OKTA ADMINISTRATOR
CERTIFICATION EXAM QUESTIONS &
ANSWERS
Is this an Okta recommendation for managing AD-sourced user passwords?
Set the password policy to never expire? - Correct Answers -No
Is this an Okta recommendation for managing AD-sourced user passwords?
Exclude executives from the password policy? - Correct Answers -No
Is this an Okta recommendation for managing AD-sourced user passwords?
Ensure Okta password settings match the settings of the AD password policy? - Correct
Answers -Yes
Is this an Okta recommendation for managing AD-sourced user passwords?
Ensure passwords are shorter than 10 characters? - Correct Answers -No
An Okta Administrator needs to add a new profile attribute from Active Directory to
Okta. Is this a task the administrator is required to perform?
Create a new Okta profile attribute? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's Operating System is macOS 10.12 "Sierra"? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's operating system is Ubuntu 20.04 LTS? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's operating system is Windows 7 64bit? - Correct Answers -No
,Is this requirement for a device to be considered a managed device?
The device has Okta Verify installed? - Correct Answers -Yes
Is this requirement for a device to be considered a managed device?
The device must have mobile device management (MDM) through a third-party
Enterprise Mobile Management (EMM) solution? - Correct Answers -Yes
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The administrator did NOT correctly configure JIT provisioning for this scenario? -
Correct Answers -No
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The administrator did NOT select all of the OU that contained the user's group
membership? - Correct Answers -Yes
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The user was NOT an existing Okta user? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
pr? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
, co? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
ne? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
eq? - Correct Answers -Yes
In order for Delegated Authentication to work, is this permission required for all Active
Directory users on the server running the Okta Agent?
Access this computer from the network? - Correct Answers -Yes
In order for Delegated Authentication to work, is this permission required for all Active
Directory users on the server running the Okta Agent?
Administrator - Correct Answers -No
Is this a user life cycle stage that profile sources manage?
certification? - Correct Answers -No
Is this a user life cycle stage that profile sources manage?
deactivation? - Correct Answers -Yes
Is this a user life cycle stage that profile sources manage?
authentication? - Correct Answers -Yes
In a global session policy rule, is this an authenticator that an Administrator can set to
establish user sessions?
Password? - Correct Answers -Yes
In a global session policy rule, is this an authenticator that an Administrator can set to
establish user sessions?
Any factor used to meet the Authentication Policy requirements? - Correct Answers -No
Is this the expected Okta platform action in a CSV directory integration import?
CERTIFICATION EXAM QUESTIONS &
ANSWERS
Is this an Okta recommendation for managing AD-sourced user passwords?
Set the password policy to never expire? - Correct Answers -No
Is this an Okta recommendation for managing AD-sourced user passwords?
Exclude executives from the password policy? - Correct Answers -No
Is this an Okta recommendation for managing AD-sourced user passwords?
Ensure Okta password settings match the settings of the AD password policy? - Correct
Answers -Yes
Is this an Okta recommendation for managing AD-sourced user passwords?
Ensure passwords are shorter than 10 characters? - Correct Answers -No
An Okta Administrator needs to add a new profile attribute from Active Directory to
Okta. Is this a task the administrator is required to perform?
Create a new Okta profile attribute? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's Operating System is macOS 10.12 "Sierra"? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's operating system is Ubuntu 20.04 LTS? - Correct Answers -No
Is this requirement for a device to be considered a managed device?
The device's operating system is Windows 7 64bit? - Correct Answers -No
,Is this requirement for a device to be considered a managed device?
The device has Okta Verify installed? - Correct Answers -Yes
Is this requirement for a device to be considered a managed device?
The device must have mobile device management (MDM) through a third-party
Enterprise Mobile Management (EMM) solution? - Correct Answers -Yes
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The administrator did NOT correctly configure JIT provisioning for this scenario? -
Correct Answers -No
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The administrator did NOT select all of the OU that contained the user's group
membership? - Correct Answers -Yes
An Okta Administrator has integrated Active Directory with Okta and enabled Just-in-
time provisioning. When an AD sourced user signs into Okta for the first time, the
administrator sees that two of the users three AD group memberships are NOT carried
over into Okta.
Is this a possible reason why two groups did NOT import?
The user was NOT an existing Okta user? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
pr? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
, co? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
ne? - Correct Answers -No
Is this the correct operator to use if creating a System Log query to return events that
exactly match event Type user.authentication.sso?
eq? - Correct Answers -Yes
In order for Delegated Authentication to work, is this permission required for all Active
Directory users on the server running the Okta Agent?
Access this computer from the network? - Correct Answers -Yes
In order for Delegated Authentication to work, is this permission required for all Active
Directory users on the server running the Okta Agent?
Administrator - Correct Answers -No
Is this a user life cycle stage that profile sources manage?
certification? - Correct Answers -No
Is this a user life cycle stage that profile sources manage?
deactivation? - Correct Answers -Yes
Is this a user life cycle stage that profile sources manage?
authentication? - Correct Answers -Yes
In a global session policy rule, is this an authenticator that an Administrator can set to
establish user sessions?
Password? - Correct Answers -Yes
In a global session policy rule, is this an authenticator that an Administrator can set to
establish user sessions?
Any factor used to meet the Authentication Policy requirements? - Correct Answers -No
Is this the expected Okta platform action in a CSV directory integration import?