wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Quiz

Total questions: 107

Worksheet time: 1hrs 10mins

Name
Class
Date
1.

Which permissions are needed for the Active Directory user required by the Windows Discovery process?

a)

DomainAdmin

b)

LdapAdmin

c)

Read/Write

d)

Read

2.

Match each component to its respective LogFile location.

4 lines
3.

You Received this Error: “Error in changepass to user domain\user on domain server (\domain)winRC=50 Access is denied”

Which root cause should you investigate?

a)

The account does not have sufficient permission to change its own password

b)

The domain controller is unreachable

c)

The password has been changed recently and minimum password age is preventing the change.

d)

The CPM service is disabled and will need to be restarted.

4.

As vault Admin you have been asked to configure LDAP authentication for your organization’s CyberArk users. Which permissions do you need to complete this task?

LDAP integration in V10 | CyberArk Docs

a)

Audit Users and Add Network Areas

b)

Audit Users and Manage Directory Mapping

c)

Audit Users and Add/Update Users

d)

Audit Users and Activate Users

5.

Which PTA sensors are required to detect suspected credential theft?

What Detections Does PTA Report? | CyberArk Docs


a)

Logs, Vault Logs

b)

Logs, Network Sensor, Vault Logs

c)

Logs, PSM Logs, CPM Logs

d)

Logs, Network Sensor, EPM

6.

You are installing HTML5 gateway on a Linux host using the RPM provided. After installing the Tomcat webapp, what is the next step in the installation process?

Install PSM HTML5 Gateway using an RPM package | CyberArk Docs


a)

Deploy the HTML5 service (guacd)

b)

Secure the connection between the guacd and the webapp

c)

Secure the webapp and JWT validation endpoint

d)

Configure ASLR

7.

To enable automatic response “Add to Pending” within PTA when unmanaged credentials are found, what are the minimum permissions required by PTAUser for the PasswordManager_Pending safe?

Configure PTA Remediations | CyberArk Docs


a)

List Accounts, View Safe Members, Add Accounts (includes update properties), Update Account Content, Update Account Properties.

b)

List Accounts, Add Accounts (includes update properties), Delete Accounts, Manage Safe

c)

Add Accounts (includes update properties), Update Account Content, Update Account properties, View Audit.

d)

View Accounts, Update Account Content, Update Account Properties, Access Safe without Confirmation, Manage Safe, View Audit.

8.

A customer’s environment three data centers, consisting of 5,000 servers in Germany, 10,000 servers in Canada, 1,500 servers in Singapore. You want to manage target servers and avoid complex firewall rules. How many CPM’s should you deploy?

Recommended Server Specifications | CyberArk Docs


a)

1

b)

3, total, 1 per data center

c)

15

d)

6, total, 2 per data center

9.

What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?

RADIUS Authentication | CyberArk Docs

a)

Log onto the PrivateArk Client, display the user properties of the user to configure, run the Authentication method drop-down list, and select RADIUS authentication.

b)

In the RADIUS server, define the CyberArk Vault as RADIUS client/agent.

c)

In the Vault Installation folder, run CAVaultManger as Administrator with the Secure Secret Files command.

d)

Navigate to /Server/Conf and open DBParms.ini and set the RadiusServersInfo parameter.

10.

Which components can connect to a satellite Vault in distributed Vault architecture?

Distributed Vaults Component Features | CyberArk Docs


a)

CPM, EPM, PTA

b)

PVWA, PSM

c)

CPM, PVWA, PSM

d)

CPM, PSM

11.

You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How should this be configured to allow for password management using least privilege?

a)

Configure each CPM to use the correct logon account

b)

Configure each CPM to use the correct reconcile account

c)

Configure the UNIX Platform to use the correct logon account

d)

Configure the UNIX Platform to use the correct reconcile account

12.

Match the built-in Vault user with the correct definition.

4 lines
13.

A new HTML5 Gateway has been deployed in your organization. Where do you configure the PSM to use the HTML5 Gateway?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/PSM_HTML5.htm


a)

Administration > Options > Privileged Session Management > Configured PSM Servers > Connection Details > Add PSM Gateway

b)

Administration > Options > Privileged Session Management > Add configured PSM Gateway Servers

c)

Administration > Options > Privileged Session Management > Configured PSM Servers > Add PSM Gateway

d)

Administration > Options > Privileged Session Management > Configured PSM Servers > Connection Details

14.

A vault Administrator team member can log in to CyberArk, but for some reason, is not given Vault Admin rights. Where can you check to verify that the Vault Admins directory mapping points to the correct AD group

LDAP integration in V10 | CyberArk Docs

a)

PVWA > User Provisioning > LDAP Integration > Mapping Criteria

b)

PVWA > User Provisioning > LDAP Integration > Map Name

c)

PVWA > Administration > LDAP Integration > Mappings

d)

PVWA > Administration > LDAP Integration > AD Groups

15.

