ACCESS-DEF · Question #12
Which protocols can CyberArk provide MFA for VPN? (Choose two.)
The correct answer is A. SAML. Note: The question says "Choose two," and the correct answers are A (SAML) and B (RADIUS) - the provided answer of only "A" appears incomplete. SAML is correct because CyberArk Identity supports SAML-based MFA, enabling it to act as an Identity Provider (IdP) that VPN solutions…
Question
Options
- ASAML
- BRADIUS
- CIMAP
- DTACACS
- ELDAP
How the community answered
(31 responses)- A90% (28)
- C6% (2)
- D3% (1)
Explanation
Note: The question says "Choose two," and the correct answers are A (SAML) and B (RADIUS) - the provided answer of only "A" appears incomplete.
SAML is correct because CyberArk Identity supports SAML-based MFA, enabling it to act as an Identity Provider (IdP) that VPN solutions can federate with for authentication. RADIUS is correct because it is the industry-standard protocol VPN clients use to communicate with authentication servers, and CyberArk can function as a RADIUS server to inject MFA into the VPN login flow.
IMAP (C) is an email retrieval protocol and has no role in authentication or MFA. LDAP (E) is a directory query protocol used to look up users, not to enforce MFA - it lacks the challenge/response flow MFA requires. TACACS+ (D) is used for authenticating access to network devices (routers, switches) rather than VPN endpoints, making it out of scope for this use case.
Memory tip: Think "VPN needs a SRong MFA" - SAML for federated/web-based flows and RADIUS for legacy VPN clients. If a protocol sounds like email (IMAP) or directory lookup (LDAP), it's not enforcing MFA.
Topics
Community Discussion
No community discussion yet for this question.