Courseiva

200-901 Understanding and Using APIs Practice Question

A developer needs to authenticate to a REST API using an API key that must be sent in a custom HTTP header named X-API-Key on every request. The team uses Python requests. Which code snippet correctly attaches the key to a GET request?

⚠ Common exam trap

The trap here is reaching for the auth parameter by habit, when the API specifically demands a custom header that requests only sends via the headers dictionary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

requests.get(url, headers={"X-API-Key": api_key})

Custom API key headers are attached by passing a dictionary to the requests headers parameter. This places X-API-Key directly on the request, matching the server's expectation. Other transports such as Basic auth, query strings, or cookies use different header names and would not satisfy the API's authentication check, causing 401 responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    requests.get(url, auth=(api_key, ""))

    Why it's wrong here

    The auth parameter with a tuple triggers HTTP Basic authentication, which Base64-encodes the credentials into an Authorization header. The server expects X-API-Key, so Basic auth would not be recognized and the request would be rejected as unauthorized. The key would also be sent in a different header than required.

  • ✗

    requests.get(url + "?X-API-Key=" + api_key)

    Why it's wrong here

    Appending the key as a query parameter places it in the URL rather than a header. The API requires the key in the X-API-Key header, so this would fail authentication. It also exposes the secret in logs, browser history, and proxy records, which is a security risk even if the server accepted query-based keys.

  • ✗

    requests.get(url, cookies={"X-API-Key": api_key})

    Why it's wrong here

    Passing the key as a cookie sends it in the Cookie header, not X-API-Key. The server would not find the expected header and would deny the request. Cookies are also subject to domain and path scoping rules that are irrelevant here and add unnecessary complexity for a simple API key scheme.

  • ✓

    requests.get(url, headers={"X-API-Key": api_key})

    Why this is correct

    Passing a dictionary to the headers parameter adds the custom header to the outgoing request. This is the standard way to send API keys that the vendor expects in a named header. The server reads X-API-Key and authorizes the call, so this snippet matches the documented requirement exactly.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.