DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A network engineer is troubleshooting an issue where an application intermittently fails to retrieve device configuration from a Cisco IOS XE device via its RESTCONF API. The engineer observes that sometimes API requests succeed, but other times they return a `401 Unauthorized` error, even though the user credentials provided are correct and have not changed. Which API authentication mechanism is most likely being used and causing this intermittent issue?

  1. AToken-based Authentication
  2. BOAuth 2.0 Client Credentials Grant
  3. CAPI Key Authentication
  4. DBasic Authentication
Show answer & explanation

Correct answer: A. Token-based Authentication

Token-based authentication often involves tokens with a limited lifespan. If the application does not refresh or re-authenticate before the token expires, subsequent requests will fail with a 401 Unauthorized error, even if the initial authentication was successful.

Why the other options are wrong

  • B. OAuth 2.0 Client Credentials Grant typically issues an access token that also has an expiration, fitting the intermittent 401 scenario.
  • C. API Key Authentication uses static keys that do not expire, so it would consistently fail or succeed, not intermittently fail.
  • D. Basic Authentication sends credentials with every request and does not expire, so it wouldn't cause intermittent 401s with valid credentials.

Token Expiration

Tokens issued by an authentication server have a limited lifespan and will become invalid after their expiration time, requiring re-authentication or token refresh.

  • Common in OAuth 2.0 and other token-based systems.
  • Designed to enhance security by limiting exposure of compromised tokens.
  • Requires client applications to manage token refresh or re-authentication.

Memory trick: Keys can expire, causing a sudden halt to access.

More Understanding and Using APIs questions