Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PT-AM-CPE Certified Professional - PingAM Exam Questions and Answers

Questions 4

Which of the following steps must be configured in PingAM to implement mutual TLS using the public key infrastructure (PKI) approach?

    Import the trusted certificates into the trust store used by the PingAM web container.

    Create a secret store in the realm that maps the appropriate secret ID with the certificate alias in the trust store. 18

    Select tls_client_auth as the authentication method in the client profile.

    Select self_signed_tls_client_auth as the authentication method in the client profile. 19

    Provide the certificate subject distinguished name in the client profile. 20

    Configure a revocation check in the client profile.

    Register the X.509 certificate in the client profile.

Options:

A.

1, 2, 4, and 7 only

B.

1, 2, 4, and 6 only

C.

1, 2, 3, and 5 only

D.

1, 2, 4, and 5 only

Buy Now
Questions 5

When removing a forgeops deployment created with the Cloud Developer Kit (CDK) with the following command:

$ /path/to/forgeops/bin/forgeops delete

What components are removed from the deployment?

Options:

A.

The Ping Identity Platform (CDK artifacts, PVCs, and the Access Management and Identity Management configurations) and ingress controller pods

B.

The Ping Identity Platform (CDK artifacts, PVCs, and the Access Management and Identity Management configurations), certificate manager, and secret agent pods

C.

The Ping Identity Platform (CDK artifacts, PVCs, and the Access Management and Identity Management configurations), ingress controller, DS operator, certificate manager, and secret agent pods

D.

The Ping Identity Platform (CDK artifacts, PVCs, and the Access Management and Identity Management configurations) pods

Buy Now
Questions 6

Which organization sets, maintains, and governs the SAML2 standard?

Options:

A.

OASIS

B.

ISC2

C.

IETF

D.

WC3

Buy Now
Questions 7

The OAuth2 authorize endpoint supports the CSRF parameter. What is CSRF?

Options:

A.

Cross Script Response Feature

B.

Cross Site Request Forgery

C.

Cross Site Request Forgery

D.

Cross System Rest Federation

Buy Now
Questions 8

Which OAuth2 flow is most appropriate to support the use case of a client application implemented in a browser using a scripted language such as JavaScript?

Options:

A.

Authorization code grant flow with PKCE

B.

Implicit grant flow

C.

Resource owner grant flow

D.

Client credentials grant flow

Buy Now
Questions 9

What are the possible outcomes of the Push Result Verifier node?

Options:

A.

Success, Failure, Waiting, Retry

B.

Success, Failure, Expired, Retry

C.

Success, Failure, Expired, Waiting

D.

Success, Failure, Expired, Waiting, Retry

Buy Now
Questions 10

Which authentication node checks and validates a recovery code used during a multi-factor authentication challenge sequence?

Options:

A.

Recovery Code Display node

B.

Recovery Code Comparator node

C.

Recovery Code Collector Decision node

D.

Recovery Code Verifier node

Buy Now
Questions 11

Which of the following tab pages in the PingAM admin UI can be used to configure the OAuth2 and OpenID Connect may act scripts used for token exchange requests?

A) The OAuth2 provider service > Advanced tab page

B) The OAuth2 provider service > Core tab page

C) The OAuth2 client profile > Advanced tab page

D) The OAuth2 client profile > OAuth2 Provider Overrides tab page

Options:

A.

B and D only

B.

A and D only

C.

A and C only

D.

B and C only

Buy Now
Questions 12

What should be configured in PingAM if you are using an LDAP directory service that does not support persistent search?

Options:

A.

Enable user data caching, which will have a negative impact on performance

B.

Enable user data caching, which will have a positive impact on performance

C.

Disable user data caching, which will have a positive impact on performance

D.

Disable user data caching, which will have a negative impact on performance

Buy Now
Questions 13

Which multi-factor authentication methods require a separate device and an application?

Options:

A.

Push, WebAuthn

B.

Push, WebAuthn, Open Authentication

C.

WebAuthn, Open Authentication

D.

Open Authentication, Push

Buy Now
Questions 14

Samantha decides to implement SAML2 auto-federation to link accounts on the service provider (SP) with the corresponding account in the identity provider (IdP). Which of the following statements describe characteristics of auto-federation?

A) Linking is based on a common NameId format value.

B) Linking is achieved by using a common attribute value.11

C) The user must log in to the IdP only to link accounts.

D) The user must log in to both the SP and the IdP to link accounts.

Answer Selection:

Options:

A.

A and D

B.

B and C

C.

B and D

D.

A and C

Buy Now
Questions 15

What is a SAML2 artifact?

Options:

A.

The SAML2 assertion

B.

The SAML2 binding name

C.

The name of a specific attribute in the assertion

D.

A value sent by the service provider to retrieve the assertion

Buy Now
Questions 16

Which of the following is an incorrect statement about session upgrade outcomes?

Options:

A.

In a server-side session configuration, when using the ForceAuth parameter and an authentication tree, PingAM issues a new session token to a user who reauthenticates, even if the current session already meets the security requirements

B.

In a server-side or client-side session configuration, PingAM issues a new session token to a user who reauthenticates, only when the current session does not meet the security requirements

C.

In a server-side session configuration, when using advices, PingAM copies the session properties to a new session and replaces the client's original session token with a new session token

D.

In a client-side session configuration, PingAM replaces the client's original session token with a new session token

Buy Now
Questions 17

Which of the following is considered a confidential OAuth2 client?

Options:

A.

Desktop clients

B.

JavaScript clients

C.

Web browsers

D.

Web applications

Buy Now
Questions 18

Which of the following best describes the relationship between users and realms?

Options:

A.

A user can be a member of one or more realms

B.

Users do not need to be a member of a realm

C.

Users are never members of a realm

D.

A user can be a member of exactly one realm

Buy Now
Questions 19

During the PingAM startup process, what is the location and name of the file that the PingAM bootstrap process uses to connect to the configuration Directory Services repository?

Options:

A.

< user-home-dir > /.openam/config/boot.json

B.

/path/to/tomcat/ < tomcat-instance-dir > /webapps/ < am-instance-dir > /boot.json

C.

< user-home > / < am-instance-dir > /boot.json

D.

< user-home-dir > / < am-instance-dir > /config/boot.json

Buy Now
Questions 20

OpenID Connect acr_values map to what component within PingAM?

Options:

A.

Authentication trees

B.

SAML Circles of Trust

C.

Authorization policies

D.

Authentication levels

Buy Now
Questions 21

Which of the following multi-factor authentication protocols are supported by PingAM?

A) Open authentication

B) Security questions

C) Web authentication

D) Universal 2nd factor authentication

E) Push authentication

Options:

A.

B, C, and D

B.

A, B, and E

C.

A, C, and E

D.

A, B, and C

Buy Now
Questions 22

Consider the following LDAP connection string:

DS1.example.com:389|01, DS2.example.com:389|01, DS2.example.com:389|02, DS1.example.com:389|02

This connection string can be used in:

Options:

A.

Identity Store

B.

Core Token Service

C.

Configuration Data Store

Which of the above options are correct?

D.

Only A is correct

E.

Only B is correct

F.

Only C is correct

G.

A, B, and C are correct

Buy Now
Questions 23

Which PingAM feature only uses the PingAM keystore?

Options:

A.

Client-side sessions

B.

Persistent Cookie node

C.

Authentication trees

D.

OAuth2 providers

Buy Now
Questions 24

For Proof of Possession OAuth2 tokens, in addition to the access token, what must be presented to the authorization server?

Options:

A.

Nonce

B.

Client JSON Web Key (JWK)

C.

State

D.

Client private certificate

Buy Now
Questions 25

Which of the following statements are correct regarding session upgrades in PingAM?

A) An authenticated user is required to authenticate again either to the same or a different authentication service.

B) The user must not change for the session upgrade to succeed.

C) The only PingAM mechanism to do a session upgrade is the ForceAuth=true request parameter.

D) A session upgrade is PingAM's mechanism to perform what is called step-up authentication.1

Options:

A.

A, C, and D

B.

B, C, and D

C.

A, B, and D

D.

A, B, and C

Buy Now
Questions 26

Which one of the default PingAM audit log file contains messages related to changes made to sessions by end users?

Options:

A.

access.audit.json

B.

config.audit.json

C.

authentication.audit.json

D.

activity.audit.json

Buy Now
Questions 27

Which token transformation is not supported by the REST security token service?

Options:

A.

Username token - > SAML2

B.

Kerberos - > SAML2

C.

OpenID Connect - > SAML2

D.

PingAM SessionToken - > SAML2

Buy Now
Questions 28

In an authentication tree process, considering best practice, where can the collected context data for mobile devices be persisted for subsequent risk analysis?

Options:

A.

In the session state

B.

In shared node state

C.

With the user profile

D.

In a browser cookie

Buy Now
Questions 29

A user's SSOTokenID is stored in a cookie when they successfully log in. What is the name of the PingAM property used to configure this cookie?

Options:

A.

com.iplanet.am.cookie.name

B.

iPlanetDirectoryPro

C.

comIplanetAmSessionCookieName

D.

com.sun.identity.agents.config.cookie.name

Buy Now
Questions 30

In which OAuth2 grant would you find a user code?

Options:

A.

Client credentials grant

B.

Authorization code grant

C.

Resource owner password credentials grant

D.

Device flow

Buy Now
Exam Code: PT-AM-CPE
Exam Name: Certified Professional - PingAM Exam
Last Update: Jun 1, 2026
Questions: 100

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11