Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Ping Identity PT-AM-CPE Exam - Topic 3 Question 12 Discussion

A non-authenticated user requests a resource protected by PingGateway or a Web Agent. Put the following events of the authentication lifecycle in chronological order:User answers the "questions asked" (callbacks) by PingAM.User tries to access a resource protected by PingGateway or a Web Agent.Session reaches a timeout value or user logs out.PingGateway or the Web Agent validates the session.User is redirected to the authentication user interface of PingAM.User is redirected to the resource.
B) 2-5-1-6-4-3
A) 2-1-4-3-5-6
C) 2-5-1-6-3-4
D) 2-1-5-6-4-3

Ping Identity PT-AM-CPE Exam - Topic 3 Question 12 Discussion

Actual exam question for Ping Identity's PT-AM-CPE exam
Question #: 12
Topic #: 3
[All PT-AM-CPE Questions]

A non-authenticated user requests a resource protected by PingGateway or a Web Agent. Put the following events of the authentication lifecycle in chronological order:

User answers the "questions asked" (callbacks) by PingAM.

User tries to access a resource protected by PingGateway or a Web Agent.

Session reaches a timeout value or user logs out.

PingGateway or the Web Agent validates the session.

User is redirected to the authentication user interface of PingAM.

User is redirected to the resource.

Show Suggested Answer Hide Answer
Suggested Answer: B

The authentication lifecycle in a Ping Identity environment follows a strict sequence to ensure that only authorized users can access protected resources. This process is governed by the interaction between a Policy Enforcement Point (PEP), such as a Web Agent or PingGateway, and the Policy Decision Point (PDP), which is PingAM.

Following the chronological flow according to the PingAM 8.0.2 'Introduction to Authentication' and 'Web Agent User Guide':

Step 2: The process begins when an unauthenticated user attempts to access a protected URL.

Step 5: The Agent/PingGateway intercepts the request, detects the absence of a valid session cookie, and redirects the user to the PingAM login URL (the UI).

Step 1: The user interacts with the AM UI, providing the necessary credentials or answering the 'callbacks' (username, password, MFA) defined in the authentication tree.

Step 6: Upon successful authentication, PingAM issues a session token and redirects the user back to the original resource they were trying to access.

Step 4: The Agent/PingGateway receives the request again, but this time it contains a session token. The agent then validates the session with PingAM to ensure it is still active and possesses the correct permissions.

Step 3: Finally, the lifecycle ends when the session expires due to inactivity (Idle Timeout), reaches its Max Session Time, or the user explicitly logs out.

Sequence 2-5-1-6-4-3 (Option B) accurately captures this 'Round-Trip' nature of modern web authentication. Options A and D are incorrect because they place the callback interaction before the initial redirect or the resource access. Option C is incorrect because it suggests the session reaches a timeout before the agent has a chance to validate the session for the current request.

============


Contribute your Thoughts:

0/2000 characters
Refugia
3 days ago
I’m leaning towards C. The flow seems right.
upvoted 0 times
...
Dalene
8 days ago
I feel like A makes more sense.
upvoted 0 times
...
Carmelina
14 days ago
This question is tricky! I think it's B.
upvoted 0 times
...
Rosalind
19 days ago
Surprised that session validation comes after the redirect!
upvoted 0 times
...
Zana
24 days ago
I think it's option D, makes the most sense.
upvoted 0 times
...
Lorrie
29 days ago
Wait, how does the session timeout fit in?
upvoted 0 times
...
Shaunna
1 month ago
Totally agree, that's the starting point!
upvoted 0 times
...
Benton
1 month ago
The user tries to access the resource first.
upvoted 0 times
...
Jovita
1 month ago
I’m pretty confident that the user gets redirected to the resource last, but I’m unsure about when the session timeout occurs in this process.
upvoted 0 times
...
Kathrine
2 months ago
I feel like the session validation happens after the user answers the questions, but I can't recall the exact sequence.
upvoted 0 times
...
Leila
2 months ago
I remember practicing a similar question, and I think the user gets redirected to the authentication UI after trying to access the resource.
upvoted 0 times
...
Rosio
2 months ago
I think the user tries to access the resource first, but I'm not entirely sure about the order of the callbacks.
upvoted 0 times
...

Save Cancel