200-901 Understanding and Using APIs Practice Question
What is the purpose of the 'Authorization' header in a REST API request?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To authenticate the client
The Authorization header carries credentials (e.g., Bearer token, Basic auth) to authenticate the client. Content-Type specifies body format. Accept specifies response format.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To enable caching of the response
Why it's wrong here
The Authorization header carries credentials, such as a bearer token or Basic scheme, so the server can authenticate the caller; caching is controlled by Cache-Control and related headers. It is tempting because authenticated responses are often cached, but caching directives belong in separate headers, not the credential field.
- ✓
To authenticate the client
Why this is correct
The Authorization header carries credentials, such as a Bearer token or Basic base64 pair, that the server validates to establish the caller's identity, satisfying the stem's requirement to authenticate the client on each REST request.
- ✗
To specify the desired response format
Why it's wrong here
The Authorization header conveys credentials for authenticating the request; response format is negotiated through the Accept header. It is tempting because clients often set both together, yet Accept is the correct header when requesting JSON or XML from a REST API.
- ✗
To specify the format of the request body
Why it's wrong here
The Authorization header carries credentials — tokens or Basic/Bearer schemes — authenticating the caller; it never declares body format. It tempts because headers do convey request metadata, and Content-Type is the header that actually specifies the body's media type, such as application/json.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.