Which is a / are best-practice(s) in a SAML 2.0 situation?
Solution: To never enable SAML for all your end-users
Reveal answer details Close answer details
Correct answerB
Okta · OKTA-CERTIFIED-ADMINISTRATOR
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which is a / are best-practice(s) in a SAML 2.0 situation? Solution: To never enable SAML for all your end-users Reveal answer details Close answer detailsCorrect answerB
Single choice
Any ... <answer_goes_here>'s credentials verified under "Test API credentials" in an Office365 app Solution: Office 365 user Reveal answer details Close answer detailsCorrect answerB
Single choice
As an Okta best-practice / recommendation: Okta encourages you to switch from Integrated Windows Authentication (IWA or DSSO) to agentless Desktop Single Sign-on (ADSSO). Okta is no longer adding new IWA functionality and offers only limited support and bug fixes. Solution: Both statements are true Reveal answer details Close answer detailsCorrect answerA
Single choice
How can SAML provision attributes via JIT? Or even create users? Solution: By including specific information in the GET API call Reveal answer details Close answer detailsCorrect answerB
Single choice
On a Windows machine, which is the right behavior if you try to sign into your Okta org and agentless DSSO is properly configured for it? Solution: You will be automatically redirected to your end user's apps dashboard without entering any credentials Reveal answer details Close answer detailsCorrect answerA
Single choice
When you call a GET API call for users / groups / and other such objects, the response is usually Paginated, in case these are a lot of objects returned. What do you do in order to retrieve all objects? Solution: You call the very same API with the help of a different token, hence will return the next page of objects Reveal answer details Close answer detailsCorrect answerB
Single choice
When a user signs out of Okta, if they are using IWA, they'll be redirected to the Sign In page and without inputting credentials they'll be signed back in Solution: Statement is true Reveal answer details Close answer detailsCorrect answerA
Single choice
When does Okta bring LDAP roles into Okta? Solution: Only during LDAP JIT Reveal answer details Close answer detailsCorrect answerB
Single choice
With Okta you federate the 'Office 365 tenant name' (which is the default Microsoft domain you have) or the 'Office 365 domain'? Solution: You federate with Okta only the 'Office 365 domain' Reveal answer details Close answer detailsCorrect answerA
Single choice
Okta has a json representation of objects such as 'users', json schema interchanged on API calls, as an example, but what about the format of information regarding of a user going to a SCIM server for creating the user in an On Premises application? Solution: Format is different: yml Reveal answer details Close answer detailsCorrect answerB
Single choice
With Okta you federate the 'Office 365 tenant name' (which is the default Microsoft domain you have) or the 'Office 365 domain'? Solution: You federate with Okta both the 'Office 365 tenant name' and the 'Office 365 domain' Reveal answer details Close answer detailsCorrect answerB
Single choice
With agentless DSSO (Desktop Single Sign-on), you still have a need of deploying IWA Agents in your Active Directory domains to implement DSSO functionality. Solution: The statement is true, as agentless DSSO means no AD agents, not no IWA agents Reveal answer details Close answer detailsCorrect answerB
Single choice
Provisioning actions between cloud-based apps / on-premises apps and Okta are completed by using: Solution: The OIDC standard Reveal answer details Close answer detailsCorrect answerB
Single choice
On a Windows machine, which is the right behavior if you try to sign into your Okta org and agentless DSSO is properly configured for it? Solution: You will be automatically redirected to your Load-Balancing Application, if you have one configured, enter credentials for it and then redirected back to Okta org Reveal answer details Close answer detailsCorrect answerB
Single choice
In Okta's KB articles the set of functions under the 'Provisioning' concept are referred to as CRUD. This is a concept you also meet when referring to CRUD APIs. What about its meaning here, in Okta's vision? Solution: In 'Provisioning', CRUD stands for Create, Read, Update, Delete Reveal answer details Close answer detailsCorrect answerB
Single choice
Does Okta require an Agent to sit in-between Okta to SCIM-enabled app on premises requests? Solution: Yes, an Okta Provisioning Agent Reveal answer details Close answer detailsCorrect answerA
Single choice
If you want to remove an attribute's value in Okta, for example a value coming from AD that is not useful in any way, you have to: Solution: Delete the mapping by the help of which the value came into Okta User Profile Reveal answer details Close answer detailsCorrect answerB
Single choice
Any ... <answer_goes_here>'s credentials verified under "Test API credentials" in an Office365 app Solution: Office 365 Global Administrator Reveal answer details Close answer detailsCorrect answerA
Single choice
The Okta On-Prem MFA Agent acts as a Radius client and communicates with the RADIUS enabled On- Solution: The statement is partically true - as it has nothing to do with RSA Reveal answer details Close answer detailsCorrect answerB
Single choice
What does it mean: "Mapping Direction AD to Okta"? Solution: Indicates a schema of attribute values flowing AD towards Okta Reveal answer details Close answer detailsCorrect answerA |