CP-PingOne-AIC
Certified Professional - PingOne Advanced Identity Cloud
Parte de Certified Professional - PingOne Advanced Identity Cloud
Proctored by Kryterion. Credential valid for 2 years. Validates configure, administer, troubleshoot, and maintain for Advanced Identity Cloud tenants (formerly ForgeRock Identity Cloud). Official recommended training: Getting Started With PingOne Advanced Identity Cloud for Administrators; PingOne Advanced Identity Cloud Deep Dive: Access Management; PingOne Advanced Identity Cloud Deep Dive: Identity Management.
Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da ping. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria ping como a fonte da verdade e confira nele antes de agendar qualquer coisa.
Section 1: Managing Advanced Identity Cloud Tenants
1.01 Explain the environment and roles for managing Advanced Identity Cloud
O que saber:- Managed cloud tenant: development, staging, production environments
- AM, IDM, DS delivered as a service - no infrastructure to run
- Tenant admin roles vs delegated realm roles
- Promotion of config between environments
1.02 Manage administrative access
O que saber:- Tenant admin, and scoped roles for teams
- SSO for administrators into the tenant
- Break-glass and least-privilege for admin access
1.03 Perform general administrative tasks
O que saber:- Config-as-code exports and promotion pipeline
- Scheduled tasks and tenant settings
- Certificate and secret management in-tenant
Section 2: Managing User Identities
2.01 Model identity objects
O que saber:- managed alpha_user / alpha_role realm objects
- Schema extension via custom properties
- Searchable and encrypted property flags
2.02 Manage event hooks
O que saber:- Event hooks fire scripts on object lifecycle events
- postCreate/postUpdate/postDelete scripting
- Outbound integration triggered by identity changes
2.03 Import and sync identities
O que saber:- CSV/bulk import into managed identities
- Reconciliation against connected systems
- Scheduling recurring sync jobs
Ferramentas: ldap-filter-explainer2.04 Manage provisioning roles and assignments with Advanced Identity Cloud
O que saber:- Provisioning roles carry assignments to target apps
- Conditional membership by query filter
- Assignment attributes flow on grant, revoke on removal
2.05 Manage custom objects and properties
O que saber:- Custom managed objects beyond user/role
- Custom properties with policy and validation
- Relationships to core objects
Section 3: Managing User Journeys
3.01 Describe the purpose of the default user journeys
O que saber:- Default journeys: Login, Registration, Reset Password, Progressive Profile
- Starting points to clone and customize
- Realm-scoped journey assignment
3.02 Modify Journeys
O que saber:- Add/remove/rearrange nodes in the journey editor
- Inner journeys for reuse
- Success/failure outcome wiring
3.03 Configure self-service journeys
O que saber:- Self-service: registration, password reset, profile update journeys
- Email/OTP verification nodes
- Progressive profiling to collect data over time
3.04 Configure Advanced Identity Cloud to use social registration and authentication
O que saber:- Social identity provider nodes (Google, Apple, etc.)
- Provider client credentials and scopes
- Account claiming/linking to existing identities
Neste site: Fluxos OAuth: escolhendo o grant em 2026Ferramentas: oauth-flow-chooser
Section 4: Integrating Applications and Gateways
4.01 Describe the role of an application in Advanced Identity Cloud
O que saber:- Applications represent OAuth/OIDC/SAML integrations
- Managed application catalog and custom apps
- Bind journeys and access policies to applications
4.02 Manage an application client profile
O que saber:- Client profile: redirect URIs, grants, scopes, token settings
- Confidential vs public client configuration
- Token lifetimes and refresh behavior
Neste site: Fluxos OAuth: escolhendo o grant em 2026, Tokens de acesso, tokens de atualização e tokens de IDFerramentas: oauth-flow-chooser4.03 Integrate PingGateway
O que saber:- PingGateway fronts legacy/on-prem apps for the cloud tenant
- Route protection consuming tenant tokens
- Hybrid bridge between cloud identity and on-prem resources
Section 5: Managing Federation
5.01 Integrate Advanced Identity Cloud with third-party services using SAML
O que saber:- Tenant as SAML IdP or SP with third parties
- Metadata exchange and signing keys
- Attribute mapping into assertions
Neste site: F5 BIG-IP APM como SAML Proxy: Modos SP e IdPFerramentas: saml-decoder5.02 Integrate Advanced Identity Cloud with third-party services using OIDC/OAuth
O que saber:- Tenant as OIDC/OAuth provider to third parties
- Client registration and scope design
- Token and claim configuration for partners
Neste site: O fluxo authorization code do OIDCFerramentas: jwt
Fontes públicas, usadas de boa-fé
Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo →