
CiscoCertified DevNet Professional
Domain 2Objective 5
Describe the Steps in the OAuth2 Three-Legged Authorization Code Grant Flow 350-901 Practice Questions (Page 1)
Part of the 2.0 Using APIs domain, which accounts for 20% of the 350-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 1–5
- 1
What should the client do with the state parameter value it receives in the redirect back from the authorization server?
Select an answer first - 2
A user is trying to authorize a third-party app to access their data. They are redirected to the authorization server, but instead of seeing a login page, they see an error saying 'Invalid redirect_uri'. What is the most likely cause of this error?
Select an answer first - 3
An OAuth2 authorization server is being configured to support multiple client applications. A security auditor warns that the server must prevent open redirect vulnerabilities. What is the most effective measure the authorization server should implement?
Select an answer first - 4
After the resource owner grants consent, how does the authorization server deliver the authorization code to the client?
Select an answer first - 5
What is the purpose of the refresh_token in the token response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-901” is a trademark of its owner, used for identification only.