Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Ping Identity PT-AM-CPE Exam - Topic 3 Question 9 Discussion

If there is a need to reset a registered device over the REST API, which one of the following statements is incorrect?
C) Only administrator accounts, not user accounts, have the ability to use the REST API for resetting a device profile
A) Administrators can provide authenticated users with a self-service page to reset their devices via the REST API
B) Administrators can call the REST API to reset a device that is out of sync, where the HOTP counter exceeds the HOTP threshold window and requires a reset
D) Administrators can call the REST API to reset a user's device profile

Ping Identity PT-AM-CPE Exam - Topic 3 Question 9 Discussion

Actual exam question for Ping Identity's PT-AM-CPE exam
Question #: 9
Topic #: 3
[All PT-AM-CPE Questions]

If there is a need to reset a registered device over the REST API, which one of the following statements is incorrect?

Show Suggested Answer Hide Answer
Suggested Answer: C

In PingAM 8.0.2, device management is a critical part of the Multi-Factor Authentication (MFA) lifecycle. When a user registers a device for Push, OATH, or WebAuthn, that information is stored as a part of their identity profile. There are many scenarios where a device might need to be reset---for example, if a phone is lost, if the ForgeRock/Ping Authenticator app is reinstalled, or if an HOTP (HMAC-based One-Time Password) counter becomes desynchronized beyond the allowed window.

According to the PingAM documentation on 'Managing Devices for MFA' and the 'REST API for Device Management':

Administrator Capabilities: Administrators have the authority to manage device profiles for any user. They can list, rename, or delete (reset) device profiles using the /json/realms/root/realms/[realm]/users/[username]/devices endpoint. This is vital for helpdesk scenarios (Option D and B).

User Self-Service (The Incorrect Statement C): Statement C is technically incorrect because PingAM's REST API specifically supports self-service device management. An authenticated end-user has the permission to manage their own devices. They can call the /json/realms/root/realms/[realm]/users/[username]/devices endpoint using their own valid SSO token to delete their own registered devices. This allows organizations to build self-service portals where users can 'Unpair' a lost device without calling support (Option A).

The internal security of PingAM ensures that while a regular user can only access their own device sub-resource, an administrator with the appropriate amAdmin or Delegate Admin privileges can access the resources of all users. Therefore, the claim that only administrator accounts can use the REST API for these actions is false and contradicts the 'User Self-Service' philosophy built into the PingAM 8 API architecture.


Contribute your Thoughts:

0/2000 characters
Berry
5 hours ago
Wait, are you saying only admins can reset? That's surprising!
upvoted 0 times
...
Arthur
5 days ago
Totally agree, C sounds off.
upvoted 0 times
...
Rebbeca
11 days ago
A) is true, admins can set up self-service.
upvoted 0 times
...
Lashawna
16 days ago
I feel like option A is definitely correct since self-service pages are common, but I’m not sure about the specifics of the REST API.
upvoted 0 times
...
Blondell
2 months ago
I’m confused about option B. It mentions the HOTP counter, and I’m not clear if that’s relevant to the reset process.
upvoted 0 times
...
Barb
2 months ago
I remember a practice question where we discussed the roles of admins versus users with the REST API. I feel like option C might be the incorrect one.
upvoted 0 times
...
Tijuana
2 months ago
I think option C sounds a bit off, but I’m not entirely sure if user accounts can access the REST API for resets.
upvoted 0 times
...

Save Cancel