UiPath-ADPv1 Generic Automation Development Practice Question
A developer is building a UiPath automation that must process invoices received as email attachments. The process runs unattended overnight and must log into a web portal that uses a multi-factor authentication prompt delivered to a shared mobile device. The developer needs to ensure the robot can complete the login without human intervention. Which approach should be used?
⚠ Common exam trap
The trap here is assuming that any MFA prompt automatically requires a human-in-the-loop action, when time-based one-time passwords can be generated and consumed by the robot itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the portal credentials in Orchestrator Assets and configure the MFA code retrieval using a TOTP-based authenticator asset.
Unattended automation that faces MFA must retrieve both the credential and the one-time code programmatically. Orchestrator credential assets protect the password, while a TOTP asset supplies the rotating code. Together they let the robot authenticate without a human, which is the only approach here that satisfies both the unattended schedule and security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a human-in-the-loop action in Orchestrator to ask an operator to type the MFA code each night.
Why it's wrong here
A human-in-the-loop action requires a person to be available and respond, which contradicts the unattended overnight requirement. While it is a valid pattern for attended scenarios, it introduces delay and dependency on human availability, making it unsuitable for a fully automated nightly process.
- ✓
Store the portal credentials in Orchestrator Assets and configure the MFA code retrieval using a TOTP-based authenticator asset.
Why this is correct
Orchestrator Assets securely store credentials, and a TOTP asset can generate time-based one-time passwords that the robot reads at runtime. This allows unattended login without a human entering the MFA code, satisfying the overnight requirement while keeping secrets out of the project files.
- ✗
Hardcode the username, password, and a static MFA backup code inside the process workflow.
Why it's wrong here
Hardcoding secrets in the workflow exposes them to anyone with project access and violates security best practices. A static backup code may also expire or be single-use, causing the unattended job to fail. This approach is insecure and unreliable for a production unattended process.
- ✗
Disable MFA on the portal account so the robot can log in with only a username and password.
Why it's wrong here
Disabling MFA weakens the security posture of the portal and is typically prohibited by IT policy. The robot should adapt to the security control, not remove it. This option solves the symptom by compromising security rather than implementing a proper automated MFA solution.
About these practice questions
This UiPath-ADPv1 question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official UiPath exam blueprint
This UiPath-ADPv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADPv1 exam.