nerdexam
CyberArk

ACCESS-DEF · Question #37

Refer to the exhibit. How should you configure this default authentication policy to ensure users must authenticate every time they try to access the CyberArk Identity portal or web applications?

The correct answer is C. Check and Select "Challenge Pass-Through Duration" to be "No Pass Through".. Challenge Pass-Through Duration controls how long a user's authentication remains valid before they must re-authenticate. Setting it to "No Pass Through" means every session requires fresh authentication - there is no cached or passed-through credential window. This directly sati

Authentication and Authorization

Question

Refer to the exhibit. How should you configure this default authentication policy to ensure users must authenticate every time they try to access the CyberArk Identity portal or web applications?

Options

  • ACheck and enable QR Code under the "Single Authentication Mechanism" section.
  • BCheck and enable Security Questions and set the number to "1".
  • CCheck and Select "Challenge Pass-Through Duration" to be "No Pass Through".
  • DCheck and Select QR Code under Challenge 1.

How the community answered

(53 responses)
  • A
    11% (6)
  • B
    4% (2)
  • C
    83% (44)
  • D
    2% (1)

Explanation

Challenge Pass-Through Duration controls how long a user's authentication remains valid before they must re-authenticate. Setting it to "No Pass Through" means every session requires fresh authentication - there is no cached or passed-through credential window. This directly satisfies the requirement that users authenticate every time they access the portal or web apps.

Why the distractors are wrong:

  • A (QR Code under Single Authentication Mechanism): Enabling a specific MFA method does not control re-authentication frequency; it only adds a factor option.
  • B (Security Questions set to 1): Again, this configures which factor is used, not how often authentication is required. Pass-through could still let users skip it on repeat visits.
  • D (QR Code under Challenge 1): Same issue - selecting an authentication method for a challenge step does not prevent pass-through. Users could still be let through without re-authenticating if pass-through is enabled.

Memory tip: Think of Pass-Through Duration as a "remember me" timer. Setting it to No Pass Through = no "remember me" - every visit demands a fresh login, regardless of what factors are configured.

Topics

#Authentication Policy#Challenge Pass-Through#Re-authentication#CyberArk Identity

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice