Okta Professional Certification Flashcards

1
Q

All eligible factor types are configured as optional in the Okta Enrollment Policy.

What is the expected outcome when end users are required to enroll?

A

A: End users are required to choose one of the approved factor types before continuing the enrollment process.

If all options are optional, but the policy is in place, the user must choose at least one approved factor in order to proceed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A company wants to automate the process of enabling employees to request access to SAML based applications. Once employees request access, application administrators need to review and accept or deny their request.

What is the Okta feature the company should use?

A

A: Application Request & Approval workflow.

This workflow enables users to request access to applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Application Integration Wizard used for?

A

A: It is used to create applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What operation types does Okta support on an Okta sourced user?

A

A: Activate, Suspend, Delete.

Hide is not an option in Okta and adding the same app multiple times to a user is not supported.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the lifecycle management operations in Okta for third-party applications?

A

A: Account creation, Update, Deactivate and Sync Password.

Account reset is not part of the lifecycle management operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who is the Okta Browser plugin management?

A

A: IT manages the plugin.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why would an end user NOT be authenticated when using MFA?

A

A: The end user made five unsuccesful attempts to authenticate using Google Authenticator.

Also, Okta supports Windows Hello for Microsoft Edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an example of a Service Provider (SP) initiated flow?

A

A: An end user logs in by navigating directly to an application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What options are available to an administrator when resetting the MFA for an end user?

A

A:

  • Reset all factors for multiple users.
  • Reset one or multiple factors for a single user

NOT available:

  • Force end users to enroll in another factor type before reset
  • Reset administration policies and restart all end users’ devices
  • Create a new policy to un-assign end users form their factors is not an administrative action
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a true statement about default policies?

A

A: Default policies CANNOT be deleted.

NOT TRUE:
- The order of the default policies can be changed.
The default policy is always the last policy evaluated and only the outcome can be modified.
- An Okta Administrator can change the group assigned to the default policy.
The default policy applies to the Everyone group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the profile types supported by Okta Universal Directory?

A

A: Application User Profile, Okta User Profile, Directory User Profile, Identity Provider User Profile.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

An Okta API token is set to expire after 30 days. What is a valid method of preventing the token from expiring?

A

A: Perform an action that requires the use of the API token. The expiration counter will reset once the API token is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the benefits of using an Okta group?

A

A: Ability to contain end users from different identity sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An Okta administrator wants to enable self-service password reset workflow for Okta sourced users. What actions are possible?

A

A:

  • The administrator can customize the ‘Forgot Password’ email template. The ‘Forgot Password’ template is a configurable template under Emails and SMS.
  • The administrator can restrict password reset workflow access to only users who are on-premise. The Password Policy rules have a configurable network parameter.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What options are allowed as verification for self-service password reset?

A

A: Email, Voice and SMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are NOT functionalities of the Okta Browser plugin?

A

A:
- Stores passwords on an end user’s local machine.
- Checks for common passwords in an Okta enabled Secure Web Authentication (SWA) application.
It can only check for common password use only for the primary authentication of the Okta user itself.
- Ensures sufficient password complexity.
It is ensured at Okta by setting Password policies , which do NOT have an effect on passwords passed or generated by the Okta browser plugin.
- Deprovision user accounts in applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What features are available with Okta MFA?

A

A:

  • Ability to require that all users enroll in Okta verify.
  • Ability to only allow IT administrators to enroll with RSA SecurID. Both enrollment and enforcement of factors is controlled at the group level.
  • Ability to allow users to choose to enroll in one MFA from a list of configured factors.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

An Okta end user has a pending request for access to Box. Why would the end user might NOT be assigned to Box?

A

A:

  • The approver for the workflow is deactivated and no one will receive the request and the user’s request is still pending.
  • The only group containing the approver used in the approval process has been deleted. If the only one group containing the approver was deleted, then no one will receive the request and the user’s request is still pending.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What information can an administrator find in the system log?

A

A: Suspicious activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the application sign-on methods that Okta supports?

A

A:

  • Secure Web Authentication (SWA)
  • Security Assertion Markup Language (SAML 2.0)
  • OpenID Connect
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the App Integration Wizard (AIW) used for?

A

A: Add applications that do NOT have prebuilt integrations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are valid ways to activate an Okta user account?

A

A:

  • Activate the Okta user account through the Okta Administrator Application
  • Activate the Okta user account through the Users API call.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is a benefit of using SAML over SWA?

A

A: SAML authentication is more secure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are the functions of the Okta browser plugin?

A

A:

  • Automatically inserts passwords on ‘password update’ pages.
  • Allows for automatic application sign-in
  • Allows end users to initiate an Okta logon from the web page
  • Automatically fills in credentials on sing-in pages
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What happens when an Active Directory integration is deactivated?

A

A: The AD users become Okta-sourced if not linked to another profile source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Which capability is available for ALL prebuilt Okta Integration Network (OIN) applications?

A

A: Group application assignment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What happens if all MFA factors are optional in an Enrollment Policy when end users enroll?

A

A: End users are required to choose a factor to enroll.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What default permission does an Active Directory service account have at installation?

A

A: The ability to JIT provision users to Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What would be a recommended way for an Okta Administrator to open a case with Okta Support?

A

A: Call the toll-free number shown in the Okta Help Center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is a standard technology that Okta uses for identity verification?

A

A: SAML.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is an example of an Identity as a Service (IDaaS) benefit provided by Okta?

A

A: Redundant architecture to ensure availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is an example of an Identity as a Service (IDaaS) benefit provided by Okta?

A

A: Redundant architecture to ensure availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which authentication method would allow a company to eliminatae application-specific passwords?

A

A: Web Services Federation (WS-Fed).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What would be a best practice authentication method for application authentication?

A

A: SAML.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which factor types are available when configuring MFA for Okta-sourced users?

A

A:

  • Okta Verify
  • SMS Authentication
  • Google Authenticator
  • FIDO2 (WebAuthn)
  • Symantec VIP
  • On-Prem MFA
  • RSA SecurID
  • Email Authentication
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What would NOT be a supported feature of Universal Directory?

A

A:

- API Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What are the features of Universal Directory?

A

A:

  • Schema Discovery
  • Data transformation
  • Attribute Level Sourcing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is a possible scenario for enabling Just-in-Time (JIT) Provisioning into Okta?

A

A: The Okta Active Directory (AD) Agent is installed and configured.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Which strategy should be used to provision user accounts from Okta to an on-premises AD or LDAP directory?

A

A: Agent-based Provisioning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which action CANNOT be performed through self-service by an end user withouut IT assistance?

A

A: Configure administrator access using the Okta user home page.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

How might Okta-sourced and directory-sourced users gain the same application access?

A

A: Create an Okta group and manually add each of the user.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

How can an end user reset their forgotten Okta password without calling their help desk?

A

A: SMS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Which action will allow users to access applications that do NOT support SAML?

A

A: Configure the applications for Secure Web Authentication (SWA).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

How could you differentiate the unique sign-on policies for Okta administrators from end users?

A

A: Group the administrators & create a sign-on policy for them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Which default base attribute can be marked as NOT required for Okta-sourced users?

A

A: Last Name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Which feature is available with Okta MFA?

A

A: Ability to require that all users enroll in Okta Verify.

46
Q

Which action allows an Okta administrator to enable self-service password reset for Okta users?

A

A: Administrators can limit password reset capability by zone.

47
Q

Which Okta feature would allow end users to grant application access to other users by request?

A

A: Application Request & Approval workflow.

48
Q

What is a valid configuration option for enforcing MFA enrollment in Okta?

A

A: Force users to enroll in MFA the first time a user is challenged for MFA.

49
Q

Which option is available for both MFA and password reset?

A

A: Security Question (Email).

50
Q

Which report should be run to reconcile application access with deactivated users in Okta?

A

A: Recent Unassignments.

51
Q

What is the minimum adminstrator role needed to configure a user as a Read-Only Administrator?

A

A: Super Administrator, only this role is allowed to create users.

52
Q

What is SAML?

A

A: Security Assertion Markup Language - standard protocol used to facilitate SSO. Can be used across multiple systems/domains by establishing a trusted relationship using digital certificates/signatures.

53
Q

What is LDAP?

A

A: Lightweight Directory Access Protocol - Directory source for users.

54
Q

What is AD?

A

A: Active Directory - MS Directory that is LDAP compliant can connect any app that uses LDAP.

55
Q

What is DSSO?

A

A: Desktop Single Sign On - Okta solution to allow users to log into AD connected computer and extend SSO to Okta configured Apps, reduce logins to Company and Cloud based apps.

56
Q

What is IWA?

A

A: Integrated Windows Authentication - AD version of DSSO, allows single login to company and some cloud apps.

57
Q

What is in Workforce Identity Cloud?

A

A: SSO, MFA, Universal Directory, LCM, API Access Management, Advanced Server Access, Access Gateway.

58
Q

What are the methods of App integration?

A

A: SAML, SWA, OIDC and SCIM.

