200-901 Understanding and Using APIs Practice Question
A network engineer is writing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) REST API. They need to authenticate and obtain a token that will be used in subsequent API calls. Which HTTP header should be included in the authentication request to specify the expected response format?
⚠ Common exam trap
Watch out — candidates often confuse the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept: application/json
To request a JSON response from the Catalyst Center authentication endpoint, the client must include the Accept header with application/json. This header informs the server of the desired response format. Other headers serve different purposes: Content-Type describes the request body, Authorization provides credentials, and X-Auth-Token is used after authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authorization: Basic <credentials>
Why it's wrong here
The Authorization header is used to provide credentials, often in Basic authentication. While Catalyst Center authentication does require credentials, the question asks for the header that specifies the expected response format. The Authorization header does not control response format; it only authenticates the request. Including it is necessary but not sufficient for specifying JSON output.
- ✓
Accept: application/json
Why this is correct
The Accept header tells the server what media type the client expects in the response. For Cisco Catalyst Center APIs, specifying application/json ensures the authentication response is returned in JSON format, which is the standard for these APIs. This allows the script to parse the token easily and use it in later calls.
- ✗
Content-Type: application/xml
Why it's wrong here
Content-Type indicates the media type of the request body, not the expected response. Specifying application/xml would tell the server the request body is XML, which is incorrect for a JSON-based authentication request. It could cause the server to reject the request or misinterpret the payload, and it does not control the response format.
- ✗
X-Auth-Token: <token>
Why it's wrong here
X-Auth-Token is a custom header used in subsequent API calls after authentication to present the token. It is not used in the initial authentication request and does not specify response format. Using it before obtaining a token would be ineffective and would not influence the server's response media type, leading to potential errors in the script.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.