In the PrivateArk Client, how do you add an LDAP group to a CyberArk Group?

Performed this in PA Client myself.


a)

Select update on the CyberArk Group, and then click ADD > LDAP group

b)

Select update on the LDAP Group, and then click ADD > LDAP Group

c)

Select MemberOf on the CyberArk Group, and then click ADD > LDAP group

d)

Select MemberOf on the LDAP Group, and then click ADD > LDAP Group

16.

What are the basic network requirements to deploy a CPM server?

a)

Port 1858 to Vault and port 443 to PVWA

b)

Port 1858 only

c)

All ports to the vault

d)

Port UDP/1858 to vault and all required ports to the targets and port 389 to the PSM.

17.

You have been asked to identify the UP or Down of Vault Services. Which CyberArk utility can you use to accomplish this task?

a)

Vault Replicator

b)

PAS Reporter

c)

Remote Control Agent

d)

Syslog

18.

What is mandatory for a PVWA installation?

a)

A DNS entry for PVWA url must be created.

b)

A company signed TLS certificate must be imported into the server

c)

A vault Administrator user must be used to register the PVWA

d)

Data Execution Prevention must be disabled.

19.

A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The vault administrator has been asked to look and the account and identify who can approve their request. What is the correct location to identify users or groups who can approve?

a)

PVWA > Administration > Platform Configurations > Edit Platform > UI & Workflows > Dual Control > Approvers

b)

PVWA > Policies > Access Control (Safes) > Safe Members > Workflow > Authorize Password Requests

c)

PVWA > Accounts List > Edit > Show Advanced Settings > Dual Control > Direct Mangers

d)

PrivateArk > Admin Tools > Users and Groups > Auditors (Group Memberships)

20.

You are helping a customer prepare a Windows server for PSM installation. What is required for a successful installation?

a)

Window 2012 KB4558843

b)

Remote Desktop services (RDS) Session Host Roles

c)

Windows 2016 KB4558843

d)

Remote Desktop services (RDS) Session Broker

21.

You have been asked to secure a set of shared accounts in CyberArk whose passwords will need to be used by end users. The account owner wants to be able to track who was using an account at any given moment. What security configuration should you recommend?

a)

Configure one-time passwords for the appropriate platform in Master Policy

b)

Configure shared account mode on the appropriate safe.

c)

Configure both one-time passwords and exclusive access for the appropriate platform in Master Policy.

d)

Configure object level access control on the appropriate safe.

22.

In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?

Three things to consider, Size of session recordings, Activity in your enterprise and Recordings Retention Period.

Considerations for installing PSM | CyberArk Docs

a)

Retention period

b)

Number of PSMs

c)

Number of users

d)

Number of targets

23.

CyberArk user Neil is trying to connect to the Target Linux server 192.168.1.64 using a domain account ACME/linuxuser01 on Domain Acme.corp using PSM for SSH server 192.168.65.145. What is the correct syntax?

ssh <vaultuser>@<targetuser>#<domainaddress>@<targetserver>@<PSMPserver>

How to connect with PSMP to a target Unix Domain account: (force.com)

a)

Ssh neil@linuxuser01:acme.corp@192.168.1.64@192.168.1.45

b)

Ssh neil@linuxuser01#acme.corp@192.168.1.64@192.168.1.45

c)

Ssh neil@linuxuser01@192.168.1.64@192.168.65.145

d)

Ssh neil@linuxuser01@acme.corp@192.168.1.64@192.168.1.45

24.

Which component must be installed on the Vault if Distributed Vaults is used with PSM?

a)

RabbitMQ

b)

Disaster Recovery

c)

Remote Control Client

d)

Distributed Vault Server

25.
a)

Windows events text recorder with automatic play-back

b)

Windows events text recorder and universal keystrokes recording simultaneously

c)

Universal keystrokes text recorder and windows events text recorder disabled.

d)

Custom audio recording for windows events.

26.

Which tools are used during a CPM renaming process?

a)

API Key Manager Utility

b)

Create Cred File Utility

c)

CPM in Domain_Hardening.ps1

d)

PM Terminal.exe

27.

If a customer has one data center and requires high availability, how many PVWA’s should be deployed.

a)

Two

b)

One PVWA cluster

c)

One

d)

Two PVWA Cluster

28.

In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA Hardening.ps1 perform when run?

a)

Performs IIS hardening: Import the CyberArk INF configuration

b)

Performs IIS hardening: Configures all group policy settings

c)

Performs IIS hardening: Renames the local Administrator Account

d)

Configures Windows Firewall: Removes all installation files.

