Courseiva

CCNA Understanding and Using APIs Questions

75 of 142 questions · Page 1/2 · Understanding and Using APIs · Answers revealed

1
MCQhard

A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?

A.Implicit grant
B.Authorization code grant
C.Resource owner password credentials grant
D.Client credentials grant
AnswerB

The authorization code grant redirects each user to Cisco Webex to authenticate and consent, then returns a short-lived code the app exchanges for an access token and a refresh token. The refresh token enables long-term access without further user interaction, and each organization consents separately, matching the stated requirements.

Why this answer

Delegated access across many organizations requires each user to authenticate and consent at Cisco Webex, which the authorization code grant accomplishes. Exchanging the returned code yields both an access token and a refresh token, so the integration can renew access silently afterward. The other grants either lack refresh capability, require unsafe password handling, or represent the app rather than the user.

Exam trap

The trap here is choosing client credentials because it needs no user interaction, overlooking that it cannot represent delegated per-organization user consent.

2
MCQeasy

A network engineer wants to retrieve the list of organizations associated with their API key from the Cisco Meraki Dashboard API. The API base URL is https://api.meraki.com/api/v1. Which HTTP request should the engineer send?

A.POST https://api.meraki.com/api/v1/organizations with the API key in the request body.
B.GET https://api.meraki.com/api/v1/organizations with the X-Cisco-Meraki-API-Key header set to the API key.
C.GET https://api.meraki.com/api/v1/organization with the API key as a query parameter.
D.GET https://api.meraki.com/api/v1/organizations with Basic authentication using the API key as the password.
AnswerB

The Meraki Dashboard API exposes organizations at the /organizations path, and authentication uses the X-Cisco-Meraki-API-Key header. A GET request to that endpoint returns the organizations the key can access. This is the documented, correct way to enumerate organizations before drilling into networks and devices.

Why this answer

The Meraki Dashboard API lists organizations at GET /api/v1/organizations and authenticates via the X-Cisco-Meraki-API-Key request header. Using the correct path and header ensures the API key is recognized and the list of accessible organizations is returned. Alternative methods such as POST, Basic auth, or query-parameter keys are not supported for this operation.

Exam trap

The trap here is confusing the plural /organizations collection endpoint with a singular path or assuming Meraki accepts the API key as a query string, when it requires a dedicated header.

3
MCQeasy

What is the purpose of the Authorization header in a REST API call?

A.To specify the content type of the request body
B.To specify the format of the response body
C.To indicate the desired language
D.To authenticate the client sending the request
AnswerD

The Authorization header carries credentials (such as a bearer token or Basic base64 pair) that the server validates to identify the calling client. It satisfies the stem's authentication requirement, distinct from content negotiation headers like Accept, which only declare the desired response format.

Why this answer

The Authorization header in an HTTP request carries credentials (such as a Bearer token, Basic auth, or API key) that the server uses to authenticate and authorize the client. It is the standard mechanism defined in RFC 7235 for transmitting authentication information with a REST API call.

Exam trap

200-901 often tests HTTP header semantics, tricking candidates into confusing Authorization with Content-Type or Accept, which control payload format rather than identity.

How to eliminate wrong answers

Option A is wrong because the content type of the request body is specified by the Content-Type header, not Authorization. Option B is wrong because the desired response format is specified by the Accept header. Option C is wrong because the desired language is specified by the Accept-Language header.

4
MCQeasy

An application needs to retrieve a list of network devices from Cisco DNA Center. Which HTTP method should be used against the /dna/intent/api/v1/network-device endpoint?

A.PUT
B.DELETE
C.GET
D.POST
AnswerC

GET retrieves a representation of the network-device collection without modifying server state, matching the read-only intent of listing devices. POST would create resources, PUT would replace them, and DELETE would remove them, none of which fit a retrieval request.

Why this answer

GET is used to retrieve resources in REST APIs.

5
MCQmedium

A developer is building a Python application that uses the Cisco Webex API to send messages. The application must authenticate on behalf of a user without storing the user's password. Which OAuth 2.0 grant type should be used to obtain an access token?

A.Resource Owner Password Credentials Grant
B.Client Credentials Grant
C.Implicit Grant
D.Authorization Code Grant
AnswerD

The Authorization Code Grant is the most secure and appropriate flow for web applications that need to access a user's resources without handling their credentials. It involves redirecting the user to Webex for authentication, then exchanging an authorization code for an access token. This flow supports refresh tokens and is recommended for server-side applications.

Why this answer

To authenticate on behalf of a user without handling their password, the Authorization Code Grant is the correct OAuth 2.0 flow. It redirects the user to the authorization server, where they authenticate directly. The application receives an authorization code, which it exchanges for an access token.

This method is secure, supports refresh tokens, and is widely recommended for server-side applications like the Python app described.

Exam trap

The trap here is confusing the Client Credentials Grant, which is for application-only authentication, with user-delegated authentication, which requires the Authorization Code Grant.

6
MCQmedium

Which authentication flow is most appropriate for a native mobile app that needs to access the Webex API on behalf of a user?

A.Client credentials grant
B.Resource owner password grant
C.Authorization code grant
D.Implicit grant
AnswerC

The authorization code grant returns a short-lived access token after the user authenticates in the browser, so the native app never handles the user's credentials directly. This satisfies the requirement to act on behalf of a user against the Webex API, unlike client credentials, which represents the app itself.

Why this answer

The authorization code grant is the correct flow because it is designed for confidential and public clients (like native mobile apps) that need to act on behalf of a user. It redirects the user to an authorization server, returns a short-lived code, and exchanges it for tokens via a secure back channel, keeping credentials out of the app. This flow supports refresh tokens and is the OAuth 2.0 recommended approach for user-delegated access to APIs like Webex.

Exam trap

The trap here is confusing the client credentials grant (for server-to-server) with user-delegated flows, or assuming the implicit grant is still acceptable for mobile apps despite its deprecation.

How to eliminate wrong answers

Option A is wrong because the client credentials grant is for machine-to-machine communication without a user context, so it cannot act on behalf of a user. Option B is wrong because the resource owner password grant requires the app to directly handle the user's credentials, which is discouraged and incompatible with modern OAuth 2.0 security best practices for third-party APIs. Option D is wrong because the implicit grant is deprecated and designed for browser-based apps, not native mobile apps, and it does not provide refresh tokens.

7
MCQmedium

A developer is building a Python script that calls the Cisco Webex REST API. The API requires an OAuth 2.0 access token that expires after 14 days. The script will run unattended on a server every hour. Which OAuth 2.0 grant type should the developer use to obtain tokens without user interaction?

A.Client Credentials grant
B.Resource Owner Password Credentials grant
C.Authorization Code grant
D.Implicit grant
AnswerA

Client Credentials is designed for machine-to-machine authentication where no user context is required. The script can exchange its client ID and client secret directly for an access token, allowing it to run unattended and refresh tokens as needed without any browser-based interaction.

Why this answer

The Client Credentials grant is the correct choice because it allows the application to authenticate itself directly with the authorization server using its client ID and secret, without any user involvement. This is ideal for server-to-server automation where the script acts on its own behalf and needs to run unattended.

Exam trap

The trap here is assuming that any OAuth 2.0 flow can be used for automation, when actually only Client Credentials is designed for machine-to-machine scenarios without user interaction.

8
MCQmedium

What is the correct URL path for retrieving the configuration of a network interface using RESTCONF on a Cisco device?

A./restconf/data/ietf-interfaces:interfaces
B./restconf/data/interfaces
C./api/restconf/data/interfaces
D./restconf/operations/get-config
AnswerA

The path `/restconf/data/ietf-interfaces:interfaces` satisfies RESTCONF's mandatory structure: the `/restconf/data` root, followed by the YANG module name (`ietf-interfaces`) and its container. This retrieves interface configuration from the Cisco device's datastore, matching the IETF standard model rather than a vendor-proprietary path.

Why this answer

RESTCONF uses /restconf/data/ followed by the YANG module path. The standard path for interfaces is /restconf/data/ietf-interfaces:interfaces.

9
MCQhard

A developer is writing a Python script to interact with a REST API that returns JSON. The script must handle rate limiting gracefully. The API returns a 429 status code with a Retry-After header when the limit is exceeded. Which approach should the developer take to ensure the script continues to function without being blocked?

A.Parse the Retry-After header and sleep for the specified number of seconds before retrying.
B.Switch to a different HTTP method to bypass the rate limit.
C.Ignore the 429 response and continue with the next request.
D.Immediately retry the request in a tight loop until it succeeds.
AnswerA

The Retry-After header indicates how long the client should wait before making another request. By sleeping for that duration, the script respects the server's rate limiting policy, avoids being blocked, and ensures that subsequent requests are likely to succeed without hitting the limit again.

Why this answer

Respecting the Retry-After header is the correct way to handle 429 responses. It tells the client exactly how long to wait before retrying, allowing the script to back off appropriately and avoid overwhelming the API. This approach ensures compliance with the API's rate limiting policy and maintains reliable operation.

Exam trap

The trap here is thinking that any retry will eventually work, but without honoring the Retry-After header, the client may be permanently blocked or cause more severe throttling.

10
MCQeasy

A network engineer is writing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) REST API. They need to authenticate and obtain a token that will be used in subsequent API calls. Which HTTP header should be included in the authentication request to specify the expected response format?

A.Authorization: Basic <credentials>
B.Accept: application/json
C.Content-Type: application/xml
D.X-Auth-Token: <token>
AnswerB

The Accept header tells the server what media type the client expects in the response. For Cisco Catalyst Center APIs, specifying application/json ensures the authentication response is returned in JSON format, which is the standard for these APIs. This allows the script to parse the token easily and use it in later calls.

Why this answer

To request a JSON response from the Catalyst Center authentication endpoint, the client must include the Accept header with application/json. This header informs the server of the desired response format. Other headers serve different purposes: Content-Type describes the request body, Authorization provides credentials, and X-Auth-Token is used after authentication.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.

11
Multi-Selectmedium

Which TWO of the following are commonly used when implementing pagination in REST APIs? (Select TWO)

Select 2 answers
A.Cursor-based token in response
B.Rate limiting headers
C.OAuth 2.0 token
D.Offset and limit query parameters
E.Webhook callback URL
AnswersA, D

Cursor-based pagination returns an opaque token pointing to the next page, avoiding skipped or duplicated records when data changes between requests. The server supplies the cursor in the response, which the client echoes back, satisfying the requirement for a commonly used pagination technique.

Why this answer

Option A (cursor-based token in response) is correct because cursor pagination returns an opaque token (often in a 'next_cursor' or Link header) that the client sends back to fetch the next page, giving stable results even when records are inserted or deleted. Option D (offset and limit query parameters) is correct because it is the most common pagination pattern, e.g. GET /items?offset=20&limit=10, where limit caps page size and offset skips records.

Option B (rate limiting headers) is wrong because headers like X-RateLimit-Remaining or Retry-After govern request throttling, not page navigation. Option C (OAuth 2.0 token) is wrong because it is an authorization credential (bearer token), unrelated to paginating result sets. Option E (webhook callback URL) is wrong because webhooks push event notifications to a subscriber endpoint, not retrieve successive pages of a collection.

12
MCQhard

A developer is using the Meraki Dashboard API and receives a 429 Too Many Requests error. The API documentation states a rate limit of 5 calls per second. What is the best practice to handle this?

A.Ignore the error and retry immediately.
B.Use a different API key to bypass the limit.
C.Increase the number of concurrent requests to exhaust the rate limit quickly.
D.Implement exponential backoff and honor the Retry-After header.
AnswerD

Exponential backoff spaces retries progressively, preventing repeated collisions with the 5 calls per second limit, while honouring Retry-After respects the server's stated wait. Together they satisfy the rate-limit constraint without hammering the Meraki Dashboard API.

Why this answer

Implementing exponential backoff with retry-after headers is the recommended approach for rate-limited APIs. Ignoring or simply retrying immediately may worsen the situation.

13
MCQhard

A developer is integrating a Python application with the Cisco DNA Center API. The application must handle rate limiting gracefully. The API returns HTTP 429 Too Many Requests with a 'Retry-After' header indicating the number of seconds to wait before retrying. Which approach best implements exponential backoff with jitter to respect the rate limit and avoid overwhelming the server?

A.Upon receiving 429, wait for the number of seconds specified in Retry-After, then retry the request. If it fails again, double the wait time and add a random jitter between 0 and 1 second.
B.Upon receiving 429, wait for a fixed 60 seconds before retrying, regardless of the Retry-After header. Repeat this fixed wait for each retry.
C.Upon receiving 429, log the error and abort the request permanently, as rate limiting indicates a fatal error.
D.Upon receiving 429, immediately retry the request in a tight loop until it succeeds, ignoring the Retry-After header.
AnswerA

This approach respects the server's Retry-After header, which is the authoritative wait time. Then, for subsequent retries, it implements exponential backoff with jitter by doubling the wait and adding randomness. This combination is a best practice for handling rate limits and transient errors, reducing the chance of repeated collisions.

Why this answer

The best practice for handling 429 responses is to honor the Retry-After header and then apply exponential backoff with jitter for subsequent retries. This respects the server's guidance while preventing synchronized retries from multiple clients. The other options either ignore the header, use fixed waits, or give up permanently, all of which are suboptimal.

Exam trap

The trap here is either ignoring the Retry-After header or implementing backoff without jitter, which can lead to thundering herd problems.

14
MCQmedium

A developer is integrating a Python script with Cisco Webex Teams. The script must create a new space and then immediately post a message to that space. After the POST to /v1/rooms, the API returns HTTP 200 with a JSON body containing the new room's id. The script then needs to send a message. Which approach correctly uses the API response to post the message to the newly created room?

A.Parse the 'Link' header from the response and use its URL as the 'roomId' in a subsequent POST to /v1/messages.
B.Use the HTTP status code 200 as the 'roomId' in a subsequent POST to /v1/messages.
C.Use the 'title' of the room as the 'roomId' in a subsequent POST to /v1/messages.
D.Extract the 'id' field from the JSON response and use it as the 'roomId' in a subsequent POST to /v1/messages.
AnswerD

The Webex Teams API returns the unique room identifier in the 'id' field of the JSON response. To post a message to that room, the developer must include that id as the 'roomId' parameter in the POST body to /v1/messages. This is the standard pattern for chaining API calls, where one response supplies the necessary identifier for the next request.

Why this answer

When creating a resource via a REST API, the response typically includes the unique identifier of the new resource. For the Webex Teams API, the POST to /v1/rooms returns a JSON object with an 'id' field. To post a message to that room, the developer must pass that 'id' as the 'roomId' in the message creation request.

This demonstrates understanding of API chaining and resource identification.

Exam trap

The trap here is assuming that a human-readable field like the room title can serve as a unique identifier, when the API requires the system-generated id.

15
MCQmedium

A developer is integrating with the Cisco Meraki Dashboard API. They need to update the name of an existing network. Which HTTP method should they use to modify only the name attribute without affecting other attributes?

A.PATCH
B.GET
C.PUT
D.POST
AnswerA

PATCH is designed for partial updates, allowing the client to send only the fields that need to be changed. In Cisco Meraki Dashboard API, using PATCH on the network endpoint with a JSON body containing just the name will update that attribute while leaving others intact. This is the correct method for modifying a single attribute without affecting the rest of the resource.

Why this answer

PATCH is the correct HTTP method for partial updates. It allows sending only the changed attribute, such as the network name, without affecting other fields. PUT replaces the entire resource, POST creates, and GET retrieves.

In Cisco Meraki API, PATCH is used to update specific attributes of a network.

Exam trap

The trap here is confusing PUT with PATCH; PUT replaces the whole resource, while PATCH only modifies specified fields.

16
MCQmedium

Which header is used to pass an API key in Meraki Dashboard API requests?

A.X-API-Key: <key>
B.Authorization: Bearer <token>
C.Authorization: Basic <base64>
D.X-Cisco-Meraki-API-Key: <key>
AnswerD

Meraki Dashboard API authenticates requests by requiring the API key in a custom X-Cisco-Meraki-API-Key request header. This satisfies the stem's constraint of passing an API key, rather than using Authorization bearer tokens or query-string credentials.

Why this answer

Meraki API uses the X-Cisco-Meraki-API-Key header for authentication.

17
MCQmedium

Which Cisco platform provides an Intent API for network automation, including endpoints for network-device, topology, and site hierarchy?

A.Cisco Catalyst Center
B.Cisco Webex
C.Cisco IOS XE
D.Meraki Dashboard
AnswerA

Cisco Catalyst Center exposes the Intent API with network-device, topology and site-hierarchy endpoints, matching the stem precisely. Competing platforms such as Meraki Dashboard or DNA Spaces expose different API surfaces, so Catalyst Center is the platform providing these specific intent endpoints.

Why this answer

Cisco Catalyst Center (formerly DNA Center) provides an Intent API that abstracts network intent into RESTful endpoints. This API includes specific endpoints for managing network devices, retrieving topology views, and interacting with site hierarchy, enabling declarative network automation without low-level device configuration.

Exam trap

Cisco often tests the distinction between device-level APIs (like IOS XE RESTCONF) and platform-level Intent APIs (like Catalyst Center), causing candidates to confuse direct device management with abstracted network automation.

How to eliminate wrong answers

Option B is wrong because Cisco Webex focuses on collaboration and messaging APIs, not network automation or device management. Option C is wrong because Cisco IOS XE provides model-driven APIs like NETCONF/RESTCONF for device-level configuration, but it does not offer a platform-level Intent API with endpoints for site hierarchy or topology. Option D is wrong because Meraki Dashboard provides a REST API for managing Meraki cloud-managed devices, but it lacks the Intent API abstraction and site hierarchy endpoints specific to Catalyst Center.

18
Multi-Selecthard

A developer is building a Python application that consumes the Cisco Webex Teams API. The application needs to handle rate limiting gracefully. Which TWO of the following are appropriate strategies when the API returns a 429 Too Many Requests status code? (Choose two.)

Select 2 answers
A.Ignore the 429 error and continue sending requests as fast as possible.
B.Implement exponential backoff, doubling the wait time after each consecutive 429 response.
C.Immediately retry the request without any delay.
D.Switch to a different API endpoint that is not rate limited.
E.Read the Retry-After header and wait for the specified number of seconds before retrying.
AnswersB, E

Exponential backoff is a robust strategy where the client increases the delay between retries after each failure, often doubling the wait time. This reduces the load on the server and increases the chance of success once the rate limit window resets. It is particularly useful when the Retry-After header is not provided or when multiple clients are competing.

Why this answer

When encountering a 429 Too Many Requests, the client should respect the Retry-After header if present, or implement exponential backoff to gradually increase wait times. These strategies prevent further rate limit violations and allow successful retries. Immediate retries, ignoring the error, or switching endpoints do not address the root cause and can lead to continued failures.

Exam trap

The trap here is thinking that retrying immediately or ignoring the error will eventually succeed, when in fact it will only prolong the rate limiting.

19
MCQhard

In the context of Cisco Webex APIs, which mechanism allows an application to receive real-time notifications when a message is created in a space?

A.Enabling Server-Sent Events (SSE)
B.Registering a webhook with the resource 'messages' and event 'created'
C.Polling the /messages endpoint every second
D.Using a long-lived HTTP connection
AnswerB

Registering a webhook targeting the 'messages' resource with the 'created' event makes Webex push an HTTP POST notification to your URL whenever a message is posted in a space, satisfying the stem's real-time notification requirement.

Why this answer

Cisco Webex APIs support webhooks, which are user-defined HTTP callbacks that the Webex cloud invokes when a specified event occurs. Registering a webhook with resource 'messages' and event 'created' causes Webex to POST a notification to your target URL whenever a new message is created in a space, enabling real-time, event-driven integration without polling. This is the standard mechanism for receiving real-time notifications in Webex.

Exam trap

200-901 often tests the misconception that real-time notifications require polling or persistent connections, when Cisco Webex specifically uses registered webhooks with resource/event pairs to deliver event-driven callbacks.

How to eliminate wrong answers

Option A is wrong because Webex does not expose Server-Sent Events (SSE) as a notification mechanism for message creation; SSE is a browser-oriented one-way streaming technology not used by the Webex webhook model. Option C is wrong because polling the /messages endpoint every second is inefficient, rate-limit-prone, and not real-time — it is an anti-pattern that Webex explicitly recommends replacing with webhooks. Option D is wrong because a long-lived HTTP connection is not how Webex delivers notifications; Webex uses discrete HTTP POST callbacks to a registered target URL, not persistent connections.

