Strengthen Security Using the Okta Policy Framework Flashcards

1
Q

Default API rate limits may vary depending on the specific endpoint URI being
accessed?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does Okta threat insight work?

A

It helps protect customers from credential based attacks AND It monitors all
authenticators across Okta’s network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of setting up Network Zones in Okta

A

To control access to specific resources based on IP address AND To create
geographic restrictions for user access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

An IP Zonne is used to define a range of gateway or proxy IP’s while a Dynanmic
Zone defines a zone rby country/region, ASN or IP type?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following is an example of authenticator method with device bound and
hardware protected characteristics

A

Okta Verify Push

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Okta requires assurance levels are satisfied before it allows the end user to access
the app. The assurance levels can be specified in

A

Authentication Policies and Global Session Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What determines the order in which policies or rules are evaluated for a context
match in Okta?

A

The priority assigned to each policy or rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is assurance in the context of Okta’s Security Policy framework?

A

The level of assurance given for the security of framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Preset authentication policies are only available for certain types of applications?

A

False (available to all)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which of the following statement is correct about authentication policies?

A

They are only evaluated if a valid Okta session already exists

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Global session policies are evaluated after authentication policies?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the Global session policy control in Okta?

A

The duration of an overall session

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

All the self-service recovery authenticators can be used for authentication?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What settings can administrators configure in the password policy in the Okta
Identity Engine (OIE)?

A

Password complexity and length requirements, Self-service recovery options

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is this a true Statement about Global Session policy persistent cookies?

A

If a user quits their browser and repoens the browser, the browser session is
persisted unless the user has signed out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Is this a condition and administrator can edit in the default Global session policy?

A

Primary factor

17
Q

Is this a true statement about adding rules to a new policy

A

The policy must have at least one rule

18
Q

Is this a true statement regarding Okta sign-on policy rules

A

A rule with a priority value of 1 takes precedence over all the rules

19
Q

Is this the policy to implement is an administrator need to ensure that all users in the
contractor group are prompted for MFA when they log on to Okta

A

Okta sign-on Policy

20
Q

A company increase security policies org security policies for both employees and
admin, company also whats amins to use okta verify as a second factor, is this the
correct way to administer?

A

Policy for admins then policy for employees