A project manager is leading the deployment of a new customer-facing mobile application that will use a RESTful API. The API will be hosted on a public cloud and must handle sensitive user data. The project sponsor is concerned about security and wants to ensure that the API uses a standard protocol for authorization and that tokens are not easily compromised. Which approach should the project manager recommend?
OAuth 2.0 is a standard authorization framework that uses access tokens to grant limited access to resources. When used over HTTPS, bearer tokens are protected in transit. This approach allows scopes, expiration, and revocation, directly addressing the sponsor's security concerns. It is the recommended standard for securing RESTful APIs in a public cloud.
Why this answer
The sponsor requires a standard authorization protocol with protected tokens for a RESTful API. OAuth 2.0 with bearer tokens over HTTPS provides scoped, revocable access tokens that are encrypted in transit. Basic authentication, API keys in client code, and SAML over HTTP are either insecure or not designed for API authorization, so they fail to meet the security requirements.
Exam trap
The trap here is assuming that any token-based scheme, such as API keys or SAML, is equivalent to OAuth 2.0 for API authorization, when OAuth 2.0 is the standard specifically designed for delegated authorization with scoped access tokens.