CP-PingOne
Certified Professional - PingOne
Parte de Certified Professional - PingOne
Proctored exam; no prerequisites. Official recommended training: Getting Started With PingOne SSO; Getting Started With PingOne MFA; PingOne Administration.
Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da ping. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria ping como a fonte da verdade e confira nele antes de agendar qualquer coisa.
Section 1: PingOne SSO
1.01 Describe how to configure the different application types available in PingOne
O que saber:- OIDC Web App, Native, SPA, Worker, and SAML application types
- Redirect URIs, token auth method, and grant selection per type
- Worker apps: no user context - management-API clients
- Attribute mappings from directory to tokens/assertions
Ferramentas: oauth-flow-chooser1.02 Describe the Application Catalog
O que saber:- Pre-built templates for common SaaS integrations
- Catalog entries pre-fill protocol settings and mappings
- Custom apps when the catalog has no match
1.03 Describe the Application Portal
O que saber:- End-user dock of assigned applications
- Portal access controlled by group/population assignment
- Branding follows the environment theme
1.04 Utilize certificates and keypairs
O que saber:- Signing keypairs for tokens and SAML assertions
- Certificate import for verification and encryption
- Rotation: issue new key, keep old for validation window
- Expiry visibility and admin alerts
Neste site: PEM, DER e os formatos de arquivo de certificadoFerramentas: x5091.05 Explain the function of resources in PingOne
O que saber:- Resources model protected APIs and their scopes
- Custom scopes attached to access tokens
- Audience values the resource server validates
- openid/profile built-ins vs custom resources
Ferramentas: jwt1.06 Describe how to configure policies in PingOne
O que saber:- Authentication policies: steps, conditions, and outcomes
- Single-factor vs step-up composition
- Policy assignment per application
- Default environment policy as the fallback
Neste site: O fluxo authorization code do OIDC
Section 2: PingOne Directory Management
2.01 Describe how to manage users in the PingOne Directory
O que saber:- User lifecycle: create, update, disable, delete
- Password state: set, force-change, unlock
- Identity attributes and custom schema extension
- Bulk import options and CSV formats
Ferramentas: ldap-filter-explainer2.02 Manage user groups
O que saber:- Static membership managed directly
- Dynamic groups via filter expressions
- Groups drive application access and role assignment
- Nested strategy: keep flat where possible
2.03 Explain the purpose and limitations of populations
O que saber:- Populations partition users within one environment
- One population per user - hard boundary
- Per-population password policies
- Populations are not groups: no app-assignment semantics
Section 3: PingOne MFA
3.01 Describe how to configure MFA policies
O que saber:- MFA policies select allowed methods and ordering
- FIDO2, TOTP authenticator, SMS/voice/email OTP, mobile push
- Device limits and pairing rules per policy
Ferramentas: totp-hotp3.02 Describe how to integrate MFA into an authentication policy
O que saber:- MFA appears as a step inside an authentication policy
- Condition-gated step-up (risk, group, application)
- Remember-device semantics and bypass windows
Ferramentas: totp-hotp3.03 Describe how to manage a user’s MFA device
O que saber:- Admin view of a user's paired devices
- Unpair/block a lost device; user re-pairs on next login
- Device nickname and usage metadata
Ferramentas: totp-hotp3.04 Explain PingOne MFA settings
O que saber:- Environment-level MFA settings vs per-policy choices
- Pairing limits, OTP lifetimes, and lockout thresholds
- Notification templates the methods consume
Ferramentas: totp-hotp
Section 4: PingOne Administration
4.01 Explain how to configure administrative roles for environments and organizations
O que saber:- Organization vs environment role scopes
- Built-ins: Organization Admin, Environment Admin, Identity Data Admin, Client App Developer
- Least privilege: scope admin roles to specific environments
- Role assignment to users or worker applications
4.02 Describe how to manage PingOne environments
O que saber:- Environment as the isolation unit (sandbox vs production)
- Region, license, and service (SSO/MFA/DaVinci) composition
- Environment properties, deletion protection
4.03 Describe how to access and collect environment audit logs
O que saber:- Audit log stream of admin and runtime events
- Console viewing with filters; export via API
- Webhook/SIEM forwarding patterns
4.04 Describe the different types of alerts available in PingOne
O que saber:- Alerts for certificate expiry, license, and key events
- Delivery to configured admin emails
- Acting before expiry: pair alerts with keypair rotation
4.05 Describe how to configure custom domains and email trust
O que saber:- Custom domain (CNAME) for auth endpoints
- Certificate provisioning for the custom domain
- Email trust: sending domain verification (SPF/DKIM alignment)
Ferramentas: x5094.06 Describe how to configure email and SMS options
O que saber:- Email/SMS sender configuration and templates
- Custom SMTP vs Ping-provided sending
- Per-language template variants
4.07 Describe metrics on user activities
O que saber:- Dashboards: sign-ons, MFA usage, active users
- Time-window filtering and CSV export
- Reading trends: adoption and failure spikes
4.08 Utilize agreements and implement them in authentication policies
O que saber:- Agreements hold versioned consent text
- Localized agreement content per language
- Enforced as an authentication-policy step - consent gate before access
4.09 Describe the options available for customizing branding and themes
O que saber:- Themes: logo, colors, backgrounds for hosted pages
- Per-environment theme defaults
- Preview before publish; template overrides for full control
4.10 Explain how to enable and add languages
O que saber:- Enable languages per environment
- Locale detection and user override
- Translated notification and agreement content pairs with themes
Fontes públicas, usadas de boa-fé
Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo →