350-401 Automation Practice Question
A network automation engineer is using Cisco DNA Center's Intent API to retrieve a list of all network devices. The engineer writes a Python script that sends a GET request to the /dna/intent/api/v1/network-device endpoint. The script receives an HTTP 403 Forbidden response. The engineer has verified that the username and password are correct and that the user has the SUPER-ADMIN-ROLE. What is the most likely cause of the issue?
⚠ Common exam trap
The trap here is assuming that correct username and password are sufficient for API access, overlooking the need for a token in the X-Auth-Token header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The API endpoint requires a valid X-Auth-Token header, which the script did not include.
Cisco DNA Center's Intent API requires token-based authentication. The script must first obtain a token from the authentication endpoint and then include it in the X-Auth-Token header for all subsequent API calls. Without this header, the server returns 403 Forbidden, indicating the request lacks proper authorization. Correct credentials alone are insufficient; the token is mandatory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The API endpoint requires a valid X-Auth-Token header, which the script did not include.
Why this is correct
Cisco DNA Center's Intent API uses token-based authentication. After authenticating via /dna/system/api/v1/auth/token, the script must include the returned token in the X-Auth-Token header for subsequent requests. Without this header, the server returns 403 Forbidden even if credentials are correct. The script likely omitted this step, causing the authorization failure.
- ✗
The script must use HTTPS instead of HTTP to access the API.
Why it's wrong here
Cisco DNA Center APIs are only accessible over HTTPS; HTTP requests would fail to connect or be redirected. The scenario does not specify the protocol, but a 403 Forbidden implies the request reached the server. If HTTP were used, the connection would likely be refused or return a different error. Thus, protocol is not the cause of the 403.
- ✗
The user account is locked due to multiple failed login attempts.
Why it's wrong here
A locked account would typically result in a 401 Unauthorized during authentication, not a 403 Forbidden on an API call. The scenario states the credentials are correct and the user has SUPER-ADMIN-ROLE, so account lockout is unlikely. The 403 indicates the request was understood but refused, often due to missing authorization token.
- ✗
The API endpoint URL is incorrect and should be /dna/intent/api/v1/network-device/count.
Why it's wrong here
The endpoint /dna/intent/api/v1/network-device is valid for retrieving device lists. Changing to /count would return only the count, not the list. The 403 error is not caused by an incorrect URL; if the URL were wrong, a 404 Not Found would be more likely. The issue is authentication/authorization, not the path.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco DNA Center Automation
Cisco DNA Center Automation is a centralized software platform that simplifies network management by automatically configuring, monitoring, and troubleshooting Cisco devices using policy-driven intent and software tools.
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.