easyMultiple Choice
200-901 Practice Question: A Python script uses the Cisco Meraki API to…
A Python script uses the Cisco Meraki API to fetch the list of organizations. The script fails with a 401 HTTP status. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between HTTP 401 (authentication failure) and 403 (authorization failure), and candidates frequently confuse these status codes, especially when the API key is valid but lacks permissions for a specific resource.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The API key is invalid or missing.
A 401 HTTP status indicates 'Unauthorized', which in the context of the Meraki API means the request lacks valid authentication credentials. The most common cause is an invalid or missing API key, as the Meraki API requires a valid API key in the `X-Cisco-Meraki-API-Key` header for all requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The API key is invalid or missing.
Why this is correct
A 401 status signals failed authentication, and the Meraki Dashboard API authenticates every request via the `X-Cisco-Meraki-API-Key` header. An invalid, revoked, or absent key therefore satisfies the stem's authentication-failure constraint directly, whereas authorisation, rate-limiting, or endpoint errors return 403, 429, or 404 respectively.
- ✗
The API request exceeded the rate limit.
Why it's wrong here
Rate limiting returns HTTP 429, not 401, so exceeding the quota cannot produce this status. It is tempting because heavy polling commonly triggers throttling, and rate-limit handling would be the correct diagnosis when the script receives 429 responses with Retry-After headers.
- ✗
The API key does not have permission to list organizations.
Why it's wrong here
A 401 signals missing, malformed or invalid credentials, which Meraki returns before evaluating key scope; insufficient permission yields 403 instead. It is tempting because authorisation failures feel similar, and this would be correct when a valid key receives 403 on an endpoint its organisation cannot access.
- ✗
The API endpoint URL is incorrect.
Why it's wrong here
A wrong URL returns 404 (Not Found), not 401, which specifically signals missing or invalid authentication credentials. The endpoint path is tempting because URL errors are common, and correcting the path would be the right fix when the API returns 404 or a connection failure.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.