Courseiva

CCNA API Automation Questions

15 questions · API Automation · All types, answers revealed

1
MCQmedium

An automation developer is using the HTTP Request activity in UiPath Studio to call a REST API that requires a bearer token. The token is stored in Orchestrator as an asset named "APIToken". The developer needs to include the token in the request header. Which approach should be used?

A.Append the token as a query parameter, such as "?token=<token>", to the request URL.
B.Use the OAuth2 activity with the token as the AccessToken property and configure the HTTP Request to use that connection.
C.Add a header named "Authorization" with the value "Bearer " + token, where token is retrieved using the Get Asset activity.
D.Set the AuthenticationType property of the HTTP Request activity to "Bearer" and provide the token in the Password field.
AnswerC

This is correct because the HTTP Request activity allows custom headers. The Get Asset activity retrieves the token from Orchestrator, and the header must be formatted as "Bearer <token>". This is the standard way to pass a bearer token in a header for REST APIs.

Why this answer

The correct approach is to retrieve the token from Orchestrator using the Get Asset activity and then add it to the request headers as "Authorization: Bearer <token>". This is the standard method for bearer token authentication in REST APIs and is fully supported by the HTTP Request activity through its Headers property.

Exam trap

The trap here is assuming that the HTTP Request activity has built-in authentication types for bearer tokens, when in fact it requires manual header configuration.

2
Multi-Selectmedium

A developer is building a UiPath automation that consumes a REST API. The API returns a JSON response with a 'status' field and a 'data' array. The developer needs to handle both successful responses and error responses gracefully. Which two actions should the developer take to ensure robust error handling? (Choose two.)

Select 2 answers
A.Deserialize the JSON response and check if the 'status' field equals 'success' before processing the 'data' array.
B.Use a Try Catch activity around the HTTP Request and handle specific exceptions like HTTPRequestException.
C.Configure the HTTP Request activity to ignore SSL certificate errors to avoid connection failures.
D.Set the HTTP Request activity's 'Continue On Error' property to True to prevent the workflow from stopping on any error.
E.Check the HTTP status code returned by the HTTP Request activity and branch based on whether it is in the 2xx range.
AnswersB, E

The HTTP Request activity may throw exceptions for network issues, timeouts, or non-success status codes if configured to do so. Wrapping it in Try Catch allows catching and handling these exceptions, preventing the automation from crashing and enabling graceful recovery or logging.

Why this answer

Robust error handling for API calls involves checking the HTTP status code to detect success or failure and using Try Catch to handle exceptions that may occur during the request. These two actions together ensure that both expected error responses and unexpected exceptions are managed, allowing the workflow to respond appropriately.

Exam trap

The trap here is relying solely on the API's JSON status field or suppressing errors with Continue On Error, which can mask failures and lead to incorrect processing.

3
MCQmedium

A developer is using the HTTP Request activity to call a REST API that returns a 401 Unauthorized response. The API documentation states that the access token must be included in the 'Authorization' header as 'Bearer <token>'. The developer has already obtained a valid token and stored it in a string variable named 'accessToken'. Which configuration should the developer apply to the HTTP Request activity to ensure the token is sent correctly?

A.In the Authentication property, select 'Bearer' and enter the accessToken variable in the Password field.
B.In the Headers property, add a new header with Name 'Authorization' and Value 'Bearer ' + accessToken.
C.In the URL property, append '?access_token=' + accessToken as a query string parameter.
D.In the Body property, add a JSON object with a key 'Authorization' and value 'Bearer ' + accessToken.
AnswerB

The Authorization header with the value 'Bearer ' concatenated with the token is the standard way to send a Bearer token. The HTTP Request activity's Headers property accepts a dictionary of header names and values. This configuration ensures the token is transmitted correctly and the API can authenticate the request.

Why this answer

To send a Bearer token, the developer must add an 'Authorization' header with the value 'Bearer ' followed by the token. The HTTP Request activity allows adding custom headers via the Headers property. This is the standard and secure method.

Other options either place the token in the wrong location or use unsupported authentication configurations.

Exam trap

The trap here is assuming the HTTP Request activity has a built-in Bearer authentication option, leading to incorrect configuration.

