Todos os guias de estudo

CP-PingOne

Certified Professional - PingOne

Parte de Certified Professional - PingOne

Proctored exam; no prerequisites. Official recommended training: Getting Started With PingOne SSO; Getting Started With PingOne MFA; PingOne Administration.

Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da ping. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria ping como a fonte da verdade e confira nele antes de agendar qualquer coisa.

Section 1: PingOne SSO

  • 1.01 Describe how to configure the different application types available in PingOne

    O que saber:
    • OIDC Web App, Native, SPA, Worker, and SAML application types
    • Redirect URIs, token auth method, and grant selection per type
    • Worker apps: no user context - management-API clients
    • Attribute mappings from directory to tokens/assertions
    Ferramentas: oauth-flow-chooser
  • 1.02 Describe the Application Catalog

    O que saber:
    • Pre-built templates for common SaaS integrations
    • Catalog entries pre-fill protocol settings and mappings
    • Custom apps when the catalog has no match
  • 1.03 Describe the Application Portal

    O que saber:
    • End-user dock of assigned applications
    • Portal access controlled by group/population assignment
    • Branding follows the environment theme
  • 1.04 Utilize certificates and keypairs

    O que saber:
    • Signing keypairs for tokens and SAML assertions
    • Certificate import for verification and encryption
    • Rotation: issue new key, keep old for validation window
    • Expiry visibility and admin alerts
    Ferramentas: x509
  • 1.05 Explain the function of resources in PingOne

    O que saber:
    • Resources model protected APIs and their scopes
    • Custom scopes attached to access tokens
    • Audience values the resource server validates
    • openid/profile built-ins vs custom resources
    Ferramentas: jwt
  • 1.06 Describe how to configure policies in PingOne

    O que saber:
    • Authentication policies: steps, conditions, and outcomes
    • Single-factor vs step-up composition
    • Policy assignment per application
    • Default environment policy as the fallback

Section 2: PingOne Directory Management

Section 3: PingOne MFA

  • 3.01 Describe how to configure MFA policies

    O que saber:
    • MFA policies select allowed methods and ordering
    • FIDO2, TOTP authenticator, SMS/voice/email OTP, mobile push
    • Device limits and pairing rules per policy
    Ferramentas: totp-hotp
  • 3.02 Describe how to integrate MFA into an authentication policy

    O que saber:
    • MFA appears as a step inside an authentication policy
    • Condition-gated step-up (risk, group, application)
    • Remember-device semantics and bypass windows
    Ferramentas: totp-hotp
  • 3.03 Describe how to manage a user’s MFA device

    O que saber:
    • Admin view of a user's paired devices
    • Unpair/block a lost device; user re-pairs on next login
    • Device nickname and usage metadata
    Ferramentas: totp-hotp
  • 3.04 Explain PingOne MFA settings

    O que saber:
    • Environment-level MFA settings vs per-policy choices
    • Pairing limits, OTP lifetimes, and lockout thresholds
    • Notification templates the methods consume
    Ferramentas: totp-hotp

Section 4: PingOne Administration

  • 4.01 Explain how to configure administrative roles for environments and organizations

    O que saber:
    • Organization vs environment role scopes
    • Built-ins: Organization Admin, Environment Admin, Identity Data Admin, Client App Developer
    • Least privilege: scope admin roles to specific environments
    • Role assignment to users or worker applications
  • 4.02 Describe how to manage PingOne environments

    O que saber:
    • Environment as the isolation unit (sandbox vs production)
    • Region, license, and service (SSO/MFA/DaVinci) composition
    • Environment properties, deletion protection
  • 4.03 Describe how to access and collect environment audit logs

    O que saber:
    • Audit log stream of admin and runtime events
    • Console viewing with filters; export via API
    • Webhook/SIEM forwarding patterns
  • 4.04 Describe the different types of alerts available in PingOne

    O que saber:
    • Alerts for certificate expiry, license, and key events
    • Delivery to configured admin emails
    • Acting before expiry: pair alerts with keypair rotation
  • 4.05 Describe how to configure custom domains and email trust

    O que saber:
    • Custom domain (CNAME) for auth endpoints
    • Certificate provisioning for the custom domain
    • Email trust: sending domain verification (SPF/DKIM alignment)
    Ferramentas: x509
  • 4.06 Describe how to configure email and SMS options

    O que saber:
    • Email/SMS sender configuration and templates
    • Custom SMTP vs Ping-provided sending
    • Per-language template variants
  • 4.07 Describe metrics on user activities

    O que saber:
    • Dashboards: sign-ons, MFA usage, active users
    • Time-window filtering and CSV export
    • Reading trends: adoption and failure spikes
  • 4.08 Utilize agreements and implement them in authentication policies

    O que saber:
    • Agreements hold versioned consent text
    • Localized agreement content per language
    • Enforced as an authentication-policy step - consent gate before access
  • 4.09 Describe the options available for customizing branding and themes

    O que saber:
    • Themes: logo, colors, backgrounds for hosted pages
    • Per-environment theme defaults
    • Preview before publish; template overrides for full control
  • 4.10 Explain how to enable and add languages

    O que saber:
    • Enable languages per environment
    • Locale detection and user override
    • Translated notification and agreement content pairs with themes

Fontes públicas, usadas de boa-fé

Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo