Courseiva

200-901 Understanding and Using APIs Practice Question

What is the purpose of the Authorization header in a REST API call?

⚠ Common exam trap

200-901 often tests HTTP header semantics, tricking candidates into confusing Authorization with Content-Type or Accept, which control payload format rather than identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To authenticate the client sending the request

The Authorization header in an HTTP request carries credentials (such as a Bearer token, Basic auth, or API key) that the server uses to authenticate and authorize the client. It is the standard mechanism defined in RFC 7235 for transmitting authentication information with a REST API call.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To specify the content type of the request body

    Why it's wrong here

    Content type is declared by the Content-Type header, which describes the request body's media type; Authorization carries credentials. It is tempting because both headers accompany a request body, and Content-Type would be the correct answer if the question asked how to tell the server the payload is JSON.

  • ✗

    To specify the format of the response body

    Why it's wrong here

    Response body format is negotiated with the Accept header, which lists media types the client can process; Authorization conveys credentials. It is tempting because both headers influence representation, and Accept would be correct if the question asked how a client requests JSON rather than XML.

  • ✗

    To indicate the desired language

    Why it's wrong here

    Desired language is requested with the Accept-Language header, which carries locale preferences; Authorization carries authentication credentials. It is tempting because both are request headers influencing the response, and Accept-Language would be correct if the question asked how to request localised content from an API.

  • ✓

    To authenticate the client sending the request

    Why this is correct

    The Authorization header carries credentials (such as a bearer token or Basic base64 pair) that the server validates to identify the calling client. It satisfies the stem's authentication requirement, distinct from content negotiation headers like Accept, which only declare the desired response format.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.