Courseiva
hardMultiple Choice

200-901 Practice Question: A developer wants to automate the provisioning of…

A developer wants to automate the provisioning of a UCS server using Cisco Intersight. Which authentication method is recommended for programmatic access?

⚠ Common exam trap

Cisco often tests the distinction between interactive (session-based) and non-interactive (API key) authentication, leading candidates to mistakenly choose session tokens or basic auth because they are familiar from other Cisco platforms like UCS Manager or APIC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

API Key with HMAC signing

Cisco Intersight recommends API key authentication with HMAC signing for programmatic access because it provides a secure, non-interactive method for automation scripts and tools. The API key consists of a key ID and a secret, and each request must include an HMAC signature generated from the request details, ensuring integrity and authenticity without exposing static credentials over the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Basic authentication with username and password

    Why it's wrong here

    Basic authentication sends a static username and password with every Intersight API call, exposing long-lived credentials and lacking scoped permissions or token expiry. It is tempting for quick scripts, but Intersight recommends API key-based signing for programmatic access, which basic auth cannot provide.

  • ✓

    API Key with HMAC signing

    Why this is correct

    Intersight's API Key with HMAC signing authenticates each programmatic request using a key ID and secret, avoiding interactive browser sign-in or stored passwords. This suits automated provisioning scripts, satisfying the requirement for secure non-interactive access to the UCS management platform.

  • ✗

    Session token from Intersight UI

    Why it's wrong here

    A session token copied from the Intersight UI is short-lived and tied to an interactive browser login, so it expires and cannot sustain automated provisioning. It is tempting because it works manually, but programmatic access requires persistent API keys rather than UI session credentials.

  • ✗

    OAuth2 with client credentials

    Why it's wrong here

    Intersight's REST API authenticates programmatic calls using HTTP message signatures with API keys, not OAuth2 client-credentials grants. OAuth2 is tempting because it is a common machine-to-machine standard, but Intersight does not issue tokens through that flow, so requests would be rejected.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.