200-901 Infrastructure and Automation Practice Question
When using the Cisco Meraki Dashboard API to create an HTTP webhook for network alerts, which authentication method is required in the request header?
⚠ Common exam trap
Cisco often tests the distinction between standard authentication methods (Bearer tokens, Basic Auth) and vendor-specific custom headers, so the trap here is that candidates may assume a common standard like OAuth 2.0 or Basic Auth applies, when the Meraki API explicitly requires its own proprietary header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
X-Cisco-Meraki-API-Key: <your_api_key>
The Cisco Meraki Dashboard API requires authentication via a custom HTTP header named `X-Cisco-Meraki-API-Key`, where the value is your API key. This is the only supported method for authenticating requests to the Meraki API, as documented in the official API reference. Option D correctly specifies this header, making it the required authentication method for creating an HTTP webhook for network alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authorization: Bearer <token>
Why it's wrong here
Meraki expects the static X-Cisco-Meraki-API-Key header, not an OAuth bearer token, so no token exchange exists to supply one. Bearer tokens are correct for OAuth 2.0 APIs such as Microsoft Graph, where scoped, expiring access tokens are issued.
- ✗
Include the API key as a query parameter.
Why it's wrong here
Meraki's Dashboard API authenticates via the X-Cisco-Meraki-API-Key request header; query-string keys are not accepted and would leave the call unauthenticated. Query parameters suit filterable GET requests, such as scoping alert history by network ID, not credential transport.
- ✗
Authorization: Basic <base64>
Why it's wrong here
Basic authentication encodes a username and password, but Meraki issues only a single API key, so no credential pair exists to encode. Basic headers are correct for legacy endpoints that authenticate with account credentials, such as older SOAP or REST services.
- ✓
X-Cisco-Meraki-API-Key: <your_api_key>
Why this is correct
The Meraki Dashboard API authenticates every call with a custom header, X-Cisco-Meraki-API-Key, carrying the user-generated key. This satisfies the stem's requirement for the header-based credential, unlike OAuth bearer tokens or basic authentication, which the API does not accept.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.