200-901 Infrastructure and Automation Practice Question
A network automation engineer is writing a Python script that uses the Meraki Dashboard API to update the VLAN configuration on a switch. The engineer needs to send a PUT request to the endpoint /devices/{serial}/switch/ports/{portId}. Which HTTP header must be included to authenticate the request?
⚠ Common exam trap
The trap here is assuming that all REST APIs use the Authorization header for API keys, when Meraki specifically requires a custom header named X-Cisco-Meraki-API-Key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
X-Cisco-Meraki-API-Key: <API key>
The Meraki Dashboard API requires the API key to be sent in the X-Cisco-Meraki-API-Key request header. This is a custom header defined by Meraki, and it must be present on every API call. Other authentication schemes such as Bearer tokens, X-Auth-Token, or Basic authentication are not supported for Meraki API keys, so requests using them will be rejected with an authentication error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
X-Cisco-Meraki-API-Key: <API key>
Why this is correct
The Meraki Dashboard API authenticates requests using the X-Cisco-Meraki-API-Key header, which contains the API key generated in the Meraki Dashboard. Without this header, the API returns a 401 Unauthorized response. The header name is specific to Meraki and must be used exactly as documented for the request to be accepted.
- ✗
Authorization: Basic <base64(API key:)>
Why it's wrong here
Basic authentication encodes a username and password in base64. The Meraki Dashboard API does not use HTTP Basic authentication for API keys. Even if the API key were encoded, the server would not recognize it as valid credentials. This option is therefore incorrect for authenticating to the Meraki Dashboard API.
- ✗
X-Auth-Token: <API key>
Why it's wrong here
X-Auth-Token is used by some APIs, such as certain OpenStack services, but it is not the authentication header for the Meraki Dashboard API. Meraki uses a specific header name that includes the vendor name. Sending X-Auth-Token will not authenticate the request and will likely produce a 401 error.
- ✗
Authorization: Bearer <API key>
Why it's wrong here
Bearer tokens are common in OAuth 2.0 APIs, but the Meraki Dashboard API does not use Bearer authentication for its standard API keys. Using Authorization: Bearer with a Meraki API key will result in an authentication failure. Meraki expects the key in a custom header, so this option is incorrect for this scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.