FC0-U71 Software Development Concepts Practice Question
A web developer is creating a weather application that retrieves data from a third-party service. The service requires an identifier to track usage and authenticate requests. The developer includes this identifier in the HTTP header of each request. What is this identifier called?
⚠ Common exam trap
The trap is conflating API keys with OAuth tokens or JWTs because all are used for API access; candidates must recognize that the scenario describes a simple static identifier for usage tracking, which is the hallmark of an API key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
API key
An API key is a unique identifier issued by a service provider to authenticate and track a client's usage of its API. It is typically passed in an HTTP header (such as `X-API-Key` or `Authorization`) with each request. This matches the scenario of a weather service requiring an identifier for usage tracking and request authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
JWT
Why it's wrong here
A JWT is a self-contained token carrying signed claims about an identity, typically used for user authentication and authorisation, not as a static service identifier sent on every request. It is tempting because JWTs do travel in HTTP headers, but they encode session or identity claims rather than tracking third-party API usage.
- ✗
Session ID
Why it's wrong here
A session ID identifies a specific user's server-side session after login, so it is meaningless to a third-party weather service that has no session with the developer's application. It is tempting because session IDs are sent in HTTP headers, but they track user state, not application-level API usage.
- ✓
API key
Why this is correct
An API key is a unique identifier issued by the third-party service, embedded in the HTTP header to authenticate each request and track usage per consumer. It satisfies the stem's requirement for an identifier that both authenticates requests and monitors consumption, unlike OAuth tokens, which delegate scoped access rather than simply identifying the calling application.
- ✗
OAuth token
Why it's wrong here
An OAuth token is issued after an authorisation grant to access protected resources on a user's behalf; it is not the fixed application identifier a service uses to track and authenticate API calls. It is tempting because OAuth tokens also appear in HTTP headers, but they represent delegated access, not the app's own credential.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.