mediumMultiple Select
REST API Best Practices in Cisco Environments
Which TWO of the following are best practices when using REST APIs in Cisco networking environments?
Quick Answer
The answer is implementing caching to reduce redundant API calls and handling HTTP error codes like 4xx and 5xx responses. Caching is a best practice because it minimizes network overhead and latency by storing frequently accessed data locally, which is especially critical in Cisco environments where APIs for DNA Center or Meraki may throttle requests under heavy load. Handling error codes ensures robust integration, as 4xx codes indicate client issues like authentication failure (401) or rate limiting (429), while 5xx codes signal server overload (503), allowing your application to retry or log appropriately. On the Cisco DevNet Associate 200-901 exam, this tests your understanding of REST API reliability and efficiency, often appearing in scenario-based questions where you must choose practices that prevent silent failures in network automation. A common trap is assuming all caching is stateless or ignoring error handling for transient faults. Remember the mnemonic “Cache and Catch” to recall that caching boosts performance while catching HTTP errors ensures resilience.
⚠ Common exam trap
Cisco often tests the misconception that polling frequently (e.g., every second) is acceptable for real-time data, but the trap is that this violates API rate-limiting best practices and ignores the recommended use of webhooks or longer intervals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Always handle HTTP error codes like 4xx and 5xx.
Option C is correct because robust REST API clients must inspect and handle HTTP status codes, treating 4xx responses (e.g., 400 Bad Request, 401 Unauthorized, 404 Not Found) as client-side errors and 5xx responses (e.g., 500 Internal Server Error, 503 Service Unavailable) as server-side failures, so the application can retry, back off, or surface meaningful errors instead of silently failing. Option E is correct because caching responses (honoring headers such as Cache-Control, ETag, and Last-Modified) reduces redundant API calls, which lowers latency and CPU load on Cisco controllers and switches that have limited management-plane resources. Option A is not a best practice because sending credentials as plain text exposes them to interception; credentials should be sent over HTTPS using tokens or Basic Auth only within TLS. Option B is not a best practice because polling every second creates excessive load and is inefficient; webhooks, streaming telemetry, or longer polling intervals with conditional requests should be used. Option D is not a best practice because embedding API keys in URL query parameters leaks them into logs, browser history, and proxies; keys should be sent in headers or stored in a secrets manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send credentials as plain text in every request.
Why it's wrong here
Plain-text credentials are exposed to anyone capturing the traffic, so they must travel over TLS or be replaced by tokens. It is tempting because basic authentication does embed a username and password in the header, which is acceptable only over an encrypted channel for low-risk internal scripts.
- ✗
Poll the API every second to get real-time updates.
Why it's wrong here
Polling every second floods the controller with redundant requests, wastes CPU and can trigger rate limiting; event-driven webhooks or streaming telemetry deliver near-real-time updates instead. Polling is tempting because it is simple to implement. A modest interval, such as every few minutes, suits non-urgent inventory or status retrieval.
- ✓
Always handle HTTP error codes like 4xx and 5xx.
Why this is correct
HTTP status codes carry the API's outcome, so treating 4xx client errors and 5xx server errors as expected conditions lets scripts branch, retry or log correctly. Ignoring them causes silent failures in automation, violating the requirement to build resilient REST integrations.
- ✗
Embed API keys directly in the URL query parameters.
Why it's wrong here
Query parameters are logged by proxies, browsers and servers, exposing the key in plaintext and enabling replay; credentials belong in the Authorization header over TLS. Embedding keys in URLs is tempting because it is quick to test. Query parameters suit non-sensitive filters such as pagination or search terms.
- ✓
Implement caching to reduce redundant API calls.
Why this is correct
Caching responses reduces redundant API calls, lowering load on network devices and improving application responsiveness, which suits REST APIs in Cisco environments. It satisfies the efficiency best-practise requirement by avoiding repeated identical requests to managed devices.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-901
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Match each HTTP method to its typical use case in REST APIs.
medium- ✓ A.GET: Retrieve a resource
- ✓ B.POST: Create a new resource
- ✓ C.PUT: Replace an existing resource
- ✓ D.DELETE: Remove a resource
- E.GET: Create a new resource
- F.POST: Retrieve a resource
Why A: Standard RESTful HTTP methods: GET retrieves, POST creates, PUT replaces, DELETE removes. Common confusions swap GET with POST or misuse PUT for partial updates (which is PATCH).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.