Okta Professional Certification Flashcards
All eligible factor types are configured as optional in the Okta Enrollment Policy.
What is the expected outcome when end users are required to enroll?
A: End users are required to choose one of the approved factor types before continuing the enrollment process.
If all options are optional, but the policy is in place, the user must choose at least one approved factor in order to proceed.
A company wants to automate the process of enabling employees to request access to SAML based applications. Once employees request access, application administrators need to review and accept or deny their request.
What is the Okta feature the company should use?
A: Application Request & Approval workflow.
This workflow enables users to request access to applications.
What is the Application Integration Wizard used for?
A: It is used to create applications.
What operation types does Okta support on an Okta sourced user?
A: Activate, Suspend, Delete.
Hide is not an option in Okta and adding the same app multiple times to a user is not supported.
What are the lifecycle management operations in Okta for third-party applications?
A: Account creation, Update, Deactivate and Sync Password.
Account reset is not part of the lifecycle management operations.
Who is the Okta Browser plugin management?
A: IT manages the plugin.
Why would an end user NOT be authenticated when using MFA?
A: The end user made five unsuccesful attempts to authenticate using Google Authenticator.
Also, Okta supports Windows Hello for Microsoft Edge
What is an example of a Service Provider (SP) initiated flow?
A: An end user logs in by navigating directly to an application.
What options are available to an administrator when resetting the MFA for an end user?
A:
- Reset all factors for multiple users.
- Reset one or multiple factors for a single user
NOT available:
- Force end users to enroll in another factor type before reset
- Reset administration policies and restart all end users’ devices
- Create a new policy to un-assign end users form their factors is not an administrative action
What is a true statement about default policies?
A: Default policies CANNOT be deleted.
NOT TRUE:
- The order of the default policies can be changed.
The default policy is always the last policy evaluated and only the outcome can be modified.
- An Okta Administrator can change the group assigned to the default policy.
The default policy applies to the Everyone group
What are the profile types supported by Okta Universal Directory?
A: Application User Profile, Okta User Profile, Directory User Profile, Identity Provider User Profile.
An Okta API token is set to expire after 30 days. What is a valid method of preventing the token from expiring?
A: Perform an action that requires the use of the API token. The expiration counter will reset once the API token is used.
What are the benefits of using an Okta group?
A: Ability to contain end users from different identity sources.
An Okta administrator wants to enable self-service password reset workflow for Okta sourced users. What actions are possible?
A:
- The administrator can customize the ‘Forgot Password’ email template. The ‘Forgot Password’ template is a configurable template under Emails and SMS.
- The administrator can restrict password reset workflow access to only users who are on-premise. The Password Policy rules have a configurable network parameter.
What options are allowed as verification for self-service password reset?
A: Email, Voice and SMS
What are NOT functionalities of the Okta Browser plugin?
A:
- Stores passwords on an end user’s local machine.
- Checks for common passwords in an Okta enabled Secure Web Authentication (SWA) application.
It can only check for common password use only for the primary authentication of the Okta user itself.
- Ensures sufficient password complexity.
It is ensured at Okta by setting Password policies , which do NOT have an effect on passwords passed or generated by the Okta browser plugin.
- Deprovision user accounts in applications
What features are available with Okta MFA?
A:
- Ability to require that all users enroll in Okta verify.
- Ability to only allow IT administrators to enroll with RSA SecurID. Both enrollment and enforcement of factors is controlled at the group level.
- Ability to allow users to choose to enroll in one MFA from a list of configured factors.
An Okta end user has a pending request for access to Box. Why would the end user might NOT be assigned to Box?
A:
- The approver for the workflow is deactivated and no one will receive the request and the user’s request is still pending.
- The only group containing the approver used in the approval process has been deleted. If the only one group containing the approver was deleted, then no one will receive the request and the user’s request is still pending.
What information can an administrator find in the system log?
A: Suspicious activity.
What are the application sign-on methods that Okta supports?
A:
- Secure Web Authentication (SWA)
- Security Assertion Markup Language (SAML 2.0)
- OpenID Connect
What is the App Integration Wizard (AIW) used for?
A: Add applications that do NOT have prebuilt integrations.
What are valid ways to activate an Okta user account?
A:
- Activate the Okta user account through the Okta Administrator Application
- Activate the Okta user account through the Users API call.
What is a benefit of using SAML over SWA?
A: SAML authentication is more secure.
What are the functions of the Okta browser plugin?
A:
- Automatically inserts passwords on ‘password update’ pages.
- Allows for automatic application sign-in
- Allows end users to initiate an Okta logon from the web page
- Automatically fills in credentials on sing-in pages
What happens when an Active Directory integration is deactivated?
A: The AD users become Okta-sourced if not linked to another profile source.
Which capability is available for ALL prebuilt Okta Integration Network (OIN) applications?
A: Group application assignment.
What happens if all MFA factors are optional in an Enrollment Policy when end users enroll?
A: End users are required to choose a factor to enroll.
What default permission does an Active Directory service account have at installation?
A: The ability to JIT provision users to Okta.
What would be a recommended way for an Okta Administrator to open a case with Okta Support?
A: Call the toll-free number shown in the Okta Help Center.
What is a standard technology that Okta uses for identity verification?
A: SAML.
What is an example of an Identity as a Service (IDaaS) benefit provided by Okta?
A: Redundant architecture to ensure availability.
What is an example of an Identity as a Service (IDaaS) benefit provided by Okta?
A: Redundant architecture to ensure availability.
Which authentication method would allow a company to eliminatae application-specific passwords?
A: Web Services Federation (WS-Fed).
What would be a best practice authentication method for application authentication?
A: SAML.
Which factor types are available when configuring MFA for Okta-sourced users?
A:
- Okta Verify
- SMS Authentication
- Google Authenticator
- FIDO2 (WebAuthn)
- Symantec VIP
- On-Prem MFA
- RSA SecurID
- Email Authentication
What would NOT be a supported feature of Universal Directory?
A:
- API Security
What are the features of Universal Directory?
A:
- Schema Discovery
- Data transformation
- Attribute Level Sourcing
What is a possible scenario for enabling Just-in-Time (JIT) Provisioning into Okta?
A: The Okta Active Directory (AD) Agent is installed and configured.
Which strategy should be used to provision user accounts from Okta to an on-premises AD or LDAP directory?
A: Agent-based Provisioning.
Which action CANNOT be performed through self-service by an end user withouut IT assistance?
A: Configure administrator access using the Okta user home page.
How might Okta-sourced and directory-sourced users gain the same application access?
A: Create an Okta group and manually add each of the user.
How can an end user reset their forgotten Okta password without calling their help desk?
A: SMS.
Which action will allow users to access applications that do NOT support SAML?
A: Configure the applications for Secure Web Authentication (SWA).
How could you differentiate the unique sign-on policies for Okta administrators from end users?
A: Group the administrators & create a sign-on policy for them.
Which default base attribute can be marked as NOT required for Okta-sourced users?
A: Last Name.