Font size
WorksheetsQuiz
Total questions: 107
Worksheet time: 1hrs 10mins
Which permissions are needed for the Active Directory user required by the Windows Discovery process?
DomainAdmin
LdapAdmin
Read/Write
Read
Match each component to its respective LogFile location.
You Received this Error: “Error in changepass to user domain\user on domain server (\domain)winRC=50 Access is denied”
Which root cause should you investigate?
The account does not have sufficient permission to change its own password
The domain controller is unreachable
The password has been changed recently and minimum password age is preventing the change.
The CPM service is disabled and will need to be restarted.
As vault Admin you have been asked to configure LDAP authentication for your organization’s CyberArk users. Which permissions do you need to complete this task?
Audit Users and Add Network Areas
Audit Users and Manage Directory Mapping
Audit Users and Add/Update Users
Audit Users and Activate Users
Which PTA sensors are required to detect suspected credential theft?
What Detections Does PTA Report? | CyberArk Docs
Logs, Vault Logs
Logs, Network Sensor, Vault Logs
Logs, PSM Logs, CPM Logs
Logs, Network Sensor, EPM
You are installing HTML5 gateway on a Linux host using the RPM provided. After installing the Tomcat webapp, what is the next step in the installation process?
Install PSM HTML5 Gateway using an RPM package | CyberArk Docs
Deploy the HTML5 service (guacd)
Secure the connection between the guacd and the webapp
Secure the webapp and JWT validation endpoint
Configure ASLR
To enable automatic response “Add to Pending” within PTA when unmanaged credentials are found, what are the minimum permissions required by PTAUser for the PasswordManager_Pending safe?
Configure PTA Remediations | CyberArk Docs
List Accounts, View Safe Members, Add Accounts (includes update properties), Update Account Content, Update Account Properties.
List Accounts, Add Accounts (includes update properties), Delete Accounts, Manage Safe
Add Accounts (includes update properties), Update Account Content, Update Account properties, View Audit.
View Accounts, Update Account Content, Update Account Properties, Access Safe without Confirmation, Manage Safe, View Audit.
A customer’s environment three data centers, consisting of 5,000 servers in Germany, 10,000 servers in Canada, 1,500 servers in Singapore. You want to manage target servers and avoid complex firewall rules. How many CPM’s should you deploy?
Recommended Server Specifications | CyberArk Docs
1
3, total, 1 per data center
15
6, total, 2 per data center
What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?
Log onto the PrivateArk Client, display the user properties of the user to configure, run the Authentication method drop-down list, and select RADIUS authentication.
In the RADIUS server, define the CyberArk Vault as RADIUS client/agent.
In the Vault Installation folder, run CAVaultManger as Administrator with the Secure Secret Files command.
Navigate to /Server/Conf and open DBParms.ini and set the RadiusServersInfo parameter.
Which components can connect to a satellite Vault in distributed Vault architecture?
Distributed Vaults Component Features | CyberArk Docs
CPM, EPM, PTA
PVWA, PSM
CPM, PVWA, PSM
CPM, PSM
You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How should this be configured to allow for password management using least privilege?
Configure each CPM to use the correct logon account
Configure each CPM to use the correct reconcile account
Configure the UNIX Platform to use the correct logon account
Configure the UNIX Platform to use the correct reconcile account
Match the built-in Vault user with the correct definition.
A new HTML5 Gateway has been deployed in your organization. Where do you configure the PSM to use the HTML5 Gateway?
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/PSM_HTML5.htm
Administration > Options > Privileged Session Management > Configured PSM Servers > Connection Details > Add PSM Gateway
Administration > Options > Privileged Session Management > Add configured PSM Gateway Servers
Administration > Options > Privileged Session Management > Configured PSM Servers > Add PSM Gateway
Administration > Options > Privileged Session Management > Configured PSM Servers > Connection Details
A vault Administrator team member can log in to CyberArk, but for some reason, is not given Vault Admin rights. Where can you check to verify that the Vault Admins directory mapping points to the correct AD group
PVWA > User Provisioning > LDAP Integration > Mapping Criteria
PVWA > User Provisioning > LDAP Integration > Map Name
PVWA > Administration > LDAP Integration > Mappings
PVWA > Administration > LDAP Integration > AD Groups
In the PrivateArk Client, how do you add an LDAP group to a CyberArk Group?
