Courseiva

200-901 Cisco Platforms and Development Practice Question

A developer is writing a Python script that uses the Cisco Meraki Dashboard API to update the VLAN configuration of a network. The script reads the API key from an environment variable and places it in the appropriate request header. Which header should the developer set, and what happens if the key is invalid?

⚠ Common exam trap

The trap here is assuming Meraki uses the same bearer-token authorization header as OAuth-based Cisco APIs, which leads to sending credentials in the wrong place.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 401 Unauthorized response

The Meraki Dashboard API uses a purpose-built header for API key authentication rather than standard HTTP bearer tokens. Placing the organization key in X-Cisco-Meraki-API-Key authenticates the call, and an invalid or revoked key yields a 401 Unauthorized response. Reading the key from an environment variable keeps credentials out of source control while still populating the correct header.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set Authorization to a Bearer token; an invalid key produces an HTTP 403 Forbidden response

    Why it's wrong here

    Bearer tokens belong to OAuth 2.0 flows, not the Meraki Dashboard API key scheme. Supplying the key this way would leave the request unauthenticated, and the server would return 401 rather than 403. The scenario explicitly uses an API key, so a bearer header is the wrong mechanism and the stated status code is also wrong.

  • ✓

    Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 401 Unauthorized response

    Why this is correct

    The Meraki Dashboard API authenticates requests with a dedicated header named X-Cisco-Meraki-API-Key carrying the organization's key. When that key is missing, revoked, or malformed, the dashboard rejects the call with a 401 Unauthorized status. This matches the scenario's requirement to read the key from an environment variable and place it in the correct header.

  • ✗

    Set X-Cisco-Meraki-API-Key; an invalid key produces an HTTP 404 Not Found response

    Why it's wrong here

    The header name is correct, but the failure status is not. Authentication failures are reported as 401 Unauthorized, whereas 404 indicates that the addressed resource does not exist. A script that keys error handling off 404 would misclassify a revoked API key as a missing VLAN, leading to incorrect retry or logging behaviour.

  • ✗

    Set X-Meraki-Token; an invalid key produces an HTTP 429 Too Many Requests response

    Why it's wrong here

    There is no X-Meraki-Token header in the Meraki Dashboard API, and 429 signals rate limiting rather than authentication failure. A request carrying a nonexistent header would simply be treated as anonymous and rejected with 401. Both the header name and the failure status described here are incorrect for this API.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.