Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A company is implementing REST API security for its internal microservices architecture. They decide to use OAuth 2.0 for delegated authorization. After a user successfully authenticates with an Identity Provider (IdP) and grants consent, the client application receives an access token. What is the primary purpose of this access token?
- ATo establish a secure, encrypted tunnel between the client and the IdP.
- BTo prove the user's identity to the client application.
- CTo refresh the user's session with the Identity Provider.
- DTo authorize the client application to make requests on behalf of the user to a resource server.
Show answer & explanationAnswer & explanation
Correct answer: D. To authorize the client application to make requests on behalf of the user to a resource server.
In OAuth 2.0, the access token is a credential that authorizes the client application to access specific protected resources on a resource server on behalf of the user, without exposing the user's credentials to the client.
Why the other options are wrong
- A. Establishing an encrypted tunnel is typically handled by TLS, not the access token itself.
- B. Proving user identity to the client is the role of an ID token (if OIDC is used), not the access token.
- C. A refresh token is used to obtain new access tokens without re-authentication.
OAuth 2.0 Access Token
A credential issued by an authorization server to a client application, allowing it to access protected resources on behalf of a user.
- Used for delegated authorization, not authentication.
- Short-lived and typically opaque to the client.
- Presented to the resource server to gain access.
Memory trick: OAuth is like getting a temporary key (access token) from a doorman (IdP) to enter a specific room (resource server) on behalf of a friend.