Question

OPC UA separates Application authentication (the client/server X.509 certificate) from User authentication (the actual end-user login), which can be Anonymous, Username/Password, or User Certificate.

OPC UALearnSecurityMedium
Answer

True

OPC UA security is layered on two axes. Application authentication answers "which software is connecting" via the X.509 Application Instance Certificate. User authentication answers "which human or service is operating that software" and is carried through the Session: it can be Anonymous, Username + Password, an X.509 user certificate, or a Kerberos/IssuedToken. This lets a single client application be used by ten different operators with different rights, and lets the server grant Anonymous read-only access while requiring Username/Password for write or Method calls.

Preparation tip

Disable Anonymous access entirely as soon as you reach commissioning: even read-only Anonymous endpoints leak the full Address Space structure to any scanner on the network.

Waitlist

OPC UA bank in preparation

The full OPC UA bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.

Join the waitlist
Want more?

See the 9 other OPC UA practice questions

Related questions

Question from our independent practice bank. OPC UA is a registered trademark of OPC Foundation, not affiliated with CertifBus.

Last updated: 19 May 2026

Join the waitlist
OPC UA waitlist