DevNet Associate (DEVASC) v1.0Understanding and Using APIsEasy

A developer is integrating a new application with an existing Cisco network device API. The API documentation specifies that all requests must include an 'Authorization' header with a 'Bearer' token. Which authentication method is being described?

  1. AOAuth 2.0
  2. BBasic Authentication
  3. CAPI Key Authentication
  4. DToken-based Authentication
Show answer & explanation

Correct answer: D. Token-based Authentication

The presence of a 'Bearer' token in the 'Authorization' header explicitly indicates token-based authentication, where a unique token is used to verify the sender's identity.

Why the other options are wrong

  • A. OAuth 2.0 is an authorization framework that often uses tokens, but the direct method described is token-based authentication, not the full OAuth flow.
  • B. Basic authentication typically uses 'Basic' followed by a base64-encoded username:password.
  • C. API key authentication usually involves sending a static key as a query parameter or custom header, not a 'Bearer' token.

Token-based Authentication

A method where a client sends an access token (e.g., JWT) in an HTTP header to authenticate and authorize requests to an API.

  • Uses a 'Bearer' token in the Authorization header.
  • Tokens are often short-lived and obtained after initial login.
  • Provides a stateless authentication mechanism.

Memory trick: Many APIs Guard Access, But Only Tokens Really Secure.

More Understanding and Using APIs questions