Courseiva

200-901 Understanding and Using APIs Practice Question

A Cisco Catalyst Center API uses OAuth 2.0 with the client credentials grant for server-to-server communication. Which token endpoint parameter should the client include to identify itself?

⚠ Common exam trap

The trap is confusing grant types: candidates may pick authorization_code or response_type=token, but the exam tests that client_credentials is the correct grant_type for server-to-server OAuth 2.0.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

grant_type=client_credentials

For OAuth 2.0 client credentials grant, the client must include grant_type=client_credentials in the token request to indicate the grant type. This is defined in RFC 6749. The client also sends its client_id and client_secret for authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    scope=admin

    Why it's wrong here

    scope=admin merely narrows the permissions the issued token carries; it does not identify the grant type, so the token endpoint cannot determine which flow to process. It is tempting because scope is a legitimate optional parameter, and it would be correct when limiting a client credentials token to specific Catalyst Center APIs.

  • ✓

    grant_type=client_credentials

    Why this is correct

    The client credentials grant requires grant_type=client_credentials in the token request body, telling the authorisation server that the client is authenticating as itself rather than on behalf of a user. This satisfies the server-to-server scenario where no user context exists.

  • ✗

    response_type=token

    Why it's wrong here

    response_type=token belongs to the authorisation endpoint for implicit flows, not the token endpoint, which expects grant_type. It is tempting because it does return an access token, but only via a browser redirect for public clients, not a back-channel server-to-server POST.

  • ✗

    grant_type=authorization_code

    Why it's wrong here

    The client credentials grant requires grant_type=client_credentials; authorization_code instead expects a user-agent redirect and an authorisation code, which server-to-server clients never obtain. It is tempting because authorisation_code is the standard grant for user-facing sign-in flows, where a browser redirect and consent are available.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.