Courseiva

200-901 Understanding and Using APIs Practice Question

A network engineer is writing a Python script that uses the requests library to call a REST API. The API requires an API key to be passed in the header. Which HTTP header field is commonly used to transmit an API key for authentication?

⚠ Common exam trap

Many exam-takers confuse headers used for content negotiation or client identification with the header intended for authentication, leading to the selection of Content-Type or Accept.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization

Authentication credentials, including API keys, are transmitted using the Authorization header. This header is designed to carry credentials such as Bearer tokens or Basic authentication strings. Other headers like Content-Type, Accept, and User-Agent serve different purposes related to content negotiation and client identification, so they are not appropriate for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Content-Type

    Why it's wrong here

    The Content-Type header indicates the media type of the request or response body, such as application/json. It does not carry authentication credentials. Using it to send an API key would be incorrect and would likely cause the server to reject the request or misinterpret the body format, leading to errors unrelated to authentication.

  • ✗

    User-Agent

    Why it's wrong here

    The User-Agent header identifies the client software making the request, such as a browser or script name. It is used for analytics, logging, or compatibility, not for authentication. Sending an API key in User-Agent would not authenticate the request and is not a recognized practice, so the server would likely reject it.

  • ✗

    Accept

    Why it's wrong here

    The Accept header tells the server what media types the client can handle in the response, such as application/json or application/xml. It is used for content negotiation, not authentication. Placing an API key in the Accept header would not authenticate the request and could cause the server to return a 401 Unauthorized response.

  • ✓

    Authorization

    Why this is correct

    The Authorization header is the standard HTTP header for carrying credentials that authenticate a client to a server. API keys are often sent as a Bearer token or a custom scheme in this header. For example, a request might include Authorization: Bearer <api_key>. This is the correct and conventional way to transmit an API key for authentication.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.