Courseiva

CCNA Api Based Automation Questions

17 questions · Api Based Automation topic · All types, answers revealed

1
MCQhard

Refer to the exhibit. You are performing an API call and receive a 400 Bad Request error. What is the most likely cause of this issue in the context of your UiPath automation?

A.The API server is currently down or under maintenance.
B.The request body content does not match the expected API schema.
C.The authentication token has expired or is invalid.
D.The requested resource path does not exist on the server.
AnswerB

A 400 error is a client-side error meaning the server cannot parse the request. This usually happens when required JSON fields are missing, data types are mismatched, or the structure is malformed. Checking the request body against the API documentation is the definitive way to resolve this specific error type.

Why this answer

A 400 Bad Request error indicates that the server could not process the request due to client-side issues, such as malformed JSON, missing mandatory fields, or invalid data types. In UiPath, this often stems from incorrect mapping of input variables to the request body. Debugging this requires verifying the request body content against the API's contract definition to ensure the data format matches the server's expected schema exactly.

Exam trap

Candidates often assume a 400 error implies a server-side outage or network issue, failing to inspect their own request body for schema mismatches or invalid JSON syntax.

2
MCQmedium

Refer to the exhibit. After invoking an API, you receive the JSON structure shown. Which activity and property configuration is required to extract the 'id' value into a variable?

A.Use 'Get Text' activity with 'data.id' as the selector.
B.Use 'Deserialize JSON' then access via 'jsonObject("data")("id").ToString'.
C.Use 'Assign' activity to read the response string directly using string splitting.
D.Use 'Deserialize JSON Array' to extract the 'id' field.
AnswerB

The Deserialize JSON activity converts the raw string into a JObject. By accessing the root object, you can traverse the hierarchy using the keys 'data' then 'id'. Converting the final result to a string allows the value to be stored in a standard UiPath string variable for later processing.

Why this answer

To extract nested values from a JSON response, one must first convert the string response into a JObject using the Deserialize JSON activity. Once in object form, the JObject can be navigated using standard dot notation or string indexing. This is a fundamental skill for API-based automation because it allows robots to programmatically access specific data fields needed for subsequent logic or UI-based interactions.

Exam trap

Candidates frequently try to access JSON values directly from the raw string output of the HTTP Request without using the 'Deserialize JSON' activity first to create a usable object.

3
MCQeasy

Which HTTP method is most appropriate when you need to create a new resource on a server, such as submitting a new expense report via an API?

A.GET
B.PUT
C.POST
D.DELETE
AnswerC

POST is the standard RESTful method for submitting data to a server to create a new entity. It is designed to handle payload bodies containing the resource details, making it the correct choice for submitting forms, reports, or new records to an API service during a UiPath automation process.

Why this answer

The POST method is the standard HTTP verb used for sending data to a server to create a new resource. In the context of UiPath, using the correct HTTP verb is essential for interacting with RESTful services as the server interprets the verb to determine the intended action. Using an incorrect verb often leads to 405 Method Not Allowed errors from the API endpoint.

Exam trap

Candidates often confuse 'POST' with 'PUT' or 'GET'. They may mistakenly select 'GET' for data submission, failing to realize 'GET' is intended for retrieving, not creating, resources.

4
MCQmedium

You are automating an API process that involves several sequential calls where the second request requires an ID generated by the first. What is the most efficient way to manage this data flow?

A.Write the first response to a CSV file and read it in the next step.
B.Store the ID in a variable and pass it to the next HTTP Request.
C.Hardcode the ID into the second activity during development.
D.Re-run the first request inside the second activity's scope.
AnswerB

Variables are the standard mechanism for passing data between activities in a workflow. This approach is efficient, secure, and preserves the execution context. By extracting the ID into a variable, the automation can dynamically update the subsequent request's body or URL parameter without incurring any performance penalties or I/O overhead.

Why this answer

Storing the response from the first API call in a variable is the most efficient way to maintain data flow. By parsing this variable and extracting the required ID, it can be passed as an argument or variable into subsequent HTTP Request activities. This approach minimizes memory footprint and keeps the workflow clean, maintainable, and easy to debug compared to writing data to temporary files or global state objects.

Exam trap

Candidates often overcomplicate the process by writing intermediate data to local text or CSV files instead of simply passing variables directly through the workflow memory.

5
MCQmedium

Which THREE of the following are valid ways to authenticate an API request in UiPath's HTTP Request activity?

A.Adding 'Authorization' key to the Headers collection.
B.Selecting 'OAuth 2.0' in the activity's Authentication tab.
C.Hardcoding credentials into the Endpoint field URL.
D.Configuring 'Basic' authentication in the Authentication tab.
E.Writing the password into a plain text file for the API to read.
AnswerA, B, D

Many APIs require an Authorization header for Bearer tokens or Basic authentication strings. Adding this key-value pair to the Headers collection is the standard way to provide credentials. UiPath treats this collection as standard HTTP headers, ensuring the request is properly authenticated when it reaches the server's security layer.

Why this answer

Authentication is fundamental to secure API consumption. UiPath supports multiple methods including API keys (passed as headers or query strings), OAuth tokens (retrieved via separate requests), and Basic Authentication (encoded in headers). Knowing these options allows developers to align their automation with the specific security standards defined by the target service provider, ensuring compliance and successful communication during the robot's runtime execution.

Exam trap

Candidates often confuse 'OAuth 2.0' with 'Basic' authentication, or forget that custom headers are a valid way to pass API keys for many modern services.

6
MCQmedium

Which TWO of the following are advantages of using API-based automation over UI-based automation in UiPath?

A.APIs are faster and more reliable as they avoid UI rendering latency.
B.API automation is easier for beginners because it requires no knowledge of JSON.
C.API automation is unaffected by changes to the UI layout or design.
D.API automation allows for visual debugging of the application state.
E.APIs are only available for web applications and never for desktop apps.
AnswerA, C

By communicating directly with the backend, API automation eliminates the time-consuming process of waiting for pages to load, scripts to execute, and UI elements to become interactive. This significantly increases execution speed and removes common failure points associated with UI responsiveness or browser-related rendering issues during robot execution.

Why this answer

API-based automation is faster and more reliable because it bypasses the rendering layer of applications. UI-based automation is susceptible to changes in the UI's layout, CSS, or browser behavior, which leads to high maintenance. APIs provide direct access to the backend data, ensuring the automation is not affected by frontend design updates, leading to significantly higher stability and throughput in large-scale enterprise environments.

Exam trap

Candidates often incorrectly claim that API automation is 'more secure' in a general sense, failing to identify that the primary advantages are speed and resilience to UI changes.

7
MCQmedium

A developer is building a UiPath automation that calls a REST API to create a new support ticket. The API documentation states that the request body must be sent as JSON with the header Content-Type: application/json. The developer uses the HTTP Request activity, sets the Method property to POST, and places the serialized JSON string in the Body property. However, the API returns a 415 Unsupported Media Type error. Which property should the developer configure to resolve this error?

A.Add a new header with the name Accept and the value application/json.
B.Change the Method property to PUT.
C.Set the Body property to a file path containing the JSON payload.
D.Set the BodyFormat property to application/json.
AnswerD

The 415 error indicates the server rejected the request because the Content-Type header was missing or incorrect. In the HTTP Request activity, the BodyFormat property controls the Content-Type header. Setting it to application/json ensures the server receives the correct media type, allowing it to parse the JSON body and process the ticket creation request successfully.

Why this answer

The 415 Unsupported Media Type status code means the server rejected the request because the payload's media type is not supported. In UiPath's HTTP Request activity, the BodyFormat property determines the Content-Type header sent with the request. Setting BodyFormat to application/json ensures the server recognizes the JSON payload and processes the ticket creation correctly.

Exam trap

The trap here is confusing the Accept header, which specifies desired response formats, with the Content-Type header, which specifies the request body's format.

8
MCQmedium

When sending a large JSON payload using the HTTP Request activity, which property must be correctly set to ensure the server processes the data as the intended format?

A.The 'Timeout' property.
B.The 'Accept' header.
C.The 'Content-Type' header.
D.The 'Authentication' property.
AnswerC

The Content-Type header is the specific instruction that tells the server the request body format is 'application/json'. Without this header, servers often default to plain text or reject the request entirely. Proper configuration ensures the server-side logic correctly deserializes the incoming byte stream into the expected object structure.

Why this answer

Setting the 'Content-Type' header is critical in API automation. It informs the server how to interpret the request body (e.g., as application/json, application/xml, or text/plain). If this header is missing or incorrect, the server may reject the request or fail to parse the body correctly, even if the payload data itself is perfectly formed according to the JSON specification.

Exam trap

Candidates often forget the 'Content-Type' header, assuming the server will automatically detect the payload format, which leads to 415 Unsupported Media Type errors during execution.

9
MCQmedium

When an API returns a 204 No Content status code, what does this signify in your UiPath automation workflow?

A.The request failed due to a server-side error.
B.The request was successful, but there is no payload body.
C.The request is unauthorized and needs a new token.
D.The API endpoint has been deprecated or removed.
AnswerB

A 204 code confirms that the server successfully processed the request and that the client does not need to expect any content in the response body. This allows the developer to skip deserialization steps, preventing errors and ensuring the automation correctly identifies the operation as complete without needing data parsing.

Why this answer

A 204 No Content status code is the server's way of indicating that the request was successful but there is no body data to return. This is common for successful 'DELETE' or 'PUT' operations. In UiPath, checking for this code is vital to prevent deserialization errors, as trying to deserialize an empty string will result in an exception in the JSON parser activity.

Exam trap

Candidates often assume a 204 status code indicates an error or a failed request, leading them to unnecessarily include error handling logic for a perfectly successful API operation.

10
MCQmedium

A developer is using the HTTP Request activity to send a POST request with a JSON body. The API returns a 201 Created status code along with a JSON response containing the newly created resource's ID. The developer needs to capture this ID for subsequent requests. Which property of the HTTP Request activity should be used to retrieve the response content?

A.Request Body
B.Status Code
C.Response Headers
D.Response Content
AnswerD

The 'Response Content' property of the HTTP Request activity holds the body of the server's response as a string. After a successful POST, this will contain the JSON with the new resource's ID. You can then deserialize it to extract the ID for later use.

Why this answer

The HTTP Request activity's 'Response Content' property contains the response body as a string. For a POST request that creates a resource, the server typically returns the created resource's details, including its ID, in the response body. This property is the correct place to retrieve that data.

Exam trap

The trap here is confusing request and response properties, or assuming the ID might be in headers when the scenario specifies a JSON response body.

11
MCQmedium

An automation project needs to retrieve secure credentials from a REST API endpoint that requires OAuth 2.0 authorization. Which activity should be utilized first to establish the connection before making subsequent data requests?

A.Invoke Workflow File
B.HTTP Request
C.Get Asset
D.Deserialize JSON
AnswerB

This activity provides the necessary framework to send authenticated requests to API endpoints. By configuring the correct endpoint URL and authentication parameters, the automation successfully requests an access token. This token acts as the credential for subsequent API calls, ensuring the process satisfies the security requirements of modern OAuth 2.0 authentication flows.

Why this answer

To interact with OAuth 2.0 secured APIs, the automation must first obtain an access token by authenticating with the identity provider. The HTTP Request activity is used to POST client credentials or grant codes to the token endpoint. Understanding this sequence is vital for API automation, as failing to handle the authentication handshake results in 401 Unauthorized errors, preventing any data exchange with protected resources during the workflow execution.

Exam trap

Candidates mistakenly look for specialized authentication activities rather than recognizing that standard web requests like HTTP Request are used to fetch OAuth tokens.

12
MCQmedium

Why is it important to include a 'User-Agent' header in your API requests when using UiPath?

A.It is required to increase the speed of the API response.
B.It helps the server identify the client for security and logging.
C.It automatically authenticates the request to the server.
D.It determines the format of the returned data.
AnswerB

APIs often whitelist or blacklist requests based on the User-Agent header. Including it helps ensure your automation is identified as a trusted client. It also assists developers in monitoring and debugging traffic patterns, ensuring that the robot is not flagged or blocked by automated security systems during high-volume operations.

Why this answer

Many APIs use the 'User-Agent' header to identify the client making the request. Some services block requests that lack a User-Agent, perceiving them as potential security threats or malicious bot traffic. By providing a descriptive User-Agent, you ensure your automation is recognized as a legitimate client, which improves the success rate of the API calls and allows the API provider to troubleshoot any issues effectively if necessary.

Exam trap

Developers often treat request headers as optional metadata, forgetting that modern web APIs frequently drop requests missing a valid User-Agent string.

13
MCQmedium

A UiPath developer is building an automation that calls a REST API to retrieve a list of active employees. The API returns the following JSON response: {"employees": [{"id": 101, "name": "Alice"}, {"id": 102, "name": "Bob"}], "total": 2}. The developer uses the HTTP Request activity, which outputs the response as a string variable named apiResponse. The developer then uses a Deserialize JSON activity to convert apiResponse into a JObject variable named jsonObj. To iterate through each employee and extract the name, which expression correctly retrieves the array of employee objects from jsonObj?

A.jsonObj.employees
B.jsonObj("employees")
C.jsonObj.SelectToken("$.employees[0].name")
D.jsonObj("employees").ToString()
AnswerB

In UiPath, when you deserialize a JSON string into a JObject, you can access properties using the indexer syntax. The property 'employees' is a top-level key, so jsonObj("employees") returns a JArray containing the employee objects. This expression is correct because it directly references the key and yields the array needed for iteration. The other options either incorrectly navigate the structure or use unsupported syntax, making this the only valid choice.

Why this answer

The JSON response has a top-level property 'employees' that contains an array of objects. After deserializing into a JObject, the correct way to retrieve this array is by using the indexer with the property name as a string, yielding a JArray. This JArray can then be used in a For Each loop to access each employee's name.

The other expressions either extract only a single value, use unsupported syntax, or convert the array to a string, none of which meet the requirement.

Exam trap

The trap here is assuming that dot notation (jsonObj.employees) works for accessing JSON properties in UiPath, when actually the JObject indexer with a string key is required.

14
MCQhard

Which activity is best suited for extracting specific data points from an XML response, as opposed to a JSON response?

A.Deserialize JSON
B.Deserialize XML
C.Read Text File
D.For Each Row
AnswerB

Deserialize XML is the dedicated activity for converting raw XML strings into an XDocument object. Once converted, the developer can apply XPath expressions to navigate the tree and extract values. This is the industry-standard way to parse XML responses, ensuring accurate data retrieval from complex hierarchical document formats in UiPath.

Why this answer

When dealing with XML, the structure is hierarchical and requires different parsing techniques than JSON. The 'Deserialize XML' activity combined with XPath queries is the standard approach in UiPath. XPath allows developers to pinpoint specific nodes within an XML tree, providing a robust method for data extraction that is resilient to node ordering or complex document structures commonly found in legacy enterprise web services.

Exam trap

Test-takers frequently confuse JSON deserialization activities with XML methods, attempting to parse hierarchical XML structures using JSON parsing logic.

15
MCQhard

A developer is using the HTTP Request activity to call an API that returns a large JSON response. The developer needs to extract a specific value from the response and use it in subsequent steps. The response is stored in a variable of type String. After deserializing the JSON into a JObject, which activity and configuration should the developer use to reliably extract the value using a JSONPath expression?

A.Use the Select Token activity, set the Input property to the original JSON string, and set the JsonPath property to the desired expression.
B.Use the Deserialize JSON activity again with the JObject as input and specify the JSONPath in the JsonPath property.
C.Use the Assign activity to call the JObject.SelectToken method directly, passing the JSONPath expression as a string argument.
D.Use the Select Token activity, set the Input property to the JObject, and set the JsonPath property to the desired expression.
AnswerD

The Select Token activity is specifically designed to query a JObject using a JSONPath expression. Setting the Input property to the deserialized JObject and providing the JSONPath in the JsonPath property returns the matching token. This is the most reliable and efficient method for extracting values from JSON in UiPath, as it leverages Newtonsoft.Json's JSONPath support.

Why this answer

After deserializing the JSON string into a JObject, the Select Token activity is the correct tool to query it with a JSONPath expression. It accepts a JObject as input and returns the matching token. Using Deserialize JSON again or passing a string to Select Token would fail.

Directly calling JObject.SelectToken is possible but not the standard UiPath approach.

Exam trap

The trap here is attempting to use Select Token directly on a JSON string without first deserializing it into a JObject.

16
MCQhard

Refer to the exhibit. The automation project consistently fails with a 'Timeout' exception during a long-running API call. What is the most appropriate action to resolve this issue?

A.Decrease the timeout value to 1000ms.
B.Increase the timeout value to a higher threshold.
C.Remove the timeout property entirely.
D.Switch the request to use the GET method instead.
AnswerB

Increasing the timeout gives the server more time to complete its processing and return a result. This is the standard resolution for workflows that are failing due to legitimate, long-running backend operations. It ensures the robot successfully collects the data without triggering a premature exception while waiting for the service response.

Why this answer

The Timeout property specifies how long the UiPath activity waits for a server response. If an API process takes longer than the configured threshold, the robot aborts the operation. Increasing this value is the correct action when dealing with known, slow-responding APIs, ensuring the robot allows sufficient time for processing without prematurely terminating the connection and causing a failure in the workflow logic.

Exam trap

Candidates often try to wrap the HTTP Request in a 'Retry Scope' to fix a timeout, rather than addressing the root cause by increasing the activity's timeout property.

17
MCQhard

When designing a robust API automation workflow in UiPath, which TWO of the following practices are considered essential for maintaining production-grade reliability?

A.Use a Try-Catch block around the HTTP Request activity.
B.Always hardcode the API secret directly in the HTTP Request activity.
C.Validate the HTTP status code in the response property after execution.
D.Store all API payloads in global variables only.
E.Disable SSL verification for all requests to ensure speed.
AnswerA, C

Wrapping network-dependent activities in Try-Catch structures is a best practice. It enables the developer to capture specific system exceptions like connection timeouts or DNS errors, allowing the robot to implement retry logic or log meaningful messages instead of abruptly crashing the entire workflow during unpredictable external service interruptions.

Why this answer

Production-grade API automation requires handling transient errors and ensuring data integrity. Implementing global exception handling via Try-Catch blocks allows for graceful failure, while checking HTTP status codes ensures the automation reacts to business logic errors rather than just network issues. These practices minimize downtime and provide auditability, which is essential when dealing with external system dependencies that may change or experience intermittent latency during high-volume processing periods.

Exam trap

Test-takers frequently rely solely on Try-Catch blocks while forgetting that HTTP errors do not always throw exceptions automatically, missing the critical requirement to validate status codes explicitly.

Ready to test yourself?

Try a timed practice session using only Api Based Automation questions.