wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CyberArk Def Exam Questions

Total questions: 70

Worksheet time: 38mins

Name
Class
Date
1.

What do you need on the Vault to support LDAP over SSL?

a)

CA Certificate(s) used to sign the External Directory certificate

b)

RECPRV.key

c)

a private key for the external directory

d)

self-signed Certificate(s) for the Vault

2.

You are troubleshooting a PVWA slow response. Which log files should you analyze first? (Choose two.)

a)

ITALog.log

b)

web.config

c)

CyberArk.WebApplication.log

d)

CyberArk.WebConsole.log

3.

What is the easiest way to duplicate an existing platform?

a)

From PrivateArk, copy/paste the appropriate Policy.ini file; then rename it.

b)

From the PVWA, navigate to the platforms page, select an existing platform that is similar to the new target account platform and then click Duplicate; name the new platform.

c)

From PrivateArk, copy/paste the appropriate settings in PVConfiguration.xml; then update the policyName variable.

d)

From the PVWA, navigate to the platforms page, select an existing platform that is similar to the new target account platform, manually update the platform settings and click "Save as" INSTEAD of save to duplicate and rename the platform.

4.

Due to corporate storage constraints, you have been asked to disable session monitoring and recording for 500 testing accounts used for your lab environment. How do you accomplish this?

a)

Master Policy>select Session Management>add Exceptions to the

platform(s)>disable Session Monitoring and Recording policies

b)

Administration>Platform Management>select the platform(s)>disable Session

Monitoring and Recording

c)

Polices>Access Control (Safes)>select the safe(s)>disable Session Monitoring

and Recording policies

d)

Administration>Conguration Options>Options>select Privilege Session

Management>disable Session Monitoring and Recording policies

5.

A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The Vault Admin has been asked to look at the account and identify who can approve their request. What is the correct location to identify users or groups who can approve?

a)

PVWA > Administration > Platform Conguration > Edit Platform > UI & Workow

> Dual Control > Approvers

b)

PVWA > Policies > Access Control (Safes) > Select the safe > Safe Members

> Workow > Authorize Password Requests

c)

PVWA > Account List > Edit > Show Advanced Settings > Dual Control > Direct

Managers

d)

PrivateArk > Admin Tools > Users and Groups > Auditors (Group Membership)

6.

What must you specify when configuring a discovery scan for UNIX? (Choose two.)

a)

Vault Administrator

b)

CPM Scanner

c)

root password for each machine

d)

list of machines to scan

e)

safe for discovered accounts

7.

To change the safe where recordings are kept for a specific platform, which setting must you update in the platform configuration?

a)

SessionRecorderSafe

b)

SessionSafe

c)

RecordingsPath

d)

RecordingLocation

8.

Which processes reduce the risk of credential theft? (Choose two.)

a)

equire dual control password access approval

b)

require password change every X days

c)

enforce check-in/check-out exclusive access

d)

enforce one-time password access

9.

You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How can this be configured to allow for password management using least privilege?

a)

Congure each CPM to use the correct logon account.

b)

Congure each CPM to use the correct reconcile account.

c)

Congure the UNIX platform to use the correct logon account.

d)

Congure the UNIX platform to use the correct reconcile account.

10.

ADR Vault became active due to a failure of the primary Vault. Service on the primary Vault has now been restored. Arrange the first steps to return the DR vault to its normal standby mode in the correct sequence.

a)
  1. Shutdown PrivateArk Service

b)

ser Failover Mode = No

c)

Start PrivateArk DR Service

11.

Which methods can you use to add a user directly to the Vault Admin Group? (Choose three.)

a)

Active Directory

b)

PACLI

c)

REST API

d)

PrivateArk Client

e)

PVWA

12.

Which Automatic Remediation is configurable for a PTA detection of a "Suspected Credential Theft"?

a)

Add to Pending

b)

Rotate Credentials

c)

Reconcile Credentials

d)

Disable Account

13.

