Month End Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

PT-AM-CPE Ping Identity Certified Professional - PingAM Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Ping Identity PT-AM-CPE Certified Professional - PingAM Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 100 questions

After installing a PingAM instance with the configuration directory path set to /home/forgerock/am, where is the default directory that contains the debug log files?

A.

/home/forgerock/am/logs

B.

/home/forgerock/am/var/logs

C.

/home/forgerock/am/var/debug

D.

/home/forgerock/am/debug

What is the purpose of the SAML2 account mapper on the service provider (SP) side?

A.

Maps multiple identity provider assertions together

B.

Maps multiple SP user accounts together

C.

Maps local user attributes to remote users' attributes

D.

Maps remote users to local user profiles

Which statements are correct about PingAM sessions?

A) When a web browser is involved, the web browser is instructed to set a cookie as the session reference.

B) When no browser is involved, PingAM returns the session reference in the JSON response.

C) PingAM can only track the session in the Core Token Service store.

D) The default session cookie name created in a web browser is iPlanetDirectoryPro.

A.

A, B, and D only

B.

A, B, and C only

C.

A, C, and D only

D.

A and B only

Why should module-based authentication be disabled in production?

A.

Module-based authentication allows a user to authenticate with the amAdmin account

B.

Module-based authentication allows a user to select any authentication level

C.

Module-based authentication allows a user to bypass steps in an authentication chain

D.

Module-based authentication allows users to authenticate in any realm

Which of the following is an incorrect statement about session upgrade outcomes?

A.

In a server-side session configuration, when using the ForceAuth parameter and an authentication tree, PingAM issues a new session token to a user who reauthenticates, even if the current session already meets the security requirements

B.

In a server-side or client-side session configuration, PingAM issues a new session token to a user who reauthenticates, only when the current session does not meet the security requirements

C.

In a server-side session configuration, when using advices, PingAM copies the session properties to a new session and replaces the client's original session token with a new session token

D.

In a client-side session configuration, PingAM replaces the client's original session token with a new session token

The Core Token Service (CTS) can be used for storing which of the following?

A.

Configuration

B.

Users

C.

Kerberos tokens

D.

OAuth2 tokens

In the OAuth2 Device Flow, which of the following HTTP codes is returned if a user has not yet authorized a client device?

A.

HTTP 403

B.

HTTP 400

C.

HTTP 401

D.

HTTP 302

An administrator has a requirement to reconfigure the attribute used to search for users in a LDAP Data Store. What Data Store configuration attribute would they need to change?

A.

LDAP Users Search Attribute

B.

LDAP Users Index Attribute

C.

LDAP Users Bind Attribute

D.

LDAP Users Find Attribute

A SAML2 identity provider (IdP) is configured in a subrealm. Which of the following URLs can be used to export the IdP metadata?

A.

It cannot be exported via a JSP, and the Amster tool has to be used

B.

http://myserver.domain.com:8080/openam/saml2/jsp/exportmetadata.jsp

C.

http://myserver.domain.com:8080/openam/saml2/jsp/exportmetadata.jsp?idp=http://myserver.domain.com:8080/openam &realm=/idprealm

D.

http://myserver.domain.com:8080/openam/saml2/jsp/exportmetadata.jsp?entityid=http://myserver.domain.com:8080/openam &realm=/idprealm

OpenID Connect acr_values map to what component within PingAM?

A.

Authentication trees

B.

SAML Circles of Trust

C.

Authorization policies

D.

Authentication levels

Sam wants to start a service provider-initiated single sign-on and redirect to their own application, myapp.com. Which of the following URLs is the correct one to perform this action?

A.

http://sso.domain.com/openam/saml2/jsp/idpSSOInit.jsp &RelayState=http%3A%2F%2Fmyapp.com

B.

http://sso.domain.com/openam/saml2/jsp/idpSSOInit.jsp &goto=http%3A%2F%2Fmyapp.com

C.

http://sso.domain.com/openam/saml2/jsp/spSSOInit.jsp &goto=http%3A%2F%2Fmyapp.com

D.

http://sso.domain.com/openam/saml2/jsp/spSSOInit.jsp &RelayState=http%3A%2F%2Fmyapp.com

In order to secure a PingAM deployment with an external configuration data store and user data store using server-side sessions, which of the following should be considered?

A.

Changing the default iPlanetDirectoryPro cookie name, Using your own key for signing, Using a specific bind account for LDAP connections, Renaming and reducing the assigned privileges of the amAdmin account

B.

Encrypting the iPlanetDirectoryPro cookie contents, Changing the default iPlanetDirectoryPro cookie name, Using your own key for signing, Using a specific bind account for LDAP connections

C.

Changing the default iPlanetDirectoryPro cookie name, Using your own key for signing, Using a specific bind account for LDAP connections, Creation of a top-level administrator other than amAdmin

D.

Changing the default iPlanetDirectoryPro cookie name, Using your own key for signing, Using a specific bind account for LDAP connections, Reducing the privileges of the amAdmin user in production

Which of the following components is used to return data to PingGateway or the agent to be included with the policy decision?

A.

Subjects

B.

Resources

C.

Response attributes

D.

Actions

Which OpenID Connect grant flow is best to use when the relying party knows the user's identifier and wishes to gain consent for an operation from the user by means of a separate authentication device?

A.

Implicit grant

B.

Authorization code grant

C.

Hybrid grant

D.

Backchannel request grant

A PingAM administrator wants to deny access to an area of a protected application if the end user has been logged in for more than 10 minutes. How can this be achieved?

A.

Use a policy with a Time environment condition

B.

Use a policy with a Current session properties environment condition

C.

Use a policy with a Scripted environment condition

D.

Use a policy with an Active session time environment condition

Which of the following would be a possible combination of fields in the JSON body when making a policy evaluation via REST?

A.

resources, subject, advices

B.

resources, subject, application

C.

resources, application, advices

D.

subject, application, advices

Which statement differentiates the ForgeOps Cloud Deployment Model (CDM) from the Cloud Developer Kit (CDK) deployment?

A.

Deployment generates random secrets

B.

Supports deployment with Google Kubernetes Engine (GKE), Amazon Elastic Kubernetes Service (EKS), or Azure Kubernetes Service (AKS) clusters

C.

Provides replicated directory services

D.

Fully integrated PingAM, PingIDM, and PingDS installations

What is a SAML2 artifact?

A.

The SAML2 assertion

B.

The SAML2 binding name

C.

The name of a specific attribute in the assertion

D.

A value sent by the service provider to retrieve the assertion

The OAuth2 authorize endpoint supports the CSRF parameter. What is CSRF?

A.

Cross Script Response Feature

B.

Cross Site Request Forgery

C.

Cross Site Request Forgery

D.

Cross System Rest Federation

In the default Cloud Developer Kit (CDK) deployment of the forgeops repository, which pods provide the user interface functionality?

A.

admin-ui, end-user-ui, login-ui

B.

amadmin-ui, idmadmin-ui, login-ui

C.

am-ui, idm-ui, login-ui

D.

am-ui, idm-ui, end-user-ui

Page: 1 / 2
Total 100 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved