Question 1
A financial services firm is implementing a stringent access policy for its traders. The policy requires that any login attempt to the trading platform from outside the corporate network (defined by a specific IP range) must be challenged with a FIDO2 hardware key. However, logins from within the corporate network should only require a password. Which CyberArk Identity feature should be used to configure this conditional logic?
Answer and explanation
Correct answer: C
Authentication Rules are the core component for implementing adaptive MFA. An administrator can create a rule that specifies a condition, such as the source IP address not being in a predefined range, and then apply a specific Authentication Profile (e.g., one requiring FIDO2) when that condition is met. The default policy can be set to password-only, which would apply to all other conditions, including logins from the corporate IP range.