350-401 Automation Practice Question
A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices. The engineer sends a GET request to /dataservice/device but receives a 403 Forbidden error. The engineer has already authenticated successfully and obtained a valid session cookie. What is the most likely reason for this error?
⚠ Common exam trap
It's easy for candidates to confuse 403 Forbidden with 401 Unauthorized; the former means authenticated but not authorized, so re-authenticating will not help.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user account does not have the necessary permissions to access the device inventory.
A 403 Forbidden error indicates that the authenticated user does not have the required permissions to access the requested resource. In vManage, user roles and group permissions control access to API endpoints. The engineer must ensure the account has read access to device inventory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session cookie has expired and needs to be renewed.
Why it's wrong here
An expired session cookie would result in a 401 Unauthorized error, not 403 Forbidden. The 403 error specifically means the user is authenticated but lacks permission. The engineer should verify the user's role and permissions rather than re-authenticating.
- ✗
The request must include an X-XSRF-TOKEN header to prevent CSRF attacks.
Why it's wrong here
While vManage may require CSRF tokens for state-changing operations like POST or PUT, a GET request typically does not require it. Moreover, the absence of a CSRF token would usually result in a 403 error only if the server enforces it for GET, which is unlikely. The more probable cause is insufficient permissions.
- ✓
The user account does not have the necessary permissions to access the device inventory.
Why this is correct
A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. Even with a valid session, the user's role must include permission to access the /dataservice/device endpoint. The engineer should check the user's role and group permissions in vManage to ensure they have read access to device inventory.
- ✗
The API endpoint /dataservice/device requires a POST request instead of GET.
Why it's wrong here
The /dataservice/device endpoint supports GET for retrieving device information. Using an incorrect HTTP method would typically result in a 405 Method Not Allowed error, not 403 Forbidden. The error indicates a permissions issue, not a method mismatch.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
Key term
Cisco SD-WAN
Cisco SD-WAN is a software-defined wide area network architecture that separates the control and data planes to centrally manage and optimize traffic across multiple WAN connections.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.