200-901 Understanding and Using APIs Practice Question
A network engineer wants to retrieve the list of organizations associated with their API key from the Cisco Meraki Dashboard API. The API base URL is https://api.meraki.com/api/v1. Which HTTP request should the engineer send?
⚠ Common exam trap
Many candidates confuse the plural /organizations collection endpoint with a singular path or assuming Meraki accepts the API key as a query string, when it requires a dedicated header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET https://api.meraki.com/api/v1/organizations with the X-Cisco-Meraki-API-Key header set to the API key.
The Meraki Dashboard API lists organizations at GET /api/v1/organizations and authenticates via the X-Cisco-Meraki-API-Key request header. Using the correct path and header ensures the API key is recognized and the list of accessible organizations is returned. Alternative methods such as POST, Basic auth, or query-parameter keys are not supported for this operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
POST https://api.meraki.com/api/v1/organizations with the API key in the request body.
Why it's wrong here
POST to /organizations is used to create a new organization, not to list existing ones, and requires a body with organization details. Sending the API key in the body is not how Meraki authenticates requests. The engineer needs a read operation, so GET with the API key header is the correct approach.
- ✓
GET https://api.meraki.com/api/v1/organizations with the X-Cisco-Meraki-API-Key header set to the API key.
Why this is correct
The Meraki Dashboard API exposes organizations at the /organizations path, and authentication uses the X-Cisco-Meraki-API-Key header. A GET request to that endpoint returns the organizations the key can access. This is the documented, correct way to enumerate organizations before drilling into networks and devices.
- ✗
GET https://api.meraki.com/api/v1/organization with the API key as a query parameter.
Why it's wrong here
The correct path is plural: /organizations. The singular form /organization is not a valid endpoint. Additionally, Meraki does not accept the API key as a query parameter; it must be sent in the X-Cisco-Meraki-API-Key header. Both the path and authentication method in this option are incorrect.
- ✗
GET https://api.meraki.com/api/v1/organizations with Basic authentication using the API key as the password.
Why it's wrong here
Meraki Dashboard API expects the API key in the X-Cisco-Meraki-API-Key header, not HTTP Basic authentication. While the URL path is correct, using Basic auth will result in a 401 Unauthorized. The engineer must set the proper custom header to authenticate successfully.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.