Courseiva
Network Fundamentals →easyMultiple Choice

200-901 Network Fundamentals Practice Question

A developer is using a REST API to retrieve data from a network controller. The API requires the client to include an API key in the HTTP request header for authentication. Which HTTP header is typically used to carry the API key?

⚠ Common exam trap

The trap here is assuming that an API key must be sent in a custom header, when the standard Authorization header is the conventional and expected location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization

The Authorization header is the standard HTTP header for transmitting authentication credentials. API keys are commonly placed in this header, often with a prefix like Bearer. Other headers like Content-Type, Accept, and User-Agent serve different purposes such as content negotiation or client identification, and are not used for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User-Agent

    Why it's wrong here

    The User-Agent header identifies the client software making the request, such as a browser or script. It is not used for authentication. While some APIs might log this information, it does not provide credentials. Therefore, it is not the correct header for an API key.

  • ✗

    Content-Type

    Why it's wrong here

    The Content-Type header indicates the media type of the request or response body, such as application/json. It does not carry authentication credentials. Using it for an API key would be incorrect and could break content negotiation. The scenario requires authentication, so this header is not appropriate.

  • ✗

    Accept

    Why it's wrong here

    The Accept header tells the server what media types the client can handle in the response. It is used for content negotiation, not for authentication. Including an API key here would be ignored by the server for authentication purposes and would not satisfy the API's requirement.

  • ✓

    Authorization

    Why this is correct

    The Authorization header is the standard HTTP header used to carry credentials for authenticating a client with a server. When using an API key, it is common to include it in the Authorization header, often with a scheme like Bearer or Basic. This header is designed specifically for authentication and is the correct choice for passing an API key.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.