Performed this in PA Client myself.
Select update on the CyberArk Group, and then click ADD > LDAP group
Select update on the LDAP Group, and then click ADD > LDAP Group
Select MemberOf on the CyberArk Group, and then click ADD > LDAP group
Select MemberOf on the LDAP Group, and then click ADD > LDAP Group
What are the basic network requirements to deploy a CPM server?
Port 1858 to Vault and port 443 to PVWA
Port 1858 only
All ports to the vault
Port UDP/1858 to vault and all required ports to the targets and port 389 to the PSM.
You have been asked to identify the UP or Down of Vault Services. Which CyberArk utility can you use to accomplish this task?
Vault Replicator
PAS Reporter
Remote Control Agent
Syslog
What is mandatory for a PVWA installation?
A DNS entry for PVWA url must be created.
A company signed TLS certificate must be imported into the server
A vault Administrator user must be used to register the PVWA
Data Execution Prevention must be disabled.
A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The vault administrator has been asked to look and the account and identify who can approve their request. What is the correct location to identify users or groups who can approve?
PVWA > Administration > Platform Configurations > Edit Platform > UI & Workflows > Dual Control > Approvers
PVWA > Policies > Access Control (Safes) > Safe Members > Workflow > Authorize Password Requests
PVWA > Accounts List > Edit > Show Advanced Settings > Dual Control > Direct Mangers
PrivateArk > Admin Tools > Users and Groups > Auditors (Group Memberships)
You are helping a customer prepare a Windows server for PSM installation. What is required for a successful installation?
Window 2012 KB4558843
Remote Desktop services (RDS) Session Host Roles
Windows 2016 KB4558843
Remote Desktop services (RDS) Session Broker
You have been asked to secure a set of shared accounts in CyberArk whose passwords will need to be used by end users. The account owner wants to be able to track who was using an account at any given moment. What security configuration should you recommend?
Configure one-time passwords for the appropriate platform in Master Policy
Configure shared account mode on the appropriate safe.
Configure both one-time passwords and exclusive access for the appropriate platform in Master Policy.
Configure object level access control on the appropriate safe.
In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?
Three things to consider, Size of session recordings, Activity in your enterprise and Recordings Retention Period.
Retention period
Number of PSMs
Number of users
Number of targets
CyberArk user Neil is trying to connect to the Target Linux server 192.168.1.64 using a domain account ACME/linuxuser01 on Domain Acme.corp using PSM for SSH server 192.168.65.145. What is the correct syntax?
ssh <vaultuser>@<targetuser>#<domainaddress>@<targetserver>@<PSMPserver>
How to connect with PSMP to a target Unix Domain account: (force.com)
Ssh neil@linuxuser01:acme.corp@192.168.1.64@192.168.1.45
Ssh neil@linuxuser01#acme.corp@192.168.1.64@192.168.1.45
Ssh neil@linuxuser01@192.168.1.64@192.168.65.145
Ssh neil@linuxuser01@acme.corp@192.168.1.64@192.168.1.45
Which component must be installed on the Vault if Distributed Vaults is used with PSM?
RabbitMQ
Disaster Recovery
Remote Control Client
Distributed Vault Server
Which item is an option for PSM recording customization?
Windows events text recorder with automatic play-back
Windows events text recorder and universal keystrokes recording simultaneously
Universal keystrokes text recorder and windows events text recorder disabled.
Custom audio recording for windows events.
Which tools are used during a CPM renaming process?
API Key Manager Utility
Create Cred File Utility
CPM in Domain_Hardening.ps1
PM Terminal.exe
If a customer has one data center and requires high availability, how many PVWA’s should be deployed.
