Courseiva
hardMultiple Choice

200-901 Practice Question: An application uses OAuth 2.0 for authorization

An application uses OAuth 2.0 for authorization. The developer receives an access token but needs to know the user's identity. Which OAuth flow should be used to also obtain an ID token that contains user claims?

⚠ Common exam trap

Cisco often tests the misconception that any OAuth 2.0 flow can provide user identity, but only OpenID Connect (specifically the Authorization Code Grant with OIDC) adds the ID token for authentication; candidates may incorrectly choose the Client Credentials Grant, which is purely for machine-to-machine authorization and never includes user claims.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization Code Grant with OpenID Connect

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0 that adds an ID token (a JWT) containing user claims such as name, email, and sub. The Authorization Code Grant with OIDC is the correct flow because it allows the client to request both an access token and an ID token, enabling the application to verify the user's identity while obtaining authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authorization Code Grant without PKCE

    Why it's wrong here

    The Authorization Code Grant without PKCE returns an access token but issues no ID token, so user claims are unavailable; OpenID Connect layered on the code flow provides the ID token. It is tempting because the code grant is the standard confidential-client flow, and it would be correct when only API authorisation, not user identity, is required.

  • ✓

    Authorization Code Grant with OpenID Connect

    Why this is correct

    OpenID Connect layers an ID token onto the Authorization Code Grant, returning a signed JWT containing user claims alongside the access token. The authorisation code exchange occurs on the backend, so the ID token's identity assertions satisfy the requirement to learn who the user is.

  • ✗

    Resource Owner Password Grant

    Why it's wrong here

    The Resource Owner Password Grant returns only access and refresh tokens; it never issues an ID token carrying user claims, so it cannot satisfy the identity requirement. It is tempting because it authenticates a named user directly with credentials, which suits trusted first-party legacy clients migrating to OAuth.

  • ✗

    Client Credentials Grant

    Why it's wrong here

    Client Credentials authenticates the application itself, not a user, so no ID token with user claims is ever issued. It is tempting because it is the standard grant for machine-to-machine daemons and services with no interactive user present.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.