WG MFA Flashcards

1
Q

Which of these must a RADIUS client have in order to connect to a RADIUS server? (Select two.)

a. The correct IP address known to the RADIUS server
b. The public key of the RADIUS server
c. The shared secret configured on the RADIUS server
d. The certificate of the RADIUS server
e. The administrator account credentials on the RADIUS server

A

A and C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you specify the domain example.local in an LDAP query? (Select one.)

a. ou=example, dc=local
b. dc=example, ou=local
c. dc=example, dc=local
d. ou=example, ou=local
e. ou=”example.local”

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of these authentication factors is the least secure for MFA? (Select one.)

a. Hardware token
b. Software token
c. QR code
d. Push notification
e. One-time password

A

E

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You can install the Logon app on which of the following operating systems? (Select two.)

a. Windows10/11
b. macOS
c. Linux
d. iOS
e. Android
f. Windows7

A

A and B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

You must install the AuthPoint Gateway on an existing RADIUS or LDAP server.

a. True
b. False

A

B False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

On the AuthPoint Users page, what does the yellow dot next to a username indicate?(Select one.)

a. The user account is locked.
b. The user account is blocked.
c. The user account is quarantined.
d. The user forgot their token.
e. The user account is not yet activated.

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where in the AuthPoint management UI do you configure the query AuthPoint uses to synchronize users from an LDAP server? (Select one.)
a. Management > Resources
b. Management > External Identities
c. Management > Gateway
d. General > Download
e. General > Settings

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The AuthPoint Gateway functions as both __________ and __________? (Select two.)

a. an LDAP client
b. an LDAP server
c. a RADIUS client
d. a RADIUS server

A

A and D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AuthPoint only imports LDAP users that have an email address.

a. True
b. False

A

A True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Where do you specify the allowed authentication methods for a resource? (Select one.)

a. In the resource configuration
b. In the authentication policy configuration
c. In the user configuration
d. In the policy object configuration
e. In the IdP portal resource

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the AuthPoint metadata used for? (Select one.)

a. To configure SAML authentication with a third-party service provider
b. To configure the Logon app for user authenticationon a Windows computer
c. To configure token security for the AuthPoint Mobile App
d. To configure a VPN client to use AuthPoint for MFA

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

One of your users does not want to use their personal phone for work, and has asked if they can use their tablet instead. This is not possible.

a. True
b. False

A

B False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

If you plan to deploy the Logon app on Windows and Mac computers, you can use the same configuration file for both platforms.

a. True
b. False

A

A True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A user lost the primary phone that they use for authentication. They did not protect their tokens with a PIN or biometrics. What security action should you take?

a. Delete the user account.
b. Block the token.
c. Block the mobile device.
d. Enable Forgot Token.
e. Migrate the user’s tokens to a new device.

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

During the AuthPoint Gateway installation, you get a permission error. You resolve the permissions problem, but when you try again the Gateway installation still fails. What could be the problem? (Select one.)

a. The LDAP System Account has the wrong credentials in AuthPoint.
b. You are trying to install the 32-bit version of the AuthPoint Gateway on a 64-bit computer.
c. The NPS role is not installed on the AD server.
d. The Gateway Registration Key is invalid because it has already been used.

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which resource type does not support the use of the QR code MFA option? (Select one.)

a.RADIUS
b.SAML
c.LogonApp
d.IdPPortal
e.ADFS

15
Q

If you uninstall and then reinstall the AuthPoint Gateway, you can re-use the same registration key when you try to install again.

a. True
b. False

16
Q

To import a third-party hardware token in your AuthPoint account, you must have:(Select two.)

a. A key file
b. A seed file
c. A token serial number
d. A mobile phone
e. An activation code

17
Q

In AuthPoint, SAML resources are the applications and services that can use SAML authentication. Which of the following is a SAML resource? (Select two.)

a. Salesforce
b. Logon app
c. An SSL VPN client
d. ADFS
e. Microsoft 365

18
Q

AuthPoint is configured to automatically block a user after ten consecutive failed password attempts, and a token after three consecutive failed token authentications. A hacker with stolen credential attempts to log in as one of your users using the wrong password three times. After the third failed authentication, the user becomes blocked.

a. True
b. False

19
Q

You can find log messages for the Logon app in the AuthPoint Gatewaylog files

a. True
b. False

20
Q

You can send RADIUS requests to a secondary AuthPoint Gateway when the primary AuthPoint Gateway is online.

a. True
b. False

21
Q

What steps are required before you install the AuthPoint Gateway? (Select three.)

a. Make sure the computer you will install the Gateway on has Internet access.
b. Make sure the computer you will install the Gateway on can communicate with your RADIUS clients and Active Directory or LDAP database.
c. Install the Gateway software on all computers in your network with AD Group Policy.
d. Make sure the Gateway configuration file is in the same directory as the Gateway installer software.
e. Make sure you have the Gateway Registration Key for your Gateway.

A

A, B and E

22
Q

Each LDAP external identity can only be added to a single primary AuthPoint Gateway.

a. True
b. False

23
You configured a RADIUS client resource for your company’s VPN, but your AuthPoint users cannot authenticate. Where can you look to start troubleshooting the RADIUS authentication failure? (Select two.) a. The security event logs on the VPN client computer b. The Gateway LDAP logfile c. The VPN client logfile d. The Gateway RADIUS logfile e. The firewall authentication logfile f. The WatchGuard Cloud audit log messages for AuthPoint
D and F
24
The IdP Portal resource enables users synced from an LDAP database to reset their own passwords. a. True b. False
B False
25
Packets sent between a RADIUS client and RADIUS server are fully encrypted. a. True b. False
B False
26
What is required to setup the Logon app? (Select three.) a. The AuthPoint Gateway must be installed on your network. b. You must configure a Logon app resource. c. The contents of the configuration file must be available to the installer. d. You must configure an external identity to sync your LDAP users. e. The Logon app must be connected to the Internet the first time you authenticate. f. You must approve a push notification to finish the installation.
B, C and E
27
When a user authenticates with the Logon app for Windows or Mac, the user’s password is sent to AuthPoint. a. True b. False
B False
28
Which of these distinguished names are correctly formatted? (Select two.) a. cn=trainer1,ou=trainingaccounts,dc=traininglab,dc=local b. cn=Trainer1,ou=TrainingAccounts,dc=TrainingLab,dc=Local c. dc=Trainer1,ou=TrainingAccounts,cn=TrainingLab,cn=Local d. cn=trainer1.ou=trainingaccounts.dc=traininglab.dc=local e. cn=trainer1,ou=trainingaccounts,dc=traininglab.local
A and B
29
Which MFA options can you use to authenticate users using RADIUS with MS-CHAPv2?(Select one.) a. Push, OTP, and QR code b. OTP and QR code c. OTP only d. Push and OTP e. Push only
E
30
You added an external identity and synced a group of LDAP users. Some users were not synced. What could be the cause? (Select one.) a. Those users did not have an email attribute. b. The AuthPoint Gateway could not reach the external identity. c. Those users do not have an AuthPoint token. d. Those users have expired passwords. e. The external identity is not configured correctly.
A