200-901 Understanding and Using APIs Practice Question
A developer is building a Python script that calls the Cisco Webex REST API. The API requires an OAuth 2.0 access token that expires after 14 days. The script will run unattended on a server every hour. Which OAuth 2.0 grant type should the developer use to obtain tokens without user interaction?
⚠ Common exam trap
The trap here is assuming that any OAuth 2.0 flow can be used for automation, when actually only Client Credentials is designed for machine-to-machine scenarios without user interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client Credentials grant
The Client Credentials grant is the correct choice because it allows the application to authenticate itself directly with the authorization server using its client ID and secret, without any user involvement. This is ideal for server-to-server automation where the script acts on its own behalf and needs to run unattended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Client Credentials grant
Why this is correct
Client Credentials is designed for machine-to-machine authentication where no user context is required. The script can exchange its client ID and client secret directly for an access token, allowing it to run unattended and refresh tokens as needed without any browser-based interaction.
- ✗
Resource Owner Password Credentials grant
Why it's wrong here
This grant requires the script to store the user's username and password, which is a security risk and not recommended for automation. It also requires a user context and does not support scenarios where the application acts on its own behalf without a user, unlike Client Credentials.
- ✗
Authorization Code grant
Why it's wrong here
The Authorization Code grant requires a user to authenticate in a browser and authorize the application, which is not feasible for an unattended hourly script. It also requires a redirect URI and user interaction, making it unsuitable for server-to-server automation without a user present.
- ✗
Implicit grant
Why it's wrong here
The Implicit grant is deprecated and intended for browser-based clients that cannot securely store a client secret. It returns the token directly in the URL fragment, which is insecure for a server-side script and does not support refresh tokens, making it a poor fit for unattended automation.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.