Two
One PVWA cluster
One
Two PVWA Cluster
In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA Hardening.ps1 perform when run?
Performs IIS hardening: Import the CyberArk INF configuration
Performs IIS hardening: Configures all group policy settings
Performs IIS hardening: Renames the local Administrator Account
Configures Windows Firewall: Removes all installation files.
Refer to the exhibit.
A customer is building a development environment in the Amazon public cloud through Amazon Web Services.
What is the ideal specification for the Vault as it will only hold less than 1,000 accounts?
T2micro
T3medium
M5large
C5large
A customer is deploying PVWAs in the Amazon Web Services Public Cloud. Which load balancing option does CyberArk recommend?
Network Load Balancer
Classic Load Balancer
HTTPS load balancer
Public standard load balancer
Due to network activity, ACME Corp’s PrivateArk server became active on the DR Vault while the Primary Vault was also running normally. All components continued to point to the Primary Vault. Which steps should you perform to restore DR replication to normal.
Replicate data from DR Vault to Primary Vault > Shutdown PrivateArk server on DR Vault > Start Replication on DR Vault
Shutdown PrivateArk server on DR Vault > Start replication on DR Vault.
Shutdown PrivateArk Server on Primary Vault > Replicate Data from DR Vault to Primary Vault > Start Replication on DR Vault.
Shutdown PrivateArk server on DR Vault > Replicate Data from DR Vault to Primary Vault > Shutdown PrivateArk server on DR Vault > Start Replication on DR Vault.
Which authentication methods does PSM for SSH support?
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/PSSO-PMSP.htm
CyberArk Password, LDAP, RADIUS, SAML
LDAP, Windows Authentication, SSH Keys
RADIUS, Oracle SSO, CyberArk Password
CyberArk Password, LDAP, RADIUS
To ensure all sessions are being recorded, a CyberArk administrator goes to the master policy and makes configuration changes. Which configuration is correct?
Require privileged session monitoring and isolation = inactive: Record and Save session activity = Active
Require privileged session monitoring and isolation = Inactive: Record and Save session activity = Inactive
Require privileged session monitoring and isolation = Active: Record and Save session activity = Active
Require privileged session monitoring and isolation = Active: Record and Save session activity = Inactive
To enable PKI Authentication for PVWA, (Version 10 and above) which web server config file must be updated and appended with the displayed settings?
To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?
List Accounts, Use Accounts
List Accounts, Use Accounts, Retrieve Accounts, Use Accounts
Use Accounts
List Accounts, Use Accounts, Retrieve accounts, Access Safe without confirmation
You have been asked to turn off the time access restrictions for a safe. Where is this setting found?
PrivateArk
RestAPI
Password Vault Web Access
Vault
What is a valid combination of primary and secondary layers of authentication to a company’s two-factor authentication policy?
RSA SecureID Authentication (in PVWA) and LDAP Authentication
CyberArk Authentication and RADIUS Authentication
Oracle SSO (in PVWA) and SAML authentication
LDAP Authentication and RADIUS Authentication
A customer wants to implement a multi-cloud strategy for a virtual deployment. What architecture should you recommend.
Primary vault in AWS, DR vault in Azure. Both Primary and DR Vault integrate with AWS Key Management Service.
Primary vault in Azure, DR vault in AWS. Both Primary and DR Vault integrate with Azure Key vault.
Primary vault in AWS and DR vault in Azure. The primary vault will be integrated with AWS Key Management service, while the DR will be integrated with Azure key vault
Primary vault in Azure, DR Vault in AWS. Neither will integrate with Cloud native Management systems. The server key will reside on the operating system.
You have been asked to limit a platform called “Windows_Servers” to safes called “WindowsDC1” and “WindowsDC2”. The platform must not be assigned to any other safes. What is the correct way to accomplish this?
https://cyberark-customers.force.com/s/article/00002012
Edit the “Windows_Servers” platform, expand “Automatic Platform Management”, then select General and modify “Allowed Safes” to be (Windowsdc1)|(WindowsDC2)
Edit the “Windows_Servers” platform, expand “Automatic Platform Management”, then select Options and modify “Allowed Safes” to be (Win*).
