hardMultiple Choice
200-901 Practice Question: A developer is integrating with Cisco SD-WAN…
A developer is integrating with Cisco SD-WAN vManage using REST APIs. After successfully submitting credentials, the API returns a 401 Unauthorized error for subsequent requests. What is the most likely missing step?
⚠ Common exam trap
Cisco often tests the distinction between session cookies and CSRF tokens, trapping candidates who assume that a successful login alone (cookie) is enough for all subsequent API calls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session token (X-XSRF-TOKEN) must be obtained and included in subsequent requests.
Cisco SD-WAN vManage uses a two-step authentication process: first, credentials are submitted to obtain a session token (X-XSRF-TOKEN) and a JSESSIONID cookie. If subsequent API requests do not include the X-XSRF-TOKEN in the HTTP header, vManage rejects them with a 401 Unauthorized error, as the token is required for CSRF protection and session validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The request URL must include an API key parameter.
Why it's wrong here
vManage authenticates via a session token obtained from the login endpoint, not a static API key query parameter; no such key exists for this API. A 401 after valid credentials means the JWT is absent from the Authorization header. API keys suit services like Meraki or DNA Center, not vManage.
- ✗
The API call must use the HTTPS protocol.
Why it's wrong here
vManage already serves its REST API over HTTPS, so the protocol is not what causes a 401 after successful authentication. The missing step is capturing the returned session token (JWT) and sending it in subsequent request headers. HTTPS would be the answer only if the endpoint were plain HTTP.
- ✗
The password must be sent in base64 encoding.
Why it's wrong here
Base64 encoding is what HTTP Basic authentication already applies to the credentials, so it adds nothing to the login exchange. The 401 arises because the JWT returned by vManage is not included in later requests. Base64 encoding would matter only when manually constructing a Basic auth header.
- ✓
The session token (X-XSRF-TOKEN) must be obtained and included in subsequent requests.
Why this is correct
Cisco SD-WAN vManage uses cookie-based session authentication: the login response sets a JSESSIONID cookie plus an X-XSRF-TOKEN header value. Subsequent REST calls must replay both, otherwise vManage rejects them with 401 despite valid credentials. Capturing the token from the authentication response satisfies the stem's requirement for authenticated follow-up requests.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.