hardMultiple Choice
200-901 Practice Question: A security team is developing an application that…
A security team is developing an application that collects network alerts from Cisco Firepower Management Center (FMC) API. The API requires OAuth2 authorization code grant flow. After obtaining an authorization code, what must the application do to get an access token?
⚠ Common exam trap
Cisco often tests the misconception that the authorization code itself can be used as a bearer token or decoded to reveal the access token, when in fact it must be exchanged at the token endpoint with client credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exchange the authorization code for an access token by calling the token endpoint with the code and client credentials.
In the OAuth2 authorization code grant flow, the authorization code is an intermediate credential that must be exchanged for an access token. The application must call the token endpoint, presenting the authorization code along with its client credentials (client ID and client secret) to receive the access token. This exchange is required by RFC 6749 and is a fundamental security measure to ensure the client is authorized to obtain the token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resend the authorization request with the code included in the redirect URI.
Why it's wrong here
Repeating the authorization request with the code in the redirect URI does not yield a token; the code must be POSTed to the token endpoint with the client ID, secret and redirect URI for validation. It is tempting because the redirect URI is where the code arrived, but that endpoint only issues codes, never tokens.
- ✗
Decode the authorization code using base64 to extract the access token.
Why it's wrong here
The authorization code is an opaque, server-issued reference, not a base64-encoded container holding an access token; decoding yields meaningless bytes. It must be exchanged at the token endpoint. It is tempting because JSON Web Tokens are base64url-encoded and decodable, but OAuth2 authorization codes are not JWTs and carry no embedded claims.
- ✗
Use the authorization code directly in subsequent API requests as a bearer token.
Why it's wrong here
The authorization code is a short-lived, single-use credential that must be exchanged at the token endpoint, authenticated with the client credentials, for an access token. Sending it as a bearer token fails because FMC rejects it as an invalid token. It is tempting because the code looks like a credential, but it is only an intermediate artefact.
- ✓
Exchange the authorization code for an access token by calling the token endpoint with the code and client credentials.
Why this is correct
In the OAuth2 authorization code grant, the code is only an intermediate credential; the client must POST it to the token endpoint along with its client credentials so the authorisation server can validate it and return the access token.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.