mediumMultiple Select
200-901 Practice Question: An application authenticates to Cisco Webex API…
An application authenticates to Cisco Webex API using OAuth2 client credentials grant. Which three pieces of information must the application include in the token request?
⚠ Common exam trap
Cisco often tests the distinction between OAuth2 grant types, and the trap here is that candidates confuse the client credentials grant with the authorization code grant, incorrectly assuming an authorization code or redirect URI is always required for any OAuth2 token request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client ID
The OAuth2 client credentials grant is a machine-to-machine flow in which the application exchanges its own credentials directly for an access token, so it must send its Client ID (B) to identify the registered integration and its Client Secret (D) to authenticate that identity to the Cisco Webex authorization server. It must also include Grant Type (E) set to the literal value "client_credentials" so the token endpoint knows which grant is being requested. An Authorization Code (A) belongs to the authorization code grant, where a user-agent redirect yields a code that is later exchanged, and a Redirect URI (C) is likewise only needed in redirect-based flows such as authorization code; neither is used when the client authenticates on its own behalf.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authorization Code
Why it's wrong here
The client credentials grant exchanges the client ID and secret directly for a token; no authorization code is issued or submitted. Authorization codes belong to the authorization code grant, where a user agent redirects and consents before the code is redeemed.
- ✓
Client ID
Why this is correct
The client credentials grant identifies the calling application, not a user, so the token request must carry the registered application's Client ID alongside the Client Secret and grant_type. Without this identifier the authorisation server cannot determine which application is requesting the token.
- ✗
Redirect URI
Why it's wrong here
Redirect URI belongs to the authorisation code grant, where the browser is sent back after user consent; the client credentials grant has no user agent, so no redirect occurs. It is tempting because redirect URIs are configured on every OAuth2 app registration, but the token request itself requires grant_type, client_id and client_secret.
- ✓
Client Secret
Why this is correct
The Client Secret acts as the application's password, proving its identity to the authorisation server during the client credentials exchange. It is one of the three mandatory parameters, paired with the Client ID and grant_type, that the token endpoint requires.
- ✓
Grant Type
Why this is correct
The grant_type parameter must be set to client_credentials so the authorisation server knows which OAuth 2.0 flow to execute. Omitting it, or supplying a different value, causes the token request to fail because the server cannot select the correct grant handling.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.