200-901 Infrastructure and Automation Practice Question
An automation engineer is using the Cisco SD-WAN (Viptela) API to retrieve a list of devices in the overlay. The engineer must authenticate and obtain a token before making subsequent API calls. Which authentication mechanism does the Cisco SD-WAN API use to issue a session token?
⚠ Common exam trap
The trap here is assuming all Cisco automation APIs use the same authentication, such as DNA Center's X-Auth-Token or Meraki's API key header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP Basic authentication to /j_security_check with username and password, returning a JSESSIONID cookie
The Cisco SD-WAN Manager (vManage) API authenticates clients by accepting a username and password at /j_security_check and returning a JSESSIONID cookie. That cookie must be included in the headers of subsequent API calls. This session-based approach is specific to SD-WAN and differs from token or key-based authentication used by other Cisco platforms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HTTP Basic authentication to /j_security_check with username and password, returning a JSESSIONID cookie
Why this is correct
The Cisco SD-WAN (Viptela) API uses a session-based authentication model. The client posts credentials to /j_security_check, and the server responds with a JSESSIONID cookie that must be included in subsequent requests. This token-based session mechanism is the standard way to authenticate to the SD-WAN Manager (vManage) API.
- ✗
API key passed in the X-Auth-Token header for every request
Why it's wrong here
The X-Auth-Token header is used by some Cisco platforms like Cisco DNA Center, but not by Cisco SD-WAN. SD-WAN requires a session cookie (JSESSIONID) obtained after posting credentials. Sending an API key header would result in an authentication error.
- ✗
OAuth 2.0 client credentials flow to /oauth/token with client ID and secret
Why it's wrong here
Cisco SD-WAN does not use OAuth 2.0 for its native API authentication. While some Cisco platforms support OAuth, vManage uses a session cookie obtained via a login form endpoint. Using an OAuth token endpoint would fail because the API does not expose it for this purpose.
- ✗
SAML assertion posted to /saml/SSO with an identity provider
Why it's wrong here
Although Cisco SD-WAN can integrate with SAML for single sign-on in the user interface, the API authentication for automation uses the /j_security_check endpoint with a username and password to obtain a JSESSIONID. SAML assertions are not the method for programmatic API access in this scenario.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.