Which item is an option for PSM recording customization?

a)

Windows events text recorder with automatic play-back

b)

Windows events text recorder and universal keystrokes recording simultaneously

c)

Universal keystrokes text recorder with windows events text recorder disabled

d)

Custom audio recording for windows events

14.

You want to create a new onboarding rule. Where do you accomplish this?

a)

In PVWA, click Reports > Unmanaged Accounts > Rules

b)

In PVWA, click Options > Platform Management > Onboarding Rules

c)

In PrivateArk, click Tools > Onboarding Rules

d)

In PVWA, click Accounts > Onboarding Rules

15.

What does the Export Vault Data (EVD) utility do?

a)

exports data from the Vault to TXT or CSV les, or to MSSQL databases

b)

generates a backup le that can be used as a cold backup

c)

exports all passwords and imports them into another instance of CyberArk

d)

keeps two active vaults in sync

16.

When are external vault users and groups synchronized by default?

a)

They are synchronized once every 24 hours between 1 AM and 5 AM.

b)

They are synchronized once every 24 hours between 7 PM and 12 AM.

c)

They are synchronized every 2 hours.

d)

They are not synchronized according to a specic schedule.

17.

You created a new safe and need to ensure the user group cannot see the password, but can connect through the PSM. Which safe permissions must you grant to the group? (Choose two.)

a)

List Accounts

b)

Use Accounts

c)

Access Safe without Conrmation

d)

Retrieve Files

e)

Conrm Request

18.

During a High Availability node switch you notice an error and the Cluster Vault Manager Utility fails back to the original node. Which log files should you check to investigate the cause of the issue? (Choose three.)

a)

PM_Error.log

b)

ClusterVault.console.log

c)

ITALog.log

d)

CyberArk Webconsole.log

e)

VaultDB.log

19.

Where can a user with the appropriate permissions generate a report? (Choose two.)

a)

PVWA > Reports

b)

PrivateArk Client

c)

Cluster Vault Manager

d)

PrivateArk Server Monitor

e)

PARClient

20.

Users are unable to launch Web Type Connection components from the PSM server. Your manager asked you to open the case with CyberArk Support. Which logs will be most useful for the CyberArk Support Team to debug the issue? (Choose three.)

a)

PSMConsole.log

b)

PSMDebug.log

c)

PMconsole.log

d)

PSMTrace.log

e)

.Component.log

21.

You have been asked to identify the up or down status of Vault Services. Which CyberArk utility can you use to accomplish this task?

a)

PrivateArk Central Administration Console

b)

PAS Reporter

c)

PrivateArk Remote Control Agent

d)

Syslog

22.

A new colleague created a directory mapping between the Active Directory groups and the Vault. Where can the newly Configured directory mapping be tested?

a)

Connect to the Active Directory and ensure the organizational unit exists.

b)

Connect to Sailpoint (or similar tool) to ensure the organizational unit is correctly

named; log in to the PVWA with "Administrator" and conrm authentication

succeeds.

c)

Search for members that exist only in the mapping group to grant them safe

permissions through the PVWA.

d)

Connect to the PrivateArk Client with the Administrator Account to see if there is

a user in the Vault Admin Group.

23.

A user needs to view recorded sessions through the PVWA.

Without giving auditor access, which safes does a user need access to

view PSM recordings? (Choose two.)

a)

Recordings safe

b)

Safe the account is in

c)

System safe

d)

PVWAConguration safe

e)

VaultInternal safe

24.

Without giving auditor access, which safes does a user need access to view PSM recordings?

a)

Recordings safe

b)

Safe the account is in

c)

System safe

d)

PVWAConfiguration safe

e)

VaultInternal safe

25.

Which file must be edited on the Vault to configure it to send data to PTA?

a)

dbparm.ini

b)

PARAgent.ini

c)

my.ini

d)

padr.ini

26.

You want to build a connector that connects to a website through the Web applications for PSM framework. Which default connector do you duplicate and modify?

a)

PSM-ChromeSample

b)

PSM-WebForm

c)

PSM-WebApp

d)

PSM-WebAppSample

27.

