200-901 Application Deployment and Security Practice Question
A developer is writing a Python script that interacts with a REST API. The API requires authentication using a token. Which HTTP header should the developer include in the request to pass the token?
⚠ Common exam trap
It's easy for candidates to confuse API key authentication with token-based authentication, leading to the use of X-API-Key instead of the standard Authorization header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization: Bearer <token>
For REST API authentication using a token, the standard method is to include the token in the Authorization header with the Bearer scheme. This is defined in RFC 6750 for OAuth 2.0 Bearer Tokens. Other headers like X-API-Key or custom headers may be used for API keys, but when the requirement is a token, Bearer is the correct choice. Cookies are for browser sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cookie: session=<token>
Why it's wrong here
Cookies are typically used for session management in web browsers, not for API token authentication in scripts. While some APIs might accept tokens in cookies, the standard and recommended approach for REST APIs is the Authorization header. Using a cookie would be unconventional and may not be supported by the API.
- ✗
X-API-Key: <token>
Why it's wrong here
The X-API-Key header is sometimes used for API key authentication, but it is not the standard for bearer tokens. The scenario specifies a token, which implies OAuth 2.0 bearer tokens. Using X-API-Key would be incorrect unless the API documentation explicitly requires it, which is not the case here.
- ✓
Authorization: Bearer <token>
Why this is correct
The Authorization header with the Bearer scheme is the standard way to transmit a token for OAuth 2.0 and many REST APIs. It clearly indicates the token type and is widely supported. Using this header ensures the API can validate the token and grant access to the requested resource.
- ✗
Authentication: Token <token>
Why it's wrong here
There is no standard HTTP header named 'Authentication' for this purpose. The correct header is 'Authorization'. Using a non-standard header will likely be ignored by the API, resulting in an authentication failure. Developers should adhere to HTTP specifications to ensure interoperability.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.