Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is designing a Python script that interacts with multiple Cisco APIs, including Cisco Webex and Cisco DNA Center. The script must authenticate to each API and handle tokens securely. Which TWO of the following practices are recommended for securely managing API credentials and tokens? (Choose two.)

⚠ Common exam trap

The trap here is underestimating the risk of hard-coding or logging credentials, which are common but dangerous shortcuts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store API keys and tokens in environment variables or a secure vault, and retrieve them at runtime.

The recommended practices are to store credentials securely (e.g., environment variables or vault) and to implement token refresh logic. These reduce the risk of credential leakage and ensure uninterrupted API access. Hard-coding, logging tokens, and sharing via email are insecure and should be avoided.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store API keys and tokens in environment variables or a secure vault, and retrieve them at runtime.

    Why this is correct

    Using environment variables or a secure vault keeps credentials out of source code, reducing the risk of accidental exposure. It allows for different configurations across environments and facilitates rotation. This is a widely recommended practice for managing secrets in applications.

  • ✗

    Share API tokens with team members via email to facilitate collaboration.

    Why it's wrong here

    Sharing tokens via email is insecure as email is not encrypted end-to-end and can be intercepted. Tokens should be distributed through secure channels like a password manager or vault. Each user should have their own credentials to maintain accountability.

  • ✓

    Implement token refresh logic to automatically obtain a new access token when the current one expires, using a refresh token.

    Why this is correct

    Token refresh logic ensures continuous access without manual intervention, improving security by limiting the lifetime of access tokens. Using refresh tokens allows the application to obtain new access tokens without re-prompting the user, which is essential for long-running scripts.

  • ✗

    Log the full API request and response, including Authorization headers, to aid in debugging.

    Why it's wrong here

    Logging Authorization headers exposes sensitive tokens in log files, which can be accessed by unauthorized users. Debugging should be done with redacted headers or in a secure environment. Best practices dictate never logging credentials or tokens.

  • ✗

    Hard-code API keys directly in the Python script for simplicity and ease of deployment.

    Why it's wrong here

    Hard-coding credentials in source code is insecure because they can be exposed if the code is shared, committed to version control, or decompiled. It also makes rotation difficult. This practice is strongly discouraged in favor of externalized secrets management.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.