Courseiva

200-901 Understanding and Using APIs Practice Question

A developer is integrating a Python application with the Cisco Webex API. The application must act on behalf of users to create messages in Webex spaces. The developer wants to avoid storing user credentials. Which OAuth 2.0 flow is most appropriate for this scenario?

⚠ Common exam trap

The trap here is assuming that the Client Credentials Grant can be used for user-context operations, when it is only for machine-to-machine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization Code Grant

The Authorization Code Grant is the most secure and appropriate OAuth 2.0 flow for applications that need to act on behalf of users without handling their credentials. It involves redirecting the user to Webex for authentication, receiving an authorization code, and exchanging it for an access token. This flow supports refresh tokens and fine-grained scopes, making it ideal for integrations that create messages on behalf of users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implicit Grant

    Why it's wrong here

    The Implicit Grant was designed for public clients like single-page applications, but it is now deprecated in OAuth 2.1 due to security weaknesses. It returns the access token directly in the URL fragment, which is less secure. Webex recommends against using it. For acting on behalf of users, the Authorization Code Grant with PKCE is preferred. Thus, Implicit is not the most appropriate choice.

  • ✓

    Authorization Code Grant

    Why this is correct

    The Authorization Code Grant is ideal for applications that need to act on behalf of users without storing their credentials. The user authenticates directly with Webex, and the application receives an authorization code, which it exchanges for an access token. This flow is secure because the application never sees the user's password, and tokens can be scoped and revoked. It is the recommended flow for web and mobile apps requiring user context.

  • ✗

    Resource Owner Password Credentials Grant

    Why it's wrong here

    The Resource Owner Password Credentials Grant requires the application to collect the user's username and password directly, which violates the requirement to avoid storing user credentials. It is only suitable for trusted first-party applications. Webex does not recommend this flow. Since the developer wants to avoid handling credentials, this grant type is not appropriate and poses security risks.

  • ✗

    Client Credentials Grant

    Why it's wrong here

    The Client Credentials Grant is used for machine-to-machine authentication where the application acts on its own behalf, not on behalf of a user. It does not involve user interaction and cannot access user-specific resources like creating messages in a user's spaces. Since the scenario requires acting on behalf of users, this flow is inappropriate and would not provide the necessary user context.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.