WorksheetsNew quiz
Total questions: 119
Worksheet time: 1hrs 29mins
What actions can be taken on a Suspended user?
Deactivate
Assign Application
Delete & Reset Multifactor
Activate
Reset Behavior Profile
Users can be unassigned from an app in the following ways:
The organizational unit (OU) that contains the user has been deselected.
The user is removed from a group that is assigned to the app.
The user no longer appears in imports after being deactivated in the app.
The user is deactivated in OKTA.
This advanced option allows user to see the plugin logs in developer console
Reset OKTA plugin
Enable OKTA plugin logs
Enable OKTA Browser logs
Use local Javascript
Which of the following statements are true ?
It is not possible to import AD user that has no first and last names
It is possible to create an OKTA mastered user that has no first and last name
It is not possible to create an OKTA mastered user that has no first and last names
It is possible to import AD user with no first and last names provided both AD and OKTA mastered user profiles have first and last names marked as optional
The following configurations can be set in the Provisioning Settings from OKTA to AD
Enable Password Sync
Provide an email address for activation emails
Configure AD username format
Create User account
Deactivate User account &
Update user attributes in AD whenever OKTA user profile is changed (for an OKTA mastered user)
Global Notifications can be set by these types of administrators
Super Admins
API Access Management Admin
Org Admins
Group Membership Admin
App admins
All websites that are granted access to your OKTA organization thru API must be configured here
Authorization Servers Claims
API token
Trusted origin
Authorization servers Scopes
OKTA supports these methods for provisioning
SCIM standard
WS-Fed
OAUTH 2.0
Template Plugin App
SWA
The default recovery method in password policies and AD delegated authentication is
SMS
Security Question
Voice call
What is the maximum validity period that can be configured for Reset\Unlock recovery emails?
15 days
1 week
1 month
180 days
90 days
Administrator can set Device Trust in a Password Policy
FALSE
TRUE
Password Age can be configured for the following types of users
Both OKTA and Active Directory mastered users
Some options of Password Age can be configured for AD mastered users
OKTA Mastered users only
AD mastered users only
What is the Default format of Username in OKTA?
First name
Email address
Display name
Last name
You can create an OKTA user account (user profile) by
Importing data using CSV file
Adding a Person manually in OKTA application
Importing data through API
Importing from external application or directory
Administrators can set Security Answer Length in the Password Policy
FALSE
TRUE
What are the options available for the administrator when trying to expire password for a user?
Create a temporary password
Send Reset Password Link
Send activation email to user
Send a temporary password to the user
Which actions can an administrator NOT do from the Dashboard?
Add Groups
Add an Admin role
Add Application
Run Reports
Unlock People & Deactivate Users
Who CANNOT remove users from groups?
App Admin
Org Admin
Mobile Admin
API Access Management Admin
Group Admin
Dashboard tabs can be managed by these administrators
Application admins
Super Admins
Mobile Admins
Org Admins
What are the few custom template apps available in OKTA?
Template WS-Fed app
Template Basic Auth app
Template Plugin app
Template Basic App
OKTA's SWA can be used for applications that cannot be setup using SAML or WS-Fed
TRUE
FALSE
The following statements apply to the Groups in OKTA
A provisioning group should be created in order to provision users to Active directory
Group priorities can be set when a single user is part of multiple groups that are assigned to an application
Security policies can be assigned to groups
Groups can be created natively in OKTA or pushed to directory or applications that support groups
Factor Sequencing supports below factors as primary method of authentication
SMS
OKTA Verify
Voice Call
Security Question
Password
Which one is a true statement about Group Rules?
Groups automate provisioning to applications
Require attributes to come from OKTA user profile
Only super admins and org admins can edit rules.
Group rules can be used to assign users to admin groups.
You can only use string attributes in basic condition group rules.
&
Only group admins who manage all groups can search for and view rules.
What is true about OKTA Verify MFA?