29.

Refer to the exhibit.

A customer is building a development environment in the Amazon public cloud through Amazon Web Services.

What is the ideal specification for the Vault as it will only hold less than 1,000 accounts?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20Cloud/AWS-System-Requirements.htm?TocPath=Installation%7CInstall%20Privileged%20Access%20Security%C2%A0in%20a%20cloud%20environment%7CIntroduction%7C_____4

a)

T2micro

b)

T3medium

c)

M5large

d)

C5large

30.

A customer is deploying PVWAs in the Amazon Web Services Public Cloud. Which load balancing option does CyberArk recommend?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.5/en/Content/PAS%20Cloud/AWS-LoadBalancer-for-PVWA.htm

a)

Network Load Balancer

b)

Classic Load Balancer

c)

HTTPS load balancer

d)

Public standard load balancer

31.

Due to network activity, ACME Corp’s PrivateArk server became active on the DR Vault while the Primary Vault was also running normally. All components continued to point to the Primary Vault. Which steps should you perform to restore DR replication to normal.

a)

Replicate data from DR Vault to Primary Vault > Shutdown PrivateArk server on DR Vault > Start Replication on DR Vault

b)

Shutdown PrivateArk server on DR Vault > Start replication on DR Vault.

c)

Shutdown PrivateArk Server on Primary Vault > Replicate Data from DR Vault to Primary Vault > Start Replication on DR Vault.

d)

Shutdown PrivateArk server on DR Vault > Replicate Data from DR Vault to Primary Vault > Shutdown PrivateArk server on DR Vault > Start Replication on DR Vault.

32.
a)

CyberArk Password, LDAP, RADIUS, SAML

b)

LDAP, Windows Authentication, SSH Keys

c)

RADIUS, Oracle SSO, CyberArk Password

d)

CyberArk Password, LDAP, RADIUS

33.

To ensure all sessions are being recorded, a CyberArk administrator goes to the master policy and makes configuration changes. Which configuration is correct?

a)

Require privileged session monitoring and isolation = inactive: Record and Save session activity = Active

b)

Require privileged session monitoring and isolation = Inactive: Record and Save session activity = Inactive

c)

Require privileged session monitoring and isolation = Active: Record and Save session activity = Active

d)

Require privileged session monitoring and isolation = Active: Record and Save session activity = Inactive

34.

To enable PKI Authentication for PVWA, (Version 10 and above) which web server config file must be updated and appended with the displayed settings?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/PKI-Authentication-Personal-Certificate.htm

4 lines
35.

To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud/Latest/en/Content/Privilege%20Cloud/privCloud-manage-safe-members.htm

a)

List Accounts, Use Accounts

b)

List Accounts, Use Accounts, Retrieve Accounts, Use Accounts

c)

Use Accounts

d)

List Accounts, Use Accounts, Retrieve accounts, Access Safe without confirmation

36.

You have been asked to turn off the time access restrictions for a safe. Where is this setting found?

a)

PrivateArk

b)

RestAPI

c)

Password Vault Web Access

d)

Vault

37.

What is a valid combination of primary and secondary layers of authentication to a company’s two-factor authentication policy?

a)

RSA SecureID Authentication (in PVWA) and LDAP Authentication

b)

CyberArk Authentication and RADIUS Authentication

c)

Oracle SSO (in PVWA) and SAML authentication

d)

LDAP Authentication and RADIUS Authentication

38.
a)

Primary vault in AWS, DR vault in Azure. Both Primary and DR Vault integrate with AWS Key Management Service.

b)

Primary vault in Azure, DR vault in AWS. Both Primary and DR Vault integrate with Azure Key vault.

c)

Primary vault in AWS and DR vault in Azure. The primary vault will be integrated with AWS Key Management service, while the DR will be integrated with Azure key vault

d)

Primary vault in Azure, DR Vault in AWS. Neither will integrate with Cloud native Management systems. The server key will reside on the operating system.

39.

You have been asked to limit a platform called “Windows_Servers” to safes called “WindowsDC1” and “WindowsDC2”. The platform must not be assigned to any other safes. What is the correct way to accomplish this?

https://cyberark-customers.force.com/s/article/00002012


a)

Edit the “Windows_Servers” platform, expand “Automatic Platform Management”, then select General and modify “Allowed Safes” to be (Windowsdc1)|(WindowsDC2)

b)

Edit the “Windows_Servers” platform, expand “Automatic Platform Management”, then select Options and modify “Allowed Safes” to be (Win*).

c)

Edit the “WindowsDC1” and WindowsDC2 safes through safe management. Add “Windows_Servers” to the “AllowedPlatforms”.

d)

Log into PrivateArk using an Administrative user. Select File, Server File Categories, Locate the Category “WindowsServersAllowedSafes” and specify “WindowsDC1.WindowDC2”.

