easyMultiple Select
200-901 Practice Question: Which two authentication methods are commonly…
Which two authentication methods are commonly used with Cisco APIs? (Choose two.)
⚠ Common exam trap
Cisco often tests the distinction between authentication methods used for API access versus those used for device management or network protocols, so the trap here is confusing SNMPv3 or SSH keys (which are for device CLI/management) with HTTP-based API authentication methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Basic Authentication over HTTPS
Basic Authentication over HTTPS (B) is correct because Cisco APIs such as the DNA Center, Meraki, and ACI REST APIs accept an HTTP Authorization header containing base64-encoded username:password credentials, with HTTPS providing transport encryption. API Token (Bearer Token) (E) is also correct because many Cisco platforms (e.g., Meraki Dashboard API with the X-Cisco-Meraki-API-Key header, Webex with OAuth bearer tokens, and DNA Center token-based auth) authenticate requests using a token rather than credentials on every call. SNMPv3 (A) is a network management protocol for polling and traps, not an HTTP API authentication method. SSH Key (C) is used for secure CLI/shell access, not for REST API authentication. RADIUS (D) is an AAA protocol for network access control (802.1X, VPN), not a mechanism for authenticating API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMPv3
Why it's wrong here
SNMPv3 authenticates network devices for monitoring via USM, not API clients calling Cisco controllers such as DNA Center or Meraki. It would be the right answer if the question asked how management platforms poll device metrics, not how applications authenticate to REST APIs.
- ✓
Basic Authentication over HTTPS
Why this is correct
Basic Authentication over HTTPS transmits a base64-encoded username and password in the request header, protected by TLS encryption. It is widely supported by Cisco API platforms such as DNA Center and Meraki, making it a common credential-based method alongside token-based approaches.
- ✗
SSH Key
Why it's wrong here
SSH keys authenticate interactive CLI and NETCONF sessions to devices, not HTTP-based Cisco API calls, which rely on tokens or basic credentials. SSH key pairs are the correct mechanism when automating device configuration over SSH rather than consuming REST endpoints.
- ✗
RADIUS
Why it's wrong here
RADIUS authenticates users connecting to network access services, not applications invoking Cisco APIs; it authorises sessions at the network edge. RADIUS would be correct if the scenario involved 802.1X or VPN user authentication rather than API client credentials.
- ✓
API Token (Bearer Token)
Why this is correct
Bearer tokens are self-contained credentials sent in the Authorization header, letting Cisco APIs authenticate each request statelessly. The token is issued after initial credential exchange, then presented on subsequent calls, satisfying stateless API authentication without resending passwords.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.