Courseiva
easyMultiple Choice

200-901 An application exposes a REST API Practice Question

An application exposes a REST API. To ensure that only authorized clients can access the API, the developer implements token-based authentication. Which HTTP header is typically used to transmit the bearer token?

⚠ Common exam trap

Cisco often tests the distinction between Authorization: Basic and Authorization: Bearer, where candidates confuse the two because both use the Authorization header, but Basic transmits credentials while Bearer transmits a token.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization: Bearer

The Authorization header with the Bearer scheme (RFC 6750) is the standard method for transmitting bearer tokens in HTTP requests. When a client authenticates and receives a token, it includes the token in the Authorization header as 'Bearer <token>', allowing the server to validate the token and authorize the request without requiring session state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cookie

    Why it's wrong here

    Cookies carry session identifiers that browsers attach automatically, not a bearer token presented in the request header. Cookies are tempting because web sessions commonly rely on them, but token-based REST authentication expects the credential in the Authorization header using the Bearer scheme.

  • ✗

    X-API-Key

    Why it's wrong here

    X-API-Key is a non-standard header for static API keys, not the registered scheme for bearer tokens. It is tempting because API-key authentication also authorises clients, but the question specifies token-based authentication, which uses Authorization: Bearer.

  • ✗

    Authorization: Basic

    Why it's wrong here

    Authorization: Basic transmits base64-encoded username and password credentials, not a bearer token. It is tempting because it is a standard Authorization header, but Basic authenticates each request with credentials rather than presenting the token issued to the client.

  • ✓

    Authorization: Bearer

    Why this is correct

    The Authorization header carries credentials for HTTP authentication, and the Bearer scheme conveys an OAuth 2.0 access token, so 'Authorization: Bearer <token>' transmits the bearer token. This satisfies the token-based authentication requirement, since servers read that header to validate client authorisation.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.