easyMultiple Choice
200-901 An application exposes a REST API Practice Question
An application exposes a REST API. To ensure that only authorized clients can access the API, the developer implements token-based authentication. Which HTTP header is typically used to transmit the bearer token?
⚠ Common exam trap
Cisco often tests the distinction between Authorization: Basic and Authorization: Bearer, where candidates confuse the two because both use the Authorization header, but Basic transmits credentials while Bearer transmits a token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization: Bearer
The Authorization header with the Bearer scheme (RFC 6750) is the standard method for transmitting bearer tokens in HTTP requests. When a client authenticates and receives a token, it includes the token in the Authorization header as 'Bearer <token>', allowing the server to validate the token and authorize the request without requiring session state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cookie
Why it's wrong here
Cookies carry session identifiers that browsers attach automatically, not a bearer token presented in the request header. Cookies are tempting because web sessions commonly rely on them, but token-based REST authentication expects the credential in the Authorization header using the Bearer scheme.
- ✗
X-API-Key
Why it's wrong here
X-API-Key is a non-standard header for static API keys, not the registered scheme for bearer tokens. It is tempting because API-key authentication also authorises clients, but the question specifies token-based authentication, which uses Authorization: Bearer.
- ✗
Authorization: Basic
Why it's wrong here
Authorization: Basic transmits base64-encoded username and password credentials, not a bearer token. It is tempting because it is a standard Authorization header, but Basic authenticates each request with credentials rather than presenting the token issued to the client.
- ✓
Authorization: Bearer
Why this is correct
The Authorization header carries credentials for HTTP authentication, and the Bearer scheme conveys an OAuth 2.0 access token, so 'Authorization: Bearer <token>' transmits the bearer token. This satisfies the token-based authentication requirement, since servers read that header to validate client authorisation.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.