FC0-U71 Software Development Concepts Practice Question
A developer is creating a cloud-based application that needs to authenticate third-party services before allowing access to its API. The developer decides to use a method where each third-party service receives a unique key that must be included in each API request. This method is known as:
⚠ Common exam trap
FC0-U71 often tests the confusion between API keys (simple per-service credentials sent on every request) and OAuth (delegated token-based authorization), so candidates pick OAuth whenever 'third-party' appears.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
API key authentication
API key authentication issues a unique key to each third-party service, which is then included in every API request (typically in a header or query string) so the server can identify and authorize the caller. This matches the scenario exactly: unique keys per consumer, presented on each request. It is a lightweight, stateless credential mechanism distinct from user-session or delegated-authorization models.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session-based authentication
Why it's wrong here
Session-based authentication issues a server-side session token after an interactive login, so third-party services would need browser-based sign-in rather than a static key. It tempts because tokens accompany subsequent requests, but the stem requires each service to hold its own unique key with no login exchange.
- ✓
API key authentication
Why this is correct
API key authentication issues each third-party service a distinct key transmitted with every API request, letting the application validate the caller's identity before granting access. This directly satisfies the stem's requirement for a unique per-service credential included in each request, unlike token-based or certificate schemes.
- ✗
Basic authentication
Why it's wrong here
Basic authentication transmits a base64-encoded username and password pair per request, not a per-service unique key. It tempts because it also sends credentials on every call, but the stem describes API keys issued individually to each third-party service, which is key-based authentication rather than credential replay.
- ✗
OAuth
Why it's wrong here
OAuth issues short-lived access tokens through an authorisation server and consent flow, not a fixed unique key per third-party service. It tempts because it also authenticates external clients to APIs, but the stem describes static keys embedded in every request, which is API key authentication rather than delegated token issuance.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A web developer is creating a weather application that retrieves data from a third-party service. The service requires an identifier to track usage and authenticate requests. The developer includes this identifier in the HTTP header of each request. What is this identifier called?
hard- A.JWT
- B.Session ID
- ✓ C.API key
- D.OAuth token
Why C: An API key is a unique identifier issued by a service provider to authenticate and track a client's usage of its API. It is typically passed in an HTTP header (such as `X-API-Key` or `Authorization`) with each request. This matches the scenario of a weather service requiring an identifier for usage tracking and request authentication.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.