nerdexam
CyberArk

ACCESS-DEF · Question #12

Which protocols can CyberArk provide MFA for VPN? (Choose two.)

The correct answer is A. SAML. Note: The question says "Choose two," and the correct answers are A (SAML) and B (RADIUS) - the provided answer of only "A" appears incomplete. SAML is correct because CyberArk Identity supports SAML-based MFA, enabling it to act as an Identity Provider (IdP) that VPN solutions…

Authentication and Authorization

Question

Which protocols can CyberArk provide MFA for VPN? (Choose two.)

Options

  • ASAML
  • BRADIUS
  • CIMAP
  • DTACACS
  • ELDAP

How the community answered

(31 responses)
  • A
    90% (28)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Note: The question says "Choose two," and the correct answers are A (SAML) and B (RADIUS) - the provided answer of only "A" appears incomplete.

SAML is correct because CyberArk Identity supports SAML-based MFA, enabling it to act as an Identity Provider (IdP) that VPN solutions can federate with for authentication. RADIUS is correct because it is the industry-standard protocol VPN clients use to communicate with authentication servers, and CyberArk can function as a RADIUS server to inject MFA into the VPN login flow.

IMAP (C) is an email retrieval protocol and has no role in authentication or MFA. LDAP (E) is a directory query protocol used to look up users, not to enforce MFA - it lacks the challenge/response flow MFA requires. TACACS+ (D) is used for authenticating access to network devices (routers, switches) rather than VPN endpoints, making it out of scope for this use case.

Memory tip: Think "VPN needs a SRong MFA" - SAML for federated/web-based flows and RADIUS for legacy VPN clients. If a protocol sounds like email (IMAP) or directory lookup (LDAP), it's not enforcing MFA.

Topics

#MFA#SAML#VPN Authentication#Identity Protocols

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice