An automation engineer must call Prism Central REST APIs to generate a weekly capacity report. The script must authenticate without embedding a user password in source control. Which method should the engineer use?
Select an answer to reveal the explanation.
Short Explanation
Think of API access like handing a guard a badge instead of your house key: you generate a Prism Central API token and send it as a bearer token. If you bake a password into a script, you've just handed over the house key. You want the token, not the raw credentials, for automated reporting.
Full Explanation
Prism Central REST automation is authenticated at the API layer, not through the browser session or hypervisor console. For unattended jobs, the supported pattern is to create a Prism Central API token and include it in the Authorization header as a bearer token. The token can be revoked independently, which is why it is preferred over interactive passwords for reporting scripts.
HTTP Basic authentication can be valid for short-lived or tightly controlled calls, but embedding an administrator password in source control defeats the requirement and creates a reusable secret that may expire or require rotation. A browser login against the Prism UI establishes a human session cookie and is not the authentication mechanism for scripted REST calls. CVM SSH key pairs secure command-line access to controller VMs; they are not HTTP API bearer credentials and cannot sign Prism REST requests.
Exam caveat: When Nutanix asks for API authentication in an automation scenario, choose the documented Prism Central token workflow unless the stem explicitly requires Basic authentication. Operational check: Generate the API token in Prism Central, store it in the automation secret store, and test one read-only API call before scheduling the report.