4
MCQmedium

A developer is building an API workflow that must call a protected endpoint. The API requires a Bearer token that expires every 60 minutes. The developer uses the HTTP Request activity in a UiPath Studio project and wants to avoid hardcoding credentials. They have already configured an Orchestrator asset of type Credential named 'ApiUser' that stores the client ID and secret. Which approach should the developer use to obtain and attach the token to each request?

A.Use the Get Asset activity to retrieve the credential as a string, then pass it directly in the body of every API request as a password field.
B.Store the token in an Orchestrator queue item and have each HTTP Request activity read the token from the queue using Get Transaction Item.
C.Configure the HTTP Request activity's Authentication property to use the Orchestrator credential asset directly, and select OAuth 2.0 as the authentication type.
D.Use the Get Credential activity to retrieve the asset, then call the token endpoint with the HTTP Request activity, store the token in a variable, and add an Authorization header with value 'Bearer ' + token to subsequent requests.
AnswerD

This approach retrieves the secret securely from Orchestrator, obtains a token via the HTTP Request activity, and attaches it as a Bearer header. It avoids hardcoding and supports token refresh by re-running the token call when needed. The variable can be reused across requests within the same run, and the credential asset is protected by Orchestrator.

Why this answer

The correct approach is to retrieve the credential asset securely, call the token endpoint to obtain a Bearer token, and then attach that token as an Authorization header on subsequent requests. This avoids hardcoding secrets and leverages Orchestrator's credential management. The token can be stored in a variable and refreshed when it expires, ensuring continued access.

Exam trap

The trap here is assuming the HTTP Request activity can directly consume an Orchestrator credential asset for OAuth 2.0 without an explicit token call.

5
MCQhard

A developer is configuring OAuth 2.0 authorization code flow within UiPath Orchestrator and API activities to connect securely to a corporate CRM system. The security team mandates that client secrets must never be exposed or stored in plain text configuration files. Which authentication mechanism or credential management pattern should the developer implement?

A.Store the client secret as an encrypted string value directly inside the project.json file using the native UiPath Studio cipher.
B.Utilize an Orchestrator Credential Asset or external Secrets Provider to retrieve the client secret dynamically at runtime.
C.Hardcode the client secret within a global workflow argument designated for input parameters across all child workflows.
D.Implement HTTP Basic Authentication instead of OAuth 2.0 to eliminate the requirement for handling client secret cryptographic keys.
AnswerB

Leveraging an Orchestrator Credential Asset or external Secrets Provider ensures that sensitive authentication data remains centralized, encrypted, and securely managed outside the automation package source code. This practice complies with security standards and simplifies secret rotation routines across environments.

Why this answer

Storing client secrets securely requires leveraging enterprise credential vaults integrated with UiPath, such as CyberArk, BeyondTrust, or Orchestrator assets, rather than hardcoding sensitive values in project configuration files. At runtime, the workflow fetches these credentials dynamically and passes them securely to the authentication endpoints, adhering strictly to enterprise security governance and compliance standards.

Exam trap

Candidates suggest storing client secrets in local project JSON files or hardcoding them, violating security mandates against plain text credential exposure.

6
MCQeasy

A developer is using the UiPath HTTP Request activity to call a REST API that returns a JSON response. The developer needs to extract a specific value from the response body. Which activity should be used to convert the JSON response string into a manipulable object?

A.Deserialize XML
B.Serialize JSON
C.Read Text File
D.Deserialize JSON
AnswerD

The Deserialize JSON activity converts a JSON string into a JObject, allowing access to properties via JToken or JObject methods. This is the standard way to parse JSON responses in UiPath and enables extraction of specific values using selectors or indexers.

Why this answer

Deserialize JSON is the correct activity to convert a JSON string into a structured object that can be queried. Serialize JSON does the reverse, and the other activities are unrelated to JSON parsing. This is a foundational step for extracting data from API responses.

Exam trap

The trap here is confusing Serialize JSON with Deserialize JSON, as their names are similar but they perform opposite functions.

7
MCQhard

A developer is using the UiPath HTTP Request activity to send a POST request to an API that expects a JSON payload. The developer has a Dictionary(Of String, Object) variable named payloadDict containing the data to send. Which approach correctly serializes the dictionary and configures the request?

A.Use the Serialize JSON activity on payloadDict to get a JSON string, then set the HTTP Request activity's Body property to that string and the Content-Type header to "application/json".
B.Set the Body property directly to payloadDict and set the Content-Type header to "application/json".
C.Use the Serialize JSON activity on payloadDict and set the Body property to the result, but leave the Content-Type header unset.
D.Use the Deserialize JSON activity on payloadDict and set the Body property to the result.
AnswerA

Serialize JSON converts the dictionary into a valid JSON string. Setting the Body property to this string and specifying the Content-Type header as "application/json" ensures the API receives the payload in the expected format. This is the standard method for sending JSON data in UiPath.

Why this answer

To send a dictionary as JSON, you must serialize it into a string using the Serialize JSON activity. Then, set the HTTP Request's Body to that string and include the Content-Type header as "application/json". This ensures the API receives a properly formatted JSON payload and interprets it correctly.

Exam trap

The trap here is confusing serialization with deserialization, or assuming the HTTP Request activity automatically serializes complex objects without explicit conversion.

8
MCQhard

A developer is automating a process that calls a REST API which returns a large JSON response containing a 'results' array with 10,000 objects. The developer uses the Deserialize JSON activity and then a For Each loop to process each object. The workflow is running slowly and consuming high memory. Which approach should the developer take to improve performance while still processing all objects?

A.Set the 'TypeArgument' property of the Deserialize JSON activity to 'System.Collections.Generic.IEnumerable(Of JObject)' to enable lazy loading.
B.Use the HTTP Request activity with the 'Save Response to File' option, then parse the JSON file in chunks using a streaming JSON parser like Newtonsoft.Json.JsonTextReader.
C.Use the 'Deserialize JSON Array' activity instead of 'Deserialize JSON' to stream the array elements one by one.
D.Use the 'JSON to DataTable' activity to convert the JSON to a DataTable, then use a For Each Row activity to process the data.
AnswerB

Saving the response to a file and then using a streaming parser like JsonTextReader allows processing the JSON without loading it all into memory. This reduces memory usage and can improve performance for large payloads. The developer can iterate over the JSON tokens and process each object individually, achieving the goal.

Why this answer

For large JSON responses, loading the entire payload into memory with Deserialize JSON can cause performance issues. Saving the response to a file and using a streaming parser such as JsonTextReader allows incremental processing, reducing memory footprint. This approach is more efficient for large datasets and still processes all objects.

Other options either do not exist in UiPath or do not solve the memory problem.

Exam trap

The trap here is assuming that changing the TypeArgument or using a non-existent activity can enable streaming, when actually a different parsing technique is required.

9
MCQmedium

A developer has built a UiPath API workflow that calls a vendor's REST endpoint returning a JSON object with a nested 'items' array. The response is large, and the developer needs to extract only the 'id' field from each element in 'items' to feed a downstream process. The HTTP Request activity's output is stored in a variable of type String. Which approach should the developer use to reliably extract the required values?

A.Use the Deserialize XML activity after converting the JSON string to XML using a custom conversion function.
B.Use a RegEx Matches activity with the pattern "\"id\":\s*\"(.*?)\"" on the response string to capture all id values.
C.Use the Deserialize JSON activity with the response string and then access the nested array using a JSONPath expression such as "$.items[*].id".
D.Use the Execute JavaScript activity to run a JavaScript snippet that parses the JSON and returns the ids as a comma-separated string.
AnswerC

Deserialize JSON converts the raw string into a JObject, enabling JSONPath queries. The expression "$.items[*].id" selects all id values from the items array, returning a JArray that can be iterated. This is the standard UiPath method for parsing structured JSON and avoids fragile string manipulation.

Why this answer

The Deserialize JSON activity is purpose-built for parsing JSON strings into a manipulable object. Using JSONPath with "$.items[*].id" directly retrieves the needed array of ids without brittle string parsing. This method is robust against formatting changes and is the UiPath-recommended way to handle nested JSON payloads in API workflows.

Exam trap

The trap here is assuming that string manipulation or regex is sufficient for JSON parsing, ignoring the structured nature of JSON and the availability of dedicated deserialization activities.

10
Multi-Selectmedium

An automation developer is troubleshooting an API workflow where a POST request to an external service intermittently returns a 429 Too Many Requests status code. Which TWO strategies should the developer implement in UiPath Studio to handle this rate-limiting scenario gracefully? (Choose two)

Select 2 answers
A.Implement a Retry Scope activity around the HTTP Request activity with a configured delay and a condition checking for status code 429.
B.Configure the HTTP Request activity to automatically restart the robot machine whenever a rate limit threshold is breached.
C.Parse the Retry-After response header returned by the API server and pass its value dynamically into a Delay activity.
D.Convert all POST requests into GET requests to bypass rate-limiting rules enforced specifically on data modification endpoints.
E.Increase the overall Windows timeout settings in the robot's local registry to force the server to accept throttled requests.
AnswersA, C

The Retry Scope activity allows the workflow to automatically catch transient errors and rate-limiting responses, repeating the API call after a specified interval until successful completion or retry exhaustion. This built-in recovery mechanism ensures robustness against temporary throttling.

Why this answer

Handling HTTP 429 status codes requires implementing resilient retry logic combined with dynamic backoff periods to respect the external API rate limits. By utilizing the Retry Scope activity paired with an exponential backoff calculation or checking the Retry-After response header, the automation workflow can pause and re-attempt execution successfully without causing permanent IP blocking or job failures.

Exam trap

Candidates select basic parallel processing or infinite loops without delay mechanisms, failing to handle API rate limits and causing job failures.

11
MCQmedium

A developer is using the UiPath HTTP Request activity to call a REST API that returns a JSON array of customer records. The API paginates results and includes a 'nextPageToken' field in the response body when more data is available. The developer needs to retrieve all pages and aggregate the results into a single DataTable. Which approach should the developer use in the UiPath workflow?

A.Use a Do While loop that repeats while the 'nextPageToken' is not empty, passing the token as a query parameter in each subsequent HTTP Request, and append each response's data to a list or DataTable.
B.Configure the HTTP Request activity to use the 'Accept' header with value 'application/json' and enable the 'Parse JSON' option, which automatically follows pagination links.
C.Use a For Each loop that iterates over the JSON array from the first response and makes a separate HTTP Request for each record's ID.
D.Set the HTTP Request activity's 'Retry' property to a high number (e.g., 10) so it automatically retries and retrieves all pages in one call.
AnswerA

This correctly implements token-based pagination. The loop continues until no token remains, and each page is processed and aggregated. UiPath's HTTP Request activity supports dynamic query parameters, and appending results to a collection handles the aggregation. This is the standard pattern for APIs that return a continuation token.

Why this answer

Token-based pagination requires a loop that continues while the token is present, using the token as a query parameter in subsequent requests. Aggregating results into a DataTable or list ensures all records are collected. The other options either misunderstand retry logic, ignore the pagination mechanism, or assume non-existent auto-pagination features.

Exam trap

The trap here is assuming that the HTTP Request activity's Retry property or Parse JSON option handles pagination automatically.

12
MCQeasy

A developer needs to call a REST API that requires an API key to be passed as a query parameter named 'api_key'. The developer is using the UiPath HTTP Request activity. Which property should the developer use to add this parameter?

A.Add a JSON body with {"api_key": "value"} in the Body property.
B.Use the Authentication property to select "API Key" and enter the value.
C.Add the parameter to the URL property by appending "?api_key=value" to the endpoint URL.
D.Add a header with Name "api_key" and Value "value" in the Headers property.
AnswerC

Query parameters are part of the URL. Appending "?api_key=value" directly to the URL is the correct way to pass an API key as a query parameter. This ensures the API receives the key as expected. The HTTP Request activity does not have a separate query parameter collection, so modifying the URL is necessary.

Why this answer

Query parameters are appended to the URL. Since the HTTP Request activity does not have a dedicated query parameter field, the developer must include "?api_key=value" in the URL property. This is the standard method for passing API keys as query parameters, ensuring the API can authenticate the request.

Exam trap

The trap here is assuming there is a dedicated query parameter section or confusing query parameters with headers, which are used for different purposes.

13
MCQmedium

An automation developer is building an integration with a third-party REST API that returns a JSON payload containing over 50,000 transaction records per request. The process frequently throws an OutOfMemoryException inside UiPath Studio when attempting to parse the entire response string using standard string manipulation. Which approach should the developer use to handle this large response efficiently?

A.Increase the available RAM on the Orchestrator robot machine to accommodate larger string allocations during the deserialization phase.
B.Wrap the HTTP Request activity inside a Parallel For Each activity to divide the response string into concurrent processing threads.
C.Configure the HTTP Request activity to stream the response directly into a JsonTextReader instance for token-based processing.
D.Disable the SSL verification properties on the HTTP Request activity to bypass encryption overhead during the large data transfer.
AnswerC

Streaming the response avoids loading the entire payload into memory by reading tokens sequentially, dramatically reducing the memory footprint of the automation process. This approach is essential for handling massive enterprise payloads reliably in production environments without resource crashes.

Why this answer

Deserializing large JSON payloads entirely into memory is a primary cause of resource exhaustion in automation workflows. By utilizing Newtonsoft.Json with JsonTextReader, developers can stream the JSON data token by token instead of loading the complete document structure into memory simultaneously. This memory-efficient architecture ensures long-running unattended processes remain stable and scale effectively when consuming massive external payloads from enterprise REST endpoints.

Exam trap

Candidates choose standard string deserialization methods for massive payloads, forgetting this loads the entire structure into memory and triggers OutOfMemoryExceptions.

14
MCQhard

A developer is using the UiPath HTTP Request activity to call an API that requires a bearer token. The token is obtained from an authentication endpoint and stored in a String variable named authToken. The developer must ensure that the token is sent in the Authorization header for every subsequent request. Which configuration in the HTTP Request activity correctly achieves this?

A.In the Body property, add a JSON object with a key "Authorization" and value "Bearer " + authToken.
B.In the Authentication property, select "Bearer Token" and enter authToken in the Token field.
C.In the Headers property, add a new header with Name "Authorization" and Value "Bearer " + authToken.
D.In the URL property, append "?Authorization=Bearer " + authToken as a query string parameter.
AnswerC

The HTTP Request activity allows custom headers via the Headers collection. Adding an Authorization header with the value "Bearer " concatenated with the token is the standard way to pass a bearer token. This ensures the token is included in the request headers as required by OAuth 2.0 bearer token usage.

Why this answer

Bearer tokens must be sent in the Authorization header with the prefix "Bearer ". The HTTP Request activity's Headers collection is the correct place to add this header dynamically using the stored token variable. This approach is secure and compliant with OAuth 2.0 standards, ensuring the API can authenticate the request.

Exam trap

The trap here is confusing where authentication credentials belong, such as placing them in the body or URL instead of the required Authorization header.

15
MCQmedium

A developer uses the HTTP Request activity in a UiPath Studio project to call a REST API that returns a deeply nested JSON response. The developer needs to extract a specific value located at a path of several levels, and the response structure may vary slightly between calls. The developer wants to avoid deserializing the entire payload into custom classes. Which approach is most appropriate?

A.Use the Deserialize JSON activity with the TypeArgument set to System.Data.DataTable, then use the Select method to filter rows containing the desired value.
B.Use the Deserialize JSON activity with the TypeArgument set to System.Collections.Generic.Dictionary(Of String, Object), then access nested levels using repeated TryGetValue calls.
C.Use the Deserialize JSON activity with the TypeArgument set to Newtonsoft.Json.Linq.JObject, then use the SelectToken method with a JSONPath expression to retrieve the nested value.
D.Use the HTTP Request activity with the Response Content property set to a string, then apply regular expressions to parse the raw JSON text for the desired value.
AnswerC

Deserializing to JObject allows dynamic traversal without predefined classes, and SelectToken supports JSONPath queries to extract nested values reliably even when the structure varies. This directly addresses the need to avoid custom classes while handling a deep, potentially inconsistent JSON hierarchy.

Why this answer

Using JObject with SelectToken leverages JSONPath to query nested values without predefined classes, which is ideal when the JSON structure may vary. It avoids brittle string parsing and the rigidity of tabular or dictionary-based deserialization, providing a flexible and maintainable solution for extracting deep values from REST API responses.

Exam trap

The trap here is assuming that any deserialization target can handle nested JSON, when only dynamic types like JObject support path-based queries without custom classes.

Ready to test yourself?

Try a timed practice session using only API Automation questions.