Oracle
1Z0-479 · Question #71
Your customer has deployed an employee portal that you have protected with Oracle Access Manager (OAM). The customer now wants a new portlet added to the home page to display the employee's salary…
The correct answer is A. Deploy Oracle Adaptive Access Manager (OAAM) and integrate it with OAM, settings OAAM as B. Configure Oracle Web Services Manager (OWSM) on the portal container to generate asecurity C. Configure a cookie response in OAM to set the risk score into a cookie D. Enable Identity Assertion propagation in the OAM policy. See the full explanation below for the reasoning.
Question
Your customer has deployed an employee portal that you have protected with Oracle Access Manager (OAM). The customer now wants a new portlet added to the home page to display the employee's salary details. The portlet will obtain the information through a call an internally exposed web service. Your customer has defined the following security requirements for the new portlet: 1. Employees must be authenticated through risk-based authentication before they can access the portal. 2. The web service must be secured from unauthenticated calls. 3. All security logic for the web service must be external to the web service. 4. The web service should return salary details only if the user's authentication risk score is below 500. Which four steps must you perform to meet the requirements for the new portlet?
Options
- ADeploy Oracle Adaptive Access Manager (OAAM) and integrate it with OAM, settings OAAM as
- BConfigure Oracle Web Services Manager (OWSM) on the portal container to generate asecurity
- CConfigure a cookie response in OAM to set the risk score into a cookie
- DEnable Identity Assertion propagation in the OAM policy.
- EConfigure OWSM to call OAAM to obtain the risk score.
- FConfigure an OWSMpolicy to protect the web service, consume the security token, and evaluate
How the community answered
(55 responses)- A76% (42)
- E13% (7)
- F11% (6)
Community Discussion
No community discussion yet for this question.