New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which token transformation is not supported by the REST security token service?

A.

Username token -> SAML2

B.

Kerberos -> SAML2

C.

OpenID Connect -> SAML2

D.

PingAM SessionToken -> SAML2

Which statements are correct in relation to an OAuth2 token exchange impersonation pattern?

A) The client may want to act as the subject on another service.

B) The client is used by a subject to act on behalf of another subject.

C) The requested token exchange involves a subject token only.

D) The requested token exchange involves a subject and actor token.

A.

A and C only

B.

B and D only

C.

B and C only

D.

A and D only

Which statements are correct about PingAM sessions?

A) When a web browser is involved, the web browser is instructed to set a cookie as the session reference.

B) When no browser is involved, PingAM returns the session reference in the JSON response.

C) PingAM can only track the session in the Core Token Service store.

D) The default session cookie name created in a web browser is iPlanetDirectoryPro.

A.

A, B, and D only

B.

A, B, and C only

C.

A, C, and D only

D.

A and B only

In the default Cloud Developer Kit (CDK) deployment of the forgeops repository, which pods provide the user interface functionality?

A.

admin-ui, end-user-ui, login-ui

B.

amadmin-ui, idmadmin-ui, login-ui

C.

am-ui, idm-ui, login-ui

D.

am-ui, idm-ui, end-user-ui

To ensure the user's full name is displayed on the consent screen for an OpenID Connect application, which string should be added into the Support Claims property on the OpenID Connect tab page of the OAuth2 Provider service in PingAM?

A.

name|en|Full name

B.

Full name|en|name

C.

full_name|Full name

D.

name|en|given_name+' '+family_name

A customer wishes to customize the OpenID Connect (OIDC) id_token JSON Web Token (JWT) to include the subject's employee number. Which of the following scripts should be customized to meet this requirement?

A.

OIDC parameters script

B.

OIDC claims script

C.

OIDC attributes script

D.

OIDC JWT script

In a default PingAM configuration, what type of keystore stores the secret ID named storepass, which contains the encrypted password of the default-keystore secret store?

A.

Keystore secret store

B.

Environment and system property secret store

C.

Filesystem secret store

D.

Hardware Security Module secret store

Which of the following best represents the information that is typically contained in the debug output?

A.

The component that created the debug entry, A header with the time and date, The running thread ID, The debug level, A general message, Optional stack trace

B.

The component that created the debug entry, A header with the time and date, The debug level, A general message, Optional stack trace

C.

The component that created the debug entry, A header with the time and date, The running thread ID, A general message, Optional stack trace

D.

A header with the time and date, The running thread ID, The debug level, A general message, Optional stack trace

Samantha decides to implement SAML2 auto-federation to link accounts on the service provider (SP) with the corresponding account in the identity provider (IdP). Which of the following statements describe characteristics of auto-federation?

A) Linking is based on a common NameId format value.

B) Linking is achieved by using a common attribute value.11

C) The user must log in to the IdP only to link accounts.

D) The user must log in to both the SP and the IdP to link accounts.

Answer Selection:

A.

A and D

B.

B and C

C.

B and D

D.

A and C

Which of the following components is used to return data to PingGateway or the agent to be included with the policy decision?

A.

Subjects

B.

Resources

C.

Response attributes

D.

Actions