Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most appropriate?

⚠ Common exam trap

ISC2 often tests the distinction between authentication mechanisms by presenting SAML 2.0 as a plausible answer for API security, but the trap here is that SAML is designed for browser-based user authentication and federation, not for direct API access from third-party applications, leading candidates to confuse identity federation with API authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OAuth 2.0 with client credentials

OAuth 2.0 with the client credentials grant is the most appropriate mechanism for machine-to-machine API access because it allows the API to authenticate the third-party application itself (the client) using a client ID and client secret, without involving end-user credentials. This grant type is specifically designed for server-to-server integrations where the client is acting on its own behalf, providing a secure, token-based approach that avoids sharing long-lived secrets directly with each API call.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Basic authentication with API keys

    Why it's wrong here

    Static API keys sent with Basic authentication are long-lived shared secrets; anyone who intercepts or extracts them from partner code gains full access, and revocation is manual. API keys suit identifying low-risk public clients or rate-limiting, not authenticating authorised partners with per-partner accountability.

  • ✓

    OAuth 2.0 with client credentials

    Why this is correct

    OAuth 2.0 client credentials issues tokens to confidential clients authenticating with their own credentials, without user involvement. This suits machine-to-machine partner integrations, satisfying the requirement that only authorised partners access the API and enabling scoped, revocable access.

  • ✗

    SAML 2.0

    Why it's wrong here

    SAML 2.0 is a browser-based federated SSO protocol exchanging XML assertions between identity and service providers; it does not authenticate machine-to-machine API calls. SAML would be correct for federating employee logins to a web application, not for partner API access.

  • ✗

    X.509 certificates

    Why it's wrong here

    X.509 certificates authenticate the client machine or application identity, not the partner organisation’s authorisation to access the API; the scenario requires verifying the partner’s permission level, not merely proving possession of a certificate. This option tempts because certificates are commonly used for mutual TLS in server-to-server API security, where they would be correct if the requirement were device-level authentication rather than partner-level authorisation.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.