20
MCQhard

In gNMI, what is the difference between dial-in and dial-out streaming?

A.Dial-in is for configuration, dial-out for telemetry
B.Dial-in: device initiates the connection; dial-out: client initiates
C.Dial-in: client initiates subscription and receives data; dial-out: device pushes data to a configured receiver
D.Dial-in uses gRPC, dial-out uses HTTP
AnswerC

Dial-in has the client open the gNMI session and subscribe, so the client receives streamed telemetry. Dial-out reverses this: the network device initiates the connection and pushes data to a preconfigured collector. The stem asks for this directional difference.

Why this answer

In gNMI, dial-in streaming refers to the client initiating a subscription request to the device, which then streams telemetry data back over the same gRPC session. Dial-out streaming, on the other hand, is a server-initiated model where the device (gNMI target) pushes telemetry data to a pre-configured receiver (collector) without waiting for a client request. Option C correctly captures this distinction: dial-in has the client subscribe and receive data, while dial-out has the device push data to a configured receiver.

Exam trap

Cisco often tests the direction of connection initiation (client vs. device) as the key differentiator, and the trap here is confusing which side initiates the connection in dial-in versus dial-out, leading candidates to reverse the roles as in Option B.

How to eliminate wrong answers

Option A is wrong because both dial-in and dial-out are used for telemetry streaming, not configuration; gNMI uses separate RPCs (Set/Get) for configuration. Option B is wrong because it reverses the roles: in dial-in, the client initiates the connection and subscription, while in dial-out, the device initiates the connection to the receiver. Option D is wrong because both dial-in and dial-out use gRPC as the transport protocol; HTTP is not used for gNMI streaming.

21
MCQeasy

Which HTTP method is used to partially update an existing resource in a RESTful API?

A.UPDATE
B.POST
C.PATCH
D.PUT
AnswerC

PATCH applies a partial modification, sending only the fields being changed rather than a full replacement representation. PUT would overwrite the entire resource, so PATCH is the method that satisfies the requirement to update part of an existing resource.

Why this answer

PATCH is the HTTP method defined for partial modifications to a resource, sending only the fields that need to change. Unlike PUT, which replaces the entire resource representation, PATCH applies a partial update, making it the correct choice for updating a subset of a resource's attributes in a RESTful API.

Exam trap

200-901 often tests the PUT vs PATCH distinction — candidates incorrectly assume PUT can be used for partial updates, when PUT replaces the entire resource and PATCH is the method specifically designed for partial modification.

How to eliminate wrong answers

Option A is wrong because UPDATE is not a standard HTTP method; HTTP defines GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS, and TRACE, but not UPDATE. Option B is wrong because POST is used to create a new resource or submit data to be processed, not to partially update an existing resource. Option D is wrong because PUT replaces the entire resource with the supplied representation; if you send only some fields with PUT, the omitted fields may be removed or reset, so it is not a partial update.

22
Multi-Selecthard

Which three statements about Webex API webhooks are true? (Choose three.)

Select 3 answers
A.Webhooks deliver event data via HTTP POST to a specified URL.
B.Webhooks require OAuth 2.0 client credentials grant for security.
C.Webhooks can be filtered to trigger only on specific resources and events.
D.Webhooks are created by sending a POST request to the /webhooks endpoint.
E.Webhooks use long polling to receive events.
AnswersA, C, D

Webhooks push notifications by sending an HTTP POST containing event payload data to the subscriber's configured target URL. This satisfies the stem's requirement for a true statement about Webex webhook delivery, distinguishing push-based event delivery from polling the API.

Why this answer

Option A is correct because Webex webhooks push event notifications as an HTTP POST request containing a JSON payload to the target URL you register. Option C is correct because when creating a webhook you specify the resource (e.g., messages, meetings, memberships) and the event (e.g., created, updated, deleted), so it only fires for those matching events. Option D is correct because webhooks are registered programmatically by sending an authenticated POST request to the Webex REST endpoint https://webexapis.com/v1/webhooks with fields such as name, targetUrl, resource, and event.

Option B is not required: webhook creation uses an OAuth 2.0 access token (often from an integration or bot), not specifically the client credentials grant, and webhook delivery itself is secured via a secret/signature rather than that grant. Option E is incorrect because Webex webhooks are push-based HTTP callbacks, not long polling.

23
MCQmedium

A developer is writing a Python script that uses the requests library to call a REST API. The API requires an API key in the header 'X-API-Key'. The developer wants to ensure the key is not hardcoded in the script and is instead read from an environment variable. Which code snippet correctly implements this?

A.import os import requests api_key = os.environ['API_KEY'] headers = {'X-API-Key': api_key} response = requests.get('https://api.example.com/data', headers=headers)
B.import os import requests api_key = os.getenv('API_KEY') headers = {'Authorization': api_key} response = requests.get('https://api.example.com/data', headers=headers)
C.import os import requests api_key = os.environ['API_KEY'] response = requests.get('https://api.example.com/data', params={'X-API-Key': api_key})
D.import os import requests api_key = os.getenv('API_KEY') response = requests.get('https://api.example.com/data', auth=(api_key, ''))
AnswerA

This snippet reads the API key from the environment variable 'API_KEY' using os.environ, then passes it in the headers dictionary to requests.get. This avoids hardcoding the key and follows security best practices. It correctly sets the custom header 'X-API-Key' as required by the API.

Why this answer

The correct approach reads the API key from an environment variable and includes it in the 'X-API-Key' header as required. Using os.environ or os.getenv is secure. Passing the key as a query parameter, in Basic Auth, or in the Authorization header does not meet the API's authentication scheme.

Exam trap

The trap here is assuming that any header can be used for an API key, but the API specifically requires the 'X-API-Key' header, not Authorization or query parameters.

24
MCQhard

A developer is integrating a Python application with the Cisco Webex API. The application must act on behalf of users to create messages in Webex spaces. The developer wants to avoid storing user credentials. Which OAuth 2.0 flow is most appropriate for this scenario?

A.Implicit Grant
B.Authorization Code Grant
C.Resource Owner Password Credentials Grant
D.Client Credentials Grant
AnswerB

The Authorization Code Grant is ideal for applications that need to act on behalf of users without storing their credentials. The user authenticates directly with Webex, and the application receives an authorization code, which it exchanges for an access token. This flow is secure because the application never sees the user's password, and tokens can be scoped and revoked. It is the recommended flow for web and mobile apps requiring user context.

Why this answer

The Authorization Code Grant is the most secure and appropriate OAuth 2.0 flow for applications that need to act on behalf of users without handling their credentials. It involves redirecting the user to Webex for authentication, receiving an authorization code, and exchanging it for an access token. This flow supports refresh tokens and fine-grained scopes, making it ideal for integrations that create messages on behalf of users.

Exam trap

The trap here is assuming that the Client Credentials Grant can be used for user-context operations, when it is only for machine-to-machine.

25
MCQmedium

A developer needs to create a Postman collection that uses a variable for the base URL and a token variable for authentication. The token is obtained from a login request and must be reused across requests. Where should the token variable be defined to persist across all requests in the collection?

A.As a data variable from a CSV file
B.As a global variable
C.As a collection variable
D.As a local variable in the login request
AnswerC

Collection variables persist across every request in the collection, so a token captured from the login response remains accessible to all subsequent requests. This satisfies the requirement to reuse the token collection-wide rather than per-request.

Why this answer

Collection variables in Postman are scoped to the entire collection, meaning they persist across all requests within that collection. By storing the token as a collection variable after the login request, it can be reused in subsequent requests without re-authentication. This is the recommended approach for sharing authentication tokens across requests in a Postman collection.

Exam trap

Cisco often tests the distinction between variable scopes in Postman, and the trap here is that candidates confuse global variables (which are too broad) with collection variables (which are correctly scoped), or mistakenly think local variables persist beyond the request in which they are defined.

How to eliminate wrong answers

Option A is wrong because data variables from a CSV file are used for data-driven testing and are only available during the execution of a single request iteration, not persisted across all requests. Option B is wrong because global variables are shared across all collections and workspaces, which is too broad and can lead to unintended overwrites or conflicts; collection variables provide the correct scope for a single collection. Option D is wrong because local variables are scoped to a single request or script execution and are not accessible outside that request, so the token would be lost after the login request completes.

26
MCQeasy

A developer wants to retrieve a list of network devices from Cisco DNA Center. Which HTTP method and URL structure should be used?

A.POST /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/network-device
C.DELETE /dna/intent/api/v1/network-device
D.PUT /dna/intent/api/v1/network-device
AnswerB

GET requests retrieve data without modifying server state, matching the read-only intent of listing network devices. The path `/dna/intent/api/v1/network-device` is Cisco DNA Center's Intent API endpoint for device inventory, satisfying the requirement to fetch the device collection. POST, PUT or DELETE would alter resources or target the wrong operation.

Why this answer

To retrieve a list of network devices from Cisco DNA Center's Intent API, the correct HTTP method is GET, which is idempotent and used for read operations. The URL path /dna/intent/api/v1/network-device is the documented endpoint for listing network devices. GET requests do not modify server state, making them appropriate for retrieval.

Exam trap

200-901 often tests REST method semantics; candidates who associate POST with 'query' or 'search' because some APIs use POST for complex queries will incorrectly choose POST instead of GET for a simple list retrieval.

How to eliminate wrong answers

Option A is wrong because POST is used to create resources or submit data, not to retrieve a list; using POST on a collection endpoint would typically create a new device entry or trigger an action. Option C is wrong because DELETE removes a resource and is not used for listing; issuing DELETE on the collection endpoint could attempt to delete devices, which is destructive. Option D is wrong because PUT is used to update or replace an existing resource, not to read a collection; it requires a resource identifier and a payload.

27
MCQhard

A developer is using the Cisco Meraki Dashboard API to update the configuration of a wireless SSID. The API requires a PUT request to /networks/{networkId}/wireless/ssids/{number}. Which HTTP header is mandatory to include the API key for authentication?

A.Content-Type: application/json
B.X-Auth-Token
C.X-Cisco-Meraki-API-Key
D.Authorization: Bearer <token>
AnswerC

The Cisco Meraki Dashboard API uses a custom header named X-Cisco-Meraki-API-Key to authenticate requests. The API key generated in the Meraki Dashboard must be included in this header for all API calls. Without it, the server returns a 401 Unauthorized error. This header is specific to Meraki and is the correct way to authenticate.

Why this answer

The Meraki Dashboard API requires the API key to be sent in the X-Cisco-Meraki-API-Key header. This custom header is the only accepted method for authentication. Other headers like Authorization or X-Auth-Token are used by different Cisco APIs and will not work with Meraki.

Content-Type is for the request body, not authentication.

Exam trap

The trap here is assuming that all Cisco APIs use the same authentication header, when Meraki specifically uses a custom X-Cisco-Meraki-API-Key header.

28
MCQmedium

Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required, such as a backend service calling Cisco API?

A.Authorization code grant
B.Password grant
C.Device code grant
D.Client credentials grant
AnswerD

The client credentials grant exchanges the application's own client ID and secret directly for an access token, with no resource owner or browser redirect involved. This matches server-to-server backend calls where no user context exists, unlike authorisation code or implicit grants.

Why this answer

Client credentials grant is designed for server-to-server scenarios without user consent. Authorization code requires user interaction. Device code is for devices with limited UI.

29
Multi-Selecthard

Which THREE of the following are characteristics of NETCONF? (Select THREE)

Select 3 answers
A.Uses SSH as the transport protocol
B.Uses HTTP as the transport protocol
C.Supports JSON encoding for data
D.Encodes operations as XML RPCs
E.Supports operations like <edit-config> and <get-config>
AnswersA, D, E

NETCONF runs over a secure, connection-oriented SSH session on port 830, giving encrypted transport and authenticated access to network devices. This satisfies the characteristic of using SSH as its transport protocol, distinguishing it from SNMP or RESTCONF over HTTPS.

Why this answer

NETCONF is defined in RFC 6241 and uses SSH as its mandatory transport protocol (port 830), so option A is correct because SSH provides the secure, connection-oriented session over which NETCONF messages are exchanged. Option D is correct because NETCONF encodes its protocol operations as XML-based RPC elements (for example, <rpc> and <rpc-reply>), making XML the required encoding for the protocol's messages. Option E is correct because NETCONF defines standard operations such as <get-config> to retrieve configuration data and <edit-config> to modify it, which are core to its configuration-management capabilities.

Option B is incorrect because HTTP is the transport used by RESTCONF, not NETCONF. Option C is incorrect because NETCONF uses XML encoding, whereas JSON encoding is a feature of RESTCONF (and other YANG-based interfaces), not of NETCONF itself.

30
MCQeasy

A developer is making a GET request to a REST API and needs to specify that the response should be in JSON format. Which HTTP header should be set?

A.Content-Type
B.User-Agent
C.Authorization
D.Accept
AnswerD

The Accept request header tells the server which media types the client can handle, so setting Accept: application/json requests a JSON response. This satisfies the stem's requirement to specify JSON as the desired response format.

Why this answer

The Accept header is used by the client to tell the server which media types (e.g., application/json) it can understand and prefers for the response. In a GET request, the client does not send a body, so Content-Type is irrelevant for specifying the response format. Setting Accept: application/json ensures the server returns JSON if it supports that format.

Exam trap

Cisco often tests the distinction between Content-Type (for request body) and Accept (for response body), leading candidates to mistakenly choose Content-Type because they confuse 'sending' data with 'receiving' data.

How to eliminate wrong answers

Option A is wrong because Content-Type indicates the media type of the request body, not the desired response format; for a GET request with no body, Content-Type has no effect on the response. Option B is wrong because User-Agent identifies the client software (e.g., browser or tool) and has no role in content negotiation. Option C is wrong because Authorization carries credentials (e.g., Bearer token) for access control, not a preference for response format.

31
MCQmedium

A developer is using gRPC/gNMI for model-driven telemetry from a Cisco device. Which of the following best describes the difference between dial-in and dial-out streaming?

A.Dial-in uses gNMI; dial-out uses NETCONF.
B.Dial-in uses TCP; dial-out uses UDP.
C.Dial-in is initiated by the network device; dial-out is initiated by the collector.
D.Dial-in is initiated by the collector; dial-out is initiated by the device.
AnswerD

In dial-in telemetry the collector opens the gRPC session to the device and subscribes; in dial-out the device initiates the connection to the collector and pushes data. This direction of session initiation is the defining difference between the two modes.

Why this answer

In dial-in telemetry, the collector (management station) initiates the connection to the network device and subscribes to telemetry data — the collector 'dials in' to the device. In dial-out telemetry, the network device initiates the connection to the collector and pushes data, which is useful when the device is behind NAT or a firewall.

Exam trap

200-901 often tests the initiator direction in telemetry modes, tricking candidates who assume the collector always initiates (as in traditional SNMP polling).

How to eliminate wrong answers

Option A is wrong because both dial-in and dial-out can use gNMI; the distinction is about who initiates the connection, not the protocol used. Option B is wrong because both modes typically use TCP (gRPC runs over HTTP/2 over TCP), not UDP. Option C is wrong because it reverses the roles — dial-in is initiated by the collector, not the device.

32
MCQmedium

Which HTTP header is used to specify the format of the request body (e.g., application/json) when sending a POST request to a REST API?

A.Accept
B.Content-Type
C.Authorization
D.X-Requested-With
AnswerB

Content-Type specifies the media type of the request body, such as application/json, so the server knows how to parse the POST payload. Accept instead describes the desired response format, so Content-Type satisfies the requirement to declare the body's format.

Why this answer

Content-Type indicates the media type of the request body. Accept indicates the desired response format. Authorization carries credentials.

33
MCQhard

A developer is implementing gRPC telemetry with dial-out streaming from a Cisco IOS XE device. Which component initiates the TCP connection to the collector?

A.A third-party orchestrator initiates
B.The network device initiates the connection
C.The collector initiates the connection
D.Both initiate simultaneously
AnswerB

In dial-out telemetry, the network device acts as the client and initiates the TCP connection to the collector, which listens as the server. This satisfies the dial-out model, reversing the dial-in approach where the collector connects to the device.

Why this answer

In dial-out streaming, the network device (server) initiates the connection to the collector (client).

34
Multi-Selectmedium

A developer is designing a Python script that interacts with a REST API. The script must handle common HTTP methods appropriately. Which TWO of the following statements correctly describe the use of HTTP methods in RESTful APIs? (Choose two.)

Select 2 answers
A.GET requests should be idempotent and safe, meaning they do not modify server state.
B.POST requests are idempotent, so sending the same POST request multiple times has the same effect as sending it once.
C.PATCH requests must always be idempotent and safe.
D.PUT requests are idempotent and are used to update or replace a resource entirely.
E.DELETE requests are not idempotent because deleting a resource twice will cause an error the second time.
AnswersA, D

In REST, GET is defined as a safe and idempotent method. Safe means it does not alter server state, and idempotent means multiple identical requests have the same effect as a single one. This is why GET is used for retrieving data without side effects, and clients can cache or retry GET requests without concern for unintended changes.

Why this answer

In REST, GET is safe and idempotent, and PUT is idempotent and used for full updates or replacements. POST is neither safe nor idempotent, DELETE is idempotent despite possible error responses, and PATCH is not guaranteed to be idempotent or safe. Understanding these properties helps developers choose the correct method and handle retries appropriately.

Exam trap

The trap here is assuming that all methods that modify state are non-idempotent, or that DELETE is not idempotent because it might return an error on subsequent calls.

35
Multi-Selecthard

Which THREE of the following are valid NETCONF operations? (Choose three.)

Select 3 answers
A.<edit-config>
B.<rpc>
C.<get-config>
D.<commit>
E.<close-session>
AnswersA, C, E

`<edit-config>` is a standard NETCONF operation, defined in RFC 6241, that loads configuration data into a target datastore such as running or candidate. It satisfies the stem's requirement for valid NETCONF operations, unlike RESTCONF-specific verbs or SNMP primitives, making it one of the three correct choices.

Why this answer

<edit-config> (A) is a valid NETCONF operation defined in RFC 6241; it loads all or part of a configuration into the specified target datastore (running, candidate, or startup) and is one of the core base protocol operations. <get-config> (C) is also a base NETCONF operation from RFC 6241; it retrieves all or part of a specified configuration datastore and is distinct from <get>, which returns both state and configuration data. <close-session> (E) is a valid NETCONF session-level operation from RFC 6241 that gracefully terminates the NETCONF session and releases any locks and resources held by the client. <rpc> (B) is not an operation but the transport-framing wrapper element that carries every NETCONF operation, and <commit> (D) is not a standalone NETCONF operation; committing the candidate datastore is performed via the <commit> element inside an <rpc> as part of the candidate capability, not as a base operation itself.

36
Multi-Selecthard

Which three statements are true about the Cisco Catalyst Center (formerly DNA Center) intent API? (Choose three.)

Select 3 answers
A.The base URL for the API includes the Catalyst Center hostname and port.
B.Authentication is done by sending a POST request to /dna/system/api/v1/auth/token with credentials.
C.The API uses only GET and POST methods.
D.It uses RESTful principles and returns JSON responses.
E.It requires an API key passed in the X-Cisco-Meraki-API-Key header.
AnswersA, B, D

Catalyst Center’s intent API is reached over HTTPS at a host-specific endpoint, so the base URL must combine the appliance’s hostname with its port, satisfying the stem’s requirement for a true statement about API structure. Requests target that address directly, making hostname and port integral rather than optional.

Why this answer

Option A is correct because every Catalyst Center intent API call is built on a base URL of the form https://<Catalyst-Center-hostname>:<port>, typically port 443 for HTTPS, followed by the service path such as /dna/intent/api/v1. Option B is correct because authentication is performed by sending a POST request with the username and password in a JSON body to /dna/system/api/v1/auth/token, which returns a JWT token used as a Bearer token in the X-Auth-Token header for subsequent calls. Option D is correct because the intent API follows RESTful principles, using resource-oriented URIs and standard HTTP verbs, and returns responses formatted as JSON.

Option C is incorrect because the API also uses PUT and DELETE methods (for example, to update or remove resources), not only GET and POST. Option E is incorrect because the X-Cisco-Meraki-API-Key header belongs to the Cisco Meraki Dashboard API, not to Catalyst Center, which relies on token-based authentication.

Exam trap

Cisco often tests the distinction between Catalyst Center and Meraki APIs, so the trap here is confusing the authentication method (token-based vs. API key) and assuming only GET/POST are used, when in fact RESTful APIs support full CRUD operations.

37
MCQeasy

A developer is building a Python application that consumes the Cisco Meraki Dashboard API. The application must store the API key securely and include it on every request. Which HTTP request header should the application set to authenticate each call?

A.Authorization: Bearer <API_KEY>
B.X-Cisco-Meraki-API-Key: <API_KEY>
C.Authorization: Basic <base64(API_KEY:)>
D.X-Auth-Token: <API_KEY>
AnswerB

The Meraki Dashboard API authenticates requests with a custom header named X-Cisco-Meraki-API-Key whose value is the API key generated in the dashboard. Setting this header on every call is the documented method, and it works alongside the required Content-Type and Accept headers for JSON payloads.

Why this answer

Cisco Meraki Dashboard API authentication uses a proprietary request header, X-Cisco-Meraki-API-Key, populated with a key created under the organization's dashboard profile. Unlike OAuth-based Cisco APIs that expect an Authorization Bearer token, Meraki requires this specific header on each call, and the application must also send appropriate Content-Type and Accept headers for JSON.

Exam trap

The trap here is assuming every Cisco API uses Authorization: Bearer, when Meraki specifically requires its own X-Cisco-Meraki-API-Key header instead.

38
MCQmedium

A REST API uses offset and limit parameters for pagination. If the first request returns items 0-49 with limit=50 and offset=0, how should the next request be constructed to get the next page?

A.offset=1, limit=50
B.offset=50, limit=50
C.offset=50, limit=100
D.offset=0, limit=100
AnswerB

Offset pagination advances by the page size, so the next page begins after the 50 items already retrieved. Keeping limit=50 and setting offset=50 returns items 50-99, satisfying the stem's requirement to fetch the subsequent page without overlap or gaps.

Why this answer

Pagination with offset and limit works by advancing the offset by the limit value to fetch the next set of items. The first request returned items 0-49 (offset=0, limit=50), so the next request should start at offset=50 with the same limit=50 to retrieve items 50-99. This ensures no overlap and no gaps in the data.

Exam trap

The trap here is that candidates mistakenly think offset should be incremented by 1 (like a page number) rather than by the limit value, leading them to choose offset=1 instead of offset=50.

How to eliminate wrong answers

Option A is wrong because offset=1 would skip item 0 and start at item 1, causing a gap and missing item 0 from the second page. Option C is wrong because offset=50 with limit=100 would retrieve items 50-149, which is not the correct next page size (should be 50 items) and could exceed the intended page size. Option D is wrong because offset=0 with limit=100 would retrieve items 0-99, which includes the already-fetched first page and changes the page size, leading to duplicate data.

39
MCQmedium

An application needs to receive real-time notifications when a new message is posted in a Webex space. Which Webex API feature should be used?

A.Establish a WebSocket connection to the Webex API
B.Create a webhook that triggers on 'messages' events
C.Use Server-Sent Events (SSE) from the Webex API
D.Poll the messages endpoint every second
AnswerB

Webhooks push event data to your HTTPS endpoint the moment a message is created, satisfying the real-time notification requirement without polling. Subscribing to the 'messages' resource delivers the posted message payload directly, whereas periodic GET requests to the messages API would introduce latency and unnecessary API calls.

Why this answer

Webex uses webhooks to push real-time event notifications to an external server. By creating a webhook that triggers on 'messages' events, the application receives an HTTP POST request whenever a new message is posted in the specified space, eliminating the need for polling or persistent connections.

Exam trap

Cisco often tests the distinction between push-based (webhooks) and pull-based (polling) mechanisms, and candidates may mistakenly assume WebSocket or SSE are available because they are common real-time technologies, but Webex specifically relies on webhooks for event-driven notifications.

How to eliminate wrong answers

Option A is wrong because Webex does not expose a WebSocket endpoint for real-time messaging events; webhooks are the standard mechanism. Option C is wrong because Webex does not support Server-Sent Events (SSE) for message notifications; SSE is not part of the Webex API. Option D is wrong because polling the messages endpoint every second is inefficient, introduces latency, and violates API rate limits; webhooks provide immediate, push-based notifications without active polling.

40
MCQmedium

A developer's script calls a REST API and receives HTTP 429 Too Many Requests. The response includes a Retry-After header with a value of 30. What should the script do to behave correctly?

A.Immediately resend the identical request in a tight loop until it succeeds.
B.Change the HTTP method from GET to POST and resend.
C.Treat the response as a permanent failure and stop all further API calls.
D.Wait at least 30 seconds, then retry the request.
AnswerD

HTTP 429 means the client exceeded an allowed request rate. The Retry-After header communicates how many seconds to pause before trying again. Honoring that value lets the server's rate window reset and gives the retry a realistic chance of success, which is the behavior API providers expect from well-behaved clients.

Why this answer

A 429 response signals that the client has exceeded a rate limit, and the accompanying Retry-After header states how long to wait before retrying. Pausing for that interval respects the server's throttling policy and avoids worsening the condition. Immediate retries, method changes, or permanently aborting all fail to follow the server's explicit guidance.

Exam trap

The trap here is treating 429 like a permanent 4xx client error instead of a transient throttling response that should be retried after the indicated delay.

41
MCQmedium

A developer is building a Python script that calls the Cisco Webex Rooms API. The API returns a JSON error response with HTTP status code 429. The script currently retries immediately in a tight loop, but the errors persist. What should the developer implement to correctly handle this response?

A.Read the Retry-After response header and wait that many seconds before retrying the request.
B.Change the HTTP method from GET to POST and resend the request.
C.Set the Authorization header to a new access token and resend the request immediately.
D.Add a Content-Type: application/json header and resend the request.
AnswerA

HTTP 429 indicates the client has exceeded the rate limit. Cisco Webex APIs include a Retry-After header specifying how long to wait before retrying. Honoring this header prevents additional throttling and aligns with API rate-limiting best practices. Immediate retries in a tight loop would continue to fail and may extend the throttling period.

Why this answer

HTTP 429 signals that the client has exceeded the API rate limit. Cisco Webex APIs return a Retry-After header indicating how long to wait before the next request. Reading and honoring that value prevents further throttling and is the standard remediation.

Immediate retries, changing methods, or refreshing tokens do not address the underlying rate-limit condition.

Exam trap

The trap here is assuming that retrying immediately or refreshing credentials will resolve a 429, when the response specifically requires the client to pause for the interval given in the Retry-After header.

42
MCQeasy

In a Postman collection, a developer stores the base URL of a Meraki API as a variable. Which Postman feature allows this?

A.Tests
B.Environments
C.Pre-request Scripts
D.Collections
AnswerB

Environments store variables as key-value pairs that Postman substitutes into requests, so the base URL can differ per deployment without editing the collection. This satisfies the requirement to hold the Meraki API base URL as a reusable variable rather than hard-coding it.

Why this answer

Environments in Postman allow developers to store variables, such as a base URL, that can be reused across requests and collections. By defining an environment with a variable for the base URL, the developer can easily switch between different environments (e.g., development, production) without modifying each request. This is the standard feature for managing variables like base URLs.

Exam trap

200-901 often tests the confusion between Environments and other Postman features like Collections or Pre-request Scripts, but Environments are specifically for managing variables across different contexts.

How to eliminate wrong answers

Option A is wrong because Tests are scripts that run after a request to validate responses, not for storing variables. Option C is wrong because Pre-request Scripts are scripts that run before a request to set up data or modify requests, but they are not the primary feature for storing reusable variables like a base URL. Option D is wrong because Collections are groups of saved requests, not a variable storage mechanism; while collections can have variables, the feature specifically designed for environment-specific variables is Environments.

43
MCQmedium

A developer is building a Python script that calls the Cisco Webex API. The API returns JSON with a top-level key "items" containing a list of records, and a "link" object with a "next" URL when more records exist. The developer needs to iterate through all pages until every record is retrieved. Which approach correctly handles this pagination style?

A.Read the "X-Total-Count" response header and loop exactly that many times using an offset parameter.
B.Request the same endpoint repeatedly and deduplicate results until the returned item count stabilizes.
C.Increment a "page" query parameter starting at 1 and stop when the response body is empty.
D.Parse the top-level "items" array, then check the "link" object for a "next" URL and request that URL until no "next" key is present.
AnswerD

This is correct because the Webex API returns records in an "items" array and provides the next page location inside a "link" object with a "next" field. The script must follow that URL iteratively, stopping when the "link" object no longer contains a "next" key, which signals the final page has been reached.

Why this answer

The Webex API paginates by returning an "items" array plus a "link" object whose "next" field holds the URL of the following page. A correct client parses each page, then follows the "next" URL until that field disappears, indicating the last page. This link-driven approach avoids guessing page sizes or totals and adapts if the server changes page boundaries.

Exam trap

The trap here is assuming every paginated API uses a numeric page or offset query parameter, when this collection instead supplies an explicit next-page URL in the response body.

44
MCQhard

In Cisco DNA Center, which API endpoint is used to retrieve the site hierarchy?

A.POST /dna/intent/api/v1/site
B.GET /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/site
D.GET /dna/intent/api/v1/topology
AnswerC

The site hierarchy is exposed through the intent API's site resource, so a GET to /dna/intent/api/v1/site returns the full site topology. This satisfies the stem's requirement to retrieve, not modify, the hierarchy, and the v1 intent path matches DNA Center's controller-level northbound interface.

Why this answer

Cisco DNA Center exposes the site hierarchy through the Intent API at GET /dna/intent/api/v1/site, which returns the list of sites with their hierarchy, parent-child relationships, and site IDs. This is the documented endpoint for retrieving site topology information.

Exam trap

200-901 often tests HTTP method semantics — candidates see a familiar path like /site and pick POST or confuse /site with /topology or /network-device.

How to eliminate wrong answers

Option A is wrong because POST to /site creates a new site rather than retrieving the hierarchy — the HTTP method is incorrect for a read operation. Option B is wrong because /network-device returns the list of managed network devices (switches, routers, WLCs), not the site hierarchy. Option D is wrong because /topology returns physical or logical topology data (links and nodes), which is related but not the site hierarchy endpoint.

45
MCQmedium

A developer is building a Python script that calls the Cisco Webex API to retrieve a list of rooms. The API returns a maximum of 100 items per page and includes a 'Link' response header with a rel="next" URL. The script must automatically fetch all pages until no 'next' link remains. Which approach should the developer implement?

A.Set the 'max' query parameter to 1000 and make a single GET request to retrieve all rooms at once.
B.Use the 'offset' query parameter, increasing it by 100 on each request until the response body is empty.
C.Increment a 'page' query parameter starting at 0 and continue until an empty JSON array is returned.
D.Parse the Link header, extract the URL with rel="next", and issue a GET request to that URL in a loop until the header is absent.
AnswerD

The Webex API uses RFC 5988 Link headers for pagination. The rel="next" URL contains the appropriate cursor or page parameters. By following this URL iteratively, the script retrieves all pages without manually constructing query strings. This is the documented and most reliable method for traversing paginated Webex API results.

Why this answer

The Webex API provides pagination through Link headers containing a rel="next" URL. Following that URL in a loop ensures all pages are retrieved. Other methods like page numbers, large max values, or offset parameters are not supported by this API and would fail to return the complete dataset.

Exam trap

The trap here is assuming that a simple page number or offset parameter can be used for pagination, when the API actually requires following the Link header.

46
MCQmedium

A developer is writing a Python script that calls the Cisco Webex Teams API. The script must handle the case where the access token has expired. Which HTTP status code should the script check for to detect an expired or invalid token?

A.403 Forbidden
B.401 Unauthorized
C.429 Too Many Requests
D.404 Not Found
AnswerB

HTTP 401 Unauthorized indicates that the request lacks valid authentication credentials. For Cisco Webex APIs, an expired or invalid access token produces a 401 response. The client should then refresh the token or re-authenticate. Checking for 401 allows the script to handle token expiration gracefully.

Why this answer

Cisco Webex APIs return HTTP 401 Unauthorized when the access token is expired, revoked, or invalid. The client should detect this status and trigger a token refresh or re-authentication flow. Other status codes such as 403, 404, or 429 represent different conditions and would not correctly identify an expired token.

Exam trap

The trap here is confusing 401 Unauthorized with 403 Forbidden, when only 401 specifically signals that the token is missing, expired, or invalid.

47
MCQmedium

An application uses the Meraki Dashboard API and receives a 429 Too Many Requests error. What is the most likely cause, and how should the application adjust?

A.The request body is malformed; check JSON syntax.
B.The API key is invalid; regenerate the key.
C.The network is down; check connectivity.
D.The application exceeded the rate limit of 5 calls per second; implement exponential backoff.
AnswerD

The Meraki Dashboard API enforces a per-organisation limit of five calls per second, so sustained bursts trigger 429 responses. Exponential backoff retries with progressively longer delays, letting the application recover without hammering the endpoint, directly satisfying the stem's requirement to identify the cause and adjust accordingly.

Why this answer

A 429 Too Many Requests error from the Meraki Dashboard API indicates that the application has exceeded the rate limit, which is 5 calls per second per organization. The correct adjustment is to implement exponential backoff to retry requests after increasing delays, respecting the Retry-After header if provided.

Exam trap

200-901 often tests HTTP status codes and their meanings, and candidates may confuse 429 with 400 or 401, or fail to recognize that rate limiting requires backoff rather than immediate retry.

How to eliminate wrong answers

Option A is wrong because a malformed request body would typically return a 400 Bad Request error, not 429. Option B is wrong because an invalid API key would return a 401 Unauthorized error. Option C is wrong because network connectivity issues would result in timeouts or connection errors, not a 429 status code.

48
MCQeasy

Which header is used in an HTTP request to tell the server the format of the request body?

A.Authorization
B.Content-Type
C.Accept
D.Host
AnswerB

Content-Type declares the media type of the request body, letting the server parse it correctly. Without it, the server may reject the payload or misinterpret JSON as form data, so it satisfies the requirement to state the body's format.

Why this answer

Content-Type header specifies the media type of the request body, e.g., application/json.

49
MCQmedium

A developer is testing a REST API with curl and receives a response body containing JSON. They want to confirm that the payload is JSON before parsing it in code. Which HTTP response header should they check?

A.User-Agent
B.Content-Type
C.Accept
D.Content-Length
AnswerB

Content-Type is a representation header that the server sets to describe the media type of the response body, for example application/json. Checking it confirms the payload format before parsing, and a value like application/json; charset=utf-8 also indicates the character encoding, which matters when decoding the bytes.

Why this answer

The Content-Type response header is the server's declaration of the media type of the returned body. When it is application/json, the developer can safely hand the body to a JSON parser; when it is something else, such as text/html for an error page, parsing as JSON would fail. Checking this header is a standard defensive step before decoding API responses.

Exam trap

The trap here is confusing the request header Accept, which expresses what the client wants, with the response header Content-Type, which states what the server actually sent.

50
MCQeasy

Which HTTP method is used to partially update a resource in a RESTful API?

A.POST
B.PUT
C.UPDATE
D.PATCH
AnswerD

PATCH applies partial modifications to a resource, sending only the fields being changed rather than a complete replacement. This satisfies the stem's requirement for a partial update, unlike PUT, which overwrites the entire resource representation. PATCH therefore matches the scenario precisely.

Why this answer

The HTTP PATCH method is used to apply partial modifications to a resource. Unlike PUT, which replaces the entire resource, PATCH only updates the specified fields, making it ideal for partial updates.

Exam trap

The trap is confusing PUT with PATCH; PUT replaces the entire resource, while PATCH performs a partial update.

How to eliminate wrong answers

Option A is wrong because POST is used to create a new resource or submit data to be processed, not for partial updates. Option B is wrong because PUT replaces the entire resource with the provided representation, not a partial update. Option C is wrong because UPDATE is not a standard HTTP method; it is a common misconception.

51
MCQmedium

A developer is writing a Python script that calls the Cisco Webex Teams API to create a new space. The API returns the new space object, including a Location header pointing to the newly created resource. Which HTTP status code should the developer expect from a successful space creation?

A.204 No Content
B.200 OK
C.201 Created
D.202 Accepted
AnswerC

201 Created is the correct status for a POST that successfully creates a new resource. The Webex API returns 201 along with the new space object and a Location header containing the URI of the created space. The developer can use this Location header to subsequently retrieve or modify the space. This status confirms that the resource was created and provides its canonical URL.

Why this answer

The correct status code for a successful resource creation via POST in the Webex API is 201 Created. This status indicates that the request has been fulfilled and has resulted in one or more new resources being created. The response typically includes a Location header with the URI of the new resource and a body containing the representation of the created space.

Understanding this helps developers correctly handle API responses and extract necessary identifiers.

Exam trap

The trap here is confusing 201 Created with 200 OK, assuming any successful response must be 200.

52
MCQhard

A developer is using NETCONF to retrieve the running configuration of a network device. Which operation should be used?

A.<get>
B.<copy-config>
C.<get-config>
D.<edit-config>
AnswerC

NETCONF's <get-config> operation retrieves configuration data from a specified datastore, such as <running/>, which is exactly the stem's requirement. It differs from <get>, which returns state and operational data, and from <edit-config>, which modifies configuration.

Why this answer

The <get-config> operation retrieves configuration from a datastore (e.g., running).

53
Multi-Selecthard

A developer is integrating with a REST API that returns JSON error responses. The team needs to handle failures robustly in code. Which TWO practices are appropriate when processing API responses? (Choose two.)

Select 2 answers
A.Retry every failed request immediately in a tight loop until it succeeds.
B.Ignore the status code and rely solely on whether the body parses as valid JSON.
C.Check the HTTP status code before attempting to parse the response body.
D.Assume any response containing the word "error" in the body indicates a failure and raise an exception.
E.Parse the response body as JSON only after confirming the content type and that the body is non-empty.
AnswersC, E

Status codes are the primary signal of success or failure in HTTP. Checking them first prevents the code from misinterpreting an error payload as valid data. For example, a 404 or 500 may return a different JSON shape than a 200, so branching on the status code avoids schema errors and lets the program route to error handling cleanly.

Why this answer

Robust API clients branch on the HTTP status code first, then guard JSON parsing by checking the content type and body presence. This ordering prevents schema mismatches when error payloads differ from success payloads and avoids parser exceptions on empty or non-JSON responses. These two practices together form a reliable foundation for error handling in any REST integration.

Exam trap

The trap here is assuming that a body which parses as JSON proves success, when error responses frequently return valid JSON with non-2xx status codes.

54
MCQmedium

A Cisco Webex bot needs to receive real-time notifications when new messages are posted in a space. Which API feature should the bot use?

A.Server-Sent Events (SSE)
B.Polling the /messages endpoint every second
C.Webhooks via the /webhooks API
D.Long polling with a keep-alive connection
AnswerC

Webhooks let the bot register a target URL with the /webhooks API; Webex then pushes HTTP POST notifications when messages are posted in the space. This satisfies the real-time requirement without polling, unlike continuously querying the messages endpoint.

Why this answer

Webex Webhooks allow real-time event notifications; the bot registers a webhook with a target URL that receives POST requests when events occur.

55
MCQeasy

A developer needs to partially update a Meraki network's configuration, changing only the time zone. Which HTTP method should be used on the network resource?

A.PUT
B.PATCH
C.DELETE
D.POST
AnswerB

PATCH sends only the changed attribute, here the time zone, leaving all other network settings untouched. PUT would require submitting the complete network configuration, risking unintended overwrites, so PATCH satisfies the partial-update constraint in the stem.

Why this answer

PATCH is used for partial updates in REST APIs.

56
MCQmedium

An engineer is writing a script that calls the Cisco DNA Center API to create a new site. The API requires the request body to be encoded as JSON. Which HTTP request header should the script set so the server interprets the payload correctly?

A.Authorization: Bearer <token>
B.Content-Type: application/json
C.Accept: application/json
D.Content-Length: application/json
AnswerB

The Content-Type header declares the media type of the entity body in the request, so setting it to application/json tells Cisco DNA Center to parse the create-site payload as JSON rather than form-encoded or plain text. Without it, the server may reject the request with 415 Unsupported Media Type or misinterpret the body, making this the correct header for the scenario.

