DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium
A network engineer is troubleshooting an issue where an application intermittently fails to retrieve device configuration from a Cisco IOS XE device via its RESTCONF API. The engineer observes that sometimes API requests succeed, but other times they return a `401 Unauthorized` error, even though the user credentials provided are correct and have not changed. Which API authentication mechanism is most likely being used and causing this intermittent issue?
- AToken-based Authentication
- BOAuth 2.0 Client Credentials Grant
- CAPI Key Authentication
- DBasic Authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Token-based Authentication
Token-based authentication often involves tokens with a limited lifespan. If the application does not refresh or re-authenticate before the token expires, subsequent requests will fail with a 401 Unauthorized error, even if the initial authentication was successful.
Why the other options are wrong
- B. OAuth 2.0 Client Credentials Grant typically issues an access token that also has an expiration, fitting the intermittent 401 scenario.
- C. API Key Authentication uses static keys that do not expire, so it would consistently fail or succeed, not intermittently fail.
- D. Basic Authentication sends credentials with every request and does not expire, so it wouldn't cause intermittent 401s with valid credentials.
Token Expiration
Tokens issued by an authentication server have a limited lifespan and will become invalid after their expiration time, requiring re-authentication or token refresh.
- Common in OAuth 2.0 and other token-based systems.
- Designed to enhance security by limiting exposure of compromised tokens.
- Requires client applications to manage token refresh or re-authentication.
Memory trick: Keys can expire, causing a sudden halt to access.