200-901 Application Deployment and Security Practice Question
A developer is writing a Python script that calls a REST API protected by OAuth 2.0. The script runs unattended on a server and must obtain an access token without any user interaction. The authorization server supports the client credentials grant. Which flow should the developer implement?
⚠ Common exam trap
The trap here is reaching for authorization code with PKCE simply because it is modern, when the absence of a user makes client credentials the only fitting grant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client credentials grant
When an application authenticates as itself rather than on behalf of a user, the client credentials grant is the correct OAuth 2.0 flow. The server script presents its client ID and secret to the token endpoint and receives an access token, with no browser redirect or user consent step. Flows requiring a user, such as authorization code with PKCE or implicit, and flows requiring user passwords do not match unattended machine-to-machine access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implicit grant
Why it's wrong here
The implicit grant returns an access token directly from the authorization endpoint and was designed for browser-based clients. It still requires a user to authenticate and authorize the request, and it has been deprecated in OAuth 2.1 due to token leakage risks. It cannot run unattended on a server and is not the appropriate choice for machine-to-machine access.
- ✗
Authorization code grant with PKCE
Why it's wrong here
The authorization code grant with PKCE is designed for public clients such as single-page apps and native applications where a user authenticates through a browser. It requires user interaction to obtain the authorization code, which an unattended server script cannot provide. While PKCE protects against code interception, it does not eliminate the need for a user in the loop, so it does not fit this scenario.
- ✓
Client credentials grant
Why this is correct
The client credentials grant is intended for machine-to-machine communication where the client authenticates with its own client ID and secret, with no end user involved. The server script can POST its credentials to the token endpoint and receive an access token directly. This matches the unattended execution requirement and the authorization server's supported grant exactly.
- ✗
Resource owner password credentials grant
Why it's wrong here
This grant requires the script to collect and transmit the resource owner's username and password, which is insecure for an unattended service and exposes user credentials to the application. It also assumes a resource owner exists whose credentials can be used. The scenario describes a server acting on its own behalf, so client credentials is the correct fit, not password credentials.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.