Courseiva

200-901 Cisco Platforms and Development Practice Question

A developer is writing a Python script that uses the Cisco Meraki Dashboard API. The script must read the API key from an environment variable named MERAKI_API_KEY and include it in every request. Which header should the script set?

⚠ Common exam trap

The trap here is assuming that Meraki uses a standard Authorization: Bearer header when it actually requires a vendor-specific X-Cisco-Meraki-API-Key header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

X-Cisco-Meraki-API-Key: <API_KEY>

The Meraki Dashboard API expects the API key in a custom HTTP header called X-Cisco-Meraki-API-Key. This is the only header that authenticates the request; standard Authorization or generic API key headers are ignored. Reading the key from an environment variable and placing it in that header keeps credentials out of source code while allowing the script to call Meraki endpoints successfully.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Api-Key: <API_KEY>

    Why it's wrong here

    A generic Api-Key header is not part of the Meraki Dashboard API authentication scheme. While some platforms accept such a header, Meraki requires its own prefixed header name. Using Api-Key would result in an authentication failure, so the script would not be able to read organization or network data.

  • ✓

    X-Cisco-Meraki-API-Key: <API_KEY>

    Why this is correct

    Meraki Dashboard API authenticates requests using a custom header named X-Cisco-Meraki-API-Key whose value is the API key generated in the dashboard. This header must be present on every call, and the script can populate it from the environment variable to avoid hardcoding the secret in source code.

  • ✗

    Authorization: Bearer <API_KEY>

    Why it's wrong here

    Meraki Dashboard API does not use the Bearer token scheme; it expects a custom header. Using Authorization would cause the API to return an authentication error because the server looks for the X-Cisco-Meraki-API-Key header, not a standard OAuth 2.0 bearer token, even though the value itself is valid.

  • ✗

    X-Auth-Token: <API_KEY>

    Why it's wrong here

    X-Auth-Token is used by some other REST APIs, but it is not recognized by the Meraki Dashboard API. Sending this header leaves the request unauthenticated, so the dashboard returns 401 Unauthorized. The developer must use the vendor-specific header name that Meraki documents for its API.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.