DevNet Associate (DEVASC) v1.0Understanding and Using APIsEasy
A developer is integrating a new application with an existing Cisco network device API. The API documentation specifies that all requests must include an 'Authorization' header with a 'Bearer' token. Which authentication method is being described?
- AOAuth 2.0
- BBasic Authentication
- CAPI Key Authentication
- DToken-based Authentication
Show answer & explanationAnswer & explanation
Correct answer: D. Token-based Authentication
The presence of a 'Bearer' token in the 'Authorization' header explicitly indicates token-based authentication, where a unique token is used to verify the sender's identity.
Why the other options are wrong
- A. OAuth 2.0 is an authorization framework that often uses tokens, but the direct method described is token-based authentication, not the full OAuth flow.
- B. Basic authentication typically uses 'Basic' followed by a base64-encoded username:password.
- C. API key authentication usually involves sending a static key as a query parameter or custom header, not a 'Bearer' token.
Token-based Authentication
A method where a client sends an access token (e.g., JWT) in an HTTP header to authenticate and authorize requests to an API.
- Uses a 'Bearer' token in the Authorization header.
- Tokens are often short-lived and obtained after initial login.
- Provides a stateless authentication mechanism.
Memory trick: Many APIs Guard Access, But Only Tokens Really Secure.