nerdexam
CyberArk

ACCESS-DEF · Question #44

Refer to the exhibit. If an Authentication Policy is configured as shown in the exhibit, which statement is correct?

The correct answer is A. The initial MFA challenge will be sent to the account in CyberArk Cloud Directory (Target). In CyberArk's Authentication Policy with account mapping, the Target account (CyberArk Cloud Directory) is the destination identity that holds the MFA configuration - so the initial MFA challenge is correctly routed there, making A correct. Why the distractors are wrong: B is…

Authentication and Authorization

Question

Refer to the exhibit. If an Authentication Policy is configured as shown in the exhibit, which statement is correct?

Options

  • AThe initial MFA challenge will be sent to the account in CyberArk Cloud Directory (Target).
  • BUpon successful logon, the user will be logged in as the account in CyberArk Cloud Directory (Target).
  • CFuture MFA challenges will be sent to the account in AD (Source).
  • DIf there is no matching email between two accounts in AD (Source) and CyberArt Cloud Directory (Target), the mapping will then look for a matching User ID.

How the community answered

(60 responses)
  • A
    80% (48)
  • B
    7% (4)
  • C
    10% (6)
  • D
    3% (2)

Explanation

In CyberArk's Authentication Policy with account mapping, the Target account (CyberArk Cloud Directory) is the destination identity that holds the MFA configuration - so the initial MFA challenge is correctly routed there, making A correct.

Why the distractors are wrong:

  • B is incorrect because successful logon keeps the user authenticated as the Source (AD) account, not the Target; the Target is only used to resolve MFA settings, not to determine the logged-in identity.
  • C is incorrect because future MFA challenges, like the initial one, are also sent to the Target (CyberArk Cloud Directory), not the Source - the Source is only used for the initial authentication credential.
  • D is incorrect because CyberArk's account mapping does not automatically fall back to matching by User ID when no email match is found; email is the defined matching attribute in this policy configuration, and a failed match would result in no mapping rather than a silent fallback.

Memory tip: Think of it as "Source authenticates, Target challenges" - the user proves who they are via AD (Source), but CyberArk looks to the Cloud Directory (Target) for how to challenge them with MFA.

Topics

#Authentication Policy#MFA Challenge Routing#Account Mapping#Directory Integration

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice