Courseiva

CCNA Understanding and Using APIs Questions

67 of 142 questions · Page 2/2 · Understanding and Using APIs · Answers revealed

76
MCQmedium

When using RESTCONF to configure a network device, what Content-Type header should be set in the HTTP request to indicate YANG data in JSON format?

A.application/yang
B.application/yang-data+json
C.application/xml
D.application/json
AnswerB

RESTCONF uses the YANG-derived media type application/yang-data+json to signal JSON-encoded YANG data in the request body. Setting it as Content-Type tells the device how to parse the payload, satisfying the stem's requirement to indicate YANG data in JSON format.

Why this answer

RFC 8040 defines the media type for YANG-modeled data encoded in JSON as 'application/yang-data+json'. When sending a RESTCONF request with a JSON body, the Content-Type header must be set to this value so the device knows to parse the payload against the YANG model using the JSON encoding rules.

Exam trap

200-901 often tests the distinction between generic JSON/XML media types and the YANG-specific '+json' structured suffix, catching candidates who assume 'application/json' is always accepted.

How to eliminate wrong answers

Option A is wrong because 'application/yang' is not a registered media type for RESTCONF payloads; YANG is the modeling language, not the wire format. Option C is wrong because 'application/xml' would indicate XML-encoded data, which RESTCONF supports as 'application/yang-data+xml', not plain XML. Option D is wrong because 'application/json' is generic JSON and does not tell the device the payload conforms to YANG data rules, so RESTCONF servers reject it.

77
MCQeasy

A developer is testing a REST API with curl and wants the response to include only the HTTP status code and response headers, discarding the body. Which curl option accomplishes this?

A.curl -o headers.txt https://api.example.com/devices
B.curl -d @payload.json https://api.example.com/devices
C.curl -X POST https://api.example.com/devices
D.curl -I https://api.example.com/devices
AnswerD

The -I option sends a HEAD request, so the server returns headers and status without a response body. This matches the goal of seeing only the status code and headers. It is the standard curl way to inspect metadata such as content type, cache directives, or rate-limit fields without downloading the full representation.

Why this answer

The -I option issues a HEAD request, which asks the server for the same headers it would send for a GET but without the body. This is ideal for checking status codes, content types, and rate-limit headers cheaply. It is a safe, idempotent inspection method that avoids transferring large payloads during API testing.

Exam trap

The trap here is confusing -o, which redirects the body to a file, with -I, which suppresses the body entirely by using the HEAD method.

78
MCQmedium

When using the Cisco DNA Center intent API to retrieve issues, the response includes a Link header with rel="next" and a URL. What type of pagination is this?

A.Offset/limit pagination
B.Cursor-based pagination via Link header
C.Page-based pagination
D.No pagination
AnswerB

A Link header carrying rel="next" with an opaque URL is cursor-based pagination: the server dictates the next page location rather than the client computing offsets. This satisfies the scenario's identification of the pagination style used by the DNA Center issues endpoint.

Why this answer

A Link header containing rel="next" with a URL is the standard HTTP mechanism for cursor-based (or token-based) pagination, where the server returns an opaque link to the next page rather than requiring the client to compute offsets. Cisco DNA Center's intent API uses this pattern, returning a Link header with rel="next" and rel="prev" as applicable. The client simply follows the URL until no next link is present.

Exam trap

200-901 often tests whether candidates recognize the Link header as cursor-based pagination rather than assuming all pagination uses offset/limit or page parameters — the header form is the giveaway.

How to eliminate wrong answers

Option A is wrong because offset/limit pagination uses query parameters like ?offset=100&limit=50, not a Link header with rel="next". Option C is wrong because page-based pagination uses ?page=2&size=50 style parameters, again not a Link header. Option D is wrong because the presence of a rel="next" Link header explicitly indicates pagination is in use; the API is not returning all results in one response.

79
MCQhard

A developer is integrating with the Cisco Webex API and wants to authenticate on behalf of users without ever handling their passwords. The integration is a web application hosted on a public server, and the developer needs a refresh token so the app can keep working after the user's access token expires. Which OAuth 2.0 grant type should be used?

A.Implicit grant
B.Client credentials grant
C.Authorization code grant with PKCE
D.Authorization code grant
AnswerD

The authorization code grant is the standard flow for confidential web applications. The user authenticates at the Cisco Webex authorization server, the app receives a short-lived code, and it exchanges that code plus its client secret for an access token and a refresh token, allowing the app to obtain new access tokens without user interaction.

Why this answer

For a confidential web application that must act on behalf of users and continue operating after access tokens expire, the OAuth 2.0 authorization code grant is the correct choice. The user's credentials are entered only at the Cisco Webex authorization endpoint, and the app receives an authorization code that it exchanges server-side, along with its client secret, for both an access token and a refresh token.

Exam trap

The trap here is choosing authorization code with PKCE because it sounds more secure, when the scenario specifies a confidential server-side web app for which the standard authorization code grant is appropriate.

80
Multi-Selectmedium

A developer is designing a REST API client that must handle rate limiting from a Cisco Webex API. The API returns HTTP 429 Too Many Requests with a 'Retry-After' header. Which two strategies should the developer implement to handle rate limiting gracefully? (Choose two.)

Select 2 answers
A.Cache all responses indefinitely to avoid making repeated requests.
B.Switch to a different API endpoint that is not rate-limited.
C.Implement exponential backoff, increasing the delay between retries after each 429 response.
D.Immediately retry the request without delay to ensure the data is retrieved as quickly as possible.
E.Parse the 'Retry-After' header and wait for the specified number of seconds before retrying the request.
AnswersC, E

Exponential backoff is a standard strategy to handle rate limiting. By increasing the wait time after each 429, the client reduces the load on the server and increases the chance of success. It is recommended in conjunction with the Retry-After header for optimal behavior.

Why this answer

To handle rate limiting gracefully, the client should respect the 'Retry-After' header and implement exponential backoff. These strategies reduce request frequency and align with server expectations. Immediate retries, switching endpoints, or indefinite caching do not properly address rate limiting and can worsen the situation.

Exam trap

The trap here is thinking that immediate retries or switching endpoints can bypass rate limiting, but the correct approach is to wait and back off as indicated by the server.

81
MCQhard

When using OAuth 2.0 client credentials flow with a Cisco API, what is the typical purpose of the access token?

A.To identify the user's role
B.To authenticate the user
C.To authorize the client application to access resources
D.To encrypt the request payload
AnswerC

The client credentials flow issues an access token representing the application itself, not a user, and the API validates that token to authorise the requested resource access. It carries granted scopes and expiry, replacing user credentials in machine-to-machine calls.

Why this answer

Client credentials flow is for server-to-server; the access token authorizes the client application to access resources on its own behalf, not on behalf of a user.

82
Multi-Selecthard

Which THREE statements about NETCONF are correct?

Select 3 answers
A.NETCONF uses HTTP as the transport protocol.
B.NETCONF uses SSH as the transport protocol.
C.The <edit-config> operation is used to modify configuration data.
D.The <get-config> operation retrieves both configuration and state data.
E.NETCONF operations are XML RPCs.
AnswersB, C, E

NETCONF mandates SSH as its transport, satisfying the stem's requirement for a secure, connection-oriented channel. Unlike SNMP's UDP-based model, SSH provides encryption, authentication and reliable delivery, over which NETCONF exchanges XML-encoded RPCs on port 830. This transport binding is defined in RFC 6242.

Why this answer

Option B is correct because NETCONF (RFC 6241) defines SSH as its mandatory transport protocol, mapping NETCONF sessions to the SSH subsystem 'netconf' on TCP port 830. Option C is correct because the <edit-config> operation is the standard NETCONF RPC for loading configuration changes into a specified datastore (running, candidate, or startup), supporting merge, replace, create, and delete operations. Option E is correct because all NETCONF protocol operations are encoded as XML-based RPCs within <rpc> and <rpc-reply> elements, using the NETCONF base namespace.

Option A is incorrect because HTTP is not the NETCONF transport; NETCONF over HTTP is not defined in the base specification (RESTCONF is the HTTP-based alternative). Option D is incorrect because <get-config> retrieves only configuration data from a datastore; state data is retrieved with the separate <get> operation.

Exam trap

Cisco often tests the distinction between NETCONF and RESTCONF transport protocols, and the specific datastore retrieval operations, leading candidates to confuse <get-config> with <get> or to assume HTTP is used for NETCONF.

83
MCQmedium

A developer is building a Python script that calls the Cisco Webex API to create a new room. The API returns a JSON payload containing the room ID. The developer needs to extract the room ID from the response and use it in a subsequent API call to add a member to that room. Which Python code snippet correctly parses the JSON response and extracts the room ID, assuming the response object is stored in a variable named `response` and the JSON key is `id`?

A.room_id = response.text['id']
B.room_id = response.json()['id']
C.room_id = response.json['id']
D.room_id = response.content['id']
AnswerB

This correctly uses the .json() method to parse the JSON response body into a Python dictionary, then accesses the 'id' key. It is the standard way to handle JSON responses in the requests library, which is commonly used for REST API calls. The resulting room_id can be used in subsequent requests.

Why this answer

The correct approach is to use the .json() method provided by the requests library to parse the JSON response into a Python dictionary, then access the 'id' key. This yields the room ID needed for subsequent API calls. The other options incorrectly assume that the response object can be indexed directly or that .json is a property.

Exam trap

The trap here is confusing the .json() method with a property, or using .text or .content directly for dictionary access.

84
Multi-Selectmedium

A developer needs to retrieve a list of network devices from Cisco DNA Center with pagination. Which TWO URL components are typically used for offset/limit pagination?

Select 2 answers
A.Link header
B.Query parameter 'page'
C.Query parameter 'limit'
D.Query parameter 'offset'
E.Path parameter 'page'
AnswersC, D

Query parameter 'limit' controls how many device records Cisco DNA Center returns per page, satisfying the pagination constraint in the stem. Paired with an offset parameter, it bounds each response, preventing oversized payloads when retrieving the device list. The API reads it from the URL query string, so no request body or custom header is needed.

Why this answer

Options C and D are correct because Cisco DNA Center's REST APIs implement offset/limit pagination through the query parameters 'limit' (the maximum number of records to return per page) and 'offset' (the number of records to skip before starting to return results), so a request such as GET /dna/intent/api/v1/network-device?offset=1&limit=10 retrieves the second page of ten devices. Option A is incorrect because the Link header is a response header used by some APIs (e.g., GitHub) to convey pagination URLs, not a URL component the developer supplies in the request. Option B is incorrect because Cisco DNA Center does not use a 'page' query parameter for offset/limit pagination.

Option E is incorrect because 'page' is not a path parameter in these API endpoints; path parameters identify specific resources, not pagination windows.

Exam trap

Cisco often tests the distinction between offset/limit pagination (using 'offset' and 'limit' query parameters) and page-based pagination (using 'page' and 'size' or 'per_page' parameters), leading candidates to mistakenly select 'page' as a correct option.

85
MCQhard

A network engineer wants to stream telemetry data from a Cisco router using gRPC. Which gRPC service model is typically used for the router to push data to a collector?

A.RESTCONF events
B.NETCONF subscription
C.Dial-in model
D.Dial-out model
AnswerD

In the dial-out model the router initiates the gRPC connection to the collector and streams telemetry over it, which suits devices behind NAT or firewalls. Dial-in would require the collector to connect inbound to the router instead.

Why this answer

Dial-out streaming (also called telemetry push) is where the device initiates the connection and sends data to the collector. Dial-in is where the collector pulls data from the device.

86
Multi-Selecteasy

Which TWO of the following HTTP methods are considered safe (idempotent and not modifying server state)? (Select two.)

Select 2 answers
A.PUT
B.DELETE
C.POST
D.GET
E.HEAD
AnswersD, E

GET is defined as a safe method because it retrieves a representation without altering server state, and it is idempotent since repeated identical requests produce the same effect. This directly satisfies the stem's requirement for methods that are both idempotent and non-modifying.

Why this answer

GET (D) is safe because it is defined by RFC 7231 as a read-only method that retrieves a representation without altering server state, and repeating it yields the same result (idempotent). HEAD (E) is also safe because it returns only the response headers for the same resource a GET would target, performing no state change and being idempotent. PUT (A) is not safe because it creates or replaces the target resource, modifying server state, even though it is idempotent.

DELETE (B) is not safe because it removes the target resource, changing server state (it is idempotent but not safe). POST (C) is neither safe nor idempotent, since it submits data that typically creates or processes a resource and can produce different results on each call.

Exam trap

The trap is conflating 'idempotent' with 'safe' — candidates pick PUT or DELETE because they are idempotent, forgetting that safety additionally requires no server-state modification.

87
MCQeasy

A developer sends a GET request to https://sandboxdnac.cisco.com/dna/system/api/v1/auth/token and receives an HTTP 401 Unauthorized response. The request included no Authorization header. Which HTTP request header must be added to obtain a token from Cisco DNA Center?

A.Authorization: Basic <base64(username:password)>
B.Content-Type: application/json
C.Authorization: Bearer <token>
D.X-Auth-Token: <apiKey>
AnswerA

Cisco DNA Center's token endpoint uses HTTP Basic authentication. The client must send the username and password Base64-encoded in the Authorization header with the Basic scheme to receive a JSON response containing a token. Without this header the controller cannot identify the caller and returns 401 Unauthorized, which matches the failure described.

Why this answer

Cisco DNA Center issues tokens through /dna/system/api/v1/auth/token, and that endpoint authenticates the caller with HTTP Basic credentials encoded in the Authorization header. Once the controller validates the username and password, it returns a token used for later intent API calls. Other headers such as Content-Type or custom token headers do not satisfy the initial credential check.

Exam trap

The trap here is assuming the token endpoint accepts a Bearer token, when it actually requires the credentials themselves encoded with the Basic scheme.

88
Multi-Selectmedium

A developer is designing a Python application that consumes several Cisco REST APIs. To make the code maintainable and secure, the developer wants to implement reusable API request handling. Which two practices should be applied? (Choose two.)

Select 2 answers
A.Store API credentials in environment variables or a secrets manager rather than hard-coding them in source files.
B.Disable TLS certificate verification to avoid errors when calling multiple APIs.
C.Write a separate copy of the authentication and request logic for each API endpoint to keep functions independent.
D.Hard-code the API key in each script so every team member can run it without configuration.
E.Centralize HTTP session creation and common headers in a reusable client module.
AnswersA, E

Embedding secrets in source code risks exposure through version control, logs, or shared repositories. Using environment variables or a dedicated secrets manager separates configuration from code, supports rotation, and limits blast radius if a repository leaks. This is a foundational secure-coding practice for any API-consuming application, including Cisco DevNet workflows.

Why this answer

Secure and maintainable API clients externalize secrets and centralize shared request logic. Storing credentials in environment variables or a secrets manager prevents accidental exposure, while a reusable client module ensures consistent authentication, headers, and error handling. Hard-coding keys, disabling TLS verification, or duplicating logic all undermine security or maintainability and should be avoided.

Exam trap

The trap here is treating convenience measures such as hard-coded keys or disabled TLS verification as acceptable shortcuts, when they directly violate the security and maintainability goals of the scenario.

89
MCQhard

A network automation engineer is writing a Python script that calls the Cisco DNA Center API to retrieve device health scores. The API enforces rate limiting and returns HTTP 429 with a 'Retry-After' header when the limit is exceeded. The script must handle this gracefully without crashing. Which code pattern correctly implements the retry logic?

A.Ignore the 429 response and continue with the next API call, assuming the data will be fetched eventually.
B.Use a try-except block to catch requests.exceptions.HTTPError, then immediately retry the request in a loop until it succeeds.
C.Check the response status code; if it is 429, read the 'Retry-After' header, sleep for the specified number of seconds, then retry the request.
D.Increase the request timeout value to 60 seconds and resend the request, hoping the rate limit resets.
AnswerC

The correct approach is to detect the 429 status, parse the 'Retry-After' header (which indicates how many seconds to wait), pause execution using time.sleep(), and then retry. This respects the server's rate limit policy and ensures the script does not overwhelm the API. It also prevents unnecessary errors and aligns with standard practices for handling rate limiting in REST APIs.

Why this answer

When an API returns HTTP 429 Too Many Requests, it often includes a 'Retry-After' header specifying how long the client should wait before retrying. The script must check for this status code, extract the header, pause for the indicated duration, and then retry the request. This ensures compliance with rate limits and maintains the script's reliability without causing further throttling.

Exam trap

The trap here is treating a 429 response like a generic error and retrying immediately, instead of using the server-provided 'Retry-After' header to determine the correct backoff period.

90
MCQmedium

A developer needs to authenticate to a REST API using an API key that must be sent in a custom HTTP header named X-API-Key on every request. The team uses Python requests. Which code snippet correctly attaches the key to a GET request?

A.requests.get(url, auth=(api_key, ""))
B.requests.get(url + "?X-API-Key=" + api_key)
C.requests.get(url, cookies={"X-API-Key": api_key})
D.requests.get(url, headers={"X-API-Key": api_key})
AnswerD

Passing a dictionary to the headers parameter adds the custom header to the outgoing request. This is the standard way to send API keys that the vendor expects in a named header. The server reads X-API-Key and authorizes the call, so this snippet matches the documented requirement exactly.

Why this answer

Custom API key headers are attached by passing a dictionary to the requests headers parameter. This places X-API-Key directly on the request, matching the server's expectation. Other transports such as Basic auth, query strings, or cookies use different header names and would not satisfy the API's authentication check, causing 401 responses.

Exam trap

The trap here is reaching for the auth parameter by habit, when the API specifically demands a custom header that requests only sends via the headers dictionary.

91
Multi-Selecthard

A developer is designing a Python application that will consume multiple REST APIs from different Cisco platforms. The application must handle common API behaviors such as authentication, rate limiting, and error responses. Which TWO of the following are best practices for making the application robust and maintainable? (Choose two.)

Select 2 answers
A.Implement exponential backoff when retrying requests after receiving 5xx errors.
B.Ignore HTTP status codes and parse the response body for error messages.
C.Hard-code API keys and tokens directly in the source code for simplicity.
D.Always use synchronous requests to simplify code and avoid concurrency issues.
E.Use a single, shared HTTP session object for all API calls to reuse connections.
AnswersA, E

Exponential backoff helps prevent overwhelming a server that is already experiencing issues. By increasing the delay between retries, it gives the server time to recover and reduces the chance of exacerbating the problem. This is a standard practice for handling transient errors and rate limiting.

Why this answer

Implementing exponential backoff for retries and using a shared HTTP session are both best practices that enhance robustness and maintainability. Exponential backoff handles transient errors gracefully, while a session improves performance and simplifies authentication management. Together, they help build a resilient application that can handle common API behaviors effectively.

Exam trap

The trap here is focusing on simplicity or quick fixes, like hard-coding credentials or ignoring status codes, instead of adopting standard resilience and security practices.

92
MCQmedium

A developer is building a Python script that calls the Cisco Webex Teams API to fetch a list of rooms. The API returns a response with a Link header containing a URL with a 'pageToken' parameter. What should the developer do to retrieve the next page of results?

A.Increment the 'page' query parameter by 1 and resend the original request.
B.Extract the URL from the Link header and make a GET request to that URL.
C.Use the 'next' field in the JSON response body to construct a new request.
D.Send a POST request to the same endpoint with the 'pageToken' in the request body.
AnswerB

The Link header follows RFC 5988 and contains a URL for the next page. The developer must parse the header, extract the URL, and issue a GET request to it to retrieve the next set of results. This is the standard cursor-based pagination method used by the Webex API.

Why this answer

The Link header in HTTP responses provides a ready-to-use URL for the next page of results. The developer should extract that URL and perform a GET request to it. This approach is consistent with RFC 5988 and is the method used by Cisco Webex APIs for cursor-based pagination.

Exam trap

The trap here is assuming that pagination always uses a page number or an offset parameter, when many modern APIs use opaque tokens provided in the Link header.

93
MCQmedium

A network automation engineer is using the Cisco DNA Center intent API to retrieve a list of network devices. Which API endpoint should be used?

A.GET /dna/intent/api/v1/site
B.GET /dna/intent/api/v1/topology
C.GET /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/issue
AnswerC

The network-device resource path under /dna/intent/api/v1 returns the device inventory, matching the requirement to retrieve a list of network devices. The intent API versioning and resource naming align exactly with the documented endpoint for this operation.

Why this answer

The correct endpoint is GET /dna/intent/api/v1/network-device because the Cisco DNA Center intent API uses this path to retrieve a list of all network devices managed by the controller. The 'network-device' resource is specifically designed for device inventory operations, returning details such as hostname, IP address, platform ID, and software version. This aligns with the intent API's purpose of abstracting underlying complexities into business-relevant resources.

Exam trap

Cisco often tests the distinction between 'network-device' (inventory) and 'topology' (relationships) — candidates mistakenly pick topology because they think 'list of devices' implies a map view, but the intent API separates raw device data from topological connections.

How to eliminate wrong answers

Option A is wrong because GET /dna/intent/api/v1/site retrieves site hierarchy information (buildings, floors, areas), not network device lists. Option B is wrong because GET /dna/intent/api/v1/topology returns the physical or logical topology map of the network, not a flat device inventory. Option D is wrong because GET /dna/intent/api/v1/issue fetches health or assurance issues (e.g., syslog, SNMP traps), not device inventory data.

94
Multi-Selecthard

A developer is designing a Cisco Catalyst Center integration that uses the intent API. Which THREE of the following are available via the intent API? (Select three.)

Select 3 answers
A.Site hierarchy
B.Network device configuration files
C.Issues and health scores
D.List of network devices
E.Real-time interface statistics
AnswersA, C, D

The intent API exposes site hierarchy endpoints, letting integrations retrieve and manage building, floor and area structures. This satisfies the stem's requirement for intent-level abstractions rather than raw device CLI, since Catalyst Center models sites as business intent objects.

Why this answer

Option A (Site hierarchy) is correct because the Cisco Catalyst Center intent API exposes site management endpoints (e.g., /dna/intent/api/v1/site) that let you create, read, and manage the site hierarchy used for policy and device assignment. Option C (Issues and health scores) is correct because the intent API provides endpoints such as /dna/intent/api/v1/issues and /dna/intent/api/v1/health that return detected issues and overall network/device health scores. Option D (List of network devices) is correct because the intent API includes device inventory endpoints (e.g., /dna/intent/api/v1/network-device) that return the list of managed network devices.

Option B is not part of the intent API's exposed capabilities, as configuration file retrieval is handled through other mechanisms such as the configuration archive or CLI-based tools rather than intent API endpoints. Option E is also not available via the intent API, since real-time interface statistics are obtained through streaming telemetry, SNMP, or the platform's monitoring/assurance data paths rather than the intent API.

95
MCQmedium

A developer is testing a custom REST API that returns a JSON error object with an HTTP 400 status when an invalid query parameter is sent. They want to confirm that the API is behaving correctly according to REST conventions. Which HTTP status code class indicates that the client's request contains an error that the client can potentially fix?

A.5xx
B.4xx
C.2xx
D.3xx
AnswerB

The 4xx class of status codes is specifically defined for client errors, indicating that the request contains bad syntax or cannot be fulfilled due to something the client did. An HTTP 400 (Bad Request) is a classic 4xx code, so this class correctly identifies that the client can potentially fix the request, for example by correcting the invalid query parameter.

Why this answer

HTTP status codes are grouped into classes, and the 4xx class is reserved for client errors. An HTTP 400 Bad Request is a 4xx code, so it signals that the client sent something invalid, such as a malformed query parameter. Recognizing this class helps developers distinguish between problems they can fix in their request and problems that originate on the server.

Exam trap

The trap here is assuming that any error status indicates a server problem, which would lead to choosing the 5xx class instead of the correct 4xx class for an HTTP 400 response.

96
MCQhard

In a RESTCONF API call to retrieve a specific interface configuration on a Cisco device, an engineer sends a GET request to /restconf/data/interfaces/interface=GigabitEthernet0/1. What Content-Type should be specified in the Accept header to receive YANG-defined JSON?

A.text/plain
B.application/xml
C.application/yang-data+json
D.application/json
AnswerC

RESTCONF encodes YANG-modelled data, and the Accept header must request the YANG media type. application/yang-data+json returns the interface configuration as YANG-defined JSON, matching the stem's requirement, whereas application/json alone is not the registered RESTCONF media type.

Why this answer

RESTCONF uses application/yang-data+json for JSON encoding of YANG data.

97
MCQmedium

When using the Meraki Dashboard API, how should the API key be included in a request?

A.In the X-Cisco-Meraki-API-Key header
B.As a query parameter named 'apiKey'
C.In the Authorization header using Bearer scheme
D.In the request body as JSON
AnswerA

Meraki Dashboard API authenticates every call by reading the key from the X-Cisco-Meraki-API-Key request header, not from a query string or bearer token. Supplying it there satisfies the stem's requirement, since the dashboard rejects requests lacking that exact header name.

Why this answer

Meraki requires the API key in a custom header X-Cisco-Meraki-API-Key.

98
MCQhard

When using gRPC/gNMI for model-driven telemetry, which mode allows the network device to push telemetry data to a collector without the collector initiating the connection?

A.Dial-out
B.gRPC streaming
C.Streaming pull
D.Dial-in
AnswerA

Dial-out mode has the network device initiate the gRPC connection to the collector, then stream telemetry. This satisfies the stem's constraint that the collector must not initiate the connection, unlike dial-in where the collector connects to the device.

Why this answer

In gRPC/gNMI-based model-driven telemetry, dial-out mode enables the network device (server) to initiate a connection to the collector (client) and push telemetry data without any prior request from the collector. This is the correct mode for unsolicited streaming telemetry, as defined in the gNMI specification (gRPC Network Management Interface).

Exam trap

Cisco often tests the distinction between dial-in and dial-out by reversing the roles of client and server, so the trap here is confusing the direction of connection initiation with the direction of data flow.

How to eliminate wrong answers

Option B is wrong because gRPC streaming is a generic transport mechanism that can be used in both dial-in and dial-out modes, but it does not specify which side initiates the connection. Option C is wrong because streaming pull is a mode where the collector initiates the connection and requests data from the device, not the device pushing data. Option D is wrong because dial-in mode requires the collector to initiate the connection to the device, which is the opposite of the scenario described.

99
MCQmedium

A developer is integrating a Python script with the Cisco Webex API to create a new team. The script sends a POST request to https://webexapis.com/v1/teams with a JSON body containing the team name. The API returns HTTP 401 Unauthorized. The developer confirms the request body and URL are correct. Which of the following is the most likely cause of the 401 response?

A.The API endpoint requires a GET request instead of POST.
B.The request is missing the Content-Type header set to application/json.
C.The request is missing a valid Authorization header with a Bearer token.
D.The request body is not formatted as XML.
AnswerC

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. The Webex API requires an OAuth 2.0 Bearer token in the Authorization header. Without it, the server rejects the request even if the URL and body are correct. The developer must obtain a valid access token and include it as 'Authorization: Bearer <token>'.

Why this answer

A 401 Unauthorized status code means the request lacks valid authentication credentials for the target resource. The Webex API requires an OAuth 2.0 Bearer token in the Authorization header. Without it, the API rejects the request regardless of the correctness of the URL or body.

The developer must obtain a valid access token and include it in the request headers.

Exam trap

The trap here is assuming that a 401 error is caused by a malformed request body or incorrect HTTP method, when it actually indicates missing or invalid authentication credentials.

100
MCQeasy

A network engineer is writing a script to interact with a Cisco DNA Center controller. They need to authenticate and obtain a token to include in subsequent API requests. Which HTTP header should they use to send the token?

A.Authorization: Bearer <token>
B.Authorization: Basic <token>
C.Cookie: token=<token>
D.X-Auth-Token: <token>
AnswerA

Cisco DNA Center uses token-based authentication where the token is sent in the 'Authorization' header with the 'Bearer' scheme. This is the standard OAuth 2.0 approach and is required for API calls after obtaining a token from the authentication endpoint.

Why this answer

Cisco DNA Center uses OAuth 2.0 token-based authentication. After obtaining a token from the authentication endpoint, the client must include it in the 'Authorization' header using the 'Bearer' scheme. This is the correct and standard way to authenticate API requests.

Exam trap

The trap here is confusing the 'Basic' authentication scheme, which uses base64-encoded credentials, with the 'Bearer' scheme used for tokens.

101
MCQhard

A developer is integrating with Cisco DNA Center's Intent API. They need to retrieve a list of all network devices and then filter for devices with a specific software version. The API returns a paginated response with a 'nextPage' field in the JSON body. Which approach should the developer use to efficiently process all devices?

A.Use the 'limit' and 'offset' query parameters, incrementing offset by the limit value until fewer results than the limit are returned.
B.Make a single GET request to /dna/intent/api/v1/network-device and parse all devices from the response, ignoring pagination.
C.Loop through pages using the 'nextPage' field from the JSON response, making subsequent GET requests to the URL provided in that field until it is null.
D.Set the 'limit' query parameter to a very high number (e.g., 10000) to retrieve all devices in one request.
AnswerC

The Intent API includes a 'nextPage' field in the response when more data is available. By following this field, the developer can retrieve all pages sequentially. This is the documented method for pagination in Cisco DNA Center, ensuring complete data retrieval without guessing parameters.

Why this answer

Cisco DNA Center's Intent API uses a 'nextPage' field in the JSON response for pagination. The developer should iterate by requesting the URL in 'nextPage' until it is null. This ensures all devices are retrieved.

Other methods like ignoring pagination, using offset, or setting a high limit are not supported or reliable.

Exam trap

The trap here is assuming that a high limit parameter can bypass pagination, but the API enforces a maximum page size and requires following the nextPage token.

102
MCQeasy

In Postman, what feature allows you to reuse a value like a base URL or token across multiple requests?

A.Mock Servers
B.Workspaces
C.Environments
D.Collections
AnswerC

Environments store key-value variables, such as a base URL or bearer token, that Postman substitutes into requests via {{variable}} syntax. Switching environments swaps values without editing each request, satisfying the requirement to reuse a value across multiple requests.

Why this answer

Environments store variables that can be referenced across requests.

103
MCQmedium

A network engineer is using the Cisco DNA Center API to retrieve a list of all sites. The API returns a large number of records, and the response includes a header indicating the total count and a limit on the number of records per page. Which HTTP response header should the engineer inspect to find the URL for the next page of results?

A.Link
B.Location
C.Retry-After
D.X-Total-Count
AnswerA

The Link header is commonly used in REST APIs for pagination, providing URLs for the next, previous, first, or last pages. In Cisco DNA Center API, when a response is paginated, the Link header contains a URL with rel="next" that the client can follow to retrieve the next set of records. Inspecting this header allows the engineer to navigate through all pages efficiently without constructing URLs manually.

Why this answer

The Link header is the standard way to provide pagination links in REST APIs. It includes a URL for the next page, allowing clients to iterate through large result sets. Other headers like X-Total-Count give total counts, Location is for resource creation, and Retry-After is for rate limiting.

Only Link directly provides the next page URL.

Exam trap

The trap here is assuming that X-Total-Count or Location headers provide pagination links, when actually the Link header is the correct one for navigating pages.

104
MCQmedium

In the Cisco DNA Center intent API, which HTTP method should be used to update a specific site's information?

A.GET
B.POST
C.PUT
D.DELETE
AnswerC

PUT replaces the identified site resource with the supplied representation, matching the intent to update a specific site. POST would create a new resource and PATCH only partially modifies, so PUT satisfies the update-existing-resource constraint.

Why this answer

For updating an existing resource, PUT is used to replace the entire resource, while PATCH is for partial updates. DNA Center intent API typically uses PUT for updates, but PATCH may also be supported. The question asks for update; PUT is the standard.

105
MCQeasy

What is the purpose of the 'Authorization' header in a REST API request?

A.To enable caching of the response
B.To authenticate the client
C.To specify the desired response format
D.To specify the format of the request body
AnswerB

The Authorization header carries credentials, such as a Bearer token or Basic base64 pair, that the server validates to establish the caller's identity, satisfying the stem's requirement to authenticate the client on each REST request.

Why this answer

The Authorization header carries credentials (e.g., Bearer token, Basic auth) to authenticate the client. Content-Type specifies body format. Accept specifies response format.

106
MCQmedium

A developer uses RESTCONF to configure a network device. What is the correct content-type header to send in the request?

A.application/json
B.application/xml
C.application/yang-data+json
D.text/plain
AnswerC

RESTCONF encodes YANG-modelled data, so requests must declare the YANG media type. application/yang-data+json tells the device the body is JSON-encoded YANG data, satisfying the RESTCONF content-type requirement; generic application/json is not the registered RESTCONF media type.

Why this answer

RESTCONF, defined in RFC 8040, uses YANG-modeled data and requires the content-type header to indicate the YANG data representation. The correct media type for JSON-encoded YANG data is application/yang-data+json, which tells the server the payload conforms to the YANG data model in JSON format. This is the standard content type for RESTCONF JSON requests.

Exam trap

200-901 often tests whether candidates know the YANG-specific media types — many incorrectly choose generic application/json or application/xml, missing that RESTCONF requires application/yang-data+json (or +xml) to bind the payload to YANG models.

How to eliminate wrong answers

Option A is wrong because application/json is a generic JSON media type that does not indicate YANG-modeled data; RESTCONF requires the YANG-specific media type to properly interpret the payload against the device's YANG models. Option B is wrong because application/xml is a generic XML type, and while RESTCONF supports XML via application/yang-data+xml, the generic XML type is not the correct RESTCONF content type. Option D is wrong because text/plain is not a structured data format and is not used by RESTCONF for configuration payloads.

107
MCQmedium

A developer is building a Python script that calls the Cisco Webex Teams API to list all memberships in a room. The API returns a maximum of 100 items per page and includes a 'Link' header in the response. The developer needs to retrieve all memberships across multiple pages. What is the correct approach to handle pagination using the Link header?

A.Use the 'max' query parameter to request all memberships in a single response, avoiding pagination.
B.Extract the 'nextPageToken' from the JSON response body and include it as a query parameter in the next request.
C.Increment the 'page' query parameter by 1 in each subsequent request until an empty response is returned.
D.Parse the Link header for the 'rel="next"' URL and make a GET request to that URL to retrieve the next page of results, repeating until no 'next' link is present.
AnswerD

The Link header follows RFC 5988 and contains URLs for pagination, with rel="next" indicating the next page. Making a GET request to that URL retrieves the next set of memberships. Repeating until no 'next' link appears ensures all pages are collected. This is the standard method for Webex Teams API pagination.

Why this answer

The correct approach is to parse the Link header for the 'rel="next"' URL and follow it. This is how the Webex Teams API implements pagination, using RFC 5988 Link headers. The other options suggest methods not supported by this API, such as page numbers, max parameter for all items, or body tokens.

Following the next link ensures all pages are retrieved correctly.

Exam trap

The trap here is assuming that pagination is always done via query parameters like page or offset, when many Cisco APIs use Link headers instead.

108
MCQmedium

An application uses OAuth 2.0 client credentials grant to authenticate with a Cisco API. Which of the following best describes this flow?

A.The application uses a username and password in the request body.
B.The application sends its client ID and secret to obtain a token directly.
C.The user provides their credentials via a consent screen.
D.A device code is displayed for the user to enter on a separate device.
AnswerB

The client credentials grant exchanges the application's own client ID and secret directly at the token endpoint, with no user interaction or browser redirect. This matches the stem's machine-to-machine scenario, where the application authenticates as itself rather than on behalf of a resource owner.

Why this answer

Client credentials grant is used for server-to-server authentication without user involvement.

109
MCQeasy

A developer is testing a REST API endpoint using curl. The API requires an API key to be sent in the HTTP header 'X-API-Key'. Which curl command correctly includes the API key?

A.curl -G "X-API-Key=abc123" https://api.example.com/resource
B.curl -H "X-API-Key: abc123" https://api.example.com/resource
C.curl -u "X-API-Key:abc123" https://api.example.com/resource
D.curl -d "X-API-Key=abc123" https://api.example.com/resource
AnswerB

The -H option in curl allows adding a custom header to the request. Specifying 'X-API-Key: abc123' correctly sets the required header. This is the standard way to pass an API key when the API expects it in a header, and it ensures the key is sent securely over HTTPS.

Why this answer

The -H flag in curl is used to add custom headers to an HTTP request. Since the API requires the API key in the 'X-API-Key' header, using -H with the appropriate header string is the correct approach. This ensures the key is transmitted as an HTTP header, which the API will validate.

Exam trap

The trap here is confusing curl options: -d sends body data, -u is for Basic Auth, and -G modifies query strings, but only -H adds a custom header.

110
MCQhard

A Cisco Catalyst Center API uses OAuth 2.0 with the client credentials grant for server-to-server communication. Which token endpoint parameter should the client include to identify itself?

A.scope=admin
B.grant_type=client_credentials
C.response_type=token
D.grant_type=authorization_code
AnswerB

The client credentials grant requires grant_type=client_credentials in the token request body, telling the authorisation server that the client is authenticating as itself rather than on behalf of a user. This satisfies the server-to-server scenario where no user context exists.

Why this answer

For OAuth 2.0 client credentials grant, the client must include grant_type=client_credentials in the token request to indicate the grant type. This is defined in RFC 6749. The client also sends its client_id and client_secret for authentication.

Exam trap

The trap is confusing grant types: candidates may pick authorization_code or response_type=token, but the exam tests that client_credentials is the correct grant_type for server-to-server OAuth 2.0.

How to eliminate wrong answers

Option A is wrong because scope=admin is not a required parameter for client credentials; scope is optional and specifies permissions. Option C is wrong because response_type=token is used in implicit grant for user-agent flows, not client credentials. Option D is wrong because grant_type=authorization_code is for the authorization code grant, which involves a user agent and authorization code exchange.

111
MCQmedium

In Postman, you want to run a collection of API requests automatically and test responses. Which feature should you use?

A.Postman Workspaces
B.Postman Monitors
C.Postman Interceptor
D.Collection Runner
AnswerD

Collection Runner executes every request in a Postman collection sequentially, applying saved data files, iterations and test scripts automatically. It satisfies the stem's requirement to run requests unattended and validate responses, unlike manual Send or Newman's command-line execution.

Why this answer

The Collection Runner runs all requests in a collection sequentially and allows tests to be evaluated.

112
MCQeasy

In Cisco DNA Center's intent API, which endpoint would you use to retrieve the list of all network devices?

A.GET /dna/intent/api/v1/topology
B.GET /dna/intent/api/v1/network-device
C.GET /dna/intent/api/v1/site
D.GET /dna/intent/api/v1/issues
AnswerB

The network-device resource under /dna/intent/api/v1 returns the inventory of managed devices. Issuing GET against this collection endpoint satisfies the requirement to list all network devices, since the intent API exposes device inventory through this specific path.

Why this answer

The correct endpoint is GET /dna/intent/api/v1/network-device. Other options are incorrect or refer to other areas like topology or site hierarchy.

113
MCQmedium

A developer is building a script to retrieve a list of network devices from Cisco DNA Center. The API response includes a 'nextToken' field in the body to indicate more results. What pagination method is being used?

A.Cursor-based pagination
B.Page-based pagination
C.Offset/Limit pagination
D.Link header pagination
AnswerA

The nextToken field is an opaque cursor marking the next page position; the client returns it unchanged to fetch subsequent results. This is cursor-based pagination, distinct from offset or page-number schemes that use numeric limits and offsets.

Why this answer

Cursor-based pagination uses a token (e.g., nextToken) to point to the next set of results, unlike offset/limit which uses page numbers.

114
MCQmedium

A Webex API request returns a 401 Unauthorized error. The developer has already obtained an access token. What is the most likely cause?

A.Invalid access token or expired token
B.Resource not found
C.Rate limit exceeded
D.Server internal error
AnswerA

A 401 response means the request lacked valid authentication credentials, so with a token already supplied the token itself is rejected — expired, malformed, or issued for the wrong integration. Authorisation failures on a valid token would instead return 403 Forbidden.

Why this answer

A 401 error typically indicates an invalid or expired token, or missing Authorization header.

115
MCQmedium

A developer is using the Webex API to create a webhook that triggers when a new message is posted in a room. What information is typically included in the webhook payload sent by Webex to the callback URL?

A.The full message content and all room members
B.The OAuth token for the bot
C.The resource type, event type, and relevant IDs (e.g., message ID, room ID)
D.The complete list of webhooks configured on the account
AnswerC

Webex webhook payloads carry the resource type, event type and identifying fields such as message ID and room ID, letting the callback URL locate the affected resource. The payload is a notification only, so the developer fetches full message details separately.

Why this answer

Webhook payloads contain event details such as resource, event type, and relevant data like message ID and room ID. The full message content is not included; the application must fetch it via API.

116
Multi-Selecthard

Which THREE of the following are characteristics of RESTCONF compared to NETCONF? (Select three.)

Select 3 answers
A.Uses HTTP as the transport protocol
B.Supports JSON encoding for YANG data
C.Employs XML Remote Procedure Calls (RPCs)
D.Uses SSH for secure transport
E.Uses YANG data models
AnswersA, B, E

RESTCONF runs over HTTP, giving it a stateless, request-response model with standard verbs, whereas NETCONF relies on SSH and XML RPC. This satisfies the stem's transport characteristic, letting clients use ordinary HTTP tooling and status codes.

Why this answer

RESTCONF is defined by RFC 8040 and uses HTTP/HTTPS as its transport protocol, so option A is correct—unlike NETCONF, which runs over SSH. RESTCONF supports both JSON and XML encoding of YANG-modeled data, making option B correct, whereas NETCONF uses XML only. Option E is correct because RESTCONF, like NETCONF, is built on YANG data models to define the data and operations exposed by the device.

Option C is not a RESTCONF characteristic: XML-based RPCs are the core mechanism of NETCONF, not RESTCONF, which uses HTTP methods (GET, POST, PUT, PATCH, DELETE). Option D is also incorrect because SSH transport is a defining feature of NETCONF, while RESTCONF relies on HTTP/HTTPS.

Exam trap

200-901 often tests the transport and encoding distinctions between RESTCONF and NETCONF, tricking candidates into selecting SSH or XML-RPC options that actually describe NETCONF.

117
MCQmedium

A developer calls a REST API with GET /api/v1/devices?limit=50 and receives the first page of results plus a body field named nextPageToken. The API documentation states that results are cursor-paginated. How should the script request the next page?

A.Call GET /api/v1/devices?limit=50&page=2.
B.Call GET /api/v1/devices?limit=100 to fetch everything at once.
C.Call GET /api/v1/devices?limit=50&offset=50.
D.Call GET /api/v1/devices?limit=50&nextPageToken=<value>.
AnswerD

Cursor pagination advances by passing the token returned in the previous response. Supplying nextPageToken with its exact opaque value tells the server where the last page ended, so it returns the following set of records. This continues until the token is absent, indicating the final page has been reached.

Why this answer

Cursor pagination relies on an opaque token that marks the position of the last retrieved record. The client echoes that token in the next request, and the server returns the subsequent slice. Loop until the token is missing.

Offset, page-number, and oversized-limit approaches do not follow the API's documented contract and can skip or repeat data.

Exam trap

The trap here is substituting familiar offset or page-number parameters for the opaque cursor token the API actually returns.

118
MCQmedium

A developer is testing a REST API that returns a JSON response with a 'Location' header when a new resource is created. The developer wants to capture the URL of the newly created resource from the response. Which HTTP status code and header should the developer look for?

A.HTTP 204 No Content and the ETag header
B.HTTP 200 OK and the Content-Location header
C.HTTP 201 Created and the Location header
D.HTTP 302 Found and the Location header
AnswerC

A successful resource creation typically returns HTTP 201 Created. The response includes a Location header that contains the URI of the newly created resource. This is a standard REST convention. The developer should check for the 201 status and then read the Location header to obtain the resource URL.

Why this answer

When a REST API creates a resource, it should return HTTP 201 Created along with a Location header that specifies the URI of the new resource. This allows the client to know where the resource can be accessed. Other status codes like 200, 204, or 302 do not serve this purpose.

The developer should check for 201 and extract the Location header value.

Exam trap

The trap here is assuming that any success code like 200 OK or any header like Content-Location will provide the new resource URI, when specifically 201 Created and the Location header are the correct indicators.

119
MCQmedium

When using the Cisco Meraki Dashboard API with pagination, the Link header in the response contains <https://api.meraki.com/api/v1/organizations?perPage=10&startingAfter=123>; rel="next". What does this indicate?

A.The API uses offset-based pagination and the next offset is 123.
B.The request should be retried after 123 seconds.
C.The response is limited to 10 items, and 123 items remain.
D.The API uses cursor-based pagination; the next page can be retrieved using the provided URL.
AnswerD

The rel="next" link embeds an opaque cursor (startingAfter=123) rather than a page number, so the API is cursor-based. Following that URL returns the next page, satisfying the pagination requirement without the client constructing offsets itself.

Why this answer

The Link header with rel="next" provides the URL for the next page of results; cursor-based pagination is used via startingAfter.

120
MCQeasy

Which HTTP method should be used to replace an entire existing resource in a RESTful API?

A.POST
B.PUT
C.PATCH
D.DELETE
AnswerB

PUT replaces the entire target resource representation with the request payload, overwriting all fields. Unlike PATCH, which applies partial modifications, PUT satisfies the stem's requirement to replace an entire existing resource in a RESTful API.

Why this answer

PUT is the correct HTTP method for replacing an entire existing resource in a RESTful API because it is defined as idempotent in RFC 7231, meaning the client sends a full representation of the resource to replace the current state at the target URI. Unlike POST, PUT is intended for full updates where the client specifies the URI and the server replaces the resource entirely with the provided payload.

Exam trap

Cisco often tests the distinction between PUT and PATCH, trapping candidates who confuse 'update' with 'replace' and incorrectly choose PATCH for full resource replacement.

How to eliminate wrong answers

Option A is wrong because POST is used to create a new subordinate resource or trigger a non-idempotent action, not to replace an existing resource. Option C is wrong because PATCH applies a partial modification to a resource using a diff or set of changes, not a full replacement. Option D is wrong because DELETE removes the resource entirely, which is the opposite of replacing it.

121
MCQmedium

Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required?

A.Implicit Grant
B.Client Credentials Grant
C.Authorization Code Grant
D.Password Grant
AnswerB

The Client Credentials Grant exchanges the application's own credentials for an access token, with no resource owner involved. This directly satisfies the stem's server-to-server constraint, where no user interaction occurs. Unlike authorisation code or implicit grants, it never prompts for user consent, making it the appropriate choice for daemon and background service integrations.

Why this answer

Client credentials grant is used for server-to-server authentication without user consent.

122
Multi-Selecthard

A developer is designing a Python application that interacts with multiple Cisco REST APIs. They need to implement robust error handling for common HTTP status codes. Which TWO of the following status codes indicate that the client should retry the request after a delay? (Choose two.)

Select 2 answers
A.400 Bad Request
B.404 Not Found
C.503 Service Unavailable
D.429 Too Many Requests
E.401 Unauthorized
AnswersC, D

HTTP 503 means the server is temporarily unable to handle the request, often due to maintenance or overload. It may include a Retry-After header. Retrying after a delay is recommended because the condition is usually transient. Many Cisco cloud APIs may return 503 during brief outages, so implementing a retry with exponential backoff improves resilience and success rates.

Why this answer

Status codes 429 and 503 indicate temporary conditions where retrying after a delay can succeed. 429 is rate limiting, and 503 is service unavailability. Both often include Retry-After headers. The other codes (401, 404, 400) represent client errors that require corrective action, not retries, because they will persist until the request or credentials are fixed.

Exam trap

The trap here is assuming that any error status should be retried, when in fact only transient errors like 429 and 503 benefit from a delayed retry; client errors require fixing the request.

123
MCQeasy

A network automation script uses the Python ncclient library to modify a device configuration. Which NETCONF operation should be used to apply configuration changes?

A.<close-session>
B.<get-config>
C.<get>
D.<edit-config>
AnswerD

NETCONF's <edit-config> operation loads a configuration datastore with the target, default-operation and config elements, applying changes to running or candidate. It is the standard operation for modifying device configuration, unlike <get-config>, which only retrieves data.

Why this answer

The <edit-config> operation is used to apply configuration changes to a device via NETCONF. It allows the client to modify the configuration data store on the server, which is exactly what the script intends to do.

Exam trap

200-901 often tests the distinction between NETCONF operations, causing candidates to confuse <get-config> with <edit-config> when asked about applying changes.

How to eliminate wrong answers

Option A is wrong because <close-session> is used to terminate a NETCONF session, not to modify configuration. Option B is wrong because <get-config> is used to retrieve configuration data, not to change it. Option C is wrong because <get> is used to retrieve both configuration and state data, but not to modify it.

124
Multi-Selecthard

A developer is troubleshooting a REST API integration that intermittently returns HTTP 429 responses. Which TWO practices help the client handle rate limiting correctly? (Choose two.)

Select 2 answers
A.Treat the 429 as a permanent failure and stop all further API calls from the application.
B.Implement exponential backoff with jitter so successive retries are spaced further apart and randomized.
C.Switch the request from HTTPS to HTTP to bypass the rate limiter.
D.Read the Retry-After response header and wait the indicated number of seconds before resending the request.
E.Immediately resend the failed request in a tight loop until a non-429 response is received.
AnswersB, D

Exponential backoff increases the delay between retries, and adding jitter randomizes those delays so many clients do not retry in lockstep. This reduces the chance of repeated 429 responses and smooths load on the API. When no Retry-After header is present, backoff with jitter is the recommended fallback strategy, making it a correct practice in this scenario.

Why this answer

Handling 429 responses well means cooperating with the server's throttling signals. Reading Retry-After gives an explicit wait time, while exponential backoff with jitter provides a robust fallback when no such header exists. Tight retry loops, transport downgrades, and abandoning the integration all fail because they either worsen the throttling or give up on recoverable conditions.

Exam trap

The trap here is treating a 429 as a fatal error or retrying instantly, when it is a temporary signal that should be answered with a deliberate, measured pause.

125
MCQmedium

A developer is writing a Python script that consumes a REST API. The API returns a large number of records and uses pagination via a 'next' link in the response body. The developer needs to automatically follow these links until all records are retrieved. Which Python library feature is most appropriate for making the HTTP requests and handling the pagination loop?

A.requests library with a while loop that checks for the 'next' link
B.http.client with a for loop over a range of page numbers
C.urllib.request with a recursive function
D.socket library to send raw HTTP requests
AnswerA

The requests library is the standard for making HTTP calls in Python. A while loop can repeatedly call the 'next' URL until it is absent, aggregating results. This approach is straightforward and effective for following pagination links provided in the response body, allowing the script to retrieve all records without manual intervention.

Why this answer

The requests library simplifies HTTP interactions and, combined with a while loop that follows the 'next' link until it is absent, efficiently retrieves all paginated records. Other options are either too low-level, assume fixed pagination, or use inappropriate constructs like recursion, making them less suitable for this task.

Exam trap

The trap here is overcomplicating the solution by choosing low-level libraries or recursion when a simple loop with requests is sufficient and standard.

126
MCQmedium

A developer is building an application that needs to retrieve information from a REST API that uses cursor-based pagination. The response includes a 'next_cursor' field when more results are available. How should the developer structure the requests to retrieve all pages of data?

A.Send multiple requests in parallel, each with a different page number, until all pages are retrieved.
B.Increment an 'offset' parameter by a fixed page size until no more results are returned.
C.Use the 'Link' header from the response to find the URL for the next page and follow it.
D.Send the first request without any pagination parameters, then use the 'next_cursor' value as a query parameter in subsequent requests until it is absent.
AnswerD

Cursor-based pagination uses an opaque cursor to mark the current position. The first request typically returns the initial page and a next_cursor if more data exists. The client then includes that cursor in the next request, repeating until no next_cursor is returned. This method ensures consistent results even if data changes between requests.

Why this answer

Cursor-based pagination requires using the cursor provided by the API to fetch the next set of results. The developer should start with a request without pagination parameters, then iteratively use the 'next_cursor' value as a parameter in subsequent requests until the cursor is no longer returned, ensuring all data is retrieved in order.

Exam trap

The trap here is assuming that pagination always uses page numbers or offsets, but this API uses an opaque cursor that must be passed exactly as provided.

127
MCQmedium

When using RESTCONF to configure a network device, which URL path prefix and content-type header should be used?

A./restconf/operations/ and Content-Type: application/xml
B./restconf/data/ and Content-Type: application/yang-data+json
C./restconf/data/ and Content-Type: application/json
D./restconf/ and Content-Type: text/plain
AnswerB

RESTCONF mandates the `/restconf/data/` prefix to address the datastore, satisfying the stem's URL path requirement. The `application/yang-data+json` media type correctly encodes YANG-modelled payloads in JSON, which RESTCONF requires for configuration bodies. Together they match the RFC 8040 conventions the device expects.

Why this answer

RESTCONF uses the '/restconf/data/' path prefix to access configuration and state data modeled in YANG, and the standard media type for JSON-encoded YANG data is 'application/yang-data+json'. The '+json' suffix is required by RFC 8040 to distinguish YANG data from generic JSON. Using '/restconf/operations/' is for invoking RPCs, not for data configuration.

Exam trap

200-901 often tests the exact RESTCONF media type; candidates pick 'application/json' because it looks familiar, but YANG data requires the '+json' suffix to be accepted by the device.

How to eliminate wrong answers

Option A is wrong because '/restconf/operations/' is used to invoke YANG-modeled RPC operations, not to configure data, and 'application/xml' would be for XML-encoded YANG data, not the JSON content type asked for. Option C is wrong because 'application/json' is not the registered media type for YANG data; RESTCONF requires 'application/yang-data+json' so the server knows the payload is YANG-modeled. Option D is wrong because '/restconf/' alone is the root and 'text/plain' is not a valid RESTCONF media type for structured data.

128
MCQeasy

A developer wants to use Postman to test a REST API that requires a Bearer token. Where should the token be placed in the request?

A.In the Authorization header
B.As a query parameter
C.In a custom header like X-Auth-Token
D.In the request body
AnswerA

Bearer tokens are transmitted as credentials in the Authorization header using the scheme "Bearer <token>". Placing it there satisfies the API's authentication requirement, so Postman sends it with every request and the server validates the caller's identity before processing.

Why this answer

The Bearer token is placed in the Authorization header using the format 'Bearer <token>'. The request body is used for data, not authentication.

129
MCQhard

A developer is integrating with a REST API that returns a 429 Too Many Requests status code along with a Retry-After header. The developer's script currently retries immediately upon receiving a 429. What should the developer do to correctly handle rate limiting?

A.Parse the Retry-After header and wait for the specified number of seconds before retrying the request.
B.Immediately retry the request with an exponential backoff starting at 1 second, ignoring the Retry-After header.
C.Reduce the request rate by adding a fixed delay of 60 seconds between all subsequent requests.
D.Switch to a different API endpoint that is not rate-limited and continue the operation there.
AnswerA

The Retry-After header indicates how long the client should wait before making another request. It can be a number of seconds or an HTTP date. Parsing it and waiting the specified time prevents further rate limiting and respects the server's limits. This is the correct way to handle 429 responses and ensures the request will likely succeed on retry.

Why this answer

The correct approach is to parse the Retry-After header and wait the specified time before retrying. This respects the server's rate limit and increases the chance of a successful request. Other options either ignore the header, switch endpoints unnecessarily, or use arbitrary delays.

Honoring Retry-After is the standard and most effective way to handle 429 responses.

Exam trap

The trap here is assuming that exponential backoff alone is sufficient, when the server explicitly provides a wait time via Retry-After.

130
MCQeasy

A network engineer is using the Cisco Meraki Dashboard API to retrieve a list of organizations. The API returns a JSON array. Which HTTP method should be used to fetch this list?

A.POST
B.GET
C.PUT
D.DELETE
AnswerB

GET is the correct HTTP method for retrieving data from a REST API. The Meraki Dashboard API uses GET for read operations, such as listing organizations, networks, or devices. It is safe and idempotent, meaning multiple identical requests have the same effect as a single one. Using GET ensures the engineer obtains the list without modifying any server state, which is essential for data retrieval.

Why this answer

The GET method is designed for retrieving data from a specified resource. In the context of the Meraki Dashboard API, listing organizations is a read-only operation, so GET is the correct choice. GET requests should not have side effects, ensuring that repeated calls do not alter the state of the server.

This aligns with REST principles and the Meraki API documentation, which specifies GET for all retrieval endpoints.

Exam trap

The trap here is assuming that any API interaction requires POST, overlooking that simple data retrieval uses GET.

131
MCQmedium

A developer needs to retrieve a list of network devices from Cisco DNA Center. Which API endpoint should be used?

A.GET /dna/intent/api/v1/network-device
B.GET /dna/intent/api/v1/topology
C.POST /dna/intent/api/v1/network-device
D.GET /dna/intent/api/v1/site
AnswerA

The network-device endpoint under the DNA Center intent API returns the device inventory list. Issuing GET against /dna/intent/api/v1/network-device satisfies the stem's requirement to retrieve network devices, since the path and verb map directly to that collection resource.

Why this answer

The intent API endpoint /dna/intent/api/v1/network-device retrieves network devices.

132
MCQhard

A developer is using the Cisco DNA Center API to retrieve device details. The API requires authentication using a token obtained from the /dna/system/api/v1/auth/token endpoint. The token has an expiration time. Which HTTP status code indicates that the token has expired and a new one must be obtained?

A.401 Unauthorized
B.500 Internal Server Error
C.404 Not Found
D.403 Forbidden
AnswerA

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. In the context of token-based authentication, if the token is expired or invalid, the server returns 401. The developer must then obtain a new token by re-authenticating. This status code specifically signals that the provided token is no longer accepted.

Why this answer

An expired or invalid token results in a 401 Unauthorized response. This tells the client that authentication credentials are missing or invalid, prompting the client to obtain a new token. 403 indicates insufficient permissions, 404 means resource not found, and 500 is a server error. Only 401 specifically addresses authentication failure.

Exam trap

The trap here is confusing 401 Unauthorized with 403 Forbidden; 401 is for authentication failures, while 403 is for authorization failures.

133
MCQeasy

A network engineer is writing a Python script that uses the requests library to call a REST API. The API requires an API key to be passed in the header. Which HTTP header field is commonly used to transmit an API key for authentication?

A.Content-Type
B.User-Agent
C.Accept
D.Authorization
AnswerD

The Authorization header is the standard HTTP header for carrying credentials that authenticate a client to a server. API keys are often sent as a Bearer token or a custom scheme in this header. For example, a request might include Authorization: Bearer <api_key>. This is the correct and conventional way to transmit an API key for authentication.

Why this answer

Authentication credentials, including API keys, are transmitted using the Authorization header. This header is designed to carry credentials such as Bearer tokens or Basic authentication strings. Other headers like Content-Type, Accept, and User-Agent serve different purposes related to content negotiation and client identification, so they are not appropriate for authentication.

Exam trap

The trap here is confusing headers used for content negotiation or client identification with the header intended for authentication, leading to the selection of Content-Type or Accept.

134
MCQeasy

A developer is writing a Python script that calls the Cisco Webex Rooms API to create a new team room. The script must send JSON data in the request body and receive JSON responses. Which HTTP header should be set to ensure the API interprets the request body as JSON and returns JSON?

A.Content-Length: <length>
B.Accept: application/json
C.Content-Type: application/json
D.Authorization: Bearer <token>
AnswerC

Setting Content-Type: application/json informs the API that the request body is formatted as JSON, so the server parses it correctly. In Cisco Webex API, this header is required when sending JSON payloads to create resources. Without it, the server may reject the request or misinterpret the data, leading to errors. This header directly addresses the need to send JSON data in the request body.

Why this answer

To send JSON data in a request body, the client must set the Content-Type header to application/json. This tells the server that the payload is JSON, enabling correct parsing. The Accept header is for response format, Authorization is for authentication, and Content-Length is for size.