OKTA Verify can be used either with Push notification or by entering a verification code
If user loses the device in which OKTA Verify is setup, OKTA Verify can be reset only by Administrator or IT
OKTA Verify is a strong MFA factor and is recommended to setup as a required factor
User will be able to setup OKTA Verify on multiple devices
Multiple accounts can be configured in OKTA verify as long as they belong to different orgs
&
Users will be able to reset MFA factor as long as they can login to their account and a device
Administrators will be able to exclude users from a Password Policy
FALSE
TRUE
Import Safeguard feature gives OKTA an ability to
Define threshold for org wide unassignments
Halt import that cause mass app unassignments
Filter users and groups during import
Prevent accidental loss of user accounts
Define threshold for app unassignments
Which OKTA feature can you use to add custom attributes to your OKTA user profile?
Profile Master
Profile Editor
Profile Mapping
Active Directory groups
Following are true when a rule-managed user is manually removed from a group
User loses access to applications managed by group rule
User cannot be assigned to any application
User cannot be added to any group
User is automatically added to the rule's, Except The following users field.
Name some of the social identity providers
Box
An OKTA Service Account can be created by
OKTA Provisioning
OKTA AD Agent
OKTA Application Integration Wizard
OKTA OPP agent
An Application specific Factor Enrollment policy can restrict user not to enroll in a certain policy
TRUE
FALSE
Authorization server configured in OKTA can act as an OpenID Connect ID provider
TRUE
FALSE
Which provisioning option does not support JIT enabled AD instances?
Licenses\Roles Management Only
Profile Sync
User Sync
Universal Sync
Is this a capability of OKTA Browser Plugin?
When end users are on a password-update page of an OKTA-enabled SWA app, the pop-up banner can automatically insert their current password.
Automatically sign in to apps provided this feature is set in the application
Automatically initiate sign into OKTA
For OKTA admins, an Admin link is available in the Your Apps dialog when sign in to OKTA
Switch between OKTA accounts provided you have previously trusted the account
Select all that is true for Lock Out settings
Show lockout failures is Early Access feature
Minimum setting is 1 minute and maximum is 999 mts for an account to be unlocked
Users have an option to unlock themselves either in OKTA only or OKTA and AD
Automatic unlock of Account is not set by default
&
Maximum number of invalid login attempts before a user gets locked out is 100
For AD mastered users, Maximum failed sign in limit in OKTA has to be set lower than that of AD to prevent AD lock out
What options are available for an administrator when a user is pending action?
Delete the user
Reset multifactor
Resend activation email
Set password and activate
What is true about Single Logout feature?
Allows logout from application and OKTA at the same time
SWA, SAML and OIDC support this feature
Configured for SP initiated flow only
Requires a digital signature for SLO request
A Provisioning error similar to this Automatic provisioning of user John Doe to app Salesforce.com failed: Matching user not found is seen because
·
Application is trying to provision into OKTA and did not find matching user
OKTA is trying to provision a user in target application and is not able to find the partial match on first or last names
OKTA is trying to provision a user in target application but Create user is not enabled in Provisioning settings of the application
OKTA is trying to provision user but user with exact match on username is not found
Is this an action that can be performed on an application?
Suspend
Activate
&
Assign to users and groups
Delete
Deactivate
Refresh application data
When an Administrator sets username and password for an application
Credentials are not exposed to end user
Password reveal feature is unavailable to the users
Password is visible to admin only when its created
If the chosen app was previously assigned to an established OKTA group, group members will require manual updates of usernames and passwords for each user.
What is true about Network Zones?
LegacyIPZone is created by default and cannot be deleted
OKTA verifies user's IP from the IP zone if configured in Sign on Policy and decides on access to OKTA Org
Network zones can be IP or Dynamic zones
Blacklisted Ips can be configured to prevent access from certain IP addresses
Can you retry the tasks that failed with the error "Insufficient licensing"?
No
Yes
Is this a feature for a group to access app outside OKTA using OKTA Browser Plugin?
No option available
Enable OKTA toolbar for group
Add a group to OKTA quick access
Enable a group for OKTA Browser plugin app access
Are GA (Generally Available) features added to the orgs automatically?
Administrators have to explicitly enable GA features
GA features are enabled for all eligible orgs automatically
No, OKTA support have to enable them explicitly
GA features are enabled for all eligible orgs automatically except some may have to go through a release process before getting released to all orgs immediately after release
When an Identity Provider authentication is used, IdP routing rules can be configured to direct end users to Identity providers login based on these factors
User's domain
User's location
All of them
User's device
User's app access
&
User's attributes
When a group is pushed to Active Directory, OKTA is the profile master of the group
FALSE
TRUE
What is the allowed length range for a password?
