
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 4Objective 9
4.9 Interpret API Authentication Mechanisms: Basic, Custom Token, and API Keys 350-201 Practice Questions (Page 1)
Part of the Automation domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
4concepts
20%of the exam
Questions 1–5
- 1
A security operations team is integrating a third-party threat intelligence API into their SIEM. The API uses custom token authentication. The token is valid for 30 minutes and must be refreshed. The SIEM platform supports a single static credential for API integrations. What is the most appropriate way to handle token refresh?
Select an answer first - 2
How does HTTP Basic authentication transmit credentials in an HTTP request?
Select an answer first - 3
A developer is implementing custom token authentication for a web API. The token is a JSON Web Token (JWT) signed with a secret key. The developer needs to validate the token on each request. What is the most important validation step?
Select an answer first - 4
A network engineer is writing a Python script to pull device inventory from a network management API. The API documentation states it supports HTTP Basic authentication over HTTPS. The engineer needs to store the credentials securely and avoid hardcoding them in the script. Which approach should the engineer use?
Select an answer first - 5
How is an API key typically transmitted in an HTTP request?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.