Strengthen Security Using the Okta Policy Framework Flashcards
Default API rate limits may vary depending on the specific endpoint URI being
accessed?
True
How does Okta threat insight work?
It helps protect customers from credential based attacks AND It monitors all
authenticators across Okta’s network
What is the purpose of setting up Network Zones in Okta
To control access to specific resources based on IP address AND To create
geographic restrictions for user access
An IP Zonne is used to define a range of gateway or proxy IP’s while a Dynanmic
Zone defines a zone rby country/region, ASN or IP type?
True
Which of the following is an example of authenticator method with device bound and
hardware protected characteristics
Okta Verify Push
Okta requires assurance levels are satisfied before it allows the end user to access
the app. The assurance levels can be specified in
Authentication Policies and Global Session Policies
What determines the order in which policies or rules are evaluated for a context
match in Okta?
The priority assigned to each policy or rule
What is assurance in the context of Okta’s Security Policy framework?
The level of assurance given for the security of framework
Preset authentication policies are only available for certain types of applications?
False (available to all)
Which of the following statement is correct about authentication policies?
They are only evaluated if a valid Okta session already exists
Global session policies are evaluated after authentication policies?
False
What does the Global session policy control in Okta?
The duration of an overall session
All the self-service recovery authenticators can be used for authentication?
True
What settings can administrators configure in the password policy in the Okta
Identity Engine (OIE)?
Password complexity and length requirements, Self-service recovery options
Is this a true Statement about Global Session policy persistent cookies?
If a user quits their browser and repoens the browser, the browser session is
persisted unless the user has signed out
Is this a condition and administrator can edit in the default Global session policy?
Primary factor
Is this a true statement about adding rules to a new policy
The policy must have at least one rule
Is this a true statement regarding Okta sign-on policy rules
A rule with a priority value of 1 takes precedence over all the rules
Is this the policy to implement is an administrator need to ensure that all users in the
contractor group are prompted for MFA when they log on to Okta
Okta sign-on Policy
A company increase security policies org security policies for both employees and
admin, company also whats amins to use okta verify as a second factor, is this the
correct way to administer?
Policy for admins then policy for employees