200-901 Understanding and Using APIs Practice Question
A developer sends a GET request to https://sandboxdnac.cisco.com/dna/system/api/v1/auth/token and receives an HTTP 401 Unauthorized response. The request included no Authorization header. Which HTTP request header must be added to obtain a token from Cisco DNA Center?
⚠ Common exam trap
The trap here is assuming the token endpoint accepts a Bearer token, when it actually requires the credentials themselves encoded with the Basic scheme.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization: Basic <base64(username:password)>
Cisco DNA Center issues tokens through /dna/system/api/v1/auth/token, and that endpoint authenticates the caller with HTTP Basic credentials encoded in the Authorization header. Once the controller validates the username and password, it returns a token used for later intent API calls. Other headers such as Content-Type or custom token headers do not satisfy the initial credential check.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization: Basic <base64(username:password)>
Why this is correct
Cisco DNA Center's token endpoint uses HTTP Basic authentication. The client must send the username and password Base64-encoded in the Authorization header with the Basic scheme to receive a JSON response containing a token. Without this header the controller cannot identify the caller and returns 401 Unauthorized, which matches the failure described.
- ✗
Content-Type: application/json
Why it's wrong here
Content-Type describes the body media type the client is sending. A GET token request typically has no body, and content negotiation does not authenticate the caller. Adding this header alone does not satisfy the authentication check, so Cisco DNA Center would still answer with 401 Unauthorized.
- ✗
Authorization: Bearer <token>
Why it's wrong here
A Bearer token is what the token endpoint returns, not what it accepts. Sending Authorization: Bearer to the authentication endpoint is circular because no token exists yet. The 401 would persist because Cisco DNA Center expects the initial credentials encoded with the Basic scheme, not a previously issued token.
- ✗
X-Auth-Token: <apiKey>
Why it's wrong here
X-Auth-Token is a custom header used by some Cisco controllers such as APIC-EM for subsequent calls, but it is not the mechanism Cisco DNA Center's /auth/token endpoint uses to validate initial credentials. Supplying an arbitrary API key here does not replace Basic authentication and the request remains unauthorized.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.