Courseiva

200-901 Application Deployment and Security Practice Question

A developer is writing a REST API client in Python that authenticates to a controller using HTTP Basic authentication over the network. The developer wants to ensure credentials are never exposed on the wire in readable form. Which implementation detail is required?

⚠ Common exam trap

The trap here is believing that Base64 encoding or client-side hashing conceals credentials, when only transport encryption actually prevents an observer from reading them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send the request only over HTTPS so the TLS session encrypts the Authorization header in transit.

HTTP Basic authentication provides no confidentiality of its own; it merely encodes the credentials. Protecting them requires an encrypted transport, which TLS provides for the whole request and response. Encoding, relocating, or hashing the credential on the client changes its representation without hiding it from an observer, so only a TLS-protected connection keeps credentials unreadable in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send the credentials in a custom request header that the server is configured to read.

    Why it's wrong here

    A custom header changes where the credentials appear but not whether they are protected. Any intermediary or observer on the path can read header values just as easily as standard ones. Unless the connection itself is encrypted, moving the credential to a different header provides no confidentiality.

  • ✗

    Hash the password with SHA-256 and send the digest in place of the password.

    Why it's wrong here

    Hashing the password client-side makes the hash itself the effective credential, so a captured hash can be replayed by an attacker. It also breaks server-side verification unless the server stores matching digests, which changes the authentication protocol. This does not deliver transport confidentiality.

  • ✗

    Base64-encode the username and password and place the result in the Authorization header.

    Why it's wrong here

    Base64 is a reversible encoding, not encryption, so anyone capturing the traffic can decode the credentials instantly. HTTP Basic authentication already performs this encoding as part of the scheme, so doing it manually adds no protection. Without a TLS tunnel the credentials remain effectively plaintext on the wire.

  • ✓

    Send the request only over HTTPS so the TLS session encrypts the Authorization header in transit.

    Why this is correct

    HTTP Basic authentication transmits credentials in an easily decoded form, so confidentiality must come from the transport. TLS encrypts the entire request, including the Authorization header, between client and server. This is the standard and expected way to protect Basic credentials, and it also protects the response and any tokens exchanged during the session.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.