Edit the “WindowsDC1” and WindowsDC2 safes through safe management. Add “Windows_Servers” to the “AllowedPlatforms”.
Log into PrivateArk using an Administrative user. Select File, Server File Categories, Locate the Category “WindowsServersAllowedSafes” and specify “WindowsDC1.WindowDC2”.
You have been asked to configure SNMP remote monitoring for your organization’s Vault servers. In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP Traps?
SNMPHostIP
SNMPTrapPort
SNMPCommunity
SNMP Version
Which component must be installed before the CPM installation
PTA
PSM
PVWA
EPM
Which components support fault tolerance.
CPM and PVWA
PVWA and PSM
PSM and PTA
CPM and PTA
In a default CyberArk installation, which group must a user be a member of to view the “reports” page in PVWA?
PVWAMonitor
ReportUsers
PVWAReports
Operators
You are creating a new REST API user that utilizes CyberArk Authentication. What is a correct process to provision this user?
PrivateArk Client > Tools > Administrative Tools > Users and Groups > New > User
PrivateArk Client > Tools > Administrative Tools > Directory Mapping > Add
PVWA > User Provisioning > LDAP Integration > Add Mapping
PVWA > User Provisioning > users and Groups > New > User
You want to generate a license capacity report. Which tool accomplishes this?
Password Vault Web Access
PrivateArk Client
DiagnoseDB Report
RestAPI
For a Digital Vault Cluster in a high availability configuration, how does the cluster determine if a node is down?
The heartbeat is no longer detected on the private network
The shared storage array is offline
An alert is generated in the Windows event log.
The Digital Vault Cluster does not detect a node failure.
You need to move a platform from using PMTerminal.exe to using Terminal Plugin Controller. What must you do?
Within PVWA, Click Administration > Platform Management, Select the platform, and then click Edit. In the left pane, click automatic password management, > CPM Plugin, Set the ExeName parameter to: CyberArk.TPC.exe
Using PrivateArk, select the PasswordManager_Shared safe and then select open. Locate the .ini file relating to the platform you wish to change, and double click. At the bottom of the file, insert a line “UseTPC” = True. Remove any lines that reference “PMTerminal” and save. Return the .ini file to the safe. Restart the CPM for this change to take effect.
Open the process file of the platform you wish to configure to use TPC. Add the following parameter under the States section. “use TPC=yes.
It is not possible to change a Platform from using PMTerminal.exe to using TPC. You must locate a new version of the platform that supports TPC and import the new platform, overwriting the existing platform.
Users are unable to launch Web Type connection components from the PSM server. Your manager asked you to open a case with CyberArk Support. Which logs will help the CyberArk Support Team debug the issue? (Choose 3)
PSMConsole.log
PSMDebug.log
PSMTrace.log
<session_ID>component.log
ITALog.log
Which of the following are mandatory when adding accounts from a file? (Choose 3)
Safe Name
Platform ID
All required properties specified in the platform
Username and Hostname
Address
Which automatic remediation is configurable for a PTA detection of a “Suspected Credential Theft”?
Add to pending
Rotate Credentials
Reconcile Credentials
Disable Account
Arrange the steps to restore a Vault using PARestore for a Backup in the correct sequence.
Ordered
1. BackupFilesDeltetion=No
2. PARestore vault.ini operator /FullVaultRestore
3. CAVaultManager RestoreDB
4. CAVaultManager RecoverBackupFiles
5. BackupFilesDeletion=Yes
1. BackupFilesDeltetion=No
2. CAVaultManager RestoreDB
3. PARestore vault.ini operator /FullVaultRestore
4. CAVaultManager RecoverBackupFiles
5. BackupFilesDeletion=Yes
1. BackupFilesDeltetion=Yes
2. CAVaultManager RestoreDB
3. PARestore vault.ini operator /FullVaultRestore
4. CAVaultManager RecoverBackupFiles
5. BackupFilesDeletion=No
Match each key to its recommended storage location.
Match the connection component to the corresponding OS/Function.
Your organization has a requirement to allow users to “check out passwords” and connect to targets with the same account through the PSM. What needs to be configured in the Master policy to ensure this will happen?
Enforce check-in/checkout exclusive access = Active: Require privileged session monitoring and Isolation = Active
Enforce check-in/check-out exclusive access = inactive: Require privileged session monitoring and isolation = inactive
Enforce checkin-in/check-out exclusive access = inactive: Record and save session activity = active
Enforce Check-in/check-out exclusive access = active: Record and save session activity = inactive.
A customer has two data centers and requires a single PVWA url. Which deployment provides the best performance and the most redundancy?
Deploy two PVWAs behind a global traffic manager
Deploy one PVWA only
Deploy two PVWAs in an active/standby mode
Deploy two PVWAs using DNS round robin
Arrange the steps to install the Password Vault Web Access (PVWA) in correct sequence
1. Run the PVWA Prerequisites.ps1 script in Powershell as Administrator
2. Run the PVWAInstallation.sp1 script in Powershell as Administrator
3. Run PVWA_Hardening.ps1 script in PowerShell as Administrator
4. Run the PVWARegisterComponent.ps1 script with the Vault password
1. Run the PVWAInstallation.sp1 script in Powershell as Administrator
2. Run the PVWA Prerequisites.ps1 script in Powershell as Administrator
3. Run PVWA_Hardening.ps1 script in PowerShell as Administrator
4. Run the PVWARegisterComponent.ps1 script with the Vault password
Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation.
255.255.255.255
8.8.8.8
192.168.1.1
1.1.1.1
Which files does the Vault Installation Wizard prompt you for during the Vault install.
Operator CD & License file
Master CD & License file
Operator C & Vault Cerificate
Master CD & DBparm.ini
Your customer, ACME Corp, whats to store the Safes Data in drive D instead of Drive C. Which file should you edit?
TSparm.ini
Vault.ini
DBParm.ini
user.ini
You are logging into CyberArk as the Master user to recover an orphaned safe. Which items are required to log in as Master?
https://cyberark-customers.force.com/s/article/How-to-log-in-as-the-Master-user
Master CD, Master Password, console access to the Vault server, Private Ark Client
Operator CD, Master Password, Console access to the PVWA server, PVWA access
Operator CD, Master Password, console access to the Vault server, Recover.exe
Master CD, Master Password, console access to the PVWA server, Recover.exe
Which certificate type do you need to configure the vault for LDAP over SSL?
the CA Certificate that signed the certificated used by the External Directory
A CA signed Certificate for the Vault server
A CA signed Certificate for the PVWA server
A self-signed Certificate for the Vault
In a rule using “Privileged Session Analysis and Response” in PTA, which session options are available to configure as responses to activities?
Suspend, Terminate, None
Suspend, Terminate, Lock Account
Pause, Terminate, None
Suspend, Terminate
A newly created platform allows users to access a Linux endpoint. When users click to connect, nothing happens. Which piece of the platform is missing?
PSM-SSH Connection Component
UnixPrompts.ini
UnixProcess.ini
PSM-RDP Connection Component
A new domain controller has been added to your domain. You need to ensure the CyberArk infrastructure can use the new domain controller for authentication. Which locations must you update?
On the Vault server in Windows\System32\ETC\Hosts and the PVWA Application under Administration > LDAP Integration > Directories > Hosts.
On the Vault server in Windows\System32\ETC\Hosts and on the PVWA server in Windows\System32\hosts
In the PrivateArk client under Tools > Administrative Tools > Directory Mapping
On the Vault server in the certificate store and on the PVWA server in the certificate store
Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence
1. Locate the CPM_Hardening.ps1 script in the installation media
2. Open Powershell as Administrator and run the script
3. Review the script log called HardeningScript.log
4. Review the script log called CYBR_Hardeningsecedit.log
1. Locate the CPM_Hardening.ps1 script in the installation media
2. Open Powershell as Administrator and run the script
3. Review the script log called CYBR_Hardeningsecedit.log
4. Review the script log called HardeningScript.log
What is the last step to ensure that a stand-along Vault is synchronized with the organizations NTP server?
