200-901 Infrastructure and Automation Practice Question
A developer writes a Python script that calls the Cisco DNA Center Intent API. The script must authenticate once and reuse the returned token on subsequent requests instead of sending credentials with every call. Which HTTP header should the script include on each API request to present the token?
⚠ Common exam trap
The trap here is assuming the token behaves like an OAuth bearer token placed in the Authorization header, when DNA Center uses its own X-Auth-Token header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
X-Auth-Token: <token>
After authenticating to the DNA Center Intent API, clients receive a token that must be sent in the X-Auth-Token header on every subsequent request. Basic credentials, cookies, and content type headers serve different purposes and do not carry the issued token. Reusing the token reduces credential exposure and matches how the controller expects stateless API calls to be authorized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Content-Type: application/json
Why it's wrong here
This header declares the media type of the request body so the server knows how to parse it. It is required for JSON payloads but conveys no identity or authorization information. Including only this header would leave the request unauthenticated, so it cannot substitute for presenting the token obtained from the authentication endpoint.
- ✗
Authorization: Basic <base64-credentials>
Why it's wrong here
Basic authentication encodes the username and password in base64 and sends them on every request. While DNA Center accepts credentials at its authentication endpoint to obtain a token, the scenario explicitly requires reusing the token rather than resending credentials. Sending Basic credentials per call also increases exposure of secrets in logs and proxies, defeating the purpose described.
- ✓
X-Auth-Token: <token>
Why this is correct
Cisco DNA Center's authentication endpoint returns a token that clients must present in the X-Auth-Token request header on subsequent API calls. This avoids re-sending credentials and lets the controller validate the session quickly. The header name is case-insensitive per HTTP, but the exact spelling matters for clarity and for tools that generate requests from documentation examples.
- ✗
Cookie: session=<token>
Why it's wrong here
Cookies carry browser session state and are typically set by servers via Set-Cookie. The DNA Center Intent API expects the authentication token in a dedicated request header, not as an HTTP cookie. Relying on a cookie header would not authenticate the API call and would likely return a 401 response, so it does not satisfy the token reuse requirement.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.