40.

You have been asked to configure SNMP remote monitoring for your organization’s Vault servers. In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP Traps?

https://cyberark-customers.force.com/s/question/0D52J00008d4L74SAE/how-to-configure-cyberark-vault-to-send-status-information-to-the-monitoring-solution-using-snmp


a)

SNMPHostIP

b)

SNMPTrapPort

c)

SNMPCommunity

d)

SNMP Version

41.

Which component must be installed before the CPM installation

a)

PTA

b)

PSM

c)

PVWA

d)

EPM

42.

Which components support fault tolerance.

a)

CPM and PVWA

b)

PVWA and PSM

c)

PSM and PTA

d)

CPM and PTA

43.

In a default CyberArk installation, which group must a user be a member of to view the “reports” page in PVWA?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/ReportsInPVWA.htm?TocPath=End%20User%7CReports%20and%20Audits%7C_____1


a)

PVWAMonitor

b)

ReportUsers

c)

PVWAReports

d)

Operators

44.

You are creating a new REST API user that utilizes CyberArk Authentication. What is a correct process to provision this user?

a)

PrivateArk Client > Tools > Administrative Tools > Users and Groups > New > User

b)

PrivateArk Client > Tools > Administrative Tools > Directory Mapping > Add

c)

PVWA > User Provisioning > LDAP Integration > Add Mapping

d)

PVWA > User Provisioning > users and Groups > New > User

45.

You want to generate a license capacity report. Which tool accomplishes this?

a)

Password Vault Web Access

b)

PrivateArk Client

c)

DiagnoseDB Report

d)

RestAPI

46.

For a Digital Vault Cluster in a high availability configuration, how does the cluster determine if a node is down?

a)

The heartbeat is no longer detected on the private network

b)

The shared storage array is offline

c)

An alert is generated in the Windows event log.

d)

The Digital Vault Cluster does not detect a node failure.

47.

You need to move a platform from using PMTerminal.exe to using Terminal Plugin Controller. What must you do?

a)

Within PVWA, Click Administration > Platform Management, Select the platform, and then click Edit. In the left pane, click automatic password management, > CPM Plugin, Set the ExeName parameter to: CyberArk.TPC.exe

b)

Using PrivateArk, select the PasswordManager_Shared safe and then select open. Locate the .ini file relating to the platform you wish to change, and double click. At the bottom of the file, insert a line “UseTPC” = True. Remove any lines that reference “PMTerminal” and save. Return the .ini file to the safe. Restart the CPM for this change to take effect.

c)

Open the process file of the platform you wish to configure to use TPC. Add the following parameter under the States section. “use TPC=yes.

d)

It is not possible to change a Platform from using PMTerminal.exe to using TPC. You must locate a new version of the platform that supports TPC and import the new platform, overwriting the existing platform.

48.

Users are unable to launch Web Type connection components from the PSM server. Your manager asked you to open a case with CyberArk Support. Which logs will help the CyberArk Support Team debug the issue? (Choose 3)

a)

PSMConsole.log

b)

PSMDebug.log

c)

PSMTrace.log

d)

<session_ID>component.log

e)

ITALog.log

49.

Which of the following are mandatory when adding accounts from a file? (Choose 3)

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/NewUI/NewUI-Add-multiple-accounts-in-PVWA.htm

a)

Safe Name

b)

Platform ID

c)

All required properties specified in the platform

d)

Username and Hostname

e)

Address

50.
a)

Add to pending

b)

Rotate Credentials

c)

Reconcile Credentials

d)

Disable Account

51.

Arrange the steps to restore a Vault using PARestore for a Backup in the correct sequence.

Ordered

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/10.10/en/Content/PASIMP/Restoring-Safes-or-the-Vault.htm#RestoreaVault

a)

1. BackupFilesDeltetion=No

2. PARestore vault.ini operator /FullVaultRestore

3. CAVaultManager RestoreDB

4. CAVaultManager RecoverBackupFiles

5. BackupFilesDeletion=Yes

b)

1. BackupFilesDeltetion=No

2. CAVaultManager RestoreDB

3. PARestore vault.ini operator /FullVaultRestore

4. CAVaultManager RecoverBackupFiles

5. BackupFilesDeletion=Yes

c)

1. BackupFilesDeltetion=Yes

2. CAVaultManager RestoreDB

3. PARestore vault.ini operator /FullVaultRestore

4. CAVaultManager RecoverBackupFiles

5. BackupFilesDeletion=No

53.

