200-901 Cisco Platforms and Development Practice Question
A developer is using the Meraki Dashboard API to list all organizations. The base URL is https://api.meraki.com/api/v1/. What is the correct endpoint and authentication method?
⚠ Common exam trap
Many candidates confuse the Meraki API's custom header authentication with more common methods like Basic Auth or Bearer tokens, or incorrectly assume the endpoint path must include the version number again.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET /organizations with X-Cisco-Meraki-API-Key header
The Meraki Dashboard API uses a custom API key for authentication, sent via the `X-Cisco-Meraki-API-Key` header. To list all organizations, the correct HTTP method is GET, and the endpoint is `/organizations` (relative to the base URL `https://api.meraki.com/api/v1/`). This matches option C exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
POST /organizations with Bearer token in Authorization header
Why it's wrong here
Listing organisations uses GET, not POST; POST /organizations would attempt to create one. The Bearer token header is right, so the error is purely the HTTP method. POST would be correct when provisioning a new organisation via the same API.
- ✗
GET /organizations with Basic Auth username and password
Why it's wrong here
The path and GET method are right, but the Meraki Dashboard API rejects Basic Auth credentials; it requires an API key supplied as a Bearer token in the Authorization header. Basic Auth suits legacy REST APIs, not Meraki.
- ✓
GET /organizations with X-Cisco-Meraki-API-Key header
Why this is correct
The Meraki Dashboard API exposes organisations at GET /organizations under the /api/v1 base URL, and authentication uses the X-Cisco-Meraki-API-Key request header carrying the dashboard API key. This matches the stem's base URL and required listing operation exactly.
- ✗
GET /v1/organizations with Cookie authentication
Why it's wrong here
The base URL already includes /api/v1, so repeating /v1 duplicates the version segment and yields an invalid path. Cookie authentication is also unsupported; the Meraki Dashboard API expects a Bearer token in the Authorization header.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.