200-901 Understanding and Using APIs Practice Question
Which three statements about Webex API webhooks are true? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Webhooks deliver event data via HTTP POST to a specified URL.
Option A is correct because Webex webhooks push event notifications as an HTTP POST request containing a JSON payload to the target URL you register. Option C is correct because when creating a webhook you specify the resource (e.g., messages, meetings, memberships) and the event (e.g., created, updated, deleted), so it only fires for those matching events. Option D is correct because webhooks are registered programmatically by sending an authenticated POST request to the Webex REST endpoint https://webexapis.com/v1/webhooks with fields such as name, targetUrl, resource, and event. Option B is not required: webhook creation uses an OAuth 2.0 access token (often from an integration or bot), not specifically the client credentials grant, and webhook delivery itself is secured via a secret/signature rather than that grant. Option E is incorrect because Webex webhooks are push-based HTTP callbacks, not long polling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Webhooks deliver event data via HTTP POST to a specified URL.
Why this is correct
Webhooks push notifications by sending an HTTP POST containing event payload data to the subscriber's configured target URL. This satisfies the stem's requirement for a true statement about Webex webhook delivery, distinguishing push-based event delivery from polling the API.
- ✗
Webhooks require OAuth 2.0 client credentials grant for security.
Why it's wrong here
Webex webhooks authenticate via a shared secret or signature verification, not the OAuth 2.0 client credentials grant, which secures server-to-server API calls rather than inbound event delivery. It tempts because client credentials genuinely suit machine-to-machine integrations that call Webex APIs directly.
- ✓
Webhooks can be filtered to trigger only on specific resources and events.
Why this is correct
Webex webhook registrations specify resource and event filters, so notifications fire only for chosen combinations such as messages:created on a particular room. This satisfies the stem's requirement for a true statement, avoiding unwanted traffic from unrelated events.
- ✓
Webhooks are created by sending a POST request to the /webhooks endpoint.
Why this is correct
Webhook registrations are managed through the Webex REST API itself, so creating one means POSTing a JSON body (name, targetUrl, resource, event) to the /webhooks collection endpoint. The API returns 201 with the webhook ID, satisfying the scenario's requirement to programmatically register event notifications.
- ✗
Webhooks use long polling to receive events.
Why it's wrong here
Webhooks deliver events by HTTP POST callbacks to a registered target URL, not by long polling. It tempts because long polling is a real Webex API technique for receiving events, but that mechanism belongs to the events API, not to webhooks.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.