200-901 Understanding and Using APIs Practice Question
An application uses OAuth 2.0 client credentials grant to authenticate with a Cisco API. Which of the following best describes this flow?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application sends its client ID and secret to obtain a token directly.
Client credentials grant is used for server-to-server authentication without user involvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application uses a username and password in the request body.
Why it's wrong here
Embedding a username and password in the request body describes resource owner password credentials, or legacy basic authentication, not client credentials. Client credentials authenticate the application itself using its client ID and secret, with no user password involved. It is tempting because credentials are sent, but the grant is userless machine-to-machine authorisation.
- ✓
The application sends its client ID and secret to obtain a token directly.
Why this is correct
The client credentials grant exchanges the application's own client ID and secret directly at the token endpoint, with no user interaction or browser redirect. This matches the stem's machine-to-machine scenario, where the application authenticates as itself rather than on behalf of a resource owner.
- ✗
The user provides their credentials via a consent screen.
Why it's wrong here
The consent screen belongs to the authorization code grant, where a resource owner approves delegated access. Client credentials involve no user at all, so no consent interaction occurs. It is tempting because consent is the familiar OAuth experience, but machine-to-machine API calls authenticate the application itself directly with its client ID and secret.
- ✗
A device code is displayed for the user to enter on a separate device.
Why it's wrong here
The client credentials grant involves no user, so no device code is issued; the application authenticates directly with its own credentials to obtain a token. Device code flow suits input-constrained devices where a user must authorise on a separate browser-equipped device.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.