Courseiva
mediumMultiple Choice

200-901 Practice Question: A Python script using the requests library to…

A Python script using the requests library to query the Cisco Meraki API returns a 403 Forbidden error. The API key is correctly set in the header. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to confuse 403 Forbidden with authentication failures (401 Unauthorized) or assume the API key is invalid, but Cisco tests the distinction that a valid key can still be denied access due to insufficient permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The API key does not have permission for the requested resource

A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. Since the API key is correctly set in the header, the most likely cause is that the API key lacks the necessary permissions (e.g., read-only key trying to modify resources, or key scoped to a different organization) for the specific resource being accessed. In Cisco Meraki, API keys are tied to specific organizations and roles, and a 403 is the standard response when the key does not have the required access rights.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The request URL is incorrect

    Why it's wrong here

    A wrong URL yields 404 Not Found, not 403, so path errors cannot explain this response. Meraki returns 403 when the key lacks permission for that organisation or network, or when the key is disabled. An incorrect URL would be the answer if the symptom were a missing-resource error.

  • ✗

    The API endpoint is rate-limiting the request

    Why it's wrong here

    Meraki signals rate limiting with HTTP 429 and a Retry-After header, not 403, so throttling is not the cause here. The 403 arises because the API key lacks access rights to the target organisation or network. Rate limiting would be correct if the script received 429 responses under heavy request volume.

  • ✓

    The API key does not have permission for the requested resource

    Why this is correct

    A 403 Forbidden with a valid key indicates authorisation failure, not authentication. The key is recognised but lacks the scope or role required for that Meraki endpoint, so the request is denied. Insufficient permissions on the key itself is the cause.

  • ✗

    The Content-Type header is missing

    Why it's wrong here

    A missing Content-Type affects how the server parses a request body, producing 400 or 415 errors, not 403. Meraki authorises each call from the X-Cisco-Meraki-API-Key header alone, so an absent Content-Type cannot trigger Forbidden. That header matters when posting JSON payloads to endpoints expecting structured data.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.