8 to 16 characters
8 to 30 characters
4 to 16 characters
4 to 30 characters
Which is a true statement about API token?
The category for API events in system log is Token Lifecycle
API tokens are valid for 30 days and automatically renew when they are used with an API request
The only time you can view the token is during the creation process.
OKTA active AD agent tokens are managed by OKTA only
Tokens are only valid if the user who created them is active
Can you remove a Group from Active Directory provisioning?
Yes, by removing the group from AD assignments
No that cannot be done
User can be activated when user is in the following state
Suspended
·
Inactive
Staged
Deactivated
Pending Activation
These administrators do not have their own set of available email notification types
Third Party Admin
App Admin
Mobile Admin
Org Admin
Report Admin
This option is available only if change password is enabled
·
perform self-service password unlock
perform self-service password reset
perform self-service password reset and unlock
Auto-confirm imported users can be configured during which process
Provisioning (To OKTA)
General Settings
Directory Integration
Manual import
How many default attributes can a OKTA master profile offer?
50 attributes
31 attributes
30 attributes
25 attributes
OKTA Browser Plugin uses this to connect to the SWA apps
TLS
SSL pinning
SSL
URL string match
You can create Custom User Types for the following types of profiles
OKTA User Profile only
OKTA and Application User Profile only
OKTA and Identity Provider User Profiles
Application User Profile only
These are few common issues seen if SAML is configured incorrectly
User experiences endless loop being redirected to OKTA login and then to application's standard login page
Identity Provider certificate has expired
Throws an error saying username is invalid or not found
User is taken to standard login page of Application instead of SSO page
Which Administrator can manage Profile Editor but not Profile mappings?
API Access Management Admin
Group Admin
Org Admin
App Admin
Bulk password reset cannot be performed on OKTA mastered users
TRUE
FALSE
How can you enable Organizational Unit updates on an OKTA user profile?
By enabling "Update OU when the group that provisions a user to AD changes " in Provisioning
During Group Push operation
During Incremental Import process
During Directory Integration
Which app simulates IDP initiated flow for a SP initiated app?
Bookmark simulator
IDP Simulator app
Bookmark App
SP initiator
OKTA username format can be one of these
UPN (User Principal Name)
<Sam account name><configurable suffix>
Custom name using OKTA expression language
<Sam account name>@<domain name>
Email address
You can configure an OKTA User Profile to use a speicific Profile Master using the following feature
Master priority in OKTA user profile
Changing the order in Profile Master
Import from a specific app or directory
Converting an individual application assignments to group assignments will result in
Users will losing access to application, if group is unassigned from the application
deactivating the individual assignments
·
disable provisioning individual users
User properties being managed by the group
Is this a capability to configure from Appearance settings?
Change color scheme on My Applications home page
Add a logo to the org
Upload Sign in background image
Add custom links to your home page
Enable OKTA footer on End users home page
Matching rules
Allow partial match on first and last name
Allow exact match on a single or combination of attributes
Auto-confirm partial or exact matches
Auto activate new users
Allow exact match to OKTA user if email matches
&
Auto confirm new users
Administrator finds this error in Dashboard->Tasks page in OKTA. What could be possible cause of this error? Insufficient account permissions on the account used to setup the API config
API integration user account might have lost the required permissions
Password for the API integration user might have changed
API username might have changed
API integration account might have expired
When a message "User is now in one-time password mode" is displayed on People page, what action might have taken on the user?
Reset Password
Unlock user
Activate user
Expire Password
What are some of the limitations for Factor sequencing?
Cannot configure in Application sign on policies
If an org uses both Delegated authentication and Factor sequencing , then AD account status is not checked during sign-in flow unless the password MFA factor is enabled
SAML based MFA or Identity Providers cannot be used as part of Factor Sequencing chain
If the sign-on policy has multiple factor chains, the user must be enrolled in the first factor from at least one factor chain.
What is true about the deactivation of an user?
Can be deleted
Deactivated user loses access to OKTA and unassigned from applications
Deactivated user can login but cannot access applications
Can be reactivated
Deactivated user cannot login to OKTA
&
Can activate in bulk
Which feature can be used to activate the users and update their group memberships when users are authenticated using AD?
Just-In-Time provisioning with delegated authentication
Directory Integration
Agentless Desktop SSO
Incremental Import
SAML can either be used in IdP initiated flows or SP initiated flows
TRUE
FALSE
What are some of the key benefits of Social Authentication?
No need to maintain separate user database, sign on and authentication infrastructure
Users do not need to remember additional password
Ensure quick and easy registration to custom apps
Easily assign applications
JIT can be enabled to create OKTA user profiles
Multiple AD groups can be mapped to a single OKTA group
TRUE
FALSE
MFA can be configured at the following level
OKTA org level
OKTA org level or Application level or both
Application level
OKTA org level or Application level
Admins will only receive emails for groups, apps, or users that they have permission to view.
TRUE
·
FALSE
Which actions can be taken on import results (imported users in Import screen)?
Confirm the Exact match user assignment which will import the user into OKTA and link to existing matched OKTA user
Select an existing OKTA user and link the imported user
Update user attributes
Confirm import of New User when there is no matching user in OKTA
Ignore the assignment which will not import the user into OKTA
Universal Directory allows you to construct custom OKTA usernames or application usernames with Universal Directory's data and expression language.
FALSE
TRUE
Network zones may be incorporated into
VPN Notifications
Password Policies
Factor Enrollment policies
Application Sign-on policies
IWA
Which statement is true about password reset?
Administrator can reset passwords even for a suspended user
A self service option is available for password reset
When a password is reset, all applications assigned to the user that support Provisioning and are Sync Password enabled are updated with the new password.
A temporary password can be sent to the OKTA mastered user after resetting the password
Which type of Administrators CANNOT do Password and MFA resets?
Help Desk Admin
Group Admin
Org Admin
API Access Management Admin
Report Admin
You can configure the following feature not to create new users during an import
Disable activate email
Do not import users
JIT provisioning
Schedule import
Which one is a true statement about Group rules?
By default, a newly created rule is active
OKTA Expression language can be used to create complex rules based on a combination of user or group attributes
Group Rules are org wide rules
User cannot be in pending or inactive state to move to an assigned group
What is the minimum and maximum number of characters a password recovery answer should contain (security answer)?
1-50 characters
4-30 characters
4-50 characters
8 - 50 characters
In which policies, can you exclude or include Users based on Location (Network Zones) in which policies?
Application Sign on and OKTA Sign on Policies
OKTA Sign on policy
Application Sign on Policy only
OKTA Sign on, Application sign on and Password Policies only
Factor enrollment policy
&
Password Policy
How is the username identified in Password Complexity requirements?
Display Name field on OKTA master profile
Username field on OKTA master profile
string before @ symbol in user's email address for OKTA mastered users
string before @ symbol in user's email address for Active Directory mastered users
Display name for Active Directory mastered users
Non pre-built OIN applications can be connected through these protocols
OID
SAML
SWA
SCIM
Kerberos
Is this an Early Access feature?
Windows Autopilot Enrollment Policy
Allow end-users to quickly access everyday apps in the OKTA Browser Plugin
Risk Based Authentication
Import Monitoring Dashboard
Phishing Resistant OKTA Verify Push
&
Factor Sequencing
Which Profiles allow creation of new custom attributes in schema?
Identity Provider profiles
Directory profiles
Application user profile
OKTA user profiles
What is required to setup AD authenticated on-prem applications in OKTA?
Delegated Authentication
SWA enabled application setup
SAML enabled application setup
Use OKTA username and password to sign into OKTA
Is this a pre-requisite for configuring Group push?
API authentication must be enabled
Provisioning to app should be enabled
For AD, OKTA service account must have permission to create groups
OKTA group must be assigned to app before push
All members of the group to be pushed must have been provisioned and assigned to app before group push is configured
Which provisioning option does not allow editing users from within Office 365 directly?
Universal Sync
Profile Sync
Licenses\Roles Management Only
User Sync
End users will be able to add apps using OKTA Browser plugin, Provided the app is allowed to be added in the Application Self Service settings
FALSE
TRUE
Super Admins can set default email notifications for all administrators
TRUE
FALSE
An API token is issued for a specific user and all requests with the token act on behalf of the user.
FALSE
TRUE
Federation Broker mode is an Early access feature. What is not true about this feature?
Its not available for OIN apps
Provisioning is not available if this feature is turned on
Import is not available along with this feature
Users or groups can still be assigned to the application
Works for SP initiated flows only
Disconnect from AD option is accessible from
Administrator Dashboard
Directory Integrations->Assignments
Application Assignments
Directory->People
OKTA uses this to transform profile attributes
OKTA Expression
OKTA Expression Language
OKTA Expression editor
OKTA Expression qualifier
What are some of the pre-requisites to install an OKTA AD agent?
Install Agent on 2 or more host servers to ensure high availability
NET 4.5.2 or higher must be installed
Host servers should be a member in the AD domain
Host server and the users can be different domain as long as host server is in the same AD forest
if there are 30k or more users, deploy minimum of 3 or more OKTA AD agents
As part of Password Policy, Self service password unlock can be configured for
OKTA mastered users
AD mastered users
Both OKTA and Active Directory mastered users
Cannot be configured as part of password policy
Which option is not available for Password unlock?
Voice call and Email
SMS and Email
&
SMS and Voice call
Voice Call
SMS
Which Application Self-service option should be enabled to configure Access request workflow for an organization application?
Allow users to add org-managed apps
Allow users to add personal apps
Approval Required
Allow users to email "Technical contact" to request an app
This option when enabled will not allow browser to remember passwords for the apps
Prevent web browsers from saving sign-in credentials
Disable browser password prompts
Recommend strong passwords for apps
Prompts to save apps to your Dashboard
Which feature allows to add additional user attributes during import?
Provisioning mapping
Schema discovery
Import from CSV
source from profile master
Import User Schema
OKTA Policy Framework principle is based on XACML principle which means
More restrictive policies are of lowest priority
Default policies should be on top ladder
Follows top down approach
Default policies should have highest priority
More restrictive policies should be of highest priority
Which self-service options can be configured for account recovery?
OKTA Verify
SMS
Voice Call
Yubi Key
When integrating OKTA with Office 365, its recommended to use an Admin account which is not part of the domain that's being federated because
Admin account that's outside the domain cannot be provisioned
To enable specific logging
To prevent lock out of admin account
To allow back door access to Office 365 in case of troubleshooting
Select all that is true for Password Age configuration
Users will not receive expiry warning if the password expiry after setting is set to less than 6 days
Password expires after setting does not appear for AD mastered users
Minimum time required between password changes can set to a maximum value of 9999 mts
Password expiry cannot be accurately calculated for users created before March 10, 2014
Maximum number of passwords that the user can use before he can reuse the password is 30
&
Maximum value that can be set for password expiry and also for prompt users to change their password is 999 days
Universal Directory supports
Directory profiles
Active Directory group profiles
Application profiles
&
OKTA user profiles
Identity Provider Profiles
OKTA group profiles
Password Policies can be applied on the following types of users:
OKTA, Directory and Identity provider profiles
Directory Mastered Users only
Application mastered
OKTA and Directory Mastered Users only
OKTA Mastered users only
Which option can warns users when orgs other than the primary OKTA org are accessed?
Turn on black list orgs
Turn on security warning
Turn on security warning and anti-phishing whitelist
Turn off whitelist orgs
API tokens issued to OKTA agents can be revoked by Administrator regardless of the token state.
FALSE
TRUE
You can choose to Auto-activate AD users
Cannot auto-activate users
When setting up Provisioning
When setting up Self service options
During Import process
When an application is mentioned as OKTA Verified, it means
It means you can provision users to applications
OKTA verified is same as SWA
Application was created either in OIN or by OKTA user community and verified by OKTA engineers
Application has been verified and tested by OKTA community
Application was created by OKTA Engineers
Which option allows Password reveal feature to be available to admin only?
Administrator sets username and password
Administrator sets username and user sets password
Users share single username and password set by Administrator
Administrator sets username and password same as OKTA username and password
User sets username and password
An administrator will be able to reset selected MFA factors when resetting MFA for all users
FALSE
TRUE
What is the retention period for System Logs?
6 months
None
3 months
1 year
Password soft lock functionality can be implemented for AD mastered users by
Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number equal to AD failed sign ins
Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number more than that of AD failed sign ins
Configuring Self Service option for Unlock Accounts
Setting the value of "Lock out user after X unsuccessful attempts" in Active Directory Password Policy to a number less than that of AD failed sign ins
