Courseiva

200-901 Cisco Platforms and Development Practice Question

A network administrator wants to use Cisco Webex APIs to automate sending messages to a specific room. Which THREE pieces of information are required to send a message using POST /v1/messages?

⚠ Common exam trap

200-901 often tests the confusion between Meraki API keys (X-Cisco-Meraki-API-Key) and Webex Bearer tokens — candidates who memorize 'Cisco API key' headers pick the wrong authentication method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Message body as plain text or markdown

Option B is correct because POST /v1/messages requires a message payload, and the Webex Messages API accepts the content as either plain text or markdown in the request body. Option C is correct because the API requires a target destination, specified as either the roomId of the room or the toPersonEmail of the recipient. Option E is correct because every Webex API request must be authenticated with an OAuth Bearer token in the Authorization header. Option A is incorrect because X-Cisco-Meraki-API-Key is used for the Meraki Dashboard API, not Webex messaging. Option D is incorrect because the Messages API does not require the recipient's user ID; it targets a room ID or recipient email instead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    X-Cisco-Meraki-API-Key header

    Why it's wrong here

    The Meraki API key authenticates against the Meraki Dashboard API, not Webex messaging; POST /v1/messages requires a Webex bearer token plus the roomId and message text. The Meraki header would be correct when automating Meraki network devices, not Webex room messaging.

  • ✓

    Message body as plain text or markdown

    Why this is correct

    The request payload must carry the actual content to deliver, supplied as the message field in JSON, formatted as plain text or markdown. This satisfies the stem's requirement for the message content itself, distinct from routing and authentication data.

  • ✓

    Room ID or email of the recipient

    Why this is correct

    The destination must be specified, either as a roomId or as a toPersonEmail value, so the API knows which room or recipient receives the message. This satisfies the routing constraint, distinguishing the target from the authentication token and message content.

  • ✗

    User ID of the recipient

    Why it's wrong here

    POST /v1/messages requires the roomId, the message text, and a valid bearer token; a recipient's user ID is unnecessary because messages post to a room, not a person. It tempts when thinking of direct messaging, but Webex rooms address destinations by roomId.

  • ✓

    Bearer token for authentication

    Why this is correct

    POST /v1/messages requires an OAuth 2.0 access token supplied in the HTTP Authorization header as a Bearer credential. This satisfies the authentication constraint, proving the caller's identity and authorising the message send against the Webex API.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.