Courseiva
easyMultiple Choice

200-901 Practice Question: A developer uses Cisco Intersight API to manage…

A developer uses Cisco Intersight API to manage UCS servers. Which authentication method is required for Intersight API calls?

⚠ Common exam trap

Cisco often tests the distinction between web UI authentication (session cookies) and API authentication (HMAC keys), and candidates mistakenly choose session cookies because they are familiar from the Intersight web interface, forgetting that API calls require a different, stateless mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

API key with HMAC signature

Cisco Intersight API requires API key authentication with HMAC (Hash-Based Message Authentication Code) signing for all REST API calls. The developer generates an API key pair (private and public) in the Intersight GUI, then uses the private key to create an HMAC-SHA256 signature over the request headers and payload. This signature is included in the Authorization header, ensuring request integrity and non-repudiation without transmitting the secret key over the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    API key with HMAC signature

    Why this is correct

    Intersight REST API calls authenticate using an API key ID paired with a secret key, signing each request with HMAC-SHA256. The signature is placed in the Authorization header, so no session token or basic credentials are used.

  • ✗

    OAuth2 token from Webex

    Why it's wrong here

    Webex OAuth2 tokens authorise Webex platform APIs, not Intersight, which validates its own API key signatures. The two are separate Cisco identity systems, so a Webex token fails authorisation outright. OAuth2 from Webex is correct when building integrations against Webex messaging, meetings or calling endpoints.

  • ✗

    Session cookie

    Why it's wrong here

    Intersight API calls require a signed API key pair, not a session cookie; cookies suit browser-based interactive sessions against the Intersight UI. A session cookie would be the right mechanism when scripting against a web application that maintains server-side login state, which Intersight's REST API does not do for programmatic access.

  • ✗

    Basic authentication with username/password

    Why it's wrong here

    Intersight rejects plain username and password credentials for API calls; it requires an API key ID paired with a secret used to sign each request. Basic authentication is the correct choice for legacy device APIs, such as older UCS Manager XML endpoints, that expose no token or key-based scheme.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.