Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Ping Identity Certified Professional - PingAccess PAP-001 Exam Questions

Page: 1 / 7 Total 70 questions

Want more questions? Get Premium Access.

Question 1

An administrator needs to support SLO (Single Logout) for a protected web application. What must be configured in a PingAccess Web Session in this situation?

Correct Answer: A. SLO scope
Explanation:

To enable Single Logout (SLO), the SLO scope must be defined in the PingAccess Web Session configuration. This determines which sessions are ended when a logout request occurs.

Exact Extract:

''The SLO scope option in a web session specifies which applications are included in a logout event when Single Logout is triggered.''

Option A (SLO scope) is correct; it explicitly enables SLO support by linking session termination across apps.

Option B (Idle timeout) is unrelated; this controls session expiration, not SLO.

Option C (Validate Session) ensures session state is synchronized but does not configure SLO.

Option D (Refresh User Attributes) is unrelated; it only controls whether attributes are reloaded.


Question 2

An administrator is setting up PingAccess to terminate SSL for a proxied application. What action must the administrator take to configure an existing certificate for that application?

Correct Answer: A. Assign the Key Pair to the Virtual Host
Explanation:

PingAccess terminates SSL at the Virtual Host level. To configure an existing certificate, the administrator must assign the appropriate Key Pair (which contains the certificate and private key) to the Virtual Host.

Exact Extract:

''SSL termination occurs on the engine listener through virtual hosts. Assign the certificate's key pair to the virtual host to secure proxied applications.''

Option A is correct --- assign the key pair to the Virtual Host for SSL termination.

Option B is incorrect --- Require HTTPS enforces secure access but does not configure SSL termination.

Option C is incorrect --- Agent Listener is for PingAccess Agents, not proxied apps.

Option D is incorrect --- secure flag affects cookie settings, not SSL certificates.


Question 3

An auto parts company wants to protect the path /parts/suspension/struts/manufacturer. Resources appear under an application Context Root of /parts with default ordering.

Which resource will the policy engine select?

Correct Answer: C. /suspension/struts/manufacturer
Explanation:

Because the application context root is /parts, resource paths are defined relative to it. The correct relative path is:

/suspension/struts/manufacturer

Exact Extract:

''Resource matching begins at the context root. The most specific matching path is selected.''

Option A is incorrect --- /*/struts/manufacturer does not match because it starts with a wildcard, not the defined path.

Option B is incorrect --- /*/manufacturer would match less specifically and at a different depth.

Option C is correct --- exact match relative to /parts.

Option D is incorrect --- too generic and not the best match.


Question 4

An application owner would like customized errors for rule violations within an application. Where is this configured?

Correct Answer: B. Within the Root Resource of the Application
Explanation:

PingAccess allows administrators to configure custom error pages or messages at the Root Resource level of an application. This ensures that when rule violations (e.g., authorization failures) occur, the application can display tailored error responses.

Exact Extract:

''Custom error handling for rule violations is configured within the Root Resource of an application.''

Option A is incorrect --- assigning a rule to a resource does not allow defining custom errors.

Option B is correct --- the Root Resource is where administrators define custom error handling for the entire application.

Option C is incorrect --- Rule Sets only combine rules; they do not handle error responses.

Option D is incorrect --- individual rule definitions do not contain custom error configurations.


Question 5

An API is hosted onsite and is using only header-based Identity Mapping. It is exposed to all clients running on the corporate network. How should the administrator prevent a malicious actor from bypassing PingAccess and spoofing the headers to gain unauthorized access to the API?

Correct Answer: A. Use ID Tokens
Explanation:

When applications depend solely on header-based identity mapping, attackers can attempt to bypass PingAccess by injecting headers directly into requests sent to the backend. To prevent spoofing, PingAccess should be configured to pass cryptographically verifiable tokens (e.g., ID tokens from OIDC) instead of relying on plain headers.

Exact Extract:

''Headers can be spoofed if not protected. Use signed tokens, such as ID tokens or JWTs, to provide strong identity assurance and prevent header injection attacks.''

Option A (Use ID Tokens) is correct --- ID tokens are signed and verifiable, preventing spoofing.

Option B (Add Site Authenticator) protects PingAccess-to-site authentication, not client-to-API spoofing.

Option C (Require HTTPS) prevents eavesdropping but does not stop header spoofing from inside the network.

Option D (Use Target Host Header) ensures host header integrity but not user identity.


Question 6

Developers report an issue with an application that is protected by PingAccess. Certain requests are not providing claims that are part of the access token.

What should the administrator add for the access token claims?

Correct Answer: D. An OAuth attribute rule
Explanation:

In PingAccess, when an application relies on claims from an OAuth access token, you must configure PingAccess to evaluate those claims and potentially inject them into headers for the backend application.

Exact Extract from PingAccess documentation:

''OAuth rules allow you to evaluate claims in OAuth access tokens. You can configure PingAccess to look at specific claims and enforce policies or pass them to target applications.''

''To extract attributes from an access token, configure an OAuth Attribute Rule.''

This clearly matches option D.

Analysis of each option:

A . An authentication requirement definition

Incorrect. Authentication requirements determine how users authenticate to applications (OIDC provider, etc.), but do not manage access token claims.

B . A web session attribute rule

Incorrect. Web session attribute rules map attributes from the authenticated user's web session (SSO session), not from OAuth access tokens.

C . An identity mapping definition

Incorrect. Identity mappings transform user attributes (from IdP to app), but they don't directly pull claims from OAuth tokens.

D . An OAuth attribute rule

Correct. This rule is specifically designed to extract and enforce policies on claims from OAuth access tokens.

Therefore, the correct answer is D. An OAuth attribute rule.


Question 7

Which two variables should be set in order for the PingAccess service script to start? (Choose 2 answers.)

Correct Answer: B. JAVA_HOME; D. PA_HOME
Explanation:

PingAccess service scripts depend on knowing:

Where the Java runtime is installed (JAVA_HOME)

Where PingAccess itself is installed (PA_HOME)

Exact Extract:

''The PingAccess startup scripts require the JAVA_HOME environment variable to locate the JDK/JRE and the PA_HOME variable to locate the PingAccess installation directory.''

Option A (J2EE_HOME) is irrelevant to PingAccess.

Option B (JAVA_HOME) is correct --- needed for Java execution.

Option C (PA_PATH) is not a standard variable.

Option D (PA_HOME) is correct --- required to point to the PingAccess installation root.

Option E (JAVA_PATH) is not valid; PATH can include Java, but JAVA_HOME is the correct environment variable.


Question 8

A protected web application requires that additional attributes be provided once the user is authenticated. Which two steps must the administrator perform to meet this requirement? (Choose 2 answers.)

Correct Answer: B. Update the Identity Mapping.; E. Update the Web Session.
Explanation:

When applications require additional attributes:

The Web Session must be configured to retrieve those attributes from the token provider (OIDC or PingFederate).

The Identity Mapping must be updated to forward those attributes to the application (e.g., as headers).

Exact Extract:

''Web sessions define how user attributes are retrieved from the token provider. Identity mappings determine how those attributes are inserted into requests to applications.''

Option A is not necessarily required; attributes can be retrieved via userinfo endpoint or access token, not only ID tokens.

Option B is correct --- Identity Mappings must be updated to pass attributes to the app.

Option C is incorrect --- Site Authenticators define how PingAccess authenticates to apps, not attribute handling.

Option D is incorrect unless the architecture specifically requires access token updates; PingAccess often uses the Web Session to fetch attributes.

Option E is correct --- Web Session must be updated to retrieve additional attributes.


Question 9

An administrator needs to configure a protected web application using the Authorization Code login flow. Which two configuration parameters must be set? (Choose 2 answers.)

Correct Answer: B. OAuth Client ID; E. OpenID Connect Login Type
Explanation:

When using the Authorization Code Flow for authentication, PingAccess must be configured with:

An OAuth Client ID that identifies the application to the IdP.

The OpenID Connect Login Type set to Authorization Code.

Exact Extract:

''When configuring an OIDC web session, specify the OAuth client ID and select the OpenID Connect login type (Authorization Code, Hybrid, or Implicit).''

Option A (OAuth Token Introspection Endpoint) is not required for Authorization Code flow --- token introspection is used in other cases.

Option B (OAuth Client ID) is correct --- required for OIDC authorization requests.

Option C (OpenID Connect Issuer) is discovered automatically via metadata when you configure the token provider.

Option D (Virtual Host) is required for application exposure but not specific to OIDC flow.

Option E (OpenID Connect Login Type) is correct --- must be set to ''Authorization Code.''


Question 10

According to a new business requirement, critical applications require dual-factor authentication when specific resources are accessed in those applications. Which configuration object should the administrator use in the applications?

Correct Answer: C. Authentication Requirements
Explanation:

PingAccess enforces step-up or multi-factor authentication using Authentication Requirements, which can be applied to specific resources within an application.

Exact Extract:

''Authentication requirements allow administrators to configure additional authentication (for example, MFA) when accessing sensitive application resources.''

Option A (UI Authentication) applies to access to the admin console, not application resources.

Option B (Auth Token Management) relates to OAuth token lifetimes and refresh, not MFA enforcement.

Option C (Authentication Requirements) is correct --- these rules enforce MFA or step-up auth for specific URLs/resources.

Option D (Authentication Challenge Policy) governs how failed auth challenges are presented but does not enforce MFA.