Courseiva
easyMultiple Choice

200-901 Practice Question: A script is using the Cisco Meraki API to fetch a…

A script is using the Cisco Meraki API to fetch a list of organizations. The script needs to authenticate with an API key. Where should the API key be included in the request?

⚠ Common exam trap

Cisco often tests the fact that many APIs use standard Bearer tokens, but the Meraki API specifically uses a custom header, so candidates mistakenly choose the Authorization header option without reading the vendor-specific documentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the request header as 'X-Cisco-Meraki-API-Key'.

The Cisco Meraki API requires the API key to be sent in a custom HTTP header named 'X-Cisco-Meraki-API-Key'. This is a vendor-specific authentication mechanism, not a standard Bearer token. Including the key in this header ensures the request is authenticated without exposing the key in the URL or body.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the HTTP Authorization header using Bearer scheme.

    Why it's wrong here

    Meraki API keys are passed in the X-Cisco-Meraki-API-Key request header, not as a Bearer token; Bearer scheme belongs to OAuth 2.0 access tokens. Bearer is tempting because it is the standard pattern for many REST APIs, and would be correct if Meraki issued OAuth tokens rather than static keys.

  • ✗

    In the request body as a JSON field.

    Why it's wrong here

    Meraki’s Dashboard API expects the key in the `X-Cisco-Meraki-API-Key` HTTP header; placing it in a JSON body leaves the header absent, so the request returns 401 Unauthorized. A JSON body field suits APIs that define credential parameters in the payload, such as some OAuth token or POST-based authentication flows.

  • ✗

    In the request URL as a query parameter.

    Why it's wrong here

    Meraki expects the API key in the `X-Cisco-Meraki-API-Key` request header, so placing it in the URL query string fails authentication. Query parameters suit filtering or pagination values, and would be the right location for something like a `perPage` or `startingAfter` argument, not credentials.

  • ✓

    In the request header as 'X-Cisco-Meraki-API-Key'.

    Why this is correct

    Meraki's REST API expects the key in a custom request header named X-Cisco-Meraki-API-Key, not as a query parameter or body field. This satisfies the stem's requirement to authenticate the organisation-listing call, since Meraki validates that header on every request before returning the organisations list.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.