Courseiva
mediumMultiple Choice

200-901 Practice Question: An engineer is troubleshooting a Cisco DNA Center…

An engineer is troubleshooting a Cisco DNA Center API call that returns a 401 error. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between HTTP status codes (401 vs 400 vs 404 vs 502) to see if candidates understand that each code maps to a specific failure category in REST API interactions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The authentication token has expired

A 401 Unauthorized error from the Cisco DNA Center API indicates that the request lacks valid authentication credentials. The most common cause is that the authentication token (JWT) obtained via the /dna/system/api/v1/auth/token endpoint has expired. Cisco DNA Center tokens have a default expiry of 60 minutes, after which the API rejects the request with a 401 status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The authentication token has expired

    Why this is correct

    A 401 response signals failed authentication, and Cisco DNA Center issues time-limited tokens that must accompany each API call. Once the token's validity window lapses, the platform rejects the request before authorisation is evaluated, so an expired token is the most likely cause of the 401.

  • ✗

    The network device is unreachable

    Why it's wrong here

    An unreachable device yields connection timeouts or 5xx responses from DNA Center, not 401, which signals failed authentication. Reachability checks are tempting when API calls fail, but they belong to connectivity troubleshooting; 401 specifically means the token or credentials were rejected.

  • ✗

    The request body is invalid

    Why it's wrong here

    An invalid request body returns 400 Bad Request after authentication succeeds, because the payload fails validation; 401 is raised before the body is processed. Schema checking is tempting when requests fail, but it applies once credentials are accepted, not when authentication itself is rejected.

  • ✗

    The API endpoint is incorrect

    Why it's wrong here

    An incorrect endpoint returns 404 Not Found, since the path cannot be matched, whereas 401 indicates the request reached a protected resource but lacked valid credentials. Verifying URLs is tempting when debugging API calls, but endpoint validation addresses routing, not authentication failures.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.