nerdexam
CyberArk

ACCESS-DEF · Question #33

This exhibit shows the base authentication policy for ACME Corporation. You must edit the policy to allow users to authenticate once if they fulfill certain authentication criteria. How should you…

The correct answer is D. Configure QR Code as "Single Authentication Mechanism". Option D is correct because designating QR Code as a "Single Authentication Mechanism" signals to the policy engine that users presenting this factor satisfy the entire authentication requirement in one step - no additional challenges are required. This directly maps to the…

Authentication and Authorization

Question

This exhibit shows the base authentication policy for ACME Corporation. You must edit the policy to allow users to authenticate once if they fulfill certain authentication criteria. How should you configure this policy to support BOTH?

Options

  • AConfigure "Challenge Pass-Through Duration" to be "always".
  • BConfigure FIDO2 authenticator as Challenge 1.
  • CConfigure FIDO2 authenticator as Challenge 2.
  • DConfigure QR Code as "Single Authentication Mechanism".

How the community answered

(36 responses)
  • A
    11% (4)
  • B
    6% (2)
  • C
    3% (1)
  • D
    81% (29)

Explanation

Option D is correct because designating QR Code as a "Single Authentication Mechanism" signals to the policy engine that users presenting this factor satisfy the entire authentication requirement in one step - no additional challenges are required. This directly maps to the goal of allowing users to authenticate once when they meet a specific criterion, supporting both scenarios referenced in the exhibit.

Why the distractors fail:

  • A is wrong because setting "Challenge Pass-Through Duration" to "always" forces the challenge to appear every time, which increases friction rather than enabling a one-step authentication path.
  • B is wrong because placing FIDO2 as Challenge 1 inserts it into a sequential, multi-challenge flow - it becomes a gate before further factors, not a standalone mechanism.
  • C is wrong for the same reason: FIDO2 as Challenge 2 makes it a secondary step in a chain, not a self-sufficient authenticator.

Memory tip: Let the word "single" carry the meaning - a Single Authentication Mechanism means "this factor alone is enough." Whenever the requirement is "authenticate once if criteria met," look for a configuration that isolates the method as sufficient on its own, not as part of a challenge sequence.

Topics

#Authentication Policy Configuration#Single Authentication Mechanism#Challenge Configuration#QR Code Authentication

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice