20% of the exam — the third-largest domain.
7 sub-topics · this deck covers sub-topic 5 of 7
↑ Module 1 OverviewNot every login looks the same. Adaptive MFA is about noticing when one looks different — and reacting to that, without just locking everyone out by default.
Behavior Detection analyzes patterns of user activity and builds profiles of typical behavior based on prior activity — tracking things like sign-ins from a new geographic location or access from an unfamiliar device.
Admins configure which behavior types to track and when a change should trigger a response — e.g., "require MFA if a user signs in from a new location or uses a new device."
This is a precise distinction the exam can test directly: anomalous behavior triggers a step-up challenge, never an outright block.
Watch for scenario questions built around this trap:
→ "Can Behavior Detection block a login outright if it looks suspicious?" = No — it can only trigger additional MFA, never deny access on its own.
Sources: help.okta.com — proc-security-behavior-detection.htm
Next: Sub 6 →