directly by the client. It is tempting because cookies often hold session tokens, but the scenario passes credentials in the header, which is the Authorization header's role.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.