59
Q

What are the first two steps to create an app integration?

A

A:

  • Create Integration
  • Add users or groups.
60
Q

What are the two sign-in flows for SAML?

A

A:

  • SP-Initiated flow - user attempts sign in, redirected to IdP, then prompt login to IdP or desktop SSO.
  • IdP initiated flow - user logs into IdP, launches SP by clicking chicklet, if no SP account, SAML can JIT.
61
Q

What needs to be provided to the SP to do SSO?

A

A:

  • IdP SSO URL
  • IdP Issuer Entity ID
  • The X.509 Cert
62
Q

Describe the Okta Browser Plug-in.

A

A: Enables auto login to apps that would manually require credentials. SWA uses browser plug-in.

63
Q

What is Universal Directory?

A

A: Manage Okta app and user profiles, 31 base attributes. Only you can modify or remove are First Name + Last Name. Default user name = email address.

64
Q

What is SCIM provisioning?

A

A: System for Cross-domain Identity Management, used to perform provisioning actions between Okta + Cloud-based or On-prem apps.

65
Q

What are the advantages to using Okta for provisioning?

A

A:

  • Account management
  • Importing users (AD, LDAP, or certain apps)
  • Configuring rules + Workflows
  • Reports
66
Q

When do you use SAML for integration? Describe the authentication method.

A

A: When the app supports SAML (like Salesforce, RingCentral, Box and ServiceNow). Between IdP and SP. SP is not authenticating, rather trusting the cert from the IdP. no user name or password exchanged, only encrypted token.

67
Q

When do you use OIDC for integration?

A

A: When you want to use social networking to authenticate or a third party app.

68
Q

When do you use SWA for integration?

A

A: Okta Secure Web Auth, when the app doesn’t support proprietary federation or SAML, like Facebook, or Southwest Airlines. Requires Okta browser plug-in. Forms based integrations.

69
Q

What are the 4 major use cases for Workflows?

A

A:

  • Comprehensive provisioning for an app.
  • Complex “joiner, mover, leaver” flows
  • Resolve identity conflict and other data issues
  • Logging and Alerting on key lifecycle events
70
Q

What does a “Staged” user status mean?

A

A: The user account has been created, but the activation process has not been initiated. Account is in a dormant stage.

71
Q

What does “Pending user action” user status mean?

A

A: The user account has been added and the activation has been initiated, but the user has not yet set a password.

72
Q

What does “Active” user status mean?

A

A: The user account is active and the person can access all assigned applications.

73
Q

What does “Deactivated” user status mean?

A

A: The user account is inactive and the admin can’t assign any applications to the user.

74
Q

What does “Password Reset” user status mean?

A

A: The user is allowed to resolve forgotten password issue by resetting the password without relying on the service desk.

75
Q

What does “Password Expired” user status mean?

A

A: The account password has expired and needs to be changed.

76
Q

What does “Locked out” user status mean?

A

A: The account has been locked due to a consecutive number of incorrect passwords used.

77
Q

What does “Suspended” user status mean?

A

A: The user cannot log in due to an action taken by the administrator.

78
Q

What does a Super Administrator have the ability to do?

A

A:

  • Has full access to perform all admin tasks and permission sets in Okta
  • Only role that can assign admin priveleges.
79
Q

What does the Organization Administrator have the ability to do?

A

A:

  • Can perform most org-wide settings.
  • Can perform all management tasks for users and groups.
  • Cannot perform any application management tasks.
80
Q

What does the Application Administrator have the ability to do?

A

A:

  • Can manage profile information
  • Can view users and groups, but not modify either.
  • Can manage information on applications to which they are assigned access.
81
Q

What does the Group Administrator have the ability to do?

A

A:

  • Can create users, deactivate users, reset passwords.
  • Can also restrict these tasks to select group or groups of Okta users.
  • Cannot perform group creation and any application management tasks.
82
Q

What does the Read Only Administrator have the ability to do?

A

A:

  • Can view and run reports
  • Can view users, groups, and applications, but cannot modify any settings.
  • Can view, but not modify organizational settings.
83
Q

What does the Help Desk Administrator have the ability to do?

A

A:

  • Can view users
  • Can reset password and MFA
  • Can clear user session
  • Can unlock users
84
Q

What are the AD Integration System requirements?

A

A:

  • Window Server 2012 R2 or later
  • Physical or virtual server
  • At least 2 CPU’s and a minimum of 8 GB RAM
  • Should be a domain member server
  • .NET 4.5.2+
  • Always on
85
Q

What user accounts are required for AD Integration?

