Courseiva

200-901 Infrastructure and Automation Practice Question

A developer is writing a Python script that will authenticate to a Cisco DNA Center controller and then call multiple REST API endpoints. The script must handle authentication securely and manage the token lifecycle. Which two practices should the developer follow? (Choose two.)

⚠ Common exam trap

The trap here is treating authentication as something to repeat for every call, when tokens are meant to be cached and reused until they expire.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the username and password in environment variables or a secrets manager rather than in the script.

Secure automation requires protecting credentials and managing tokens efficiently. Storing secrets outside the code prevents leaks, and reusing a valid token until expiration avoids unnecessary authentication calls. The other options either weaken security or add avoidable overhead that can trigger rate limits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store the username and password in environment variables or a secrets manager rather than in the script.

    Why this is correct

    Credentials embedded in source code can leak through version control, logs, or shared repositories. Reading them from environment variables or a secrets manager keeps them out of the codebase and supports rotation. This is a foundational secure coding practice for API automation.

  • ✗

    Disable TLS certificate verification to simplify HTTPS calls to the controller.

    Why it's wrong here

    Disabling certificate verification exposes the script to man-in-the-middle attacks and defeats the purpose of HTTPS. While it may bypass certificate errors during testing, it is not a secure practice for production automation and should never be recommended.

  • ✓

    Reuse the authentication token for all subsequent API calls until it expires, then obtain a new one.

    Why this is correct

    Cisco DNA Center returns a token with a limited lifetime. Reusing it avoids unnecessary authentication calls and reduces load on the controller. When the token expires, the script should detect the expiration and request a new token rather than failing.

  • ✗

    Call the authentication endpoint before every API request to guarantee a fresh token.

    Why it's wrong here

    Authenticating before every request adds significant overhead and can trigger rate limiting on the controller. Tokens are designed to be reused until expiration. This practice is inefficient and does not improve security in a meaningful way.

  • ✗

    Hardcode the token in the script to avoid repeated authentication calls during development.

    Why it's wrong here

    Hardcoding a token is insecure because tokens grant access to the controller and can be extracted from the script. Tokens also expire, so a hardcoded value will eventually fail. This practice creates both security and reliability problems.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.