mediumMultiple Select
350-401 Practice Question: Which three statements about REST API…
Which three statements about REST API authentication and security are true? (Choose three.)
⚠ Common exam trap
The trap is thinking API keys are as secure as OAuth tokens, or that base64 encoding provides security, which it does not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Token-based authentication typically uses the HTTP Authorization header to pass the token.
Option A is correct because token-based authentication (e.g., Bearer tokens) conventionally transmits the token in the HTTP Authorization header, such as 'Authorization: Bearer <token>', allowing the server to validate the caller's identity on each request. Option B is correct because HTTPS (HTTP over TLS) encrypts data in transit, protecting credentials, tokens, and payloads from eavesdropping and man-in-the-middle attacks, and is a baseline recommendation for any REST API. Option E is correct because OAuth 2.0 is an authorization framework that issues access tokens with defined scopes, enabling delegated, limited access to REST API resources without sharing user credentials. Option C is incorrect because API keys are simple static identifiers with no built-in scoping, expiration, or delegation, so they do not provide the same security level as OAuth 2.0 tokens. Option D is incorrect because base64 encoding is not encryption; Basic authentication over HTTP exposes credentials in easily decodable form and is only safe when layered over HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Token-based authentication typically uses the HTTP Authorization header to pass the token.
Why this is correct
Token-based authentication conveys credentials as a bearer token inside the HTTP Authorization request header, letting the API validate the caller without server-side session state. This satisfies the stem's requirement for a true REST API security statement.
- ✓
HTTPS is recommended for REST APIs to ensure data encryption in transit.
Why this is correct
HTTPS wraps REST API traffic in TLS, encrypting requests and responses in transit and preventing interception or tampering. This satisfies the stem's requirement for a true statement about REST API security, addressing confidentiality rather than authentication.
- ✗
API keys provide the same level of security as OAuth 2.0 tokens.
Why it's wrong here
API keys and OAuth 2.0 tokens offer distinct security models. API keys are typically static, long-lived credentials used for identifying a calling application or service, providing broad access based on their presence. OAuth 2.0 tokens, however, are dynamically issued, short-lived, and grant granular, scoped access on behalf of a resource owner, often after user consent, with an authorisation server (like Microsoft Entra ID) managing the authentication flow. While API keys are suitable for simple application identification or machine-to-machine communication, they lack the delegated authorisation, scope control, and token expiry mechanisms inherent to OAuth 2.0, which provide a significantly different security posture.
- ✗
Basic authentication over HTTP is secure because the credentials are base64-encoded.
Why it's wrong here
Base64 is reversible encoding, not encryption, so credentials travel in cleartext over HTTP and any interceptor recovers them instantly; TLS is what protects them. It is tempting because Basic authentication itself is a legitimate REST mechanism, and it would be acceptable only when carried over HTTPS, where the transport layer provides confidentiality.
- ✓
OAuth 2.0 is an authorization framework that can be used for REST API access.
Why this is correct
OAuth 2.0 is an authorisation framework, not an authentication protocol; it issues access tokens granting scoped permissions to protected REST resources. This matches the stem's request for true statements about REST API security, distinguishing authorisation from authentication mechanisms.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.