mediumMultiple Select
200-901 Practice Question: An application is secured using OAuth 2.0 for…
An application is secured using OAuth 2.0 for Cisco Webex API access. Which three components are involved in the authorization code grant flow? (Choose three.)
⚠ Common exam trap
Cisco often tests the distinction between the components used in the initial authorization code grant flow versus those used in subsequent token refresh, causing candidates to incorrectly include the Refresh Token as a required component of the initial flow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client Secret
In the OAuth 2.0 authorization code grant flow used for Cisco Webex API access, the Client ID (B) is the public identifier the application presents to the Webex authorization server to identify itself during the authorization request, making it a required component. The Client Secret (A) is the confidential credential the application uses when exchanging the authorization code at the token endpoint, authenticating the client to the Webex authorization server. The Authorization Code (C) is the short-lived credential returned to the redirect URI after the user grants consent, which the client then exchanges for access and refresh tokens, so it is central to this grant type. The Refresh Token (D) is not part of the initial authorization code grant exchange itself—it is an optional token that may be issued alongside the access token for later use to obtain new access tokens. An API Key (E) is a separate static credential mechanism and is not a component of the OAuth 2.0 authorization code grant flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Client Secret
Why this is correct
The client secret authenticates the application itself when redeeming the authorization code at the token endpoint, satisfying the requirement that confidential clients prove their identity during the OAuth 2.0 authorization code grant. Without it, Webex cannot verify the requesting application, so token exchange fails.
- ✓
Client ID
Why this is correct
In the OAuth 2.0 authorization code grant flow, the Client ID is a public identifier issued by the authorisation server (e.g., Cisco Webex Identity) that uniquely identifies the application to the server during the initial authorisation request. The stem specifies "authorization code grant flow," which requires the client to present its Client ID in the redirect URI to obtain the authorisation code, satisfying the constraint that the client must be registered and recognised before exchanging credentials for tokens.
- ✓
Authorization Code
Why this is correct
The authorization code is the short-lived credential returned to the redirect URI after user consent, then exchanged at the token endpoint for access and refresh tokens. It is the central artefact of the authorization code grant flow.
- ✗
Refresh Token
Why it's wrong here
The refresh token is issued alongside the access token to obtain new access tokens without re-prompting, so it is an output of the flow rather than a participating component. It is tempting because refresh tokens are central to OAuth 2.0 token lifecycle management, and they do appear in the authorization code grant's token response.
- ✗
API Key
Why it's wrong here
API keys are a separate credential scheme for identifying projects or callers, and Cisco Webex OAuth 2.0 authorization code grants exchange an authorization code for tokens instead. It is tempting because API keys do authenticate some Webex integrations, but they play no part in the authorization code grant's redirect-and-exchange sequence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.