200-901 Infrastructure and Automation Practice Question
A developer is writing a Python script that will authenticate to a Cisco DNA Center controller and then call multiple REST API endpoints. The script must handle authentication securely and manage the token lifecycle. Which two practices should the developer follow? (Choose two.)
⚠ Common exam trap
The trap here is treating authentication as something to repeat for every call, when tokens are meant to be cached and reused until they expire.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the username and password in environment variables or a secrets manager rather than in the script.
Secure automation requires protecting credentials and managing tokens efficiently. Storing secrets outside the code prevents leaks, and reusing a valid token until expiration avoids unnecessary authentication calls. The other options either weaken security or add avoidable overhead that can trigger rate limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store the username and password in environment variables or a secrets manager rather than in the script.
Why this is correct
Credentials embedded in source code can leak through version control, logs, or shared repositories. Reading them from environment variables or a secrets manager keeps them out of the codebase and supports rotation. This is a foundational secure coding practice for API automation.
- ✗
Disable TLS certificate verification to simplify HTTPS calls to the controller.
Why it's wrong here
Disabling certificate verification exposes the script to man-in-the-middle attacks and defeats the purpose of HTTPS. While it may bypass certificate errors during testing, it is not a secure practice for production automation and should never be recommended.
- ✓
Reuse the authentication token for all subsequent API calls until it expires, then obtain a new one.
Why this is correct
Cisco DNA Center returns a token with a limited lifetime. Reusing it avoids unnecessary authentication calls and reduces load on the controller. When the token expires, the script should detect the expiration and request a new token rather than failing.
- ✗
Call the authentication endpoint before every API request to guarantee a fresh token.
Why it's wrong here
Authenticating before every request adds significant overhead and can trigger rate limiting on the controller. Tokens are designed to be reused until expiration. This practice is inefficient and does not improve security in a meaningful way.
- ✗
Hardcode the token in the script to avoid repeated authentication calls during development.
Why it's wrong here
Hardcoding a token is insecure because tokens grant access to the controller and can be extracted from the script. Tokens also expire, so a hardcoded value will eventually fail. This practice creates both security and reliability problems.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.