Match the connection component to the corresponding OS/Function.

4 lines
54.

Your organization has a requirement to allow users to “check out passwords” and connect to targets with the same account through the PSM. What needs to be configured in the Master policy to ensure this will happen?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Working-with-Master-Policy-Rules.htm

a)

Enforce check-in/checkout exclusive access = Active: Require privileged session monitoring and Isolation = Active

b)

Enforce check-in/check-out exclusive access = inactive: Require privileged session monitoring and isolation = inactive

c)

Enforce checkin-in/check-out exclusive access = inactive: Record and save session activity = active

d)

Enforce Check-in/check-out exclusive access = active: Record and save session activity = inactive.

55.

A customer has two data centers and requires a single PVWA url. Which deployment provides the best performance and the most redundancy?

a)

Deploy two PVWAs behind a global traffic manager

b)

Deploy one PVWA only

c)

Deploy two PVWAs in an active/standby mode

d)

Deploy two PVWAs using DNS round robin

56.

Arrange the steps to install the Password Vault Web Access (PVWA) in correct sequence

a)

1. Run the PVWA Prerequisites.ps1 script in Powershell as Administrator

2. Run the PVWAInstallation.sp1 script in Powershell as Administrator

3. Run PVWA_Hardening.ps1 script in PowerShell as Administrator

4. Run the PVWARegisterComponent.ps1 script with the Vault password

b)

1. Run the PVWAInstallation.sp1 script in Powershell as Administrator

2. Run the PVWA Prerequisites.ps1 script in Powershell as Administrator

3. Run PVWA_Hardening.ps1 script in PowerShell as Administrator

4. Run the PVWARegisterComponent.ps1 script with the Vault password

57.

Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation.

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Event-Notification-Engine.htm?TocPath=Administration%7CComponents%7CEmail%20notifications%7C_____0

a)

255.255.255.255

b)

8.8.8.8

c)

192.168.1.1

d)

1.1.1.1

58.

Which files does the Vault Installation Wizard prompt you for during the Vault install.

a)

Operator CD & License file

b)

Master CD & License file

c)

Operator C & Vault Cerificate

d)

Master CD & DBparm.ini

59.
a)

TSparm.ini

b)

Vault.ini

c)

DBParm.ini

d)

user.ini

60.

You are logging into CyberArk as the Master user to recover an orphaned safe. Which items are required to log in as Master?

https://cyberark-customers.force.com/s/article/How-to-log-in-as-the-Master-user

a)

Master CD, Master Password, console access to the Vault server, Private Ark Client

b)

Operator CD, Master Password, Console access to the PVWA server, PVWA access

c)

Operator CD, Master Password, console access to the Vault server, Recover.exe

d)

Master CD, Master Password, console access to the PVWA server, Recover.exe

61.
a)

the CA Certificate that signed the certificated used by the External Directory

b)

A CA signed Certificate for the Vault server

c)

A CA signed Certificate for the PVWA server

d)

A self-signed Certificate for the Vault

62.

In a rule using “Privileged Session Analysis and Response” in PTA, which session options are available to configure as responses to activities?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Security-Configuration.htm?TocPath=End%20User%7CSecurity%20Events%7C_____3

a)

Suspend, Terminate, None

b)

Suspend, Terminate, Lock Account

c)

Pause, Terminate, None

d)

Suspend, Terminate

63.

A newly created platform allows users to access a Linux endpoint. When users click to connect, nothing happens. Which piece of the platform is missing?

a)

PSM-SSH Connection Component

b)

UnixPrompts.ini

c)

UnixProcess.ini

d)

PSM-RDP Connection Component

64.

A new domain controller has been added to your domain. You need to ensure the CyberArk infrastructure can use the new domain controller for authentication. Which locations must you update?

a)

On the Vault server in Windows\System32\ETC\Hosts and the PVWA Application under Administration > LDAP Integration > Directories > Hosts.

b)

On the Vault server in Windows\System32\ETC\Hosts and on the PVWA server in Windows\System32\hosts

c)

In the PrivateArk client under Tools > Administrative Tools > Directory Mapping

d)

On the Vault server in the certificate store and on the PVWA server in the certificate store

65.
a)

1. Locate the CPM_Hardening.ps1 script in the installation media

2. Open Powershell as Administrator and run the script

3. Review the script log called HardeningScript.log

4. Review the script log called CYBR_Hardeningsecedit.log

b)

1. Locate the CPM_Hardening.ps1 script in the installation media

2. Open Powershell as Administrator and run the script

3. Review the script log called CYBR_Hardeningsecedit.log

4. Review the script log called HardeningScript.log

66.

