DevNet Associate (DEVASC) v1.0Understanding and Using APIsHard

A developer is integrating an application with a Cisco API that uses Basic Authentication. The application needs to send a username and password with each API request. To ensure these credentials are transmitted securely, which underlying HTTP mechanism is crucial for protecting Basic Authentication credentials?

  1. ABase64 encoding of the credentials.
  2. BHTTP/2 protocol for faster encryption.
  3. CDigest Authentication for challenge-response.
  4. DTLS/SSL encryption of the entire communication channel.
Show answer & explanation

Correct answer: D. TLS/SSL encryption of the entire communication channel.

Basic Authentication sends credentials as a Base64-encoded string, which is not encryption and can be easily decoded. Therefore, it is absolutely crucial that Basic Authentication is always used over a secure channel, specifically one encrypted with TLS/SSL (HTTPS). TLS/SSL encrypts the entire HTTP communication, protecting the Base64-encoded credentials from interception.

Why the other options are wrong

  • A. Base64 encoding is merely obfuscation, not encryption. It can be easily reversed to reveal the plaintext credentials.
  • B. HTTP/2 is a protocol version focused on performance; while it can use TLS, it's not the primary mechanism for credential security.
  • C. Digest Authentication is a different, more secure authentication scheme than Basic Authentication, but it's not the mechanism that secures Basic Authentication itself.

Basic Authentication Security

Basic Authentication, which sends Base64-encoded credentials, is only secure when protected by an encrypted communication channel like TLS/SSL (HTTPS).

  • Credentials sent as `username:password` Base64-encoded string.
  • Base64 encoding is not encryption; it's easily reversible.
  • Requires HTTPS to prevent credentials from being intercepted in plaintext.
  • Simple to implement but inherently less secure than token-based methods if not over HTTPS.

Memory trick: Your basic key needs a strong, encrypted tunnel to be safe.

More Understanding and Using APIs questions