Okta Professional Cert Study Flashcards

1
Q

What are the 3 types of users in Okta?

A

Okta-Sourced (Mastered), Directory-Sourced (Mastered), App-Sourced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is SAML?

A

Security Assertion Markup Language - standard protocol used to facilitate SSO. Can be used across multiple systems/domains by establishing a trusted relationship using digital certificates/signatures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is LDAP?

A

Lightweight Directory Access Protocol - Directory source for users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is AD?

A

Active Directory - MS Directory that is LDAP compliant can connect any app that uses LDAP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is DSSO?

A

Desktop Single Sign On - Okta solution to allow users to log into AD connected computer and extend SSO to Okta configured Apps, reduce logins to Company and Cloud based apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is IWA?

A

Integrated Windows Authentication - AD version of DSSO, allows single login to company and some cloud apps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is in Workforce Identity Cloud?

A

SSO, MFA, Universal Directory, LCM, API Access Management, Advanced Server Access, Access Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is in Customer Identity Cloud?

A

Auth0, Authenticating User management, MFA, LCM, B2B Int, Access Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the methods of App integration?

A

SAML, SWA, OIDC and SCIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the first two steps to create an app integration?

A
  1. Create Integration, 2. Add users or groups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the two sign-in flows for SAML?

A
  1. SP-Initiated flow - user attempts sign in, redirected to IdP, then prompt login to IdP or desktop SSO.
  2. IdP initiated flow - user logs into IdP, launches SP by clicking chicklet, if no SP account, SAML can JIT.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What needs to be provided to the SP to do SSO?

A
  1. IdP SSO URL
  2. IdP Issuer Entity ID
  3. The X.509 Cert
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Describe the Okta Browser Plug-in.

A

Enables auto login to apps that would manually require credentials. SWA uses browser plug-in.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Universal Directory?

A

Manage Okta app and user profiles, 31 base attributes. Only you can modify or remove are First Name + Last Name. Default user name = email address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is SCIM provisioning?

A

System for Cross-domain Identity Management, used to perform provisioning actions between Okta + Cloud-based or On-prem apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the advantages to using Okta for provisioning?

A
  1. Account management
  2. Importing users (AD, LDAP, or certain apps)
  3. Configuring rules + Workflows
  4. Reports
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When do you use SAML for integration? and describe the authentication method.

A

When app supports SAML, like Salesforce, RingCentral, Box and ServiceNow. Between IdP and SP. SP is not authenticating, rather trusting the cert from the IdP. no user name or password exchanged, only encrypted token.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

When do you use WS-FED for app integration?

A

When MS Mastered? - check this

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

When do you use OIDC for integration?

A

When you want to use social networking to authenticate or a third party app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

When do you use SWA for integration?

A

Okta Secure Web Auth, when app doesn’t support proprietary federation or SAML. like Facebook, or Southwest Airlines. Requires Okta browser plug-in. Forms based integrations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are the 4 major use cases for Workflows?

A
  1. Comprehensive provisioning for an app.
  2. Complex “joiner, mover, leaver” flows
  3. Resolve identity conflict and other data issues
  4. Logging and Alerting on key lifecycle events
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What does a “Staged” user status mean?

A

The user account has been created, but the activation process has not been initiated. Account is in a dormant stage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What does “Pending user action” user status mean?

A

The user account has been added and the activation has been initiated, but the user has not yet set a password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What does “Active” user status mean?

A

The user account is active and the person can access all assigned applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What does “Deactivated” user status mean?

A

The user account is inactive and the admin can’t assign any applications to the user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What does “Password Reset” user status mean?

A

The user is allowed to resolve forgotten password issue by resetting the password without relying on the service desk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What does “Password Expired” user status mean?

A

The account password has expired and needs to be changed.

28
Q

What does “Locked out” user status mean?

A

The account has been locked due to a consecutive number of incorrect passwords used.

29
Q

What does “Suspended” user status mean?

A

The user cannot log in due to an action taken by the administrator.

30
Q

What does a Super Administrator have the ability to do?

A
  1. Has full access to perform all admin tasks and permission sets in Okta
  2. Only role that can assign admin priveleges.
31
Q

What does the Organization Administrator have the ability to do?

A
  1. Can perform most or-wide settings.
  2. Can perform all management tasks for users and groups.
  3. Cannot perform any application management tasks.
32
Q

What does the Application Administrator have the ability to do?

A
  1. Can manage profile information
  2. Can view users and groups, but not modify either.
  3. Can manage information on applications to which they are assigned access.
33
Q

What does the Group Administrator have the ability to do?

A
  1. Can create users, deactivate users, reset passwords.
  2. Can also restrict these tasks to select group or groups of Okta users.
  3. Cannot perform group creation and any application management tasks.
34
Q

What does the Read Only Administrator have the ability to do?