Only Content-Type directly addresses the request body format.

Exam trap

The trap here is confusing the Accept header, which specifies desired response format, with the Content-Type header, which specifies the format of the request body.

135
MCQmedium

A Webex bot needs to receive real-time notifications when a new message is posted in a Webex space. Which Webex API feature should the bot implement?

A.Long polling
B.Polling the messages API every second
C.Webhooks
D.Server-Sent Events
AnswerC

Webhooks let the bot register a callback URL that Webex pushes events to, delivering new-message notifications in real time. Polling the messages endpoint would add latency and waste API calls, so webhooks satisfy the real-time constraint directly.

Why this answer

Webhooks allow the bot to receive HTTP callbacks for events like message creation.

136
MCQhard

A developer is integrating with Cisco DNA Center. After a successful POST to create a new site, the API returns HTTP 202 Accepted with a task ID in the response body. The developer needs to confirm when the site creation completes. What should the developer do next?

A.Immediately issue a GET to the site endpoint and assume the site exists if any response is returned.
B.Resend the original POST request with the same payload until a 201 Created is returned.
C.Poll the task endpoint using the returned task ID until the task status indicates success or failure.
D.Treat the 202 response as final success and proceed without further verification.
AnswerC

A 202 Accepted response indicates the request was accepted for asynchronous processing. Cisco DNA Center returns a task ID that can be queried via the task API. Polling that endpoint reveals the final status, such as success or failure, along with any error details. This is the documented pattern for long-running operations.

Why this answer

Cisco DNA Center uses asynchronous task processing for many write operations. A 202 Accepted response includes a task ID, and the client must poll the task endpoint until the status reflects completion. Treating 202 as success, resending the POST, or immediately reading the resource can produce duplicates or false assumptions about the resource state.

Exam trap

The trap here is interpreting HTTP 202 Accepted as a final success code, when it only confirms the request was queued for asynchronous processing.

137
MCQmedium

When using the Meraki Dashboard API, what is the correct method to authenticate requests?

A.Include an API key in the Authorization header as a Bearer token
B.Use a session token obtained from a login endpoint
C.Use Basic authentication with username and password
D.Include an API key in the X-Cisco-Meraki-API-Key header
AnswerD

Meraki Dashboard API authenticates each request with a static API key supplied in the X-Cisco-Meraki-API-Key header, satisfying the stem's requirement for the correct authentication method. Unlike OAuth bearer tokens, no token exchange or refresh occurs; the key is generated per organisation or per administrator in the Dashboard.

Why this answer

The Meraki Dashboard API uses a unique API key for authentication, which must be included in the `X-Cisco-Meraki-API-Key` header. This key is generated per user in the Meraki Dashboard and identifies the request without requiring a session or password. Option D correctly specifies this custom header, which is the only supported method for authenticating requests to the Meraki API.

Exam trap

Cisco often tests the misconception that all REST APIs use standard Bearer tokens or OAuth, but the Meraki API deliberately uses a custom header to emphasize vendor-specific authentication patterns that candidates must memorize.

How to eliminate wrong answers

Option A is wrong because the Meraki API does not use Bearer tokens in the Authorization header; it uses a custom header (`X-Cisco-Meraki-API-Key`) instead of the standard `Authorization: Bearer` format. Option B is wrong because the Meraki API does not have a login endpoint or session tokens; authentication is stateless and key-based. Option C is wrong because Basic authentication with username and password is not supported; the API key is a static, pre-generated token that does not involve credentials in the request.

138
MCQmedium

Which NETCONF operation is used to retrieve the entire configuration datastore from a network device?

A.<edit-config>
B.<get>
C.<get-config>
D.<commit>
AnswerC

The <get-config> operation retrieves configuration data from a specified datastore, and with no source filter it returns the entire running configuration. Unlike <get>, which returns state and operational data, <get-config> targets configuration only, satisfying the requirement to pull the full datastore.

Why this answer

<get-config> retrieves configuration datastore. <get> retrieves state and config data. <edit-config> modifies configuration. <commit> confirms a candidate configuration.

139
MCQmedium

A developer is integrating with a REST API that uses rate limiting. The API documentation states that clients can make 100 requests per minute. The developer's application needs to fetch data from multiple endpoints. Which HTTP status code should the application expect if it exceeds the rate limit, and what header might indicate when to retry?

A.429 Too Many Requests with Retry-After header
B.503 Service Unavailable with Retry-After header
C.401 Unauthorized with WWW-Authenticate header
D.403 Forbidden with X-RateLimit-Reset header
AnswerA

HTTP 429 Too Many Requests is the standard status code for rate limiting. The Retry-After header, when included, indicates how long the client should wait before making another request. This combination allows the application to handle rate limiting gracefully by pausing and retrying after the specified period.

Why this answer

HTTP 429 Too Many Requests is specifically defined for rate limiting scenarios. When a client exceeds the allowed request rate, the server responds with 429 and may include a Retry-After header indicating how many seconds to wait before retrying. This allows clients to implement backoff strategies.

Other status codes like 403, 503, and 401 relate to authorization, server availability, and authentication, respectively, not rate limiting.

Exam trap

The trap here is assuming that any error with a Retry-After header indicates rate limiting, but only 429 is the correct status code for exceeding rate limits.

140
MCQhard

A developer is writing a script that calls a REST API returning JSON. The script uses the Python requests library and must detect when the server responds with a 429 Too Many Requests status. Which expression correctly evaluates the status code?

A.if response.reason == 429:
B.if response.ok == 429:
C.if response.headers["Status"] == 429:
D.if response.status_code == 429:
AnswerD

The status_code attribute of a requests Response holds the integer HTTP status. Comparing it to 429 directly identifies the rate-limit condition. This is the canonical check and works regardless of the response body or headers, making it the reliable way to branch into backoff logic.

Why this answer

The requests library exposes the numeric HTTP status through the status_code attribute, so comparing it to 429 is the correct way to detect rate limiting. Attributes like ok and reason serve different purposes and do not carry the integer code. Checking status_code enables the script to trigger backoff and honor Retry-After headers appropriately.

Exam trap

The trap here is confusing the boolean ok flag or the textual reason string with the numeric status code that actually identifies a 429.

141
MCQmedium

A developer is building a script that authenticates to the Cisco DNA Center API. The documentation states that the authentication endpoint returns a token that must be included in subsequent API calls. Which authentication scheme does Cisco DNA Center expect for those subsequent calls?

A.A custom X-Auth-Token header containing the token returned by the authentication endpoint
B.An Authorization header with the Bearer scheme followed by the token
C.A Cookie header containing the session identifier issued at login
D.HTTP Basic authentication using the username and password on every request
AnswerB

Cisco DNA Center's authentication endpoint returns a token that clients present in the Authorization header using the Bearer scheme, for example 'Authorization: Bearer <token>'. This is the documented mechanism for authenticating subsequent API calls, and the token expires after a set period, prompting re-authentication. It is the correct scheme for the scenario.

Why this answer

Cisco DNA Center authenticates clients through a dedicated endpoint that returns a token, and that token is then presented in the Authorization header using the Bearer scheme. This keeps credentials off subsequent requests and allows the token to expire on a schedule. Basic auth, custom token headers, and session cookies do not match the documented mechanism and would not authenticate successfully.

Exam trap

The trap here is assuming that any token obtained from an authentication endpoint can be placed in an arbitrary custom header, when the platform expects the standard Bearer scheme.

142
MCQhard

A developer is writing an integration that calls a REST API which returns a large collection of items across many pages. The API documentation states that the response includes a 'next' link when more results are available. Which approach correctly retrieves the complete collection?

A.Request the collection once and assume all items are returned in a single response.
B.Increase the request timeout so the server returns all pages in one response.
C.Follow the 'next' link in each response and request it repeatedly until no 'next' link is present.
D.Send the same request repeatedly and merge the responses until the total item count stops growing.
AnswerC

Following the 'next' link provided by the API is the documented way to traverse pages, because the server controls how subsequent pages are addressed and may use opaque cursors. Repeating this until the response contains no 'next' link guarantees the entire collection is retrieved. This approach adapts to the server's cursor scheme rather than guessing page parameters, making it the correct choice.

Why this answer

When an API advertises a 'next' link, the intended traversal is to request that link and repeat until the response no longer includes one. This respects server-controlled cursors and guarantees every page is visited. Assuming a single response is complete, replaying the identical request, or extending timeouts all fail because none of them advances through the paginated result set.

Exam trap

The trap here is assuming that a larger timeout or a repeated identical request will surface more records, when only following the server-provided next link advances the cursor.

← PreviousPage 2 of 2 · 142 questions total

Ready to test yourself?

Try a timed practice session using only Understanding and Using APIs questions.