300-445 exam dumps

300-445 practice question 162 of 255

Designing and Implementing Enterprise Network Assurance. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-445 Question 162

Select 2

Your organization is building an enterprise-grade web application that requires users to authenticate. The application must support secure delegated access to resources hosted on third-party services (e.g., Google Drive or Dropbox) without sharing user credentials. Which web authentication methods would you implement to meet this requirement?

  1. A

    Basic Authentication

  2. B

    OAuth

  3. C

    SAML

  4. D

    Digest Authentication

  5. E

    Bearer Tokens

Show answer and explanation

Correct answers: B, E

Explanation

To enable secure delegated access to third-party resources, OAuth is the industry-standard protocol. It allows users to grant limited access to their resources without exposing their credentials. Bearer Tokens, often used with OAuth, act as proof of authorization to access these resources. Basic and Digest Authentication do not support delegated access, and SAML is designed for federated identity and SSO rather than delegated access.

  • A. Incorrect.

    Basic Authentication involves sending the username and password directly with each request, which is insecure unless combined with HTTPS. It does not support delegated access to third-party resources.

  • B. Correct.

    OAuth is designed for secure delegated access. It allows users to authorize third-party applications to access their resources without sharing their credentials.

  • C. Incorrect.

    SAML is primarily used for Single Sign-On (SSO) and federated identity management but is not designed for delegated access to third-party resources.

  • D. Incorrect.

    Digest Authentication hashes the username and password before sending them but does not support delegated access to third-party services.

  • E. Correct.

    Bearer Tokens are often used in conjunction with OAuth to grant access to resources. They allow secure access to third-party services without requiring users to share credentials.

Timed practice exam

Take a 300-445 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam