200-901 Cisco Platforms and Development Practice Question
A developer is using the Cisco DNA Center API and receives a token. How is this token typically used in subsequent API requests?
⚠ Common exam trap
Cisco often tests the specific header name (X-Auth-Token) versus the more generic Authorization header with Bearer scheme, so the trap here is that candidates familiar with OAuth 2.0 may incorrectly choose Option D, not realizing that Cisco DNA Center uses its own proprietary header for token transmission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the X-Auth-Token header
The Cisco DNA Center API uses token-based authentication where the token is passed in the X-Auth-Token HTTP header for subsequent requests. This is the standard method specified in the Cisco DNA Center API documentation, ensuring the server can validate the session without relying on cookies or query parameters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
As a query parameter named token
Why it's wrong here
Cisco DNA Center expects the token in the HTTP Authorization request header, not appended to the URL, so a query parameter named token is ignored and the call returns 401. It is tempting because query parameters do carry API keys in some other platforms, and they are visible in logs for debugging.
- ✗
In the request body
Why it's wrong here
The token belongs in the HTTP Authorization header, not the request payload, so placing it in the body leaves the header unauthenticated and the API rejects the call. It is tempting because POST bodies carry credentials in some custom authentication schemes, such as form-based login flows.
- ✓
In the X-Auth-Token header
Why this is correct
Cisco DNA Center issues a token on authentication, and subsequent calls must carry it in the X-Auth-Token HTTP header. This satisfies the API's authorisation requirement, letting the developer call protected endpoints without resending credentials each time.
- ✗
In the Authorization header as Bearer <token>
Why it's wrong here
Cisco DNA Center expects the token in the X-Auth-Token header, not the Authorization header. Bearer tokens are the OAuth 2.0 convention used by many cloud APIs, which makes this option tempting. Using the wrong header returns HTTP 401, so requests fail authentication despite a valid token.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.