nerdexam
CyberArk

ACCESS-DEF · Question #7

Refer to the exhibit. Which statements are correct regarding this Authentication Policy? (Choose two.) Authentication Policy for CyberArk Identity Applies to all web logins to CyberArk Identity…

The correct answer is B. If users have set up CyberArk Mobile Authenticator as an MFA, they will still receive the Push Notification to confirm the request even if they mistyped their password. Option B is correct because the checked setting - "Continue with additional challenges after failed challenge" - instructs CyberArk Identity to keep presenting subsequent MFA challenges even when a prior factor fails. Since the user's CyberArk Mobile Authenticator Push…

Authentication and Authorization

Question

Refer to the exhibit. Which statements are correct regarding this Authentication Policy? (Choose two.) Authentication Policy for CyberArk Identity Applies to all web logins to CyberArk Identity, including the Admin and User Portal and on-demand Other Settings [x] Continue with additional challenges after failed challenge [ ] Do not send challenge request when previous challenge response failed

Options

  • AUsers will still be asked for their MFA even if they mistyped their username.
  • BIf users have set up CyberArk Mobile Authenticator as an MFA, they will still receive the Push Notification to confirm the request even if they mistyped their password.
  • CUsers will not be notified which challenge they failed if their login attempt failed.
  • DIf users have set up a Security Question as an MFA, the Security Question will not be displayed to the user to answer even if they mistyped their password.
  • EIf the first factor is password and the user is an Active Directory user and the Active Directory is unavailable, this setting does not matter because the user will not be able to authenticate through Active Directory credentials and will see the message "Active Directory not available".

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    73% (24)
  • C
    9% (3)
  • D
    12% (4)
  • E
    3% (1)

Explanation

Option B is correct because the checked setting - "Continue with additional challenges after failed challenge" - instructs CyberArk Identity to keep presenting subsequent MFA challenges even when a prior factor fails. Since the user's CyberArk Mobile Authenticator Push Notification is an additional challenge after the password step, it will still be sent even if the password was entered incorrectly.

Why the distractors are wrong:

  • A - The setting governs failed challenges, not unrecognized usernames. If the username doesn't exist, the system can't locate the user or their MFA configuration, so this setting doesn't come into play.
  • C - The setting controls flow-continuation behavior, not error-message content. It says nothing about hiding or showing which specific challenge failed.
  • D - This is the opposite of what the enabled setting does. Because "Continue with additional challenges" is checked, a Security Question would still be displayed after a failed password attempt - not suppressed.
  • E - AD unavailability causes a system-level failure on the password challenge, and the "continue" setting would still trigger subsequent MFA challenges; the AD error doesn't bypass the authentication policy logic entirely.

Memory tip: Think of the checked setting as "fail forward through MFA" - once enabled, a wrong password is treated as a failed-but-not-final step, so every downstream challenge (push, security question, OTP) is still fired.

Topics

#Authentication Policy#Multi-Factor Authentication#Challenge Flow#CyberArk Identity

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice