CP-PingAM
Certified Professional - PingAM
Parte de Certified Professional - PingAM
Proctored by Kryterion. Credential valid for 3 years. Validates install, configure, administer, troubleshoot, and maintain for PingAM (formerly ForgeRock Access Management). Official recommended training: PingAM Deep Dive; PingAM: Customization and APIs.
Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da ping. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria ping como a fonte da verdade e confira nele antes de agendar qualquer coisa.
Section 1: Enhancing Intelligent Access
1.01 Exploring authentication mechanisms
O que saber:- Authentication journeys (trees) composed of nodes
- Realms partition configuration and identities
- Node types: collectors, deciders, verifiers
- Success/failure paths and inner-tree nesting
1.02 Protecting a website with PingGateway
O que saber:- PingGateway as the reverse-proxy policy-enforcement point
- Routes protect legacy apps without code changes
- Gateway consumes AM sessions/tokens to gate access
1.03 Controlling access
O que saber:- Authorization: policy sets, resource types, policies
- Subjects, environment conditions, and response attributes
- Policy decision via the policies endpoint or agents
Section 2: Improving Access Management Security
2.01 Increasing authentication security
O que saber:- MFA nodes: OATH, push, WebAuthn in journeys
- Account lockout and intelligent throttling
- Device profiling and trusted-device marking
2.02 Modifying a user’s authentication experience based on context
O que saber:- Contextual branching: IP range, device, time, user attributes
- Scripted decision nodes for custom context
- Different journeys per persona or channel
2.03 Checking risk continuously
O que saber:- Continuous risk: evaluate mid-session, not only at login
- Transactional authorization for sensitive actions
- Step-up when the risk signal changes
Section 3: Extending Services Using OAuth2-Based Protocols
3.01 Integrating applications with OAuth 2.0 (OAuth2)
O que saber:- AM as the OAuth2 authorization server per realm
- Client registration: confidential vs public, grants, scopes
- Token endpoint auth methods; token lifetimes
Neste site: Fluxos OAuth: escolhendo o grant em 2026, Clientes públicos vs confidenciais, e onde o PKCE se encaixaFerramentas: oauth-flow-chooser3.02 Integrating applications with OpenID Connect (OIDC)
O que saber:- OIDC provider atop OAuth2: id_token issuance
- Claims mapping from identity attributes
- Discovery and JWKS endpoints per realm
Ferramentas: oauth-flow-chooser3.03 Authenticating OAuth2 clients and using mutual TLS (mTLS) in OAuth2 for proof-of-possession (PoP)
O que saber:- Client auth: secret, private_key_jwt, mutual TLS
- mTLS certificate-bound access tokens (proof-of-possession)
- Sender-constrained tokens defeat token replay
Ferramentas: x5093.04 Transforming OAuth2 tokens
O que saber:- Token exchange/transformation between formats and audiences
- Scripted token modification for claim shaping
- When a downstream needs a different token than the client holds
Ferramentas: jwt3.05 Implementing social authentication
O que saber:- Social identity provider nodes in journeys
- Provider client credentials and redirect wiring
- Account linking to existing identities
Neste site: Fluxos OAuth: escolhendo o grant em 2026
Section 4: Federating Across Entities Using SAML2
4.01 Implementing single sign-on (SSO) using SAML v2.0 (SAML2)
O que saber:- AM as SAML2 IdP or SP; entities and metadata exchange
- Assertion signing/encryption keys
- Attribute mapping into assertions; NameID formats
Neste site: F5 BIG-IP APM como SAML Proxy: Modos SP e IdPFerramentas: saml-decoder4.02 Delegating authentication using SAML2
O que saber:- Delegated authentication: SP defers to a remote IdP
- SP-initiated vs IdP-initiated flows
- Circle of trust groups the federation partners
Neste site: F5 BIG-IP APM como SAML Proxy: Modos SP e IdPFerramentas: saml-decoder
Section 5: Installing and Deploying AM
5.01 Installing and upgrading AM
O que saber:- Deploy the AM WAR on a servlet container
- Configuration and identity stores on PingDS
- Upgrade path: config export, amupgrade tooling, version order
5.02 Hardening AM security
O que saber:- Change default admin credentials and cookie names
- Restrict endpoints; secure cookies; CSRF protections
- Secret stores for keys instead of inline config
5.03 Clustering AM
O que saber:- Multiple AM servers behind a load balancer per site
- CTS-based sessions make instances stateless
- Sticky vs stateless routing considerations
5.04 Deploying PingOne Advanced Identity Platform to the Cloud
O que saber:- PingOne Advanced Identity Platform: AM/IDM/DS as managed cloud
- Tenant environments replace self-managed infrastructure
- Config-as-code promotion between tenant environments
Fontes públicas, usadas de boa-fé
Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo →