200-901 Understanding and Using APIs Practice Question
A network engineer is writing a script to interact with a Cisco DNA Center controller. They need to authenticate and obtain a token to include in subsequent API requests. Which HTTP header should they use to send the token?
⚠ Common exam trap
Many candidates confuse the 'Basic' authentication scheme, which uses base64-encoded credentials, with the 'Bearer' scheme used for tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization: Bearer <token>
Cisco DNA Center uses OAuth 2.0 token-based authentication. After obtaining a token from the authentication endpoint, the client must include it in the 'Authorization' header using the 'Bearer' scheme. This is the correct and standard way to authenticate API requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization: Bearer <token>
Why this is correct
Cisco DNA Center uses token-based authentication where the token is sent in the 'Authorization' header with the 'Bearer' scheme. This is the standard OAuth 2.0 approach and is required for API calls after obtaining a token from the authentication endpoint.
- ✗
Authorization: Basic <token>
Why it's wrong here
The 'Basic' scheme is used for username and password authentication, not for bearer tokens. Cisco DNA Center's token-based authentication requires the 'Bearer' scheme. Using 'Basic' with a token would be incorrect and would not authenticate the request.
- ✗
Cookie: token=<token>
Why it's wrong here
Cisco DNA Center does not use cookies for API authentication. Tokens are passed in the 'Authorization' header. Sending the token as a cookie would not be recognized by the API and would result in an authentication error.
- ✗
X-Auth-Token: <token>
Why it's wrong here
While some APIs use custom headers like 'X-Auth-Token', Cisco DNA Center specifically expects the token in the standard 'Authorization' header with the 'Bearer' prefix. Using a custom header would result in an authentication failure and a 401 Unauthorized response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.