Why this answer

Content-Type describes the media type of the request body, which is exactly what a server needs in order to parse a JSON payload. Cisco DNA Center's create-site operation expects application/json, so the client must send that header or risk a 415 error. Accept negotiates the response format, Authorization supplies credentials, and Content-Length must be a byte count, so none of those substitutes for declaring the request body encoding.

Exam trap

The trap here is confusing Accept, which describes what the client wants back, with Content-Type, which describes what the client is sending.

57
MCQeasy

A network automation engineer wants to retrieve a list of all network devices from Cisco DNA Center. Which HTTP method and URL path should be used with the DNAC intent API?

A.PUT /dna/intent/api/v1/network-device
B.POST /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/network-device
D.DELETE /dna/intent/api/v1/network-device
AnswerC

Retrieving devices is a read operation, so GET is correct; the intent API path /dna/intent/api/v1/network-device returns the device inventory collection. POST would create resources and PUT would replace them, so GET against that exact path satisfies the stem's requirement.

Why this answer

The intent API uses GET to retrieve data, and /dna/intent/api/v1/network-device is the correct path for listing network devices.

58
MCQeasy

A developer is integrating a Python script with the Cisco Webex API. The script needs to read the value of the HTTP status code returned by the API to decide whether to retry a request. Using the requests library, which attribute of the response object should the developer inspect?

A.response.headers['Status']
B.response.reason
C.response.status_code
D.response.ok
AnswerC

The requests library exposes the numeric HTTP status code of the server's reply through the status_code attribute, so a script can compare it against values such as 200, 401, or 429 and branch its retry logic accordingly. This is the standard, documented way to read the code without parsing the raw message, making it the right choice for a Webex integration that must react to rate limiting or authentication failures.

Why this answer

The requests library parses the HTTP status line of the server response and stores the numeric code in the status_code attribute. A client integrating with the Webex API reads that integer to detect conditions such as 401 for bad tokens or 429 for rate limiting, then decides whether to retry, refresh credentials, or fail. The boolean ok, the reason phrase, and header lookups do not provide the exact numeric value needed.

Exam trap

The trap here is assuming that a boolean success indicator such as ok carries the same information as the numeric status code, when it collapses every failure into a single False.

59
MCQeasy

A network engineer is using curl to test a REST API endpoint on a Cisco IOS XE device that supports RESTCONF. The engineer wants to retrieve the configuration of the GigabitEthernet1 interface. Which curl command correctly sends a GET request to the RESTCONF API with the appropriate headers to retrieve the interface configuration in JSON format?

A.curl -X POST -H 'Accept: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
B.curl -X GET -H 'Accept: application/json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
C.curl -X GET -H 'Accept: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
D.curl -X GET -H 'Content-Type: application/yang-data+json' 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1'
AnswerC

This command uses the correct HTTP method (GET) and sets the Accept header to 'application/yang-data+json', which tells the RESTCONF server to return the data in JSON format according to the YANG data model. The URL path correctly targets the specific interface using the ietf-interfaces module.

Why this answer

To retrieve data via RESTCONF, a GET request must be sent with the Accept header set to 'application/yang-data+json' to request JSON-formatted YANG data. The URL must correctly reference the data node using the module name and interface name. The other options use incorrect headers or HTTP methods.

Exam trap

The trap here is confusing the Accept header with Content-Type, or using the wrong HTTP method for retrieval.

60
MCQmedium

A developer is writing a Python script that calls the Cisco Webex API. The script must handle the case where the API returns a 429 Too Many Requests response. Which HTTP response header should the script inspect to determine how long to wait before retrying the request?

A.X-RateLimit-Limit
B.Cache-Control
C.Retry-After
D.Link
AnswerC

The Retry-After header is the standard HTTP mechanism for a server to tell a client how many seconds to wait before making another request. Cisco Webex APIs return this header on 429 responses, so the script should read its value and sleep for that duration before retrying, avoiding further throttling and potential temporary blocking.

Why this answer

When a REST API throttles a client with 429 Too Many Requests, the standard way to communicate the required backoff is the Retry-After response header, which contains either a number of seconds or an HTTP date. Cisco Webex returns this header, so a well-behaved client reads it and delays the next attempt accordingly, rather than retrying immediately and remaining throttled.

Exam trap

The trap here is assuming any rate-limit-related header such as X-RateLimit-Limit or X-RateLimit-Remaining tells you how long to wait, when only Retry-After conveys the backoff duration.

61
MCQmedium

In the OAuth 2.0 authorization code flow, what does the client receive after the user grants authorization?

A.An authorization code
B.A client secret
C.A refresh token
D.An access token
AnswerA

The client receives a short-lived authorization code, which it then exchanges at the token endpoint for access and ID tokens. This satisfies the flow's security constraint: tokens are never exposed to the user agent via the front channel, only the single-use code, which is bound to the client and redirect URI.

Why this answer

In the OAuth 2.0 authorization code flow, after the user grants authorization, the authorization server redirects the client with an authorization code in the query string. This code is a temporary credential that the client must exchange for an access token by sending it along with its client credentials to the token endpoint. The authorization code itself is not the final token; it is a one-time-use intermediary that prevents the access token from being exposed to the user agent.

Exam trap

Cisco often tests the distinction between what is received immediately after user authorization (the authorization code) versus what is obtained after the subsequent token exchange (access token and optionally a refresh token), causing candidates to mistakenly select the access token.

How to eliminate wrong answers

Option B is wrong because a client secret is a static credential pre-shared between the client and authorization server, not something received after user authorization. Option C is wrong because a refresh token is issued only after the client exchanges the authorization code for an access token at the token endpoint, not immediately upon user grant. Option D is wrong because the access token is not directly returned to the client after user authorization; the client must first exchange the authorization code for it via a back-channel request to the token endpoint.

62
Multi-Selectmedium

A developer is writing a Python script that consumes a REST API which returns JSON error bodies. The script must distinguish client mistakes from server-side problems and react accordingly. Which TWO HTTP status code ranges or codes indicate conditions the client should handle as errors caused by the request or by the server rather than success? (Choose two.)

Select 2 answers
A.3xx redirection status codes
B.200 OK
C.4xx client error status codes
D.101 Switching Protocols
E.5xx server error status codes
AnswersC, E

Codes in the 4xx class indicate the request itself was flawed, such as 400 for malformed syntax, 401 for missing credentials, 403 for insufficient permission, or 404 for an unknown resource. The script should inspect these codes and avoid blind retries, since resending the same request typically reproduces the same failure until the request is corrected.

Why this answer

The 4xx class identifies requests the client got wrong, and the 5xx class identifies server-side failures. Together they form the error conditions a consuming script must branch on: 4xx usually requires fixing the request, while 5xx usually warrants retries with backoff. Success codes, redirections, and informational responses belong to different handling paths.

Exam trap

The trap here is lumping all non-200 responses into one error bucket, ignoring that 3xx and 1xx responses are not failures at all.

63
MCQmedium

A network engineer wants to use NETCONF to change the hostname of a Cisco device. Which operation should be used?

A.<lock>
B.<copy-config>
C.<edit-config>
D.<get-config>
AnswerC

The `<edit-config>` operation writes configuration changes into the running datastore, which is exactly what altering a hostname requires. It targets the specified configuration node and applies the new value, satisfying NETCONF's requirement for modifying device configuration rather than merely retrieving state with `<get-config>`.

Why this answer

The <edit-config> operation is used to modify configuration data in NETCONF.

64
MCQhard

A developer is using the ncclient library in Python to connect to a network device via NETCONF. Which operation should be used to modify the running configuration and commit the changes?

A.validate() followed by get_config()
B.get_config() followed by copy_config()
C.edit_config() followed by commit()
D.discard_changes() followed by edit_config()
AnswerC

The NETCONF edit_config() operation writes changes into the candidate datastore, satisfying the requirement to modify configuration without immediately affecting the running state. commit() then promotes the candidate to running, which the stem explicitly demands. This two-step sequence matches the candidate-to-running workflow that NETCONF's distinct datastores enforce.

Why this answer

In NETCONF, the `edit-config()` operation is used to modify the running configuration, and the `commit()` operation is required to make those changes permanent when the device operates in candidate configuration mode. The ncclient library provides these methods to align with the NETCONF protocol's standard operations.

Exam trap

Cisco often tests the distinction between candidate and running datastores, and the trap here is that candidates assume `edit_config()` alone commits changes, forgetting that a separate `commit()` is required when the device uses a candidate configuration model.

How to eliminate wrong answers

Option A is wrong because `validate()` checks the syntactic correctness of a configuration but does not modify it, and `get_config()` retrieves configuration data without making changes. Option B is wrong because `get_config()` retrieves configuration, and `copy_config()` copies a configuration from one datastore to another (e.g., running to startup), but neither directly modifies the running configuration with a commit step. Option D is wrong because `discard_changes()` reverts uncommitted changes in a candidate datastore, and `edit_config()` modifies the configuration; performing `discard_changes()` before `edit_config()` would discard any pending changes but does not achieve a commit of new modifications.

65
MCQmedium

A developer is building a Python script that calls the Cisco Webex Rooms API. The script must handle rate limiting gracefully by reading the response headers when the API returns HTTP 429. Which response header should the script inspect to determine how long to wait before retrying?

A.X-RateLimit-Reset
B.Retry-After
C.Location
D.WWW-Authenticate
AnswerB

The Retry-After header is a standard HTTP response header that indicates how many seconds the client should wait before making a follow-up request. When the Webex API returns 429 Too Many Requests, it includes Retry-After so the client can pause accordingly, avoiding further throttling and ensuring the script respects the service's rate limits.

Why this answer

When the Webex API throttles a client with HTTP 429, it includes the Retry-After header to specify the number of seconds to wait. Reading this header allows the script to implement an appropriate backoff, respecting the service's limits and avoiding further penalties. The other headers serve different purposes and do not provide rate-limit timing information.

Exam trap

The trap here is assuming that a custom header like X-RateLimit-Reset is always used for rate limiting, when the Webex API specifically relies on the standard Retry-After header.

66
MCQeasy

Which HTTP method should be used to partially update an existing resource in a REST API?

A.PUT
B.DELETE
C.POST
D.PATCH
AnswerD

PATCH applies partial modifications to an existing resource, sending only the fields being changed. PUT would replace the entire resource representation, so PATCH uniquely satisfies the stem's requirement to partially update a resource without overwriting unspecified attributes.

Why this answer

PATCH is used for partial updates, while PUT replaces the entire resource.

