What is the purpose of the engine.ssl.protocols in the run.properties file?
The property engine.ssl.protocols in run.properties specifies the TLS protocol versions that PingAccess engines will support for incoming HTTPS traffic.
Exact Extract:
''The engine.ssl.protocols property configures which TLS versions are enabled for HTTPS listeners.''
Option A (ciphers) is incorrect --- cipher suites are defined separately, not in this property.
Option B (HTTPS port) is incorrect --- the port is defined in the engine listener, not here.
Option C (TLS versions) is correct --- this property controls TLS version support (e.g., TLSv1.2, TLSv1.3).
Option D (clustering) is incorrect --- clustering does not depend on this property.
An application is hosted on a server that requires clients to authenticate using a username:password pair. This application is behind PingAccess, which is acting as a gateway. What action should the administrator take to allow PingAccess to access the application?
When a back-end site requires HTTP Basic Authentication, PingAccess supports this via a Basic Authentication Site Authenticator. The authenticator is configured with credentials so that PingAccess can successfully authenticate to the target site.
Exact Extract:
''PingAccess can authenticate to target sites using a Site Authenticator. Use the Basic Authentication Site Authenticator when the site requires a username and password.''
Option A is incorrect --- identity mappings are used to forward user attributes, not for site-to-site authentication.
Option B is incorrect --- web sessions represent end-user sessions, not back-end credentials.
Option C is correct --- the Basic Authentication Site Authenticator should be configured on the Site.
Option D is incorrect --- mTLS authenticates with certificates, not username/password.
An administrator needs to configure a protected web application using the Authorization Code login flow. Which two configuration parameters must be set? (Choose 2 answers.)
When using the Authorization Code Flow for authentication, PingAccess must be configured with:
An OAuth Client ID that identifies the application to the IdP.
The OpenID Connect Login Type set to Authorization Code.
Exact Extract:
''When configuring an OIDC web session, specify the OAuth client ID and select the OpenID Connect login type (Authorization Code, Hybrid, or Implicit).''
Option A (OAuth Token Introspection Endpoint) is not required for Authorization Code flow --- token introspection is used in other cases.
Option B (OAuth Client ID) is correct --- required for OIDC authorization requests.
Option C (OpenID Connect Issuer) is discovered automatically via metadata when you configure the token provider.
Option D (Virtual Host) is required for application exposure but not specific to OIDC flow.
Option E (OpenID Connect Login Type) is correct --- must be set to ''Authorization Code.''
Developers report an issue with an application that is protected by PingAccess. Certain requests are not providing claims that are part of the access token.
What should the administrator add for the access token claims?
In PingAccess, when an application relies on claims from an OAuth access token, you must configure PingAccess to evaluate those claims and potentially inject them into headers for the backend application.
Exact Extract from PingAccess documentation:
''OAuth rules allow you to evaluate claims in OAuth access tokens. You can configure PingAccess to look at specific claims and enforce policies or pass them to target applications.''
''To extract attributes from an access token, configure an OAuth Attribute Rule.''
This clearly matches option D.
Analysis of each option:
A . An authentication requirement definition
Incorrect. Authentication requirements determine how users authenticate to applications (OIDC provider, etc.), but do not manage access token claims.
B . A web session attribute rule
Incorrect. Web session attribute rules map attributes from the authenticated user's web session (SSO session), not from OAuth access tokens.
C . An identity mapping definition
Incorrect. Identity mappings transform user attributes (from IdP to app), but they don't directly pull claims from OAuth tokens.
D . An OAuth attribute rule
Correct. This rule is specifically designed to extract and enforce policies on claims from OAuth access tokens.
Therefore, the correct answer is D. An OAuth attribute rule.
A PingAccess API deployment requires multiple Access Token Managers to maintain compliance with customer requirements. Which feature must be set on the Token Provider configuration?
When using multiple Access Token Managers, the Send Audience option ensures that tokens are scoped properly and validated against the intended resource/application.
Exact Extract:
''Enable Send Audience in the token provider configuration to support environments with multiple Access Token Managers and enforce correct audience restrictions.''
Option A (Subject Attribute Name) is unrelated --- it maps user identity but not token manager selection.
Option B (Send Audience) is correct --- required when multiple ATMs are in use.
Option C (Use Token Introspection Endpoint) is optional and depends on deployment, not mandatory for multiple ATMs.
Option D (Client Secret) is part of OAuth client credentials, not specific to multiple ATMs.
Betty Perez
16 days agoHeather Harris
27 days agoRobert Phillips
2 months agoAngela Thompson
2 months agoRebecca Thomas
2 months agoRichard Rogers
3 months agoHarold Adams
2 months agoNathan Cooper
3 months agoKenneth Perez
2 months agoChristopher Scott
3 months agoLaura Bell
3 months agoShenika
3 months agoFiliberto
4 months agoIzetta
4 months agoBarrett
4 months agoJaime
4 months agoTammy
5 months agoHelene
5 months agoSherita
5 months agoWillie
5 months agoGracia
6 months agoNelida
6 months agoDiego
6 months agoDorothea
6 months agoCaitlin
7 months agoTemeka
7 months agoBulah
7 months agoRolande
7 months agoPaz
8 months agoSamuel
8 months agoBillye
8 months agoMarquetta
8 months agoTerrilyn
9 months agoRebeca
9 months agoBelen
9 months agoBrianne
9 months agoRhea
10 months agoKristel
10 months agoDaisy
10 months agoKatina
10 months ago