Courseiva

200-901 Understanding and Using APIs Practice Question

A network engineer is writing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) REST API. They need to authenticate and obtain a token that will be used in subsequent API calls. Which HTTP header should be included in the authentication request to specify the expected response format?

⚠ Common exam trap

Watch out — candidates often confuse the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accept: application/json

To request a JSON response from the Catalyst Center authentication endpoint, the client must include the Accept header with application/json. This header informs the server of the desired response format. Other headers serve different purposes: Content-Type describes the request body, Authorization provides credentials, and X-Auth-Token is used after authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authorization: Basic <credentials>

    Why it's wrong here

    The Authorization header is used to provide credentials, often in Basic authentication. While Catalyst Center authentication does require credentials, the question asks for the header that specifies the expected response format. The Authorization header does not control response format; it only authenticates the request. Including it is necessary but not sufficient for specifying JSON output.

  • ✓

    Accept: application/json

    Why this is correct

    The Accept header tells the server what media type the client expects in the response. For Cisco Catalyst Center APIs, specifying application/json ensures the authentication response is returned in JSON format, which is the standard for these APIs. This allows the script to parse the token easily and use it in later calls.

  • ✗

    Content-Type: application/xml

    Why it's wrong here

    Content-Type indicates the media type of the request body, not the expected response. Specifying application/xml would tell the server the request body is XML, which is incorrect for a JSON-based authentication request. It could cause the server to reject the request or misinterpret the payload, and it does not control the response format.

  • ✗

    X-Auth-Token: <token>

    Why it's wrong here

    X-Auth-Token is a custom header used in subsequent API calls after authentication to present the token. It is not used in the initial authentication request and does not specify response format. Using it before obtaining a token would be ineffective and would not influence the server's response media type, leading to potential errors in the script.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.