Okta Administrator Certification Flashcards

1
Q

Which Okta administrator role can promote a regular user to Read-Only Administrator?

A

A: Super Administrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which method can an administrator use to create a read-only API token?

A

A: Log on as Read-Only Administrator and create an API token.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which component is a minimum prerequisite for deploying On Prem Desktop SSO in a company?

A

A: Properly Installed Okta Active Directory Agent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which sign-on method should be used to configure SSO for a web app that does NOT support federation?

A

A: SWA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which statement is true about mappings with Universal Directory?

A

A: It supports SpEL functions for transforming data attributes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which system log query can an administrator run to check on deleted API tokens?

A

A: eventType eq “system.api_token.revoke”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is protected by API rate limits?

A

A: The Okta service from load spikes or service interrupts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a best practice when configuring high availability for the Okta Active Directory (AD) Agent?

A

A: Set up two or more Active DIrectory Agents for each domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does an administrator need from an SP to configure a SAML-enabled application that is NOT part of the OIN?

A

A: SAML Metadata.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

At logon, users can authenticate with Delegated Authentication, but functions like reset password do NOT work. Why?

A

A: An administrator has not set up password reset capability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which feature should be configured to ensure users are prompted for MFA every time they access a specific application?

A

A: Application Sign-on policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which Okta feature can be used to determine whether a user should have access to an application?

A

A: Application Access Audit Report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which expression correctly transforms a username to this format: firstname.lastname@okta.com?

A

A: source.firstName + “.” + source.lastName + “@okta.com”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An administrator logs on to the Okta Administrator App but is NOT able to see any reports. What is the likely reason?

A

A: The administrator is logged on as a Group Administrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What will the Okta browser plugin do after it is deployed with SWA applications?

A

A: Monitor password updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should be configured to automate activation of new users during an import from AD to Okta in an existing Okta org?

A

A: Auto-activate new users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which statement is true about applications that are available in the Okta Integration Network (OIN)?

A

A: OIN applications are available to all Okta customers.

18
Q

Which administrator role can create groups in Okta?

A

A: Organization Administrator.

19
Q

Where can an administrator see the attributes that can be updated between Okta and configured apps?

A

A: Profile Editor.

20
Q

What can a group in Okta be used for?

A

A: To assign specific entitlements within an application.

21
Q

What will an outside-the-network user experience when signing on to an org that deployed DSSO functionality?

A

A: The user will be prompted for credentials.

22
Q

According to best practice, which account should an administrator use to install DSSO?

A

A: The Okta Sourced Administrator account with Super Administrator privileges.

23
Q

What should administrators do to support Active Directory Password Reset functionality for end users?

A

A: Promote the Active Directory service account to the correct permissions.

24
Q

What is a best practice when installing the Okta Active Directory Agent?

A

A: Use an Okta-sourced Super Administrator account.

25
Q

A company application requires an LDAP managerid attribute. Which statement about LDAP profile mappings is true?

A

A: Any Okta-imported attributes can be mapped to the application profile.

26
Q

What is an appropiate method for importing Active Directory-sourced users into Okta?

A

A: Manually run the import from the Okta administrator application.

27
Q

What is the correct method of enabling Verbose Logging in the Okta Active Directory (AD) Agent?

A

A: Set Verbose Logging as “True” in Agent config file; restart Agent Service.

28
Q

When a user is in the network, what would prevent Desktop Single Sign-On (SSO) from signing the user in automatically?

A

A: The user’s Active Directory (AD) account is locked.

29
Q

What is required to configure delegated authentication with Active Directory domains?

A

A: Service account in Active Directory.

30
Q

Which Okta Administrator role should be used to create an API key that CANNOT change configurations in Okta?

A

A: Read-Only Administrator.

31
Q

Which password policy feature can prevent Okta-sourced users from changing their new user password for at least 5 days?

A

A: Minimum password age.

32
Q

Which type of MFA rule can an Okta Administrator use for behavior detection at sign-on?

A

A: Device.

33
Q

What does the Enchanced Group Push allow administrators to do?

A

A: Push to specific groups from Okta that exist in specific applications.

34
Q

Which syntax will transform emails in this format “jsmith@oktaice.com” to usernames in this format “jsmith”?

A

A: String.substringBefore(“jsmith@oktaice.com”, “@”)

35
Q

Which statement about profile attributes is true?

A

A: Attributes can be modified with the People Editor.

36
Q

Multiple profile sources are being used with Okta. ALS is NOT enabled. What determines the source of the attributes?

A

A: Attribute Source priority.

37
Q

What should an Okta Administrator use to configure a custom ASP.net application that requires federation?

A

A: WS-Fed template.

38
Q

Which component is required for Delegated Authentication?

A

A: The Okta AD Agent installed and configured in the Okta org.

39
Q

Which SWA template app should be used to create a custom application with Username, Password and submit button fields?

A

A: Template Plugin App.

40
Q

What is required during an Identity Provider (IdP) initiated sign-on to confirm a SAML assertion?

A

A: IdP signature certificate.