200-901 Understanding and Using APIs Practice Question
A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?
⚠ Common exam trap
The trap here is choosing client credentials because it needs no user interaction, overlooking that it cannot represent delegated per-organization user consent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization code grant
Delegated access across many organizations requires each user to authenticate and consent at Cisco Webex, which the authorization code grant accomplishes. Exchanging the returned code yields both an access token and a refresh token, so the integration can renew access silently afterward. The other grants either lack refresh capability, require unsafe password handling, or represent the app rather than the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implicit grant
Why it's wrong here
The implicit grant returns an access token directly from the authorization endpoint and historically served browser-based apps. It does not issue a refresh token, so the integration could not renew access without prompting users again. That conflicts with the requirement for unattended refresh across many organizations, making it unsuitable here.
- ✓
Authorization code grant
Why this is correct
The authorization code grant redirects each user to Cisco Webex to authenticate and consent, then returns a short-lived code the app exchanges for an access token and a refresh token. The refresh token enables long-term access without further user interaction, and each organization consents separately, matching the stated requirements.
- ✗
Resource owner password credentials grant
Why it's wrong here
This grant requires the integration to collect each user's username and password directly, which is unsafe and defeats delegated authorization. It also cannot represent per-organization consent, and multi-factor authentication breaks it. Cisco Webex expects proper delegated flows, so this approach is both insecure and impractical.
- ✗
Client credentials grant
Why it's wrong here
Client credentials authenticate the application itself, not an end user, so the resulting token carries no user context or per-organization consent. It cannot act on behalf of members of many customer organizations. This grant suits service-owned resources, not delegated multi-tenant user access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.