200-901 Understanding and Using APIs Practice Question
A developer is integrating a Python script with the Cisco Webex API to create a new team. The script sends a POST request to https://webexapis.com/v1/teams with a JSON body containing the team name. The API returns HTTP 401 Unauthorized. The developer confirms the request body and URL are correct. Which of the following is the most likely cause of the 401 response?
⚠ Common exam trap
The trap here is assuming that a 401 error is caused by a malformed request body or incorrect HTTP method, when it actually indicates missing or invalid authentication credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The request is missing a valid Authorization header with a Bearer token.
A 401 Unauthorized status code means the request lacks valid authentication credentials for the target resource. The Webex API requires an OAuth 2.0 Bearer token in the Authorization header. Without it, the API rejects the request regardless of the correctness of the URL or body. The developer must obtain a valid access token and include it in the request headers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The API endpoint requires a GET request instead of POST.
Why it's wrong here
Using the wrong HTTP method would usually return a 405 Method Not Allowed, not a 401 Unauthorized. The Webex API does accept POST for creating teams, so the method is appropriate. The 401 status clearly indicates missing or invalid authentication, not a method mismatch.
- ✗
The request is missing the Content-Type header set to application/json.
Why it's wrong here
While the Content-Type header is important for the server to parse the body correctly, omitting it would not cause a 401 Unauthorized. Instead, the server might return a 400 Bad Request or process the body incorrectly. The 401 response is specifically about authentication, not content negotiation.
- ✓
The request is missing a valid Authorization header with a Bearer token.
Why this is correct
A 401 Unauthorized response indicates that the request lacks valid authentication credentials. The Webex API requires an OAuth 2.0 Bearer token in the Authorization header. Without it, the server rejects the request even if the URL and body are correct. The developer must obtain a valid access token and include it as 'Authorization: Bearer <token>'.
- ✗
The request body is not formatted as XML.
Why it's wrong here
The Webex API expects JSON for most endpoints, not XML. However, an incorrect body format would typically result in a 400 Bad Request, not a 401 Unauthorized. A 401 specifically points to an authentication issue, so the body format is not the cause here.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.