What is the last step to ensure that a stand-along Vault is synchronized with the organizations NTP server?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/following-vault-Installation.htm

a)

Restart the Vault Application using the PrivateArk Client

b)

Restart the organizations NTP servers

c)

Restart the Vault Application using the PrivateArk Central Administration Console

d)

Restart the Vault Event Notification Engine service

67.

A customer wants to store PSM recordings for 100 days. They estimate they will have 10 Windows sessions per day for 100 minutes each. How much storage is required for the Vault and PAReplicate for the PSM recordings

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.3/en/Content/PAS%20INST/Considerations-Before-Installing-PSM.htm#_Ref465255572
HINT:Sessions (?) (?) minutes = ? minutes     ? minutes ? days * ?kb/min = ? KB = ?GB

a)

25 GB

b)

500 GB

c)

5 GB

68.
a)

DBParm.ini and CAVaultManager.exe

b)

VaultKeys.ini and CAVultManger.exe

c)

DBParm.ini and ChageServerKeys.exe

d)

VaultKeys.ini and ChangeServerKeys.exe

69.

In large enterprise environments with complicated network zoning, what is the main reason to install more than one CPM?

a)

to utilize a load balancer to distribute workloads between multiple servers

b)

to manage passwords on the DR vault

c)

to increase performance of CPMs

d)

to avoid implementing complex firewall rules

70.

What is the configuration file used by the CPM scanner when scanning UNIX/Linux devices?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud/Latest/en/Content/PASIMP/PVWA-Accounts-Feed.htm

a)

UnixPrompts.ini

b)

plink.exe

c)

dbparm.ini

d)

PVConfig.xml

71.

You need to enable the PSM for all platforms. Where do you perform this task?

a)

Platform Management > (Platform) > UI & Workflows

b)

Master Policy > Session Management

c)

Master Policy > Privileged Access Workflows

d)

Administration > Options > Connection Components

72.
a)

Install the Vault in the cloud the same way that you would in an on-premises environment. Place the server key in a password protected folder on the operating system.

b)

Install the Vault in the cloud the same way that you would in an on-premises environment. Purchase a Hardware Security Module to secure the server key.

c)

Install the Vault using the Amazon Machine images and secure the server key using native cloud Key management Systems.

d)

Install the Vault using the Amazon Machine images and security the server key with a Hardware Security Module.

73.

In PVWA, you are attempting to play a recording made of a session by user jsmith, but there is no option to “Fast Forward” within the video. It plays and only allows you to skip between commands instead. You are also unable to download the video. What could be the cause?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Monitoring-Privileged-Sessions.htm?TocPath=End%20User%7CMonitor%20Sessions%7CClassic%20Interface%7C_____1

a)

Recording is of a PSM for SSH session

b)

The browser you are using is out of date and needs an update to be supported

c)

You do not have the “View Audit” permission on the safe where the account is stored

d)

You need to update the recorder settings in the platform to enable screen capture every 10000ms or less

74.

After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.1.1.2. What should you do?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/following-vault-Installation.htm

a)

Edit DBParm.ini to add: AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2], Yes, 123: outbound/udp

b)

Edit DBParm.ini to add: NTPServer=[10.1.1.1:123/UDP: 10.2.2.2:123/UDP]

c)

Edit DBParm.ini to add:AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2],Yes,123:outbound/udp,123:inbound/udp

d)

Edit the Windows Firewall configuration to add a rule for Port 123/udp outbound to 10.1.1.1 and 10.2.2.2

75.

There is a requirement for a password to change between 01:00 and 03:00 on Saturdays and Sundays: however, this does not work consistently. Which platform setting may be the cause?

https://cyberark-customers.force.com/s/article/00000745

a)

The interval setting for the platform is incorrect and must be less than 120

b)

The ImmediateInterval setting for the platform is incorrect and must be greater than or equal to 1

c)

The DaysToRun setting for the platform is incorrect and must be set to SAT, SUN

d)

The HeadStartInterval setting for the platform is incorrect and must be set to 0

76.

For each listed prerequisite, identify if it is mandatory or not mandatory to run the PSM Health Check.

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PSM/psm_healthcheck.htm

a)

a. PSM service installed on Windows 2008 R2, Windows 2012 R2, or Windows 2016 Not Mandatory

b. PSM Service installed on Windows 2012 R2, Windows 2016 R2, or Windows 2019 Mandatory

c. A valid SSL certificate is installed on the Web Server Mandatory

d. Web Server (IIS 8.5) role is installed. Mandatory

b)

a.  PSM service installed on Windows 2008 R2, Windows 2012 R2, or Windows 2016 Mandatory

b.  PSM Service installed on Windows 2012 R2, Windows 2016 R2, or Windows 2019 Mandatory

c.  A valid SSL certificate is installed on the Web Server Mandatory

d.  Web Server (IIS 8.5) role is installed.                                                                                                Mandatory


77.

