During the creation of QnA (Questions and Answers) credentials, the system currently allows users to submit custom security questions directly within the API request, bypassing the predefined question set configured in the environment.
To enforce strict security policies, organizations may need to disable custom question submission and restrict users to selecting only predefined security questions fetched from the existing QnA configuration.
Symantec Strong Authentication 9.1.5.1
RHEL 9.4
To enforce the restriction and limit security questions strictly to the predefined configuration, apply the required software update:
Download the patch Symantec-StrongAuth-DE669847-DevPatch from this knowledge base article.
Apply the patch to your environment following standard hotfix deployment procedures.
Once applied, custom questions submitted in SOAP requests or console profiles during QnA credential creation will be rejected, ensuring only predefined, configured questions are permitted.
Please reach out to Support if there are any questions or concerns.