nerdexam
CyberArk

ACCESS-DEF · Question #43

Your organization wants to implement passwordless authentication for business critical web applications. CyberArk Identity manages access to these applications. What can you do to facilitate the…

The correct answer is A. Configure a certificate-based authentication policy in CyberArk Identity that only allows access to CyberArk Identity or the business critical web applications. Option A is correct because certificate-based authentication is a recognized passwordless method - users authenticate via cryptographic certificates (something they have) rather than a password (something they know). Scoping the CyberArk Identity policy to only allow access to…

Authentication and Authorization

Question

Your organization wants to implement passwordless authentication for business critical web applications. CyberArk Identity manages access to these applications. What can you do to facilitate the enforcement of this passwordless authentication initiative? (Choose two.)

Options

  • AConfigure a certificate-based authentication policy in CyberArk Identity that only allows access to CyberArk Identity or the business critical web applications.
  • BSend an email to the affected users and get them to renew their authentication token(s).
  • CRoll out the CyberArk Windows Cloud Agent to the affected endpoints.
  • DRefresh the endpoint operating system and define the new authentication method.
  • ERoll out Secure Web Sessions to the applicable users.

How the community answered

(47 responses)
  • A
    72% (34)
  • B
    13% (6)
  • C
    4% (2)
  • D
    9% (4)
  • E
    2% (1)

Explanation

Option A is correct because certificate-based authentication is a recognized passwordless method - users authenticate via cryptographic certificates (something they have) rather than a password (something they know). Scoping the CyberArk Identity policy to only allow access to the critical applications enforces the passwordless requirement without disrupting other systems.

B is wrong because emailing users to renew tokens is an administrative communication step, not a technical enforcement mechanism - it doesn't configure or mandate passwordless authentication in CyberArk Identity.

C is wrong because the CyberArk Windows Cloud Agent is an endpoint privilege management tool; it doesn't directly configure or enforce authentication policies for web applications in CyberArk Identity.

D is wrong because reimaging or refreshing the operating system is a disruptive, drastic action that doesn't configure authentication policies within CyberArk Identity at all.

E is wrong because Secure Web Sessions provides session monitoring and control after authentication - it's a session-security feature, not an authentication method, so it doesn't enforce passwordless login.

Note: The question instructs "Choose two," but only one answer (A) is marked correct as presented - flag this discrepancy if reviewing study materials.

Memory tip: Think "Certificate = No Password" - whenever an exam asks about passwordless enforcement in an identity platform, look for the option that introduces certificate-based (or biometric) auth policies, not email workflows or endpoint reimages.

Topics

#Passwordless Authentication#Certificate-based Auth#Access Policies#CyberArk Identity

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice