200-901 Understanding and Using APIs Practice Question
Which authentication flow is most appropriate for a native mobile app that needs to access the Webex API on behalf of a user?
⚠ Common exam trap
A common mix-up: candidates confuse the client credentials grant (for server-to-server) with user-delegated flows, or assuming the implicit grant is still acceptable for mobile apps despite its deprecation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization code grant
The authorization code grant is the correct flow because it is designed for confidential and public clients (like native mobile apps) that need to act on behalf of a user. It redirects the user to an authorization server, returns a short-lived code, and exchanges it for tokens via a secure back channel, keeping credentials out of the app. This flow supports refresh tokens and is the OAuth 2.0 recommended approach for user-delegated access to APIs like Webex.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Client credentials grant
Why it's wrong here
Client credentials authenticates the application itself, not a user, so no delegated user context reaches the Webex API. It suits daemon or service-to-service calls with no interactive user, which is the opposite of acting on a user's behalf.
- ✗
Resource owner password grant
Why it's wrong here
The resource owner password grant requires the app to collect the user's Webex credentials directly, breaking delegated-authorisation security and precluding MFA or SSO. It only fits legacy trusted first-party clients where redirect-based flows are impossible.
- ✓
Authorization code grant
Why this is correct
The authorization code grant returns a short-lived access token after the user authenticates in the browser, so the native app never handles the user's credentials directly. This satisfies the requirement to act on behalf of a user against the Webex API, unlike client credentials, which represents the app itself.
- ✗
Implicit grant
Why it's wrong here
The implicit grant returns tokens directly in the URL fragment, exposing them to interception and offering no refresh token, so it cannot securely sustain on-behalf-of API calls from a native app. It exists for browser-based JavaScript clients where no backend can hold a secret.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.