Courseiva

200-901 Infrastructure and Automation Practice Question

A developer is writing a Python script that authenticates to Cisco DNA Center using the token-based authentication API. The script must obtain a token and reuse it for subsequent REST calls until it expires. Which HTTP header should the script include in each subsequent API request to pass the token?

⚠ Common exam trap

The trap here is assuming that DNA Center follows the standard OAuth 2.0 Bearer token pattern, when it actually uses a custom X-Auth-Token header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

X-Auth-Token: <token>

Cisco DNA Center's token-based authentication flow returns a token from the /auth/token endpoint, and that token must be presented in the X-Auth-Token header for all subsequent API requests. Other common authentication headers like Authorization: Bearer or custom cookie schemes are not recognized by DNA Center. Using the correct header ensures the script can reuse the token until it expires, avoiding repeated authentication calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    X-Auth-Token: <token>

    Why this is correct

    Cisco DNA Center returns an authentication token in the response body when you POST to /dna/system/api/v1/auth/token with Basic Auth credentials. That token must then be supplied in the X-Auth-Token HTTP header on every subsequent API call. This is the documented and required header for token-based authentication with DNA Center, making it the correct choice for the script.

  • ✗

    Cookie: session=<token>

    Why it's wrong here

    DNA Center does not use HTTP cookies for its token-based authentication mechanism. The token is transmitted in a custom header, not as a session cookie. Relying on a Cookie header would result in the API treating the request as unauthenticated and returning an error. This approach is not supported by the DNA Center platform, so it is incorrect.

  • ✗

    Authorization: Bearer <token>

    Why it's wrong here

    Cisco DNA Center's token-based authentication uses the X-Auth-Token header, not the OAuth 2.0 Bearer scheme. While Bearer tokens are common in many REST APIs, DNA Center specifically expects the token value under X-Auth-Token. Using Authorization: Bearer would cause the API to reject the request with an authentication error, so this header is incorrect for this scenario.

  • ✗

    X-Cisco-Token: <token>

    Why it's wrong here

    There is no X-Cisco-Token header defined in the Cisco DNA Center API authentication scheme. While the name sounds plausible, the actual header is X-Auth-Token. Using a non-existent header would cause DNA Center to reject the request as unauthenticated. The developer must use the documented header name to successfully authenticate subsequent calls.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.