Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-901 Exam - Topic 13 Question 75 Discussion

An application has initiated an OAuth authorization code grant flow to get access to an API resource on behalf of an end user.Which two parameters are specified in the HTTP request coming back to the application as the end user grants access? (Choose two.)
B) access token and expiration time to access the API resource
A) access token and a refresh token with respective expiration times to access the API resource
C) redirect URI a panel that shows the list of permissions to grant
D) code that can be exchanged for an access token
E) state can be used for correlation and security checks

Cisco 350-901 Exam - Topic 13 Question 75 Discussion

Actual exam question for Cisco's 350-901 exam
Question #: 75
Topic #: 13
[All 350-901 Questions]

An application has initiated an OAuth authorization code grant flow to get access to an API resource on behalf of an end user.

Which two parameters are specified in the HTTP request coming back to the application as the end user grants access? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Lorenza
9 months ago
I’m not sure about D, isn’t it just the access token we get back?
upvoted 0 times
...
Frederica
9 months ago
I agree with B, but D seems more relevant for the flow.
upvoted 0 times
...
Evelynn
10 months ago
Surprised that state is not a required parameter in the response!
upvoted 0 times
...
Olga
10 months ago
I thought it was A and B? Isn't the refresh token always included?
upvoted 0 times
...
Roxane
10 months ago
Definitely B and D! Those are the key ones.
upvoted 0 times
...
Lizette
10 months ago
I’m pretty certain that the access token and its expiration time are included, but I’m confused about the refresh token part.
upvoted 0 times
...
Colby
11 months ago
I feel like the redirect URI might be involved, but I can't recall if it's actually returned in this step.
upvoted 0 times
...
Gregoria
11 months ago
I remember practicing a question like this, and I think the code that can be exchanged for an access token is definitely part of the response.
upvoted 0 times
...
Reid
11 months ago
I think the response includes an access token, but I'm not sure if it also has a refresh token or just the expiration time.
upvoted 0 times
...
Hailey
11 months ago
I've got this! The answer is D and E - the code that can be exchanged for an access token, and the state parameter for correlation and security checks.
upvoted 0 times
...
Lavonne
11 months ago
I remember learning about the authorization code grant flow, but I'm having trouble recalling all the details. I'll need to carefully read through the question again.
upvoted 0 times
...
Willodean
11 months ago
Okay, let's think this through step-by-step. The key is to focus on the parameters returned in the authorization code grant flow.
upvoted 0 times
...
Catherin
11 months ago
Hmm, I'm a bit unsure about the difference between access tokens and refresh tokens. I'll need to review that part of the material.
upvoted 0 times
...
Willard
11 months ago
This looks like a pretty straightforward OAuth question. I'm confident I can handle this one.
upvoted 0 times
...
Jennie
11 months ago
Hmm, I'm a bit unsure about this one. The question covers a lot of different responsibilities, and I want to make sure I understand them all before selecting an answer.
upvoted 0 times
...
Art
11 months ago
I'm a bit confused on this one. I'll have to review the RouterOS documentation to be sure.
upvoted 0 times
...
Luz
11 months ago
I've got this! Restarting the server is the way to go. That should give me a chance to apply any necessary security updates without causing too much downtime.
upvoted 0 times
...
Susana
1 year ago
Wait, wait, wait... is the answer not 'All of the above, plus a free pizza and a pony'? *scratches head* Seriously though, D and E seem like the way to go.
upvoted 0 times
Salley
1 year ago
Absolutely, D) and E) are the ones specified in the HTTP request during the OAuth authorization code grant flow.
upvoted 0 times
...
Iraida
1 year ago
So, we all agree on D) and E) as the correct parameters, right?
upvoted 0 times
...
Freeman
1 year ago
Yeah, E) state can be used for correlation and security checks is also important for security.
upvoted 0 times
...
Vanna
1 year ago
I think D) code that can be exchanged for an access token is definitely one of the parameters.
upvoted 0 times
...
...
Bok
1 year ago
Ooh, this one's tricky! I'm gonna go with D and E. Gotta love those security checks, am I right? *winks*
upvoted 0 times
Jillian
1 year ago
User2: Yeah, those security checks are important. Better safe than sorry.
upvoted 0 times
...
Lynette
1 year ago
User1: I think it's D and E too. Can't be too careful with security.
upvoted 0 times
...
...
Gerald
1 year ago
Obviously, the answer is D and E. What is this, an OAuth trivia quiz? I could answer these questions in my sleep!
upvoted 0 times
...
Wilbert
1 year ago
I believe the code that can be exchanged for an access token is also specified in the HTTP request.
upvoted 0 times
...
Marya
1 year ago
Hmm, I'm not sure about this one. I was thinking that B and D would be the right answers, but now I'm second-guessing myself. Maybe I should have paid more attention in that OAuth lecture...
upvoted 0 times
...
Susana
1 year ago
I agree with Ernie. The access token and refresh token are needed for accessing the API resource.
upvoted 0 times
...
Kristal
1 year ago
I think the correct answers are D and E. The authorization code grant flow returns a code that can be exchanged for an access token, and the state parameter is used for correlation and security checks.
upvoted 0 times
Willie
1 year ago
That's correct. Those are the two parameters specified in the HTTP request.
upvoted 0 times
...
Viva
1 year ago
And the state parameter is important for security checks.
upvoted 0 times
...
Maia
1 year ago
Yes, you're right. The code is exchanged for an access token.
upvoted 0 times
...
Lavonne
1 year ago
I think the correct answers are D and E.
upvoted 0 times
...
...
Ernie
1 year ago
I think the parameters specified in the HTTP request are the access token and a refresh token.
upvoted 0 times
...

Save Cancel