Restart the Vault Application using the PrivateArk Client
Restart the organizations NTP servers
Restart the Vault Application using the PrivateArk Central Administration Console
Restart the Vault Event Notification Engine service
A customer wants to store PSM recordings for 100 days. They estimate they will have 10 Windows sessions per day for 100 minutes each. How much storage is required for the Vault and PAReplicate for the PSM recordings
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.3/en/Content/PAS%20INST/Considerations-Before-Installing-PSM.htm#_Ref465255572
HINT:Sessions (?) (?) minutes = ? minutes ? minutes ? days * ?kb/min = ? KB = ?GB
25 GB
500 GB
5 GB
Which configuration file and Vault utility are used to migrate the server key to an HSM?
DBParm.ini and CAVaultManager.exe
VaultKeys.ini and CAVultManger.exe
DBParm.ini and ChageServerKeys.exe
VaultKeys.ini and ChangeServerKeys.exe
In large enterprise environments with complicated network zoning, what is the main reason to install more than one CPM?
to utilize a load balancer to distribute workloads between multiple servers
to manage passwords on the DR vault
to increase performance of CPMs
to avoid implementing complex firewall rules
What is the configuration file used by the CPM scanner when scanning UNIX/Linux devices?
UnixPrompts.ini
plink.exe
dbparm.ini
PVConfig.xml
You need to enable the PSM for all platforms. Where do you perform this task?
Platform Management > (Platform) > UI & Workflows
Master Policy > Session Management
Master Policy > Privileged Access Workflows
Administration > Options > Connection Components
A customer is moving from an on-premises to a public cloud deployment. What is the best and most cost-effective option to secure the server key?
Install the Vault in the cloud the same way that you would in an on-premises environment. Place the server key in a password protected folder on the operating system.
Install the Vault in the cloud the same way that you would in an on-premises environment. Purchase a Hardware Security Module to secure the server key.
Install the Vault using the Amazon Machine images and secure the server key using native cloud Key management Systems.
Install the Vault using the Amazon Machine images and security the server key with a Hardware Security Module.
In PVWA, you are attempting to play a recording made of a session by user jsmith, but there is no option to “Fast Forward” within the video. It plays and only allows you to skip between commands instead. You are also unable to download the video. What could be the cause?
Recording is of a PSM for SSH session
The browser you are using is out of date and needs an update to be supported
You do not have the “View Audit” permission on the safe where the account is stored
You need to update the recorder settings in the platform to enable screen capture every 10000ms or less
After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.1.1.2. What should you do?
Edit DBParm.ini to add: AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2], Yes, 123: outbound/udp
Edit DBParm.ini to add: NTPServer=[10.1.1.1:123/UDP: 10.2.2.2:123/UDP]
Edit DBParm.ini to add:AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2],Yes,123:outbound/udp,123:inbound/udp
Edit the Windows Firewall configuration to add a rule for Port 123/udp outbound to 10.1.1.1 and 10.2.2.2
There is a requirement for a password to change between 01:00 and 03:00 on Saturdays and Sundays: however, this does not work consistently. Which platform setting may be the cause?
The interval setting for the platform is incorrect and must be less than 120
The ImmediateInterval setting for the platform is incorrect and must be greater than or equal to 1
The DaysToRun setting for the platform is incorrect and must be set to SAT, SUN
The HeadStartInterval setting for the platform is incorrect and must be set to 0
For each listed prerequisite, identify if it is mandatory or not mandatory to run the PSM Health Check.
