Q5Application Deployment and Security
A developer has completed implementing a REST API, but when it runs, it returns a 401 error message. What must be done on the API to resolve the issue?
← → navigate · a answer
Community votes
Discussion · 16
15
I think the answer should be B.
401 is for unauthenticated, A and D are similar and tied to authorization
10
Answer is B.
401 is "unauthorized": authentication is incorrect or missing
A & D are for 403 "Forbidden"
C is for 404 "Not found"
4
"The HTTP 401 Unauthorized client error status response code means that the request has not been applied because it lacks valid authentication credentials for the target resource.
This status is sent with a WWW-Authenticate header that contains information on how to authorize correctly.
This status is similar to 403, but in this case, authentication is possible."
https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401
3
I go with 'B'
B 3
Selected Answer: B
Messy question... badly written. All options seem wrong somehow, but B looks like the least wrong of them all.
3
B
401 Unauthorized: Authentication is required (API key, API token, or
username and password). If the API was previously accessible, be
aware that keys and tokens can expire, and usernames and passwords
can be changed.
- 403 Forbidden: You are authenticated and authorized but do not have
the permission to access the resource.
B 2
Selected Answer: B
HTTP 401 response: the client request has not been completed because it lacks valid authentication credentials for the requested resource
B 2
Selected Answer: B
B. 401 means the request is unauthenticated. 403 would mean you are authenticated, but don't have the permissions (unauthorized).
1
401 Unauthorized
The request requires user authentication.
1
B
https://airbrake.io/blog/http-errors/401-unauthorized-error
1
I would go with B but it's a weird question as you do not know if additional rights are needed. It can be that the account works but needs extra rights, and configuring new credentials will not solve the issue if the underlying issue isn't fixed.
Again a great Cisco exam question.
1
Answer is B
401 Unauthorized: Authentication is required (API key, API token, or username and password).
If the API was previously accessible, be aware that keys and tokens can expire, and usernames
and passwords can be changed
1
Very confusing question:
If the request included authentication credentials, then the 401
response says that authorization has been refused for those
credentials. The user agent MAY repeat the request with a new or
replaced Authorization header field (Section 4.2). If the 401
response contains the same challenge as the prior response, and the
user agent has already attempted authentication at least once, then
the user agent SHOULD present the enclosed representation to the
user, since it usually contains relevant diagnostic information.
B 1
Selected Answer: B
The correct answer is B
401 is about unauthenticated, while 403 is about unauthorized.
B 1
Selected Answer: B
B is correct
401 = unauthorized": authentication incorrect or missing
B 1
Selected Answer: B
answer should be b