exam questions

Exam PAM-SEN All Questions

View all questions & answers for the PAM-SEN exam

Exam PAM-SEN topic 1 question 62 discussion

Actual exam question from CyberArk's PAM-SEN
Question #: 62
Topic #: 1
[All PAM-SEN Questions]

What authentication methods can be implemented to enforce Two-Factor Authentication (2FA) for users authenticating to CyberArk using both the PVWA (through the browser) and the PrivateArk Client?

  • A. LDAP and RADIUS
  • B. CyberArk and RADIUS
  • C. SAML and Cyber Ark
  • D. SAML and RADIUS
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rlam
Highly Voted 11 months, 3 weeks ago
Selected Answer: A
LDAP & RADIUS The question is about enabling 2FA on PVWA and PrivateArk There's no SAML in PrivateArk Client And there's no "CyberArk" in PrivateArk Client either.
upvoted 9 times
...
JM_Olympus
Most Recent 1 month, 2 weeks ago
A https://docs.cyberark.com/pam-self-hosted/Latest/en/Content/PAS%20INST/Authenticating-to-the-Privileged-Account-Security-Solution.htm#Secondaryauthentication adding LDAP or RADIUS for a second factor
upvoted 1 times
...
ildab
8 months, 2 weeks ago
Authentication Methods in PrivateArk: - PrivateArk authentication -NT PrivateArk authentication - PKi - Radius - LDAP Thus no SAML or CyberArk Authentication Ans: A
upvoted 1 times
...
Cavdog
10 months, 1 week ago
Selected Answer: D
I absolutely despise this question and deliberated on it for a really long time, as the combinations are really weird and it’s not really possible to enforce real 2FA for both the PVWA and the PAClient with any of them however the combination of SAML and RADIUS will allow real 2FA at the PVWA but will still prompt for username password and token at the PAClient although it’s technically just authenticating via the RADIUS server and not a separate LDAP query via the vault (I don’t think). I also can’t find any proper references to confirm this one way or the other. So if I had to guess I would suggest D. as being the closest to real 2FA for both PVWA and PAClient (I hope that's right). https://docs.cyberark.com/PAS/Latest/en/Content/PAS%20INST/Authenticating-to-the-Privileged-Account-Security-Solution.htm#:~:text=CyberArk%20support%20representative.-,Secondary%20authentication,-Secondary%20authentication%20strengthens
upvoted 1 times
...
KGdidonato
1 year ago
Selected Answer: D
SAML & RADIUS There are two groups of authentications: Primary Auth Type - IIS (SFE and PVWA)-> Windows, Oracle SSO, PKI (Client Certificate) RSA, SAML Secondary Auth Type - Vault-> CyberArk, LDAP, Radius https://cyberark-customers.force.com/s/article/Two-Factor-Authentication-2FA-on-Web-component-Possible-Combination
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago