Courseiva
easyMultiple Choice

200-901 Practice Question: A developer is creating an application that uses…

A developer is creating an application that uses the Cisco Webex Teams API to send messages. What authentication method is typically used?

⚠ Common exam trap

Candidates often confuse API Keys with OAuth 2.0 tokens, assuming a simple key is sufficient, but Webex Teams requires the OAuth 2.0 flow for user-specific actions like sending messages, not just a static key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OAuth 2.0

The Cisco Webex Teams API uses OAuth 2.0 as its primary authentication method for applications that need to act on behalf of a user. OAuth 2.0 provides delegated access via access tokens, allowing the application to send messages without exposing user credentials. This is the standard for modern REST APIs that require secure, scoped access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session cookies

    Why it's wrong here

    Session cookies suit browser-based web sessions, not stateless REST API calls; Webex expects an Authorization bearer header. Cookies are tempting because they authenticate interactive web logins, but programmatic Webex access requires OAuth 2.0 tokens, not a session established by form login.

  • ✗

    Basic Auth

    Why it's wrong here

    Webex Teams rejects Basic Auth for API calls; credentials must be exchanged for an OAuth 2.0 access token. Basic Auth is tempting because it is the simplest HTTP authentication and works for many internal APIs, but Webex mandates bearer tokens obtained through its OAuth flow.

  • ✓

    OAuth 2.0

    Why this is correct

    The Webex Teams REST API issues short-lived OAuth 2.0 bearer tokens, obtained via an integration or service app, which the developer sends in the Authorization header with each request. Basic authentication and static API keys are not the standard mechanism.

  • ✗

    API Key

    Why it's wrong here

    Webex Teams issues short-lived OAuth 2.0 bearer tokens via an integration or service app; a static API key is not an accepted credential. API keys are tempting because many REST services use them for server-to-server calls, but Webex requires token exchange with scopes for messaging.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.