Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Ping Identity PT-AM-CPE Exam - Topic 1 Question 6 Discussion

Actual exam question for Ping Identity's PT-AM-CPE exam
Question #: 6
Topic #: 1
[All PT-AM-CPE Questions]

In which OAuth2 grant would you find a user code?

Show Suggested Answer Hide Answer
Suggested Answer: D

The Device Authorization Grant (commonly referred to as the Device Flow, RFC 8628) is a specialized OAuth 2.0 grant flow supported by PingAM 8.0.2. It is designed for internet-connected devices that either lack a browser or have limited input capabilities (e.g., Smart TVs, IoT devices, or CLI tools).

In this flow, the interaction is split between the 'Device' and a 'Secondary Device' (like a smartphone or laptop) that has a full browser. The User Code is a fundamental component of this process:

Device Request: The device requests a code from PingAM.

PingAM Response: AM returns a Device Code (for the device) and a User Code (a short, human-readable string like BCDF-GHJK).

User Action: The device displays the User Code and a verification URL to the user.

Authorization: The user navigates to the URL on their smartphone, logs into PingAM, and enters the User Code.

Token Issuance: Once the user authorizes the request, the device (which has been polling AM using the Device Code) receives the Access and Refresh tokens.

The User Code is unique to the Device Flow (Option D). It is not used in the Client Credentials Grant (which is machine-to-machine), the Authorization Code Grant (which uses a redirect-based code), or the Resource Owner Password Credentials Grant (which uses direct username/password submission). In PingAM 8.0.2, administrators can configure the length, character set, and expiration time of these user codes within the OAuth2 Provider settings.


Contribute your Thoughts:

0/2000 characters
Carol
15 days ago
Wait, are you sure? I thought it was B) Authorization code grant.
upvoted 0 times
...
Gladys
20 days ago
Agreed, user codes are used in the device flow!
upvoted 0 times
...
Gerri
25 days ago
It's definitely D) Device flow.
upvoted 0 times
...
Meghann
1 month ago
Yup, D) is correct. User codes are part of the device flow!
upvoted 0 times
...
Alyce
1 month ago
Wait, are you all sure about that? Sounds kinda off.
upvoted 0 times
...
Dorothy
1 month ago
No way, it's D) for sure!
upvoted 0 times
...
Blondell
2 months ago
I thought it was B) Authorization code grant.
upvoted 0 times
...
Fannie
2 months ago
Definitely D) Device flow. That's where the user code is used.
upvoted 0 times
...
Rolland
2 months ago
I’m confused; I thought user codes were part of the Resource owner password credentials grant, but now I’m second-guessing myself.
upvoted 0 times
...
Rozella
2 months ago
I practiced a similar question about OAuth2, and I think the Device flow is the right answer for user codes.
upvoted 0 times
...
Troy
2 months ago
I remember studying the different OAuth2 flows, and I feel like the user code might be in the Authorization code grant, but that seems off.
upvoted 0 times
...
Glendora
2 months ago
I think the user code is related to the Device flow, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel