Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is writing a Python script that calls the Cisco Webex Teams API. The script must handle the case where the access token has expired. Which HTTP status code should the script check for to detect an expired or invalid token?

⚠ Common exam trap

A common mix-up: candidates confuse 401 Unauthorized with 403 Forbidden, when only 401 specifically signals that the token is missing, expired, or invalid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

401 Unauthorized

Cisco Webex APIs return HTTP 401 Unauthorized when the access token is expired, revoked, or invalid. The client should detect this status and trigger a token refresh or re-authentication flow. Other status codes such as 403, 404, or 429 represent different conditions and would not correctly identify an expired token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    403 Forbidden

    Why it's wrong here

    403 Forbidden means the server understood the request but refuses to authorize it, often due to insufficient permissions. While it can occur with valid tokens lacking scope, it is not the primary signal for an expired token. Cisco Webex returns 401 for invalid or expired tokens, so checking 403 would miss the expiration case.

  • ✓

    401 Unauthorized

    Why this is correct

    HTTP 401 Unauthorized indicates that the request lacks valid authentication credentials. For Cisco Webex APIs, an expired or invalid access token produces a 401 response. The client should then refresh the token or re-authenticate. Checking for 401 allows the script to handle token expiration gracefully.

  • ✗

    429 Too Many Requests

    Why it's wrong here

    429 Too Many Requests signals rate limiting, not authentication failure. It occurs when the client exceeds allowed request frequency. While important to handle, it is unrelated to token expiration. The script should check 401 for expired tokens and handle 429 separately with backoff.

  • ✗

    404 Not Found

    Why it's wrong here

    404 Not Found indicates the requested resource does not exist. It has no relationship to authentication or token validity. An expired token would not cause a 404 unless the URL itself were wrong. The developer should check for 401 to detect authentication failures.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.