Courseiva
mediumMultiple Select

200-901 Practice Question: An application is secured using OAuth 2.0 for…

An application is secured using OAuth 2.0 for Cisco Webex API access. Which three components are involved in the authorization code grant flow? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between the components used in the initial authorization code grant flow versus those used in subsequent token refresh, causing candidates to incorrectly include the Refresh Token as a required component of the initial flow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client Secret

In the OAuth 2.0 authorization code grant flow used for Cisco Webex API access, the Client ID (B) is the public identifier the application presents to the Webex authorization server to identify itself during the authorization request, making it a required component. The Client Secret (A) is the confidential credential the application uses when exchanging the authorization code at the token endpoint, authenticating the client to the Webex authorization server. The Authorization Code (C) is the short-lived credential returned to the redirect URI after the user grants consent, which the client then exchanges for access and refresh tokens, so it is central to this grant type. The Refresh Token (D) is not part of the initial authorization code grant exchange itself—it is an optional token that may be issued alongside the access token for later use to obtain new access tokens. An API Key (E) is a separate static credential mechanism and is not a component of the OAuth 2.0 authorization code grant flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Client Secret

    Why this is correct

    The client secret authenticates the application itself when redeeming the authorization code at the token endpoint, satisfying the requirement that confidential clients prove their identity during the OAuth 2.0 authorization code grant. Without it, Webex cannot verify the requesting application, so token exchange fails.

  • ✓

    Client ID

    Why this is correct

    In the OAuth 2.0 authorization code grant flow, the Client ID is a public identifier issued by the authorisation server (e.g., Cisco Webex Identity) that uniquely identifies the application to the server during the initial authorisation request. The stem specifies "authorization code grant flow," which requires the client to present its Client ID in the redirect URI to obtain the authorisation code, satisfying the constraint that the client must be registered and recognised before exchanging credentials for tokens.

  • ✓

    Authorization Code

    Why this is correct

    The authorization code is the short-lived credential returned to the redirect URI after user consent, then exchanged at the token endpoint for access and refresh tokens. It is the central artefact of the authorization code grant flow.

  • ✗

    Refresh Token

    Why it's wrong here

    The refresh token is issued alongside the access token to obtain new access tokens without re-prompting, so it is an output of the flow rather than a participating component. It is tempting because refresh tokens are central to OAuth 2.0 token lifecycle management, and they do appear in the authorization code grant's token response.

  • ✗

    API Key

    Why it's wrong here

    API keys are a separate credential scheme for identifying projects or callers, and Cisco Webex OAuth 2.0 authorization code grants exchange an authorization code for tokens instead. It is tempting because API keys do authenticate some Webex integrations, but they play no part in the authorization code grant's redirect-and-exchange sequence.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.