Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A company is implementing REST API security for its internal microservices architecture. They decide to use OAuth 2.0 for delegated authorization. After a user successfully authenticates with an Identity Provider (IdP) and grants consent, the client application receives an access token. What is the primary purpose of this access token?

  1. ATo establish a secure, encrypted tunnel between the client and the IdP.
  2. BTo prove the user's identity to the client application.
  3. CTo refresh the user's session with the Identity Provider.
  4. DTo authorize the client application to make requests on behalf of the user to a resource server.
Show answer & explanation

Correct answer: D. To authorize the client application to make requests on behalf of the user to a resource server.

In OAuth 2.0, the access token is a credential that authorizes the client application to access specific protected resources on a resource server on behalf of the user, without exposing the user's credentials to the client.

Why the other options are wrong

  • A. Establishing an encrypted tunnel is typically handled by TLS, not the access token itself.
  • B. Proving user identity to the client is the role of an ID token (if OIDC is used), not the access token.
  • C. A refresh token is used to obtain new access tokens without re-authentication.

OAuth 2.0 Access Token

A credential issued by an authorization server to a client application, allowing it to access protected resources on behalf of a user.

  • Used for delegated authorization, not authentication.
  • Short-lived and typically opaque to the client.
  • Presented to the resource server to gain access.

Memory trick: OAuth is like getting a temporary key (access token) from a doorman (IdP) to enter a specific room (resource server) on behalf of a friend.

More Security questions