200-901 Understanding and Using APIs Practice Question
A developer is integrating with the Cisco Webex API and wants to authenticate on behalf of users without ever handling their passwords. The integration is a web application hosted on a public server, and the developer needs a refresh token so the app can keep working after the user's access token expires. Which OAuth 2.0 grant type should be used?
⚠ Common exam trap
The trap here is choosing authorization code with PKCE because it sounds more secure, when the scenario specifies a confidential server-side web app for which the standard authorization code grant is appropriate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization code grant
For a confidential web application that must act on behalf of users and continue operating after access tokens expire, the OAuth 2.0 authorization code grant is the correct choice. The user's credentials are entered only at the Cisco Webex authorization endpoint, and the app receives an authorization code that it exchanges server-side, along with its client secret, for both an access token and a refresh token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implicit grant
Why it's wrong here
The implicit grant returns an access token directly from the authorization endpoint without a token exchange, and it never issues a refresh token. It was intended for browser-based clients but has been deprecated in OAuth 2.1 due to token leakage risks, so it cannot satisfy the requirement for long-lived access via refresh tokens.
- ✗
Client credentials grant
Why it's wrong here
The client credentials grant is designed for machine-to-machine communication where no user context exists, so it issues tokens tied to the application itself rather than to a user. It does not return a refresh token and cannot represent a user's identity, making it unsuitable for an integration that acts on behalf of individual Webex users.
- ✗
Authorization code grant with PKCE
Why it's wrong here
Authorization code with PKCE is the recommended flow for public clients such as mobile and single-page apps, but this scenario describes a confidential web application on a server. PKCE adds protection that is unnecessary here and, while it can still issue refresh tokens, it is not the flow Cisco documents for confidential server-side Webex integrations.
- ✓
Authorization code grant
Why this is correct
The authorization code grant is the standard flow for confidential web applications. The user authenticates at the Cisco Webex authorization server, the app receives a short-lived code, and it exchanges that code plus its client secret for an access token and a refresh token, allowing the app to obtain new access tokens without user interaction.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.