Exercises

OAuth 2.0 and OpenID Connect for Backend Developers

Assess your practical understanding of OAuth 2.0 and OpenID Connect in backend systems. This quiz covers protocol roles, authorization flows, PKCE, access and ID tokens, security parameters, token validation, refresh tokens, scopes, introspection, and machine-to-machine authentication. The questions range from foundational concepts to security decisions that backend developers must make when integrating an identity provider.

Answer the questions below and check the explanation for each answer.

0/13 answered

  1. 1

    What is the primary purpose of OAuth 2.0?

  2. 2

    In the illustrated OAuth architecture, which component validates the access token before returning the requested data?

    Question 2
  3. 3

    What does OpenID Connect add on top of OAuth 2.0?

  4. 4

    In the authorization code flow with PKCE shown, which value does the client send to the token endpoint to prove it initiated the request?

    Question 4
  5. 5

    Which token should a backend API normally accept as proof that a client is authorized to call it?

  6. 6

    When validating a JWT access token, which combination of checks is essential?

    Question 6
  7. 7

    What security threat is the OAuth state parameter primarily intended to mitigate?

  8. 8

    What is the purpose of the nonce parameter in an OpenID Connect authentication request?

  9. 9

    Which OAuth 2.0 grant is most appropriate for the illustrated service-to-service request with no end user involved?

    Question 9
  10. 10

    Why should an authorization server require an exact redirect URI match for a registered client?

  11. 11

    What is the best practice when defining scopes for an application that only needs to read customer profiles?

  12. 12

    In the illustrated refresh-token rotation sequence, what should the authorization server do if an already-used refresh token is presented again?

    Question 12
  13. 13

    When an API receives an opaque access token, how can it obtain the token's active status and authorization metadata from the issuer?

Download the App now to have access to + 5000 free courses, exercises, certificates and lots of content without paying anything!

  • 100% free online courses from start to finish

    Thousands of online courses in video, ebooks and audiobooks.

  • More than 60 thousand free exercises

    To test your knowledge during online courses

  • Valid free Digital Certificate with QR Code

    Generated directly from your cell phone's photo gallery and sent to your email

Cursa app on the ebook screen, the video course screen and the course exercises screen, plus the course completion certificate