Courseiva

200-901 Cisco Platforms and Development Practice Question

A developer is writing a script that uses the Cisco DNA Center Intent API to retrieve a list of all sites in the network hierarchy. The developer needs to authenticate first. Which authentication method should be used to obtain a token for subsequent API calls?

⚠ Common exam trap

The trap here is assuming DNA Center uses API keys or OAuth 2.0, when it actually requires Basic authentication to obtain an X-Auth-Token.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send a POST request to /dna/system/api/v1/auth/token with Basic authentication using the username and password.

Cisco DNA Center's Intent API uses a token-based authentication flow. The client sends a POST to /dna/system/api/v1/auth/token with HTTP Basic authentication, and the response includes a token. That token is then sent in the X-Auth-Token header for subsequent API calls, such as retrieving the site hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Send a POST request to /dna/system/api/v1/auth/token with Basic authentication using the username and password.

    Why this is correct

    Cisco DNA Center's Intent API requires obtaining a token by posting to /dna/system/api/v1/auth/token with Basic authentication. The response contains a token that must be included in the X-Auth-Token header for subsequent calls. This is the documented authentication flow for DNA Center.

  • ✗

    Use OAuth 2.0 client credentials flow with a client ID and secret to obtain an access token.

    Why it's wrong here

    While some Cisco platforms support OAuth, DNA Center's Intent API authentication uses Basic auth to obtain an X-Auth-Token, not OAuth 2.0 client credentials. The client ID and secret flow is not the documented method for DNA Center token acquisition. This option describes a different authentication model.

  • ✗

    Send a POST request to /dna/system/api/v1/auth/token with the username and password in the JSON body.

    Why it's wrong here

    The DNA Center token endpoint expects Basic authentication in the Authorization header, not credentials in the JSON body. Sending credentials in the body is not supported and would result in an authentication error. The correct method uses the Authorization header with base64-encoded credentials.

  • ✗

    Send a GET request to /dna/system/api/v1/auth/token with an API key in the query string.

    Why it's wrong here

    DNA Center does not use API keys in query strings for authentication. The token endpoint requires a POST with Basic authentication, not a GET with an API key. Using this method would fail because the endpoint expects credentials in the Authorization header.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.