200-901 Understanding and Using APIs Practice Question
A developer needs to use Postman to test an API that uses Basic authentication. How should the credentials be configured in Postman?
⚠ Common exam trap
200-901 often tests the difference between authentication schemes — candidates confuse Basic (Base64 user:pass) with Bearer (token) and pick the option that mentions Base64 but uses the wrong scheme or location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Authorization tab, select Basic Auth, and enter username and password
Postman's Authorization tab provides a built-in Basic Auth type where you enter the username and password; Postman automatically Base64-encodes them and constructs the 'Authorization: Basic <credentials>' header per RFC 7617. This is the correct and standard way to configure Basic authentication in Postman.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send the credentials in the request body as JSON
Why it's wrong here
Basic authentication transmits credentials in the Authorization header as base64(username:password); the request body carries payload data, not authentication. Postman's Authorization tab, set to Basic Auth, builds that header automatically. Body-based credentials suit APIs that define custom JSON login fields, not the Basic scheme.
- ✓
Use the Authorization tab, select Basic Auth, and enter username and password
Why this is correct
Configuring Basic Auth on the Authorization tab injects the credentials as a Base64-encoded `Authorization: Basic` header on every request, satisfying the stem's requirement to test a Basic-authenticated API. Postman handles encoding automatically, so the username and password need not be manually concatenated or encoded before sending.
- ✗
Set the Authorization header to 'Bearer base64(username:password)'
Why it's wrong here
The Bearer scheme expects an OAuth 2.0 access token, not base64-encoded credentials. Basic authentication uses the scheme name 'Basic' followed by base64(username:password) in the Authorization header. Bearer tokens are correct when the API delegates authentication to an authorisation server issuing access tokens.
- ✗
Add a query parameter 'auth' with base64-encoded credentials
Why it's wrong here
Basic authentication places base64(username:password) in the Authorization header; query parameters appear in URLs, logs and browser history, exposing credentials. Postman's Authorization tab with Basic Auth constructs the header. Query-string credentials suit only APIs explicitly designed to accept an API key that way.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.