Which option in the PrivateArk client is used to update users’ Vault group memberships?

a)

Update > General tab

b)

Update > Authorizations tab

c)

Update > Member Of tab

d)

Update > Group tab

78.

Match the Status of Services on a DR Vault to what is displayed when it is operating normally in replication mode.

4 lines
79.

In your organization the “click to connect” button is not active by default. How can this be activated?

a)

Policies > Master Policy > Allow EPV transparent connections > Inactive

b)

Policies > Master Policy > Session Management > Require Privileged session monitoring and isolation > Add Exception

c)

Policies > Master Policy > Allow EPV transparent connections > Active

d)

Policies > Master Policy > Password Management

80.

The Privileged Access Management solution provides an out-of-the-box target platform to manage SSH keys, called UNIX Via SSH Keys. How are these keys managed?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/SSHKM/Managing%20SSH%20Keys.htm?TocPath=Administration%7CComponents%7CSSH%C2%A0Key%20Manager%7C_____5

a)

CyberArk stores Private keys in the Vault and updates Public keys on target systems

b)

CyberArk stores Public keys in the Vault and updates Private keys on the target systems

c)

CyberArk does not store Public or Private keys and instead uses a reconcile account to create keys on demand

d)

CyberArk stores both Private and Public keys and can update target systems with either key.

81.
a)

500 GB

b)

1 TB

c)

same as disk size on Satellite Vault

d)

same as disk size on primary vault

82.
a)

Auditors

b)

Vault Admin

c)

DR Users

d)

Operators

83.

You just configured the usage in CyberArk and want to update its password. What is the least intrusive way to accomplish this?

a)

Use the “change” button on the usage’s details page

b)

Use the “Change” button on the parent account’s details page

c)

Use the “Sync” button on the usage’s details page

d)

Use the “reconcile button on the parent’s details page

84.
a)

proxymng

b)

psmp_maintenance

c)

psmpmaintenanceuser

d)

psmpmnguser

85.

A company requires challenge/response multi-factor authentication for PSMP sessions. Which server must you integrate with the CyberArk vault?

a)

LDAP

b)

PKI

c)

SAML

d)

RADIUS

86.

When running a “Privileged Accounts Inventory” Report through the Reports page in PVWA on a specific safe, which permission’s are required on that safe to show complete account inventory information?

a)

List Accounts, View Safe Members

b)

Mange Safe Owners

c)

List Accounts, Access Safe without confirmation

d)

Mange Safe, View Audit

87.
a)

Platform

b)

Connection Component

c)

CPM

d)

Vault

88.
a)

Port 1858 must be opened between the load balancer and the PVWAs

b)

The load balancer must be configured in DNS round robin

c)

The load balancer must support “sticky sessions”

d)

The LoadBalancerClientAddressHeader parameter in the PVwA.ini file must be set

89.

Which statement is correct concerning accounts that are discovered, but cannot be added to the Vault by an automated onboarding rule?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.2/en/Content/PASIMP/automatic_onboarding_rules.htm

a)

They are added to the Pending Accounts list and can be reviewed and manually uploaded

b)

They cannot be onboarded to the Password Vault

c)

They must be uploaded using third party tools

d)

They are not part of the Discovery Process

90.

You need to recover an account localadmin02 for target server 10.0.123.73 stored in Safe Team1. What do you need to recover and decrypt the object? (choose 3)

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Recover.htm?tocpath=Administrator%7CUtilities%7CServer%20Utilities%7C_____3

a)

Recovery Private Key

b)

Recover.exe

c)

Vault Data

d)

Recovery Public Key, Server Key, Master Password

91.

You are setting up a Linux host to act as an HTML 5 gate for PSM sessions. Which servers need to be trusted by the Linux host to secure communications through the gateway?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/Install_PSM_HTML5.htm?TocPath=Installation%7CSet%20up%20the%20environment%7CInstall%20PSM%7CInstall%20PSM%20HTML5%20Gateway%7C_____0

a)

PSM and PVWA

b)

PSM and CPM

c)

PVWA and Vault

d)

Vault and PSM

92.

After installing the first PSM server and before installing additional PSM servers, you must ensure the user performing the installation is not a direct owner of which safe?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/Optional-Installing-Multiple-PSM-Servers.htm

a)

PSMUnmanagedSessionAccounts Safe

b)

PSMRecordingsSessionAccounts Safe

c)

PSMUnmangedApplicationAccounts Safe

d)

PSMSessionBackupAccounts Safe

93.

Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM. Which file should you update to allow this to run?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/Install_PSM_harden.htm

a)

PSMConfigureAppLocker.xml

b)

PSMHardening.xml

c)

PSMAppconfig.xml

d)

PSMConfigureHardening.xml

94.

You are responsible for installing a CPM. Which Vault Authorizations will your CyberArk user need to install the CPM?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/CPM-install-requirements.htm#!#Vault

a)

Add Safes, Add/Update Users, Manage Directory Mapping

b)

Add Safes, Add/Update Users, Reset Users’ Passwords, Activate Users, Manage Server File Categories

c)

Manage Directory Mapping, Backup All Safes, Restore All Safes

d)

Audit Users, Activate Users, Add Network Areas, Manage Directory Mapping

95.

You are installing PSM for SSH with AD-Bridge in CyberArkSSHD mode for your customer, ACME Corp. What do you need to install to meet your customers needs? (Choose 2)

https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud/Latest/en/Content/Privilege%20Cloud/PrivCloud-setup-PSM-SSH.htm

a)

libssh

b)

CARKpsmp-infra

c)

CARKpsmp

d)

CARKpsmp-ADBridge

96.
a)

Vault Admins

b)

CPM User

c)

Auditors

d)

Administrators

97.

You have been asked to install three additional PSMs after the initial PSM install. The first PSM was installed with a secondary Administrator account. Which account should you use when installing the new PSMs?

a)

Use the Default Administrator account

b)

Use the Secondary Administrator account

c)

You may use any user in the Vault Admin Group

d)

Create a new Administrator for the installation

98.

When creating Distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/Distributed-Vault-Limitations.htm

a)

5 – number of primary and satellite vaults can be specified during installation

b)

3 – All primary

c)

6 – 1 Primary and 5 satellite

d)

1- - 2 primary and 8 satellite

99.
a)

Recordings file path

b)

Recording’s codec

c)

Recording’s retention period

d)

Recordings file type

100.
a)

Internet Explorer

b)

Google Chrome

c)

Microsoft Edge

d)

Firefox

101.

What is a requirement for setting fault tolerance for PSMs?

a)

Use a load balancer

b)

use a backup solution

c)

CPM must be in all data centers

d)

Install the Vault in an HA Cluster

102.

A customer installed multiple PVWAs in the production environment behind a load balancer VIP. They subsequently observed that all incoming traffic from the load balancer VIP goes to only one PVWA, even though all the PVWAs are up and running. What could be the likely cause of this situation?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PSM/ExampleLoadBalancer.htm?TocPath=System%20Requirements%7CSet%20up%20the%20environment%7CPSM%20installation%20considerations%7CInstall%20PSM%20HTML5%20Gateway%7CExample%20of%20how%20to%20configure%20a%20load%20balancer%7C_____0

a)

The load balancing algorithm is the least connections algorithm

b)

The Certificate of the load balancer is not a wild card cert

c)

The load balancing pool only has one PVWA server

d)

SSL passthrough is not configured on the load balancer

103.

You are configuring the vault to send syslog audit data to your organization’s SIEM solution. What is a valid value for the SyslogServerProtocol parameter in DBPARM.ini file?

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASREF/DBParm.ini.htm

a)

TLS

b)

SSH

c)

SMTP

d)

SNMP

104.

You have been asked to design the number of PVWAs a customer must deploy. The customer has three data centers with a distributed vault in each, requires high availability, and wants to use all vaults, at all times. How many PVWAs does the customer need?

a)

six

b)

four

c)

two

d)

three

105.
a)

Join the server to the domain

b)

install a clean operating system

c)

install anti-virus software

d)

Copy the master CD to a folder on the Vault server

106.

Your customer has five main data centers with one PVWA in each center under different URLs. How can you make this setup fault tolerant?

a)

This setup is already fault tolerant

b)

Install more PVWAs in each data center

c)

Continuously monitor PVWA status and send users the link to another PVWA if issues are encountered

d)

Load balance all PVWAs under same urL

107.

What is the easiest way to duplicate an existing platform?

a)

From PrivateArk, copy/paste the appropriate Policy.ini file: then rename it.

b)

from the PVWA, navigate to the platforms page, select the existing platform that is similar to the new target account platform and click Duplicate, name the new platform.

c)

From PrivateArk, cop/paste the appropriate setting in the PVConfiguration.xml then update the policName variable.

d)

From the PVWA, navigate to the platforms page, select existing platform that is similar to the new target account platform, manually update the platform settings and click “Save as” instead of save to duplicate and rename the platform.