Courseiva

200-901 Cisco Platforms and Development Practice Question

A developer is using the Cisco DNA Center API and receives a token. How is this token typically used in subsequent API requests?

⚠ Common exam trap

Cisco often tests the specific header name (X-Auth-Token) versus the more generic Authorization header with Bearer scheme, so the trap here is that candidates familiar with OAuth 2.0 may incorrectly choose Option D, not realizing that Cisco DNA Center uses its own proprietary header for token transmission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the X-Auth-Token header

The Cisco DNA Center API uses token-based authentication where the token is passed in the X-Auth-Token HTTP header for subsequent requests. This is the standard method specified in the Cisco DNA Center API documentation, ensuring the server can validate the session without relying on cookies or query parameters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    As a query parameter named token

    Why it's wrong here

    Cisco DNA Center expects the token in the HTTP Authorization request header, not appended to the URL, so a query parameter named token is ignored and the call returns 401. It is tempting because query parameters do carry API keys in some other platforms, and they are visible in logs for debugging.

  • ✗

    In the request body

    Why it's wrong here

    The token belongs in the HTTP Authorization header, not the request payload, so placing it in the body leaves the header unauthenticated and the API rejects the call. It is tempting because POST bodies carry credentials in some custom authentication schemes, such as form-based login flows.

  • ✓

    In the X-Auth-Token header

    Why this is correct

    Cisco DNA Center issues a token on authentication, and subsequent calls must carry it in the X-Auth-Token HTTP header. This satisfies the API's authorisation requirement, letting the developer call protected endpoints without resending credentials each time.

  • ✗

    In the Authorization header as Bearer <token>

    Why it's wrong here

    Cisco DNA Center expects the token in the X-Auth-Token header, not the Authorization header. Bearer tokens are the OAuth 2.0 convention used by many cloud APIs, which makes this option tempting. Using the wrong header returns HTTP 401, so requests fail authentication despite a valid token.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.