PK0-005 Practice Question: Basics of IT Infrastructure and IT Project Management
A project manager is leading the deployment of a new customer-facing mobile application that will use a RESTful API. The API will be hosted on a public cloud and must handle sensitive user data. The project sponsor is concerned about security and wants to ensure that the API uses a standard protocol for authorization and that tokens are not easily compromised. Which approach should the project manager recommend?
⚠ Common exam trap
The trap here is assuming that any token-based scheme, such as API keys or SAML, is equivalent to OAuth 2.0 for API authorization, when OAuth 2.0 is the standard specifically designed for delegated authorization with scoped access tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OAuth 2.0 with bearer tokens over HTTPS
The sponsor requires a standard authorization protocol with protected tokens for a RESTful API. OAuth 2.0 with bearer tokens over HTTPS provides scoped, revocable access tokens that are encrypted in transit. Basic authentication, API keys in client code, and SAML over HTTP are either insecure or not designed for API authorization, so they fail to meet the security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
API keys embedded in client-side code
Why it's wrong here
API keys embedded in client-side code can be extracted by anyone who inspects the application. They provide no user-level authorization and cannot be easily revoked without breaking the app. This is not a standard authorization protocol and does not protect sensitive user data, making it unsuitable for the mobile application.
- ✗
Basic authentication over HTTP
Why it's wrong here
Basic authentication sends credentials in base64-encoded plaintext with each request. Over HTTP, this is easily intercepted. Even over HTTPS, it lacks token-based authorization and does not support scopes or expiration. This approach is insecure and does not meet the sponsor's requirement for a standard authorization protocol with protected tokens.
- ✗
SAML assertions sent over HTTP
Why it's wrong here
SAML is primarily used for web browser single sign-on, not for securing RESTful APIs in mobile applications. Sending SAML over HTTP exposes assertions to interception. While SAML can be used with OAuth in some flows, it is not the standard protocol for API authorization and does not meet the requirement for secure token handling.
- ✓
OAuth 2.0 with bearer tokens over HTTPS
Why this is correct
OAuth 2.0 is a standard authorization framework that uses access tokens to grant limited access to resources. When used over HTTPS, bearer tokens are protected in transit. This approach allows scopes, expiration, and revocation, directly addressing the sponsor's security concerns. It is the recommended standard for securing RESTful APIs in a public cloud.
Go deeper
Related to this question
About these practice questions
One of 954 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.