67
MCQmedium

A developer is using the Meraki Dashboard API and notices that some requests return a 429 status code. What is the most likely cause?

A.The organization ID is incorrect.
B.The request payload is too large.
C.The API key is invalid.
D.The rate limit of 5 requests per second has been exceeded.
AnswerD

HTTP 429 Too Many Requests signals rate limiting. The Meraki Dashboard API enforces a limit of 5 calls per second per organisation; exceeding it returns 429 until the window resets. The Retry-After header indicates how long to wait, so the cause is request volume, not authentication or payload errors.

Why this answer

HTTP 429 means 'Too Many Requests.' The Meraki Dashboard API enforces a rate limit of 5 requests per second per organization, and exceeding it returns a 429 with a Retry-After header. The developer should implement exponential backoff and respect the Retry-After value.

Exam trap

200-901 often tests HTTP status code meanings — candidates confuse 429 (rate limit) with 401 (auth), 404 (not found), or 413 (payload too large).

How to eliminate wrong answers

Option A is wrong because an incorrect organization ID returns a 404 Not Found, not 429. Option B is wrong because an oversized payload returns 413 Payload Too Large or 400 Bad Request, not 429. Option C is wrong because an invalid API key returns 401 Unauthorized, not 429.

68
Multi-Selectmedium

A developer is designing a Python script that interacts with multiple Cisco APIs, including Cisco Webex and Cisco DNA Center. The script must authenticate to each API and handle tokens securely. Which TWO of the following practices are recommended for securely managing API credentials and tokens? (Choose two.)

Select 2 answers
A.Store API keys and tokens in environment variables or a secure vault, and retrieve them at runtime.
B.Share API tokens with team members via email to facilitate collaboration.
C.Implement token refresh logic to automatically obtain a new access token when the current one expires, using a refresh token.
D.Log the full API request and response, including Authorization headers, to aid in debugging.
E.Hard-code API keys directly in the Python script for simplicity and ease of deployment.
AnswersA, C

Using environment variables or a secure vault keeps credentials out of source code, reducing the risk of accidental exposure. It allows for different configurations across environments and facilitates rotation. This is a widely recommended practice for managing secrets in applications.

Why this answer

The recommended practices are to store credentials securely (e.g., environment variables or vault) and to implement token refresh logic. These reduce the risk of credential leakage and ensure uninterrupted API access. Hard-coding, logging tokens, and sharing via email are insecure and should be avoided.

Exam trap

The trap here is underestimating the risk of hard-coding or logging credentials, which are common but dangerous shortcuts.

69
MCQmedium

A developer is testing a REST API using curl. The API returns a JSON response with a status code of 201. What does this status code indicate about the request?

A.The request was successful and the response contains a representation of the modified resource.
B.The request was successful and a new resource was created.
C.The request was accepted for processing but has not been completed.
D.The request was successful but the response body is empty.
AnswerB

HTTP 201 Created indicates that the request has succeeded and has led to the creation of a new resource. The response typically includes a Location header with the URI of the new resource. This is the correct interpretation for a POST request that creates a resource. It is a success status code in the 2xx range.

Why this answer

The 201 Created status code indicates that the request was successful and a new resource was created. It is commonly returned after a POST request to a collection endpoint. The response may include a Location header and a body with the new resource.

Other status codes like 200, 202, and 204 have different meanings. Understanding these distinctions is essential for API testing and development.

Exam trap

The trap here is confusing 201 Created with 200 OK or 202 Accepted, which have different implications for resource creation and processing.

70
Multi-Selecthard

A developer is building a Python application that integrates with Cisco DNA Center. The application needs to authenticate and then retrieve a list of network devices. The developer decides to use the DNA Center Intent API. Which two steps are required to successfully authenticate and make an API call? (Choose two.)

Select 2 answers
A.Generate a JWT token using the DNA Center certificate and sign each request with it.
B.Send a POST request to /dna/system/api/v1/auth/token with Basic Auth credentials to obtain a token.
C.Use OAuth 2.0 with the client credentials grant to obtain an access token from the /token endpoint.
D.Include the obtained token in the 'X-Auth-Token' header for subsequent API requests.
E.Pass the username and password as query parameters in each API request.
AnswersB, D

The DNA Center Intent API requires obtaining an authentication token by sending a POST request to the /dna/system/api/v1/auth/token endpoint. The request must include Basic Auth headers with the username and password. The response contains a token that must be used in subsequent API calls. This step is essential for authentication and is documented in the Cisco DNA Center Platform API guide.

Why this answer

To authenticate with the DNA Center Intent API, the developer must first obtain a token by sending a POST request with Basic Auth credentials to the token endpoint. Then, that token must be included in the 'X-Auth-Token' header for all subsequent API calls. This two-step process ensures secure authentication and authorization.

The other options describe incorrect or insecure methods that are not supported by DNA Center.

Exam trap

The trap here is assuming DNA Center uses OAuth 2.0 or JWT, when it actually uses a simple token-based system with Basic Auth.

71
MCQeasy

A network engineer is using the Cisco DNA Center API to retrieve a list of all sites. The API response is a JSON object with a 'response' array containing site objects. The engineer wants to extract the name of each site. Which Python code snippet correctly parses the JSON response and prints each site name?

A.for site in response.json(): print(site['name'])
B.print(response.json()['name'])
C.for site in response.json()['sites']: print(site['name'])
D.for site in response.json()['response']: print(site['name'])
AnswerD

This snippet correctly accesses the 'response' key from the parsed JSON and iterates over the list of site objects, printing the 'name' field of each. The Cisco DNA Center API returns a JSON object with a top-level 'response' key containing an array of site details, so this approach accurately extracts the required information.

Why this answer

The Cisco DNA Center API returns site data within a top-level 'response' array. To print each site name, the code must parse the JSON, access the 'response' list, iterate over each site dictionary, and print the 'name' value. The correct snippet does exactly that, while the others either misidentify the key or attempt to iterate over the wrong structure.

Exam trap

The trap here is assuming that the API response directly contains a list of sites or that the top-level object has a 'name' field, rather than nesting the data under 'response'.

72
MCQeasy

Which HTTP method is idempotent and safe?

A.GET
B.DELETE
C.POST
D.PUT
AnswerA

GET retrieves a representation without altering server state, satisfying both safety (no side effects) and idempotence (repeated identical requests yield the same result). Unlike POST, which creates or modifies resources, GET is defined by RFC 9110 as both safe and idempotent, making it the only listed method meeting both constraints.

Why this answer

GET is both idempotent and safe because it is designed to retrieve a resource without causing any side effects on the server. According to RFC 7231, a safe method does not modify the resource state, and an idempotent method guarantees that multiple identical requests produce the same result as a single request. GET satisfies both conditions, as it never alters server state and repeating the same GET request returns the same representation.

Exam trap

Cisco often tests the distinction between idempotent and safe by pairing DELETE (idempotent but not safe) or PUT (idempotent but not safe) as distractors, leading candidates to assume that any method that can be repeated safely is also safe, when in fact safety requires no server-side state change.

How to eliminate wrong answers

Option B (DELETE) is wrong because while DELETE is idempotent (repeated calls have the same effect as one call, typically returning 404 after the first deletion), it is not safe because it modifies server state by removing a resource. Option C (POST) is wrong because POST is neither safe nor idempotent; it creates or updates a resource, and multiple identical POST requests can result in multiple resource creations or side effects. Option D (PUT) is wrong because although PUT is idempotent (replacing a resource with the same representation yields the same state), it is not safe because it modifies server state by updating or creating a resource.

73
MCQeasy

What HTTP method should be used to update only the description field of a network device resource via a REST API?

A.DELETE
B.PUT
C.POST
D.PATCH
AnswerD

PATCH applies a partial modification, sending only the description field in the request body while leaving all other device attributes untouched. PUT would replace the entire resource representation, risking unintended overwrites of unmentioned fields. This satisfies the stem's constraint of updating solely the description.

Why this answer

PATCH is used for partial updates, whereas PUT replaces the entire resource. GET retrieves, POST creates, DELETE removes.

74
MCQmedium

What is the correct Content-Type header value for a RESTCONF request using JSON encoding?

A.application/yang-data+json
B.application/json
C.text/json
D.application/xml
AnswerA

`application/yang-data+json` is the media type RESTCONF mandates for JSON-encoded YANG data, as defined in RFC 8040. It satisfies the stem's JSON encoding constraint by pairing the `+json` structured suffix with the `yang-data` subtype, letting the server parse the payload against the YANG schema rather than treating it as generic JSON.

Why this answer

RESTCONF uses application/yang-data+json for JSON and application/yang-data+xml for XML. application/json is not specific to YANG data.

75
MCQhard

A developer needs to use Postman to test an API that uses Basic authentication. How should the credentials be configured in Postman?

A.Send the credentials in the request body as JSON
B.Use the Authorization tab, select Basic Auth, and enter username and password
C.Set the Authorization header to 'Bearer base64(username:password)'
D.Add a query parameter 'auth' with base64-encoded credentials
AnswerB

Configuring Basic Auth on the Authorization tab injects the credentials as a Base64-encoded `Authorization: Basic` header on every request, satisfying the stem's requirement to test a Basic-authenticated API. Postman handles encoding automatically, so the username and password need not be manually concatenated or encoded before sending.

Why this answer

Postman's Authorization tab provides a built-in Basic Auth type where you enter the username and password; Postman automatically Base64-encodes them and constructs the 'Authorization: Basic <credentials>' header per RFC 7617. This is the correct and standard way to configure Basic authentication in Postman.

Exam trap

200-901 often tests the difference between authentication schemes — candidates confuse Basic (Base64 user:pass) with Bearer (token) and pick the option that mentions Base64 but uses the wrong scheme or location.

How to eliminate wrong answers

Option A is wrong because Basic authentication credentials belong in the Authorization header, not the request body — sending them in the body is non-standard and the server will not recognize them as auth. Option C is wrong because the Bearer scheme is for token-based auth (OAuth 2.0), not Basic auth, and Basic auth uses the 'Basic' scheme with Base64(username:password), not 'Bearer'. Option D is wrong because passing credentials as a query parameter is insecure (they appear in logs and URLs) and is not how Basic auth works — the credentials must go in the Authorization header.

Page 1 of 2 · 142 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Understanding and Using APIs questions.