Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is building a Python script that calls the Cisco Webex REST API. The API requires an OAuth 2.0 access token that expires after 14 days. The script will run unattended on a server every hour. Which OAuth 2.0 grant type should the developer use to obtain tokens without user interaction?

⚠ Common exam trap

The trap here is assuming that any OAuth 2.0 flow can be used for automation, when actually only Client Credentials is designed for machine-to-machine scenarios without user interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client Credentials grant

The Client Credentials grant is the correct choice because it allows the application to authenticate itself directly with the authorization server using its client ID and secret, without any user involvement. This is ideal for server-to-server automation where the script acts on its own behalf and needs to run unattended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client Credentials grant

    Why this is correct

    Client Credentials is designed for machine-to-machine authentication where no user context is required. The script can exchange its client ID and client secret directly for an access token, allowing it to run unattended and refresh tokens as needed without any browser-based interaction.

  • ✗

    Resource Owner Password Credentials grant

    Why it's wrong here

    This grant requires the script to store the user's username and password, which is a security risk and not recommended for automation. It also requires a user context and does not support scenarios where the application acts on its own behalf without a user, unlike Client Credentials.

  • ✗

    Authorization Code grant

    Why it's wrong here

    The Authorization Code grant requires a user to authenticate in a browser and authorize the application, which is not feasible for an unattended hourly script. It also requires a redirect URI and user interaction, making it unsuitable for server-to-server automation without a user present.

  • ✗

    Implicit grant

    Why it's wrong here

    The Implicit grant is deprecated and intended for browser-based clients that cannot securely store a client secret. It returns the token directly in the URL fragment, which is insecure for a server-side script and does not support refresh tokens, making it a poor fit for unattended automation.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.