200-901 Understanding and Using APIs Practice Question
When using the Meraki Dashboard API, what is the correct method to authenticate requests?
⚠ Common exam trap
Cisco often tests the misconception that all REST APIs use standard Bearer tokens or OAuth, but the Meraki API deliberately uses a custom header to emphasize vendor-specific authentication patterns that candidates must memorize.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include an API key in the X-Cisco-Meraki-API-Key header
The Meraki Dashboard API uses a unique API key for authentication, which must be included in the `X-Cisco-Meraki-API-Key` header. This key is generated per user in the Meraki Dashboard and identifies the request without requiring a session or password. Option D correctly specifies this custom header, which is the only supported method for authenticating requests to the Meraki API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include an API key in the Authorization header as a Bearer token
Why it's wrong here
Meraki expects the API key in the X-Cisco-Meraki-API-Key header, not as a Bearer token in Authorization. It is tempting because Bearer tokens are the common OAuth 2.0 pattern for REST APIs, but Meraki does not implement OAuth bearer authentication for dashboard calls.
- ✗
Use a session token obtained from a login endpoint
Why it's wrong here
The Meraki Dashboard API authenticates with a static API key sent in the X-Cisco-Meraki-API-Key header; no login endpoint issues session tokens. It is tempting because session tokens suit many REST APIs, but Meraki's dashboard uses long-lived keys instead of session-based authentication.
- ✗
Use Basic authentication with username and password
Why it's wrong here
Meraki Dashboard API authenticates with a dashboard API key sent in the X-Cisco-Meraki-API-Key header; Basic username/password credentials are not accepted. Basic authentication would suit a legacy service exposing an HTTP Basic realm, not Meraki's key-based scheme.
- ✓
Include an API key in the X-Cisco-Meraki-API-Key header
Why this is correct
Meraki Dashboard API authenticates each request with a static API key supplied in the X-Cisco-Meraki-API-Key header, satisfying the stem's requirement for the correct authentication method. Unlike OAuth bearer tokens, no token exchange or refresh occurs; the key is generated per organisation or per administrator in the Dashboard.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.