200-901 Software Development and Design Practice Question
A developer is designing a Python script that needs to make multiple REST API calls to different endpoints sequentially. The script must handle the following requirements: (1) Use a variable timeout for each request, (2) Include an authorization token in every request, (3) Parse JSON responses. Which TWO features of the requests library should be used? (Choose two.)
⚠ Common exam trap
Cisco often tests the distinction between the `auth` parameter (for Basic Auth) and the `headers` parameter (for bearer tokens), causing candidates to mistakenly choose Option D when they should use Option E.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the `timeout` parameter to specify a maximum wait time.
Option B is correct because the requests library's timeout parameter accepts a float or tuple (connect, read) value that sets the maximum number of seconds to wait for a response, directly satisfying the requirement for a variable timeout on each request. Option E is correct because the headers parameter takes a dictionary such as {'Authorization': 'Bearer <token>'}, which is the standard way to attach an authorization token to every request. Option A is not correct because the data parameter is used for form-encoded or raw request bodies, not for parsing JSON responses, and JSON bodies are typically sent via the json parameter. Option C is not correct because verify=False disables TLS certificate verification, which is a security risk and unrelated to timeouts, tokens, or JSON parsing. Option D is not correct because the auth parameter expects an authentication handler or a (username, password) tuple for HTTP Basic/Digest auth, not a token, and tokens belong in headers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the `data` parameter to JSON for request body.
Why it's wrong here
The `data` parameter sends form-encoded bodies, not JSON, so it fails the JSON parsing requirement; `json=` is the correct parameter for JSON payloads. It is tempting because `data` does carry request bodies, and it is correct when posting form-encoded content rather than JSON.
- ✓
Use the `timeout` parameter to specify a maximum wait time.
Why this is correct
The `timeout` parameter sets a per-request maximum wait in seconds, satisfying requirement (1) for a variable timeout on each sequential call. Passing a distinct value to each `requests.get()` or `requests.post()` invocation prevents a slow endpoint from blocking the script indefinitely.
- ✗
Use `verify=False` to speed up requests.
Why it's wrong here
Disabling TLS certificate verification removes transport security and does nothing for timeouts, tokens or JSON parsing, so it fails every stated requirement. It is tempting when debugging self-signed certificates, where `verify=False` legitimately bypasses validation errors, but that is a troubleshooting shortcut, not a design feature.
- ✗
Set the `auth` parameter with a tuple (username, token).
Why it's wrong here
The `auth` tuple triggers HTTP Basic authentication, which base64-encodes credentials rather than sending the bearer token the API expects. It is tempting because `auth` is the library's standard credential mechanism, and it would be correct for endpoints using Basic authentication instead of token-based authorisation.
- ✓
Use the `headers` parameter to include the authorization token.
Why this is correct
The `headers` parameter accepts a dictionary, so an authorization token can be attached to every request, meeting requirement (2). Passing `{'Authorization': 'Bearer <token>'}` to each call ensures the token accompanies all sequential REST API calls without altering the URL or body.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.