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PSM/psm_healthcheck.htm
a. PSM service installed on Windows 2008 R2, Windows 2012 R2, or Windows 2016 Not Mandatory
b. PSM Service installed on Windows 2012 R2, Windows 2016 R2, or Windows 2019 Mandatory
c. A valid SSL certificate is installed on the Web Server Mandatory
d. Web Server (IIS 8.5) role is installed. Mandatory
a. PSM service installed on Windows 2008 R2, Windows 2012 R2, or Windows 2016 Mandatory
b. PSM Service installed on Windows 2012 R2, Windows 2016 R2, or Windows 2019 Mandatory
c. A valid SSL certificate is installed on the Web Server Mandatory
d. Web Server (IIS 8.5) role is installed. Mandatory
Which option in the PrivateArk client is used to update users’ Vault group memberships?
Update > General tab
Update > Authorizations tab
Update > Member Of tab
Update > Group tab
Match the Status of Services on a DR Vault to what is displayed when it is operating normally in replication mode.
In your organization the “click to connect” button is not active by default. How can this be activated?
Policies > Master Policy > Allow EPV transparent connections > Inactive
Policies > Master Policy > Session Management > Require Privileged session monitoring and isolation > Add Exception
Policies > Master Policy > Allow EPV transparent connections > Active
Policies > Master Policy > Password Management
The Privileged Access Management solution provides an out-of-the-box target platform to manage SSH keys, called UNIX Via SSH Keys. How are these keys managed?
CyberArk stores Private keys in the Vault and updates Public keys on target systems
CyberArk stores Public keys in the Vault and updates Private keys on the target systems
CyberArk does not store Public or Private keys and instead uses a reconcile account to create keys on demand
CyberArk stores both Private and Public keys and can update target systems with either key.
How much disk space do you need on the server for a PAReplicate?
500 GB
1 TB
same as disk size on Satellite Vault
same as disk size on primary vault
Which CyberArk group does a user need to be part of to view recordings or live monitor sessions?
Auditors
Vault Admin
DR Users
Operators
You just configured the usage in CyberArk and want to update its password. What is the least intrusive way to accomplish this?
Use the “change” button on the usage’s details page
Use the “Change” button on the parent account’s details page
Use the “Sync” button on the usage’s details page
Use the “reconcile button on the parent’s details page
What is the default username for the PSM for SSH maintenance user?
proxymng
psmp_maintenance
psmpmaintenanceuser
psmpmnguser
A company requires challenge/response multi-factor authentication for PSMP sessions. Which server must you integrate with the CyberArk vault?
LDAP
PKI
SAML
RADIUS
When running a “Privileged Accounts Inventory” Report through the Reports page in PVWA on a specific safe, which permission’s are required on that safe to show complete account inventory information?
List Accounts, View Safe Members
Mange Safe Owners
List Accounts, Access Safe without confirmation
Mange Safe, View Audit
When onboarding multiple accounts from the pending Accounts list, which associated setting must be the same across the selected accounts?
Platform
Connection Component
CPM
Vault
You are installing multiple PVWAs behind a load balancer. Which statement is correct?
Port 1858 must be opened between the load balancer and the PVWAs
The load balancer must be configured in DNS round robin
The load balancer must support “sticky sessions”
The LoadBalancerClientAddressHeader parameter in the PVwA.ini file must be set
Which statement is correct concerning accounts that are discovered, but cannot be added to the Vault by an automated onboarding rule?
They are added to the Pending Accounts list and can be reviewed and manually uploaded
They cannot be onboarded to the Password Vault
They must be uploaded using third party tools
They are not part of the Discovery Process
You need to recover an account localadmin02 for target server 10.0.123.73 stored in Safe Team1. What do you need to recover and decrypt the object? (choose 3)
Recovery Private Key
Recover.exe
Vault Data
Recovery Public Key, Server Key, Master Password
You are setting up a Linux host to act as an HTML 5 gate for PSM sessions. Which servers need to be trusted by the Linux host to secure communications through the gateway?
PSM and PVWA
PSM and CPM
PVWA and Vault
Vault and PSM
After installing the first PSM server and before installing additional PSM servers, you must ensure the user performing the installation is not a direct owner of which safe?
PSMUnmanagedSessionAccounts Safe
PSMRecordingsSessionAccounts Safe
PSMUnmangedApplicationAccounts Safe
PSMSessionBackupAccounts Safe
Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM. Which file should you update to allow this to run?
PSMConfigureAppLocker.xml
PSMHardening.xml
PSMAppconfig.xml
PSMConfigureHardening.xml
You are responsible for installing a CPM. Which Vault Authorizations will your CyberArk user need to install the CPM?
Add Safes, Add/Update Users, Manage Directory Mapping
Add Safes, Add/Update Users, Reset Users’ Passwords, Activate Users, Manage Server File Categories
Manage Directory Mapping, Backup All Safes, Restore All Safes
Audit Users, Activate Users, Add Network Areas, Manage Directory Mapping
You are installing PSM for SSH with AD-Bridge in CyberArkSSHD mode for your customer, ACME Corp. What do you need to install to meet your customers needs? (Choose 2)
libssh
CARKpsmp-infra
CARKpsmp
CARKpsmp-ADBridge
To mange automated onboarding rules, a CyberArk user must be a member of which group
Vault Admins
CPM User
Auditors
Administrators
You have been asked to install three additional PSMs after the initial PSM install. The first PSM was installed with a secondary Administrator account. Which account should you use when installing the new PSMs?
Use the Default Administrator account
Use the Secondary Administrator account
You may use any user in the Vault Admin Group
Create a new Administrator for the installation
When creating Distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
5 – number of primary and satellite vaults can be specified during installation
3 – All primary
6 – 1 Primary and 5 satellite
1- - 2 primary and 8 satellite
A customer asked you to help scope the company’s PSM deployment. What should be included in the scoping conversation?
Recordings file path
Recording’s codec
Recording’s retention period
Recordings file type
Which browser is supported for PSM Web Connectors developed using the CyberArk Plugin Generator Utility (PGU)?
Internet Explorer
Google Chrome
Microsoft Edge
Firefox
What is a requirement for setting fault tolerance for PSMs?
Use a load balancer
use a backup solution
CPM must be in all data centers
Install the Vault in an HA Cluster
A customer installed multiple PVWAs in the production environment behind a load balancer VIP. They subsequently observed that all incoming traffic from the load balancer VIP goes to only one PVWA, even though all the PVWAs are up and running. What could be the likely cause of this situation?
The load balancing algorithm is the least connections algorithm
The Certificate of the load balancer is not a wild card cert
The load balancing pool only has one PVWA server
SSL passthrough is not configured on the load balancer
You are configuring the vault to send syslog audit data to your organization’s SIEM solution. What is a valid value for the SyslogServerProtocol parameter in DBPARM.ini file?
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASREF/DBParm.ini.htm
TLS
SSH
SMTP
SNMP
You have been asked to design the number of PVWAs a customer must deploy. The customer has three data centers with a distributed vault in each, requires high availability, and wants to use all vaults, at all times. How many PVWAs does the customer need?
six
four
two
three
Which pre-requisite step must be completed before installing a Vault?
Join the server to the domain
install a clean operating system
install anti-virus software
Copy the master CD to a folder on the Vault server
Your customer has five main data centers with one PVWA in each center under different URLs. How can you make this setup fault tolerant?
This setup is already fault tolerant
Install more PVWAs in each data center
Continuously monitor PVWA status and send users the link to another PVWA if issues are encountered
Load balance all PVWAs under same urL
What is the easiest way to duplicate an existing platform?
From PrivateArk, copy/paste the appropriate Policy.ini file: then rename it.
from the PVWA, navigate to the platforms page, select the existing platform that is similar to the new target account platform and click Duplicate, name the new platform.
From PrivateArk, cop/paste the appropriate setting in the PVConfiguration.xml then update the policName variable.
From the PVWA, navigate to the platforms page, select existing platform that is similar to the new target account platform, manually update the platform settings and click “Save as” instead of save to duplicate and rename the platform.
