Which TWO of the following are valid OAuth 2.0 grant types? (Select TWO)
Trap 1: API key
API key is a separate authentication method, not OAuth 2.0.
Trap 2: Basic authentication
Basic is an HTTP authentication scheme, not an OAuth 2.0 grant.
Trap 3: Implicit grant
Implicit is deprecated in OAuth 2.0 Security BCP.
- A
Client credentials
Client credentials is a defined OAuth 2.0 grant type for machine-to-machine authorisation, where the client authenticates directly and no resource owner is involved. It exchanges the client's own credentials for an access token, satisfying the question's requirement for valid grant types.
- B
Authorization code
Authorization code is a core OAuth 2.0 grant type, exchanging a short-lived code for tokens via a back channel, which keeps credentials out of the browser. It satisfies the stem's requirement for valid grant types, alongside client credentials, implicit and resource owner password credentials.
- C
API key
Why it fails: API key is a separate authentication method, not OAuth 2.0.
- D
Basic authentication
Why it fails: Basic is an HTTP authentication scheme, not an OAuth 2.0 grant.
- E
Implicit grant
Why it fails: Implicit is deprecated in OAuth 2.0 Security BCP.