Q39Security
Refer to the exhibit. Which feature must be configured in Postman to receive a response from a Cisco Nexus 9000 Series Switch?
← → navigate · a answer
Community votes
Discussion · 10
A 4
Selected Answer: A
The correct asnwer is A
Subsequent operations on the REST API can use this token value as a cookie named APIC-cookie to authenticate future requests
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/3-x/rest-api-config/b_Cisco_APIC_REST_API_Configuration_Guide_3x/b_Cisco_APIC_REST_API_Configuration_Guide_chapter_01.html
2
The question is about Nexus 9000 RSET API, your response and link are about APIC and ACI REST API.
I think the correct answer is C
C 2
Selected Answer: C
The answer is C because the URL structure (api/mo/sys/intf/phys-[eth1/3].json) matches the NX-API interface of the Nexus NX-OS software. ACI physical interfaces are usually referred to in the context of fabric nodes (switches in the ACI fabric) and use URLs like /api/node/mo/topology/pod-[pod-id]/node-[node-id]/sys/phys-[eth1/3].json.
With that distinction, the endpoint shown targets the Nexus 9000 NX-OS and not Cisco ACI. I hope this helps.
A 1
Selected Answer: A
From what I found, I think it is A
A 1
Selected Answer: A
From Nexus REST API documentation:
The usual sequence for configuration is:
Authenticate: Call https://<IP of Nexus switch>/api/aaaLogin.xml with a payload that in XML is <aaaUser name='username' pwd= 'password'/>. This call returns a cookie value that the browser uses for the next calls.
Send POST to apply the configuration: The URL of the POST message changes depending on the object, the following is an example: https://<IP of Nexus switch>/api/mo/sys/bgp/inst.json, where api means that this call is to the API, mo means that this call is to modify a managed object, bgp/inst refers to the BGP instance, and .json means that the payload is in JSON format. If the end of the URL were .xml, that would mean that the payload is in XML format.
1
I don't think you are correct. Because the sequence you mentioned is about ACI / APIC and not Nexus NX OS. I think it should be C.
C 1
Selected Answer: C
NX-API is built into the authentication system on the device. Users must have the proper accounts to access the device through NX-API. NX-API uses HTTP basic authentication. All requests must include the username and password in the HTTP header.
C 1
Selected Answer: C
Agree with asd248402. C.
If you look at the address in the URL, it is HTTP and from the official cert book, chapter 16 "Key Topic":
Authentication
There are different kinds of authentication for REST APIs. This means they can use the API to carry out operations that not only read data but also add, edit, and delete data. These access rights are usually based on user-assigned roles such as Administrator that would have full rights to change data, whereas a plain User role might have read-only access rights.
The following list shows the types of authentication controls:
None: The Web API resource is public; anyone can make a call. Generally, this is the case for GET methods, rarely for POST, PUT, DELETE.
Basic HTTP: The username and password are sent to the server in an encoded string.
<SNIP>
1
Another snippet from the same section and mentions Google (postman)
An application programming interface (API) is a way for two pieces of software to communicate with each other. An API allows for the creation of rich applications with a wide range of functionality. Let’s walk through an example.
Suppose you are the creator of an online marketplace named Jack’s Shop, where people can come to buy stuff and have it delivered to their home/office. How do you track which user purchased what? You need to keep a database with user accounts and user order history. But you don’t want to maintain a user credentials database in-house. You would like your users to log in using their Google or Facebook accounts. How do you do this? A simple answer to this question would be using the Facebook API or Google API to authenticate users.
A 1
Selected Answer: A
To access the API, you first log in with a username/password to the aaaLogin.json page, then you get a token that you use for all later API calls, like the one shown. So the answer is A.