exam questions

Exam 350-901 All Questions

View all questions & answers for the 350-901 exam

Exam 350-901 topic 1 question 68 discussion

Actual exam question from Cisco's 350-901
Question #: 68
Topic #: 1
[All 350-901 Questions]

In the three-legged OAuth2 process, after the authorization server presents a form to the resource owner to grant access, what is the next step?

  • A. The resource owner authenticates and optionally authorizes with the authorization server.
  • B. The user who owns the resource initiates a request to the OAuth client.
  • C. If the resource owner allows access, the authorization server sends the OAuth client a redirection.
  • D. A form to allow or restrict access is submitted by the owner of the resource.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Johnno26
Highly Voted 2 years ago
Selected Answer: D
D seems correct: https://www.ibm.com/docs/en/datapower-gateways/10.0.1?topic=flows-three-legged-oauth-flow
upvoted 10 times
...
python_tamer
Highly Voted 1 year, 11 months ago
Selected Answer: D
A - This happens earlier in the flow, before authz server presents form to grant access. B - Definitely not C - Happens later in the flow. D - Correct answer. Kudos to Johnno26 for the link which has every step word for word!
upvoted 6 times
...
samael666
Most Recent 3 weeks ago
Selected Answer: C
Option D is a obious result, the owner will submit something, but the questions says what happen after, so after the owner respond the AuthServer will redirect to the client sending the authorization code
upvoted 1 times
...
isaacmejia
2 months ago
Selected Answer: D
A user, as the resource owner, initiates a request to the OAuth client. The OAuth client sends the resource owner a redirection to the authorization server. The resource owner authenticates and optionally authorizes with the authorization server. The authorization server presents a form to the resource owner to grant access. The resource owner submits the form to allow or to deny access. Based on the response from the resource owner, the following processing occurs: If the resource owner allows access, the authorization server sends the OAuth client a redirection with the authorization grant code or the access token. If the resource owner denies access, the request is redirected to the OAuth client but no grant is provided.
upvoted 1 times
...
doble_h
2 months ago
Selected Answer: C
The resource owner makes a decision to grant or deny access to the application (OAuth client)
upvoted 1 times
...
johntermlen
5 months, 3 weeks ago
Selected Answer: C
The other options are incorrect. Option A is incorrect because the resource owner does not authenticate with the authorization server in this step. Option B is incorrect because the user who owns the resource does not initiate a request to the OAuth client in this step. Option D is incorrect because the owner of the resource does not submit a form to allow or restrict access in this step.
upvoted 3 times
...
vrossa
7 months, 1 week ago
Option D is incorrect because it mentions a form being submitted by the owner of the resource to allow or restrict access. While the resource owner may provide consent through a form, the submission of the form is not the next step after the authorization server presents the form. The next step is the resource owner authenticating and optionally authorizing with the authorization server.
upvoted 1 times
...
Teringzooi
1 year, 3 months ago
Selected Answer: D
Answer = D https://www.ibm.com/docs/en/datapower-gateways/10.0.1?topic=flows-three-legged-oauth-flow
upvoted 1 times
...
designated
1 year, 5 months ago
Selected Answer: D
D is correct 1. A user, as the resource owner, initiates a request to the OAuth client. 2. The OAuth client sends the resource owner a redirection to the authorization server. 3. The resource owner authenticates and optionally authorizes with the authorization server. 4. The authorization server presents a form to the resource owner to grant access. 5. The resource owner submits the form to allow or to deny access. 6. Based on the response from the resource owner, the following processing occurs: A) If the resource owner allows access, the authorization server sends the OAuth client a redirection with the authorization grant code or the access token. B) If the resource owner denies access, the request is redirected to the OAuth client but no grant is provided.
upvoted 1 times
designated
1 year, 5 months ago
7. The OAuth client sends the following information to the token endpoint (authorization server). -Authorization grant code -Client ID -Client secret or client certificate 8. If verified, the authorization server sends the OAuth client an access token and optionally a refresh token. 9. The OAuth client sends the access token to the resource server to request protected resources. 10. If the access token is valid for the requested resources, the OAuth client can access the protected resources.
upvoted 1 times
...
...
rhmgh
1 year, 12 months ago
Maybe C is correct "If the resource owner grants access, the authorization server redirects the user's browser back to the client using the redirection URI provided earlier (in the request or during client (registration). The redirection URI includes an authorization code and any local state provided by the client earlier" "Assuming the resource owner grants access, the authorization server redirects the user-agent back to the client using the redirection URI provided earlier (in the request or during client (registration). The redirection URI includes an authorization code and any local state provided by the client earlier."
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago