Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is testing a REST API endpoint using curl. The API requires an API key to be sent in the HTTP header 'X-API-Key'. Which curl command correctly includes the API key?

⚠ Common exam trap

Candidates often confuse curl options: -d sends body data, -u is for Basic Auth, and -G modifies query strings, but only -H adds a custom header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

curl -H "X-API-Key: abc123" https://api.example.com/resource

The -H flag in curl is used to add custom headers to an HTTP request. Since the API requires the API key in the 'X-API-Key' header, using -H with the appropriate header string is the correct approach. This ensures the key is transmitted as an HTTP header, which the API will validate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    curl -G "X-API-Key=abc123" https://api.example.com/resource

    Why it's wrong here

    The -G option converts data specified with -d into a query string. However, without -d, it does nothing. Even if used with -d, it would append the key as a URL parameter, not a header. The API expects the key in a header, so this would fail authentication.

  • ✓

    curl -H "X-API-Key: abc123" https://api.example.com/resource

    Why this is correct

    The -H option in curl allows adding a custom header to the request. Specifying 'X-API-Key: abc123' correctly sets the required header. This is the standard way to pass an API key when the API expects it in a header, and it ensures the key is sent securely over HTTPS.

  • ✗

    curl -u "X-API-Key:abc123" https://api.example.com/resource

    Why it's wrong here

    The -u option is used for HTTP Basic Authentication, which expects a username and password separated by a colon. Using it with 'X-API-Key:abc123' would send the string as Basic Auth credentials, not as a custom header, and the API would not interpret it correctly.

  • ✗

    curl -d "X-API-Key=abc123" https://api.example.com/resource

    Why it's wrong here

    The -d option sends data in the request body, typically for POST requests. This would not set a header and would instead send the API key as form data, which the API would not recognize. It also changes the request method to POST by default, which may not be appropriate for the endpoint.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.