A
  1. Can view and run reports
  2. Can view users, groups, and applications, but cannot modify any settings.
  3. Can view, but not modify organizational settings.
35
Q

What does the Help Desk Administrator have the ability to do?

A
  1. Can view users
  2. Can reset password and MFA
  3. Can clear user session
  4. Can unlock users
36
Q

What are the AD Integration System requirements?

A
Window Server 2012 R2 or later
Physical or virtual server
At least 2 CPU's and a minimum of 8 GB RAM
Should be a domain member server
.NET 4.5.2+
Always on
37
Q

What user accounts are required for AD Integration?

A
  1. AD admin account
  2. AD service account for Okta
  3. Okta Super Admin account
38
Q

What are the AD sizing best practices for 0-30K users?

A

2 Okta AD Agents (per AD)

39
Q

What are the AD sizing best practices for 30K - 100K users?

A

3 Okta AD Agents (per AD)

40
Q

What are the AD sizing best practices for 100K+ users?

A

Work with Okta professional services

41
Q

What are the LDAP Agent Installation Server System Requirements?

A

Windows based agent:
- Windows Server 2008 R2+
- Windows server must be able to reach the LDAP host
Linux based agent:
- RPM-enabled distribution: CentOS, Red Hat
- DPKG-enabled distribution: Debian, Ubuntu

42
Q

What are the three types of Groups in Okta?

A
  1. Okta Groups = only Okta, directory and application sourced users.
  2. Directory Groups = created and managed by external directory. only directory-sourced users can be members of Directory Groups. If external directory is deactivated or deleted, associated groups are no longer in Okta.
  3. Application Groups = groups created and managed in an app. pulled into Okta during app creation. if app connector is deactivated or deleted, group no longer appears in Okta
43
Q

What are the filters available in OIN?

A
  1. SAML
  2. OpenID Connect
  3. WS-Federation
  4. Secure Web Authentication
  5. Provisioning
  6. Workflows Compatible
44
Q

What information can you view on Trust.okta.com

A
  1. System Status: Operational, etc
  2. 12 month availability percentage
  3. Security and Compliance information
45
Q

What can you view on Support.okta.com

A
  1. system status
  2. Release notes
  3. support knowledgebase articles
  4. Community portal
  5. Case Studies
  6. Support
46
Q

Are API tokens listed as suspicious until they are used once?

A

yes

47
Q

Do API tokens use a reversible encryption?

A

no, tokens are stored with an irreversible hash

48
Q

Is an API token visible only during creation?

A

yes, once you dismiss the window displaying the token, you cannot view it again

49
Q

What MFA options provide strong and effective resistance against MITM attacks?

A

U2F

50
Q

How can an admin assign an application to a user?

A

Group or Individual assignment

51
Q

Is this a required step to integrate Okta with LDAP?

- Install and configure the Okta LDAP Agent

A

Yes, this option is correct because the Okta LDAP agent is require to allow secure communication with Okta

52
Q

Is this a required step to integrate Okta with LDAP?

- Create a new LDAP directory

A

NO, Okta does NOT require a separate LDAP directory to store users.

53
Q

If a user cannot recall their password for a SWA app, what feature can they use to retrieve it?

A

“Reveal Password” - not password reset, this isn’t an option, nor is forgotten password

54
Q

Are you able to filter for “Supported Operating System” on the OIN?

A

NO, integration properties (SAML,etc) and name

55
Q

What are two security authentication factors that generate a 6 digit code soft token for Okta?

A

Google Authenticator, Okta Verify

56
Q

What is the first step to troubleshoot the Okta Browser plug-in?

A

Verity if it is enabled on the client’s browser.

57
Q

What are the importing methods for creating groups in Okta?

A

Groups must be created from the Okta admin application or imported from a directory or applicatino

58
Q

How does an Okta admin assign users to applications based on user profile attributes?

A

Group Rules

59
Q

What Okta product allows an Admin to create a custom authorization server?

A

API Access Management

60
Q

How long are API tokens valid?

A

30 days and automatically renew every time they are used with an API request. When a token has been inactive for more than 30 days it is revoked and cannot be used again.

61
Q

What does green API token status mean?

A

Token has been used within the last three days

62
Q

What does Gray API token status mean?

A

Token has not been used in the last three days, and today is at least 7 days before it’s expiration date.

63
Q

What does Red API token status mean?

A

Token is within 7 days of expiring

64
Q

What does Yellow token status mean?

A

Token is suspicious.

65
Q

Why is an API token considered suspicious?

A

A suspicious token is associated with an agent that is not registered in Okta. To investigate, click on token name and review the provisioning for the associated agent.