hardMultiple Choice
200-901 Practice Question: A developer wants to automate the provisioning of…
A developer wants to automate the provisioning of a UCS server using Cisco Intersight. Which authentication method is recommended for programmatic access?
⚠ Common exam trap
Cisco often tests the distinction between interactive (session-based) and non-interactive (API key) authentication, leading candidates to mistakenly choose session tokens or basic auth because they are familiar from other Cisco platforms like UCS Manager or APIC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
API Key with HMAC signing
Cisco Intersight recommends API key authentication with HMAC signing for programmatic access because it provides a secure, non-interactive method for automation scripts and tools. The API key consists of a key ID and a secret, and each request must include an HMAC signature generated from the request details, ensuring integrity and authenticity without exposing static credentials over the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Basic authentication with username and password
Why it's wrong here
Basic authentication sends a static username and password with every Intersight API call, exposing long-lived credentials and lacking scoped permissions or token expiry. It is tempting for quick scripts, but Intersight recommends API key-based signing for programmatic access, which basic auth cannot provide.
- ✓
API Key with HMAC signing
Why this is correct
Intersight's API Key with HMAC signing authenticates each programmatic request using a key ID and secret, avoiding interactive browser sign-in or stored passwords. This suits automated provisioning scripts, satisfying the requirement for secure non-interactive access to the UCS management platform.
- ✗
Session token from Intersight UI
Why it's wrong here
A session token copied from the Intersight UI is short-lived and tied to an interactive browser login, so it expires and cannot sustain automated provisioning. It is tempting because it works manually, but programmatic access requires persistent API keys rather than UI session credentials.
- ✗
OAuth2 with client credentials
Why it's wrong here
Intersight's REST API authenticates programmatic calls using HTTP message signatures with API keys, not OAuth2 client-credentials grants. OAuth2 is tempting because it is a common machine-to-machine standard, but Intersight does not issue tokens through that flow, so requests would be rejected.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.