Courseiva
Automation →easyMultiple Choice

350-401 Automation Practice Question

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices. The engineer sends a GET request to /dataservice/device but receives a 403 Forbidden error. The engineer has already authenticated successfully and obtained a valid session cookie. What is the most likely reason for this error?

⚠ Common exam trap

It's easy for candidates to confuse 403 Forbidden with 401 Unauthorized; the former means authenticated but not authorized, so re-authenticating will not help.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user account does not have the necessary permissions to access the device inventory.

A 403 Forbidden error indicates that the authenticated user does not have the required permissions to access the requested resource. In vManage, user roles and group permissions control access to API endpoints. The engineer must ensure the account has read access to device inventory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session cookie has expired and needs to be renewed.

    Why it's wrong here

    An expired session cookie would result in a 401 Unauthorized error, not 403 Forbidden. The 403 error specifically means the user is authenticated but lacks permission. The engineer should verify the user's role and permissions rather than re-authenticating.

  • ✗

    The request must include an X-XSRF-TOKEN header to prevent CSRF attacks.

    Why it's wrong here

    While vManage may require CSRF tokens for state-changing operations like POST or PUT, a GET request typically does not require it. Moreover, the absence of a CSRF token would usually result in a 403 error only if the server enforces it for GET, which is unlikely. The more probable cause is insufficient permissions.

  • ✓

    The user account does not have the necessary permissions to access the device inventory.

    Why this is correct

    A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. Even with a valid session, the user's role must include permission to access the /dataservice/device endpoint. The engineer should check the user's role and group permissions in vManage to ensure they have read access to device inventory.

  • ✗

    The API endpoint /dataservice/device requires a POST request instead of GET.

    Why it's wrong here

    The /dataservice/device endpoint supports GET for retrieving device information. Using an incorrect HTTP method would typically result in a 405 Method Not Allowed error, not 403 Forbidden. The error indicates a permissions issue, not a method mismatch.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.