A

A:

  • AD admin account
  • AD service account for Okta
  • Okta Super Admin account
86
Q

What are the AD sizing best practices for 0-30K users?

A

A: 2 Okta AD Agents (per AD).

87
Q

What are the AD sizing best practices for 30K - 100K users?

A

A: 3 Okta AD Agents (per AD).

88
Q

What are the AD sizing best practices for 100K+ users?

A

A: Work with Okta professional services.

89
Q

What are the LDAP Agent Installation Server System Requirements?

A

A:
- Windows based agent:
- Windows Server 2008 R2+
- Windows server must be able to reach the LDAP host
Linux based agent:
- RPM-enabled distribution: CentOS, Red Hat
- DPKG-enabled distribution: Debian, Ubuntu

90
Q

What are the three types of Groups in Okta?

A

A:

  • Okta Groups = only Okta, directory and application sourced users.
  • Directory Groups = created and managed by external directory. only directory-sourced users can be members of Directory Groups. If external directory is deactivated or deleted, associated groups are no longer in Okta.
  • Application Groups = groups created and managed in an app. pulled into Okta during app creation. if app connector is deactivated or deleted, group no longer appears in Okta
91
Q

What are the filters available in OIN?

A

A:

  • SAML
  • OpenID Connect
  • WS-Federation
  • Secure Web Authentication
  • Provisioning
  • Workflows Compatible
92
Q

What information can you view on Trust.okta.com?

A

A:

  • System Status: Operational, etc
  • 12 month availability percentage
  • Security and Compliance information
93
Q

What can you view on Support.okta.com?

A

A:

  • system status
  • Release notes
  • support knowledgebase articles
  • Community portal
  • Case Studies
  • Support
94
Q

Are API tokens listed as suspicious until they are used once?

A

A: Yes.

95
Q

Do API tokens use a reversible encryption?

A

A: No, tokens are stored with an irreversible hash.

96
Q

Is an API token visible only during creation?

A

A: Yes, once you dismiss the window displaying the token, you cannot view it again.

97
Q

What MFA options provide strong and effective resistance against MITM attacks?

A

A: U2F - U2F (Universal 2nd Factor) is an authentication standard that uses one key for multiple services. It simplifies and elevates the security provided by 2FA (two-factor authentication).

FIDO U2F tokens enable users to quickly and securely access any website or online service that supports the FIDO U2F protocol using a single device. To authenticate, a user simply inserts a universal serial bus (USB) token into any port. Then, the user presses the U2F token button and enters his or her password or PIN.

98
Q

How can an admin assign an application to a user?

A

A: Group or Individual assignment.

99
Q

Is this a required step to integrate Okta with LDAP?

- Install and configure the Okta LDAP Agent

A

A: Yes, this option is correct because the Okta LDAP agent is required to allow secure communication with Okta.

100
Q

Is this a required step to integrate Okta with LDAP?

- Create a new LDAP directory

A

A: No, Okta does NOT require a separate LDAP directory to store users.

101
Q

If a user cannot recall their password for a SWA app, what feature can they use to retrieve it?

A

A: “Reveal Password” - not password reset, this isn’t an option, nor is forgotten password.

102
Q

Are you able to filter for “Supported Operating System” on the OIN?

A

A: No, integration properties (SAML,etc) and name.

103
Q

What are two security authentication factors that generate a 6 digit code soft token for Okta?

A

A: Google Authenticator, Okta Verify.

104
Q

What is the first step to troubleshoot the Okta Browser plug-in?

A

A: Verify if it’s enabled on the client’s browser.

105
Q

What are the importing methods for creating groups in Okta?

A

A: Groups must be created from the Okta admin application or imported from a directory or application.

106
Q

How does an Okta admin assign users to applications based on user profile attributes?

A

A: Group Rules.

107
Q

What Okta product allows an Admin to create a custom authorization server?

A

A: API Access Management.

108
Q

How long are API tokens valid?

A

A: 30 days and automatically renew every time they are used with an API request. When a token has been inactive for more than 30 days it is revoked and cannot be used again.

109
Q

What does green API token status mean?

A

A: Token has been used within the last three days.

110
Q

What does Gray API token status mean?

A

A: Token has not been used in the last three days, and today is at least 7 days before it’s expiration date.

111
Q

What does Red API token status mean?

A

A: Token is within 7 days of expiring.

112
Q

What does Yellow token status mean?

A

A: Token is suspicious.

113
Q

Why is an API token considered suspicious?

A

A: A suspicious token is associated with an agent that is not registered in Okta. To investigate, click on token name and review the provisioning for the associated agent.