Courseiva

200-901 Understanding and Using APIs Practice Question

A developer's integration must call a Cisco Webex API on behalf of users across many customer organizations. Each organization administers its own users and consents independently, and the integration must refresh access without user interaction after initial consent. Which OAuth 2.0 grant type should the integration use?

⚠ Common exam trap

The trap here is choosing client credentials because it needs no user interaction, overlooking that it cannot represent delegated per-organization user consent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization code grant

Delegated access across many organizations requires each user to authenticate and consent at Cisco Webex, which the authorization code grant accomplishes. Exchanging the returned code yields both an access token and a refresh token, so the integration can renew access silently afterward. The other grants either lack refresh capability, require unsafe password handling, or represent the app rather than the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implicit grant

    Why it's wrong here

    The implicit grant returns an access token directly from the authorization endpoint and historically served browser-based apps. It does not issue a refresh token, so the integration could not renew access without prompting users again. That conflicts with the requirement for unattended refresh across many organizations, making it unsuitable here.

  • ✓

    Authorization code grant

    Why this is correct

    The authorization code grant redirects each user to Cisco Webex to authenticate and consent, then returns a short-lived code the app exchanges for an access token and a refresh token. The refresh token enables long-term access without further user interaction, and each organization consents separately, matching the stated requirements.

  • ✗

    Resource owner password credentials grant

    Why it's wrong here

    This grant requires the integration to collect each user's username and password directly, which is unsafe and defeats delegated authorization. It also cannot represent per-organization consent, and multi-factor authentication breaks it. Cisco Webex expects proper delegated flows, so this approach is both insecure and impractical.

  • ✗

    Client credentials grant

    Why it's wrong here

    Client credentials authenticate the application itself, not an end user, so the resulting token carries no user context or per-organization consent. It cannot act on behalf of members of many customer organizations. This grant suits service-owned resources, not delegated multi-tenant user access.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.