Courseiva

200-901 Understanding and Using APIs Practice Question

Which three statements are true about the Cisco Catalyst Center (formerly DNA Center) intent API? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between Catalyst Center and Meraki APIs, so the trap here is confusing the authentication method (token-based vs. API key) and assuming only GET/POST are used, when in fact RESTful APIs support full CRUD operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The base URL for the API includes the Catalyst Center hostname and port.

Option A is correct because every Catalyst Center intent API call is built on a base URL of the form https://<Catalyst-Center-hostname>:<port>, typically port 443 for HTTPS, followed by the service path such as /dna/intent/api/v1. Option B is correct because authentication is performed by sending a POST request with the username and password in a JSON body to /dna/system/api/v1/auth/token, which returns a JWT token used as a Bearer token in the X-Auth-Token header for subsequent calls. Option D is correct because the intent API follows RESTful principles, using resource-oriented URIs and standard HTTP verbs, and returns responses formatted as JSON. Option C is incorrect because the API also uses PUT and DELETE methods (for example, to update or remove resources), not only GET and POST. Option E is incorrect because the X-Cisco-Meraki-API-Key header belongs to the Cisco Meraki Dashboard API, not to Catalyst Center, which relies on token-based authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The base URL for the API includes the Catalyst Center hostname and port.

    Why this is correct

    Catalyst Center’s intent API is reached over HTTPS at a host-specific endpoint, so the base URL must combine the appliance’s hostname with its port, satisfying the stem’s requirement for a true statement about API structure. Requests target that address directly, making hostname and port integral rather than optional.

  • ✓

    Authentication is done by sending a POST request to /dna/system/api/v1/auth/token with credentials.

    Why this is correct

    The intent API authenticates by POSTing credentials to /dna/system/api/v1/auth/token, which returns a time-limited token. Subsequent calls carry that token in the X-Auth-Token header, satisfying the stem's requirement for a true statement about Catalyst Center authentication rather than basic auth or Microsoft Entra ID.

  • ✗

    The API uses only GET and POST methods.

    Why it's wrong here

    The Catalyst Center intent API also uses PUT and DELETE for updating and removing configurations, so restricting it to GET and POST is false. It is tempting because read-and-create operations dominate typical automation scripts, making those two verbs appear sufficient; full CRUD coverage requires all four methods.

  • ✓

    It uses RESTful principles and returns JSON responses.

    Why this is correct

    The Cisco Catalyst Center intent API is REST-based, exchanging JSON payloads over HTTPS, which satisfies the stem's requirement for true statements about its interface. This contrasts with legacy CLI or SNMP management, where structured, programmatic intent configuration and telemetry retrieval are unavailable.

  • ✗

    It requires an API key passed in the X-Cisco-Meraki-API-Key header.

    Why it's wrong here

    The X-Cisco-Meraki-API-Key header belongs to the Meraki Dashboard API, not the Catalyst Center intent API, which authenticates with a token from /dna/system/api/v1/auth/token. It is tempting because both are Cisco management APIs using HTTP headers for authentication, so the header name looks familiar; the platforms and endpoints differ entirely.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.