Courseiva
mediumMultiple Select

200-901 Practice Question: An application authenticates to Cisco Webex API…

An application authenticates to Cisco Webex API using OAuth2 client credentials grant. Which three pieces of information must the application include in the token request?

⚠ Common exam trap

Cisco often tests the distinction between OAuth2 grant types, and the trap here is that candidates confuse the client credentials grant with the authorization code grant, incorrectly assuming an authorization code or redirect URI is always required for any OAuth2 token request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client ID

The OAuth2 client credentials grant is a machine-to-machine flow in which the application exchanges its own credentials directly for an access token, so it must send its Client ID (B) to identify the registered integration and its Client Secret (D) to authenticate that identity to the Cisco Webex authorization server. It must also include Grant Type (E) set to the literal value "client_credentials" so the token endpoint knows which grant is being requested. An Authorization Code (A) belongs to the authorization code grant, where a user-agent redirect yields a code that is later exchanged, and a Redirect URI (C) is likewise only needed in redirect-based flows such as authorization code; neither is used when the client authenticates on its own behalf.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authorization Code

    Why it's wrong here

    The client credentials grant exchanges the client ID and secret directly for a token; no authorization code is issued or submitted. Authorization codes belong to the authorization code grant, where a user agent redirects and consents before the code is redeemed.

  • ✓

    Client ID

    Why this is correct

    The client credentials grant identifies the calling application, not a user, so the token request must carry the registered application's Client ID alongside the Client Secret and grant_type. Without this identifier the authorisation server cannot determine which application is requesting the token.

  • ✗

    Redirect URI

    Why it's wrong here

    Redirect URI belongs to the authorisation code grant, where the browser is sent back after user consent; the client credentials grant has no user agent, so no redirect occurs. It is tempting because redirect URIs are configured on every OAuth2 app registration, but the token request itself requires grant_type, client_id and client_secret.

  • ✓

    Client Secret

    Why this is correct

    The Client Secret acts as the application's password, proving its identity to the authorisation server during the client credentials exchange. It is one of the three mandatory parameters, paired with the Client ID and grant_type, that the token endpoint requires.

  • ✓

    Grant Type

    Why this is correct

    The grant_type parameter must be set to client_credentials so the authorisation server knows which OAuth 2.0 flow to execute. Omitting it, or supplying a different value, causes the token request to fail because the server cannot select the correct grant handling.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.