200-901 Infrastructure and Automation Practice Question
A developer writes a script that calls a Cisco DNA Center intent API to create a new site. The first call returns HTTP 401 Unauthorized. The script already retrieved a token earlier in the same run. Which action should the script take next?
⚠ Common exam trap
The trap here is reading 401 as a permissions or method problem and changing the request shape, when it actually points to an invalid or expired token that must be refreshed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Re-authenticate to obtain a fresh token and resend the request with the new token in the header.
HTTP 401 means the authentication credential was not accepted, and the most common cause in DNA Center automation is a token that expired between acquisition and use. Re-authenticating to get a fresh token and resending the request with the updated X-Auth-Token header resolves the failure at its source and completes the site creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the HTTP method from POST to GET and resubmit the site creation payload.
Why it's wrong here
The HTTP method is unrelated to an authentication failure; a 401 is returned before the request body or verb is meaningfully processed. Switching to GET would also be semantically wrong for creating a site and would not create anything. It neither fixes the credential issue nor performs the intended operation.
- ✓
Re-authenticate to obtain a fresh token and resend the request with the new token in the header.
Why this is correct
A 401 indicates the token was rejected, most commonly because it expired between retrieval and use. Re-authenticating against the DNA Center authentication endpoint yields a new token, and resending the original request with that token in the X-Auth-Token header is the correct recovery. This addresses the actual cause rather than masking it.
- ✗
Assume the site already exists and stop the script without further action.
Why it's wrong here
Unauthorized does not mean the resource exists; it means the caller was not allowed to perform the operation with the credentials supplied. Silently stopping leaves the site uncreated and hides a real authentication defect. The script should resolve the credential problem and retry, not abandon the task.
- ✗
Retry the identical request in a tight loop until it succeeds.
Why it's wrong here
A tight retry loop against an authentication failure will keep failing because the underlying token problem is never addressed; it just floods the controller and may trigger throttling. The 401 signals that the credential presented is not accepted, so repeating the same call cannot change the outcome. The script must refresh its authentication instead.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.