Courseiva

200-901 Understanding and Using APIs Practice Question

Which OAuth 2.0 grant type is most appropriate for a server-to-server integration where no user interaction is required, such as a backend service calling Cisco API?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client credentials grant

Client credentials grant is designed for server-to-server scenarios without user consent. Authorization code requires user interaction. Device code is for devices with limited UI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authorization code grant

    Why it's wrong here

    The authorization code grant requires a browser redirect and a user authenticating at the authorization server to obtain the code, which no backend service can supply. It is tempting because it is the recommended flow for web applications acting on behalf of a signed-in user.

  • ✗

    Password grant

    Why it's wrong here

    The password grant requires the resource owner's username and password to be sent to the token endpoint, and it presumes a user whose credentials exist; a backend service has no such user. It is tempting for legacy first-party clients that collect credentials directly, such as a vendor's own mobile app.

  • ✗

    Device code grant

    Why it's wrong here

    The device code grant requires a human to visit a verification URI and enter a code on a second device, so it still depends on user interaction. It is tempting because it suits input-constrained devices such as smart TVs or CLI tools where a browser cannot be launched locally.

  • ✓

    Client credentials grant

    Why this is correct

    The client credentials grant exchanges the application's own client ID and secret directly for an access token, with no resource owner or browser redirect involved. This matches server-to-server backend calls where no user context exists, unlike authorisation code or implicit grants.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.