Courseiva
Automation →hardMultiple Choice

350-401 Automation Practice Question

A network engineer is using the Cisco Catalyst Center (formerly DNA Center) Intent API to retrieve a list of all network devices. The engineer sends a GET request to /dna/intent/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token from /dna/system/api/v1/auth/token. What is the most likely reason for the 401 error?

⚠ Common exam trap

The trap here is assuming that Catalyst Center uses standard OAuth Bearer tokens, when it actually requires a proprietary X-Auth-Token header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The token must be included in the request header as 'X-Auth-Token: <token>'.

The Cisco Catalyst Center Intent API uses a custom authentication header named 'X-Auth-Token' to pass the token obtained from the authentication endpoint. Failure to include this header, or using a different scheme like Bearer, results in a 401 Unauthorized error. The engineer must set 'X-Auth-Token' with the token value in all subsequent API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The token has expired and must be refreshed every 60 minutes.

    Why it's wrong here

    While Catalyst Center tokens do expire, typically after 60 minutes, the engineer just obtained a valid token. The scenario states the token is valid, so expiration is unlikely. A 401 error could be due to token expiration, but given the immediate use, it's more likely a header issue. The token lifetime is a factor but not the primary cause here.

  • ✗

    The token must be URL-encoded before being placed in the header.

    Why it's wrong here

    Tokens are typically alphanumeric strings that do not require URL encoding when placed in HTTP headers. URL encoding is for query parameters or form data. Placing a URL-encoded token in the header would likely cause an invalid token error. The token should be used as-is in the X-Auth-Token header.

  • ✓

    The token must be included in the request header as 'X-Auth-Token: <token>'.

    Why this is correct

    The Cisco Catalyst Center Intent API requires the authentication token to be passed in the HTTP header 'X-Auth-Token'. If the token is included in the body or as a query parameter, the API will reject the request with 401 Unauthorized. The engineer must set the header correctly. This is a common mistake when first using the API.

  • ✗

    The API endpoint requires the token to be sent as a Bearer token in the Authorization header.

    Why it's wrong here

    Catalyst Center does not use the standard Bearer token scheme. It uses a custom header 'X-Auth-Token'. Using 'Authorization: Bearer <token>' will result in a 401 error because the API does not recognize this format. The engineer must use the vendor-specific header. This is a key difference from many REST APIs.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.