DevNet Associate (DEVASC) v1.0Understanding and Using APIsEasy
A network security engineer is designing a system to integrate a new application with a Cisco API. The application needs to securely obtain an access token without exposing client credentials in the user agent, and it will be primarily used for server-to-server communication. Which OAuth 2.0 grant type is most appropriate for this scenario?
- AAuthorization Code Grant
- BImplicit Grant
- CClient Credentials Grant
- DResource Owner Password Credentials Grant
Show answer & explanationAnswer & explanation
Correct answer: C. Client Credentials Grant
The Client Credentials Grant is designed for machine-to-machine authentication where a client application acts on its own behalf, not on behalf of a user. This fits the server-to-server communication requirement and securely handles credentials.
Why the other options are wrong
- A. The Authorization Code Grant is for web applications and requires user interaction to obtain consent.
- B. The Implicit Grant is considered less secure and is typically used for single-page applications where tokens are directly returned to the user agent.
- D. The Resource Owner Password Credentials Grant is discouraged due to security concerns as it requires the client to handle the user's credentials directly.
OAuth 2.0 Client Credentials Grant
An OAuth 2.0 grant type used when a client application needs to access protected resources on its own behalf, without a user's direct involvement. It's suitable for machine-to-machine authentication.
- Used for server-to-server communication.
- Client authenticates directly with the authorization server using its own credentials.
- No user interaction required.
- Returns an access token directly to the client.
Memory trick: Always Consider If Really Obvious, or Client Credentials Grant.