200-901 Understanding and Using APIs Practice Question
A developer is designing a Python application that will consume multiple REST APIs from different Cisco platforms. The application must handle common API behaviors such as authentication, rate limiting, and error responses. Which TWO of the following are best practices for making the application robust and maintainable? (Choose two.)
⚠ Common exam trap
The trap here is focusing on simplicity or quick fixes, like hard-coding credentials or ignoring status codes, instead of adopting standard resilience and security practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement exponential backoff when retrying requests after receiving 5xx errors.
Implementing exponential backoff for retries and using a shared HTTP session are both best practices that enhance robustness and maintainability. Exponential backoff handles transient errors gracefully, while a session improves performance and simplifies authentication management. Together, they help build a resilient application that can handle common API behaviors effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement exponential backoff when retrying requests after receiving 5xx errors.
Why this is correct
Exponential backoff helps prevent overwhelming a server that is already experiencing issues. By increasing the delay between retries, it gives the server time to recover and reduces the chance of exacerbating the problem. This is a standard practice for handling transient errors and rate limiting.
- ✗
Ignore HTTP status codes and parse the response body for error messages.
Why it's wrong here
HTTP status codes are the standard way to determine the outcome of a request. Ignoring them can lead to incorrect handling of errors, as some APIs may return errors in the body but with a 200 status. Relying solely on the body is unreliable and can cause the application to miss critical failures.
- ✗
Hard-code API keys and tokens directly in the source code for simplicity.
Why it's wrong here
Hard-coding credentials in source code is a security risk because they can be exposed if the code is shared or stored in version control. It also makes rotation difficult. Best practice is to use environment variables or a secure secrets manager to store sensitive information.
- ✗
Always use synchronous requests to simplify code and avoid concurrency issues.
Why it's wrong here
While synchronous requests are simpler, they can block the application and reduce throughput, especially when calling multiple APIs. For robust and scalable applications, asynchronous requests or concurrency can be beneficial. However, the question asks for best practices for robustness and maintainability, and using synchronous only is not a best practice for performance.
- ✓
Use a single, shared HTTP session object for all API calls to reuse connections.
Why this is correct
Using a session object, such as requests.Session() in Python, allows connection pooling and reuse, which improves performance and reduces latency. It also can persist headers and authentication across requests, simplifying code and ensuring consistency when interacting with multiple endpoints.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.