Courseiva

200-901 Infrastructure and Automation Practice Question

A developer is writing a Python script that authenticates to the Cisco DNA Center REST API. The script must include an authentication token in the HTTP headers of every subsequent API call. Which HTTP header should the developer populate with the token returned by the authentication endpoint?

⚠ Common exam trap

The trap here is assuming that a token is always sent with the standard Authorization: Bearer header, when DNA Center specifically requires X-Auth-Token.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

X-Auth-Token

DNA Center issues a time-limited token from its authentication endpoint, and every subsequent REST call must present that token in the X-Auth-Token request header. Standard OAuth schemes, invented vendor headers, and cookie-based sessions are not honored by the controller, so only the documented X-Auth-Token header will authenticate the script successfully.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    X-Auth-Token

    Why this is correct

    Cisco DNA Center returns a token from the /dna/system/api/v1/auth/token endpoint that must be sent in the X-Auth-Token header on all subsequent requests. This is the vendor-specific header name DNA Center enforces for token-based authentication, so the script will receive 401 Unauthorized responses if it places the token anywhere else.

  • ✗

    Authorization: Bearer

    Why it's wrong here

    The Bearer scheme belongs to OAuth 2.0 and is used by many cloud APIs, but DNA Center does not validate the token through this header. Sending the token as a Bearer credential results in an authentication failure because the controller expects its own X-Auth-Token header instead of a standard Authorization field.

  • ✗

    Cookie: sessionToken

    Why it's wrong here

    DNA Center does not use cookie-based session tokens for its REST API. Developers sometimes assume web-style cookies carry the token, but the platform is stateless and requires the token in the X-Auth-Token header, so a Cookie header will not authenticate any request.

  • ✗

    X-Cisco-Token

    Why it's wrong here

    X-Cisco-Token is not a header recognized by the DNA Center platform. Although it sounds vendor-specific, the actual header is X-Auth-Token; using X-Cisco-Token causes the API to treat the request as unauthenticated and return an error, so the script would need to be corrected.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.