ETExamTower
Q58Security

Drag and drop the REST API authentication methods from the left to the descriptions on the right. <DragDrop items={["HTTP basic authentication","OAuth","secure vault"]} slots={[{"answer":"secure vault","id":"slot1","label":"public API resource"},{"answer":"HTTP basic authentication","id":"slot2","label":"username and password in an encoded string"},{"answer":"OAuth","id":"slot3","label":"authorization through identity provider"}]} explanation={"HTTP Basic authentication encodes the username and password together for the Authorization header. OAuth delegates authorization to an identity provider. A secure vault is exposed as a public API resource in this matching set.\n\n**Learn more:** [Cisco DevNet: RESTful API Essentials - Authentication](https://community.cisco.com/t5/devnet-general-knowledge-base/restful-api-essential-authentication/ta-p/4800269) · [Cisco Catalyst Center API Authentication](https://developer.cisco.com/docs/catalyst-center/authentication/)"} reuse={false} />

← → navigate · a answer
Discussion · 10
9
you are wrong, OAuth needs an identity provider to get the interchange of Tokens and then the user access without the use of user/pass. OAuth is not an application, its a protocol. Two different things. Answer is correct.
6
How can a public API resource be in a secure vault? It's public (!) and stores no credentials. I think it should be: Public API resource - OAuth username and passeord in an encoded string - secure vault authorization through indentity provider - HTTP basic authentication
2
I think the provided answer is correct, do a quick google search of cisco secure vault, theres not that much info on it though.
2
Please type oauth in google. It is Public API resource. Answer should be; OAuth HTTP basic authentication Secure Vault
1
OAuth is a way to get access to protected data from an application. It's safer and more secure than asking users to log in with passwords., NO CORRECT , , oauth is an application
1
Agree with Johconnor
1
OAuth is one of many solutions you can use to protect your APIs and other resources. It lets users securely delegate access to resources without sharing their original credentials. OAuth2 has been around since 2012 as a standard and is built on lessons from other, earlier standards, including OAuth1 and SAML.
1
I'm confused. What's the correct answer?
1
HTTP basic authentication -username and password in an encoded string OAuth - authorization through identity provider Public API - public API resource
1
The correct answer is: Public API resource = OAuth. OAuth is used to protect APIs, it's like when you login to a remote website with Your Google Login Creds. The remote website sends an authentication token to Google, Google authenticates you, if authenticated, allows the access request to the user request. username and password in an encoded string = HTTP basic Authentication because you can do basic username and password authentication via HTTP basic authentication because HTTP is encoded with UTF-8, ASCII, ISO-8859-1, or BASE64 for example. These are all basic HTTP methods of Encoding. Authorization through identity provider = SecureVault because SecureVault is like CyberArk, it centralizes credentials and becomes the identity provider and only allows you to log into appliances and devices after authenticating with the SecureVault (such as CyberArk).