Courseiva
mediumMultiple Choice

200-901 Practice Question: An engineer uses the Cisco Webex Teams API to…

An engineer uses the Cisco Webex Teams API to send a message to a room. The API returns HTTP 403 Forbidden. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between HTTP 401 (authentication failure, e.g., expired or invalid token) and HTTP 403 (authorization failure, e.g., valid token but insufficient permissions), so candidates must not confuse the two.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token does not have permission to post to that room.

HTTP 403 Forbidden indicates the server understood the request but refuses to authorize it. In the context of the Cisco Webex Teams API, this status code most commonly means the access token provided does not have the required scopes or permissions to post messages to the specified room. The token may be valid and not expired, but it lacks the authorization (e.g., the `spark:rooms_write` scope) needed for the action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The message payload is too large.

    Why it's wrong here

    A 403 indicates the request was authenticated but lacks permission, typically a missing or incorrect OAuth scope, or a bot token without room membership. Payload size returns 413. 403 is correct when the token's scopes do not cover the requested action.

  • ✗

    The bot token has expired.

    Why it's wrong here

    An expired bot token yields HTTP 401 Unauthorized, since the credential itself is rejected as invalid. A 403 means the token authenticated successfully but lacks permission to post to that room. Token expiry is the right diagnosis when every API call fails identically, not just room-scoped writes.

  • ✗

    The room ID is incorrect.

    Why it's wrong here

    A malformed or nonexistent room ID returns HTTP 404 Not Found, because the addressed resource cannot be located. HTTP 403 Forbidden instead signals the request reached an existing resource the authenticated principal may not act upon. Incorrect identifiers are the cause to suspect when errors vary per endpoint.

  • ✓

    The token does not have permission to post to that room.

    Why this is correct

    HTTP 403 Forbidden means the request was authenticated but the caller lacks authorisation for the target resource. A Webex token scoped without permission to post messages to that specific room produces exactly this response, unlike 401, which signals invalid or missing credentials.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.