DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium

A developer is writing a Python application that needs to interact with a secure REST API. The API uses OAuth 2.0 for authorization and requires an access token in the 'Authorization: Bearer' header for every request. The application successfully obtains an access token, but the API still returns a 401 Unauthorized error. Which of the following is the most likely reason for this error, assuming the token itself is valid and not expired?

  1. AThe API's firewall is blocking the application's IP address.
  2. BThe application is using HTTP instead of HTTPS.
  3. CThe access token is not included in the correct header format.
  4. DThe application is sending the request to the wrong endpoint.
Show answer & explanation

Correct answer: C. The access token is not included in the correct header format.

Even if an access token is valid, it must be sent in the correct format for the API to process it. For OAuth 2.0 Bearer tokens, this typically means including it in the 'Authorization' header with the 'Bearer' scheme, like `Authorization: Bearer <access_token>`. An incorrect format would lead to a 401 Unauthorized error.

Why the other options are wrong

  • A. A firewall blocking an IP would typically result in a connection timeout or a different HTTP status code (e.g., 403 Forbidden if the server responds but explicitly denies the IP, or no response at all).
  • B. While using HTTP instead of HTTPS is a security risk, it would more likely result in connection errors or a 403 Forbidden if the API explicitly enforces HTTPS, not a 401 due to an invalid token format.
  • D. Sending to the wrong endpoint might result in a 404 Not Found or a different functional error, but less likely a 401 Unauthorized if the token is otherwise valid.

OAuth 2.0 Bearer Token Usage

An OAuth 2.0 Bearer token is a security token that grants access to protected resources. It must be included in the HTTP 'Authorization' header in the format `Authorization: Bearer <access_token>`.

  • Used for authorization in API requests.
  • Must be sent in the `Authorization` HTTP header.
  • Uses the `Bearer` scheme.
  • API validates token for authenticity and permissions.

Memory trick: Token's fine, but the envelope's wrong.

More Application Deployment and Security questions