A new HTML5 Gateway has been deployed in your organization. From the PVWA, arrange the first steps to configure a PSM host to use the HTML5 Gateway in the correct sequence.

a)

Administration>Options

Administration>Options

b)

Privileged Session

Management

c)

Congured PSM Server

and select existing

PSM host

Congured PSM Server

and select existing

PSM host

d)

Connection Details

e)

Add PSM gateway

Add PSM gatewa

28.

When an account is unable to change its own password, how can you ensure that password reset with the reconcile account is performed each time instead of a change?

a)

Set the parameter RCAllowManualReconciliation to Yes.

b)

Set the parameter ChangePasswordinResetMade to Yes.

c)

Set the parameter IgnoreReconcileOnMissingAccount to No.

d)

Set the UnlockUserOnReconcile to Yes.

29.

In a default CyberArk installation, which group must a user be a member of to view the 'reports' page in PVWA?

a)

PVWAMonitor

b)

ReportUsers

c)

PVWAReports

d)

Operators

30.

Your organization requires all passwords be rotated every 90 days. Where can you set this requirement?

a)

Master Policy

b)

Safe Templates

c)

PVWAConfiguration.xml

d)

Platform Configuration

31.

According to CyberArk, which issues most commonly cause installed components to display as disconnected in the System Health Dashboard? (Choose two.)

a)

network instabilities/outages

b)

vault license expiry

c)

credential de-sync

d)

browser compatibility issues

e)

installed location file corruption

32.

Where can reconcile and/or logon accounts be linked to an account? (Choose two.)

a)

account settings

b)

platform settings

c)

master policy

d)

safe settings

e)

service account settings

33.

You are running a 'Privileged Accounts Inventory' Report through the Reports page in PVWA on a specific safe. To show complete account inventory information, which permission/s are needed on that safe?

a)

List Accounts, View Safe Members

b)

Manage Safe Owners

c)

List Accounts, Access Safe without confirmation

d)

Manage Safe, View Audit

34.

Which dependent accounts does the CPM support out-of-the-box?

a)

Windows Registry

b)

Solaris Configuration file

c)

Windows Scheduled Tasks

d)

Windows DCOM Applications

e)

Windows Services

35.

A password compliance audit found: 1) One-time password access of 20 domain accounts that are members of Domain Admins group in Active Directory are not being enforced. 2) All the sessions of connecting to domain controllers are not being recorded by CyberArk PSM. What should you do to address these findings?

a)

Edit the Master Policy and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.

b)

Edit safe properties and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.

c)

Edit CPM Settings and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.

d)

Contact the Windows Administrators and request them to add two policy exceptions at Active Directory Level: enable 'Enforce one-time password access', enable 'Record and save session activity'.

36.

If PTA is integrated with a supported SIEM solution, which detection becomes available?

a)

unmanaged privileged account

b)

privileged access to the Vault during irregular days

c)

riskySPN

d)

exposed credentials

37.

Which change could CyberArk make to the REST API that could cause existing scripts to fail?

a)

adding optional parameters in the request

b)

adding additional REST methods

c)

removing parameters

d)

returning additional values in the response

38.

You created a new platform by duplicating the out-of-box Linux through the SSH platform. Without any change, which Text Recorder Type(s) will the new platform support?

a)

SSH Text Recorder

b)

Universal Keystrokes Text Recorder

c)

Events Text Recorder

d)

SQL Text Recorder

e)

Telnet Commands Text Recorder

39.

You are creating a Dual Control workflow for a team's safe. Which safe permissions must you grant to the Approvers group?

a)

List accounts, Authorize account request

b)

Retrieve accounts, Access Safe without confirmation

c)

Retrieve accounts, Authorize account request

d)

List accounts, Unlock accounts

40.

In addition to add accounts and update account contents, which additional permission on the safe is required to add a single account?

a)

Upload Accounts Properties

b)

Rename Accounts

c)

Update Account Properties

d)

Manage Safe

41.

You want to give a newly-created group rights to review security events under the Security pane. You also want to be able to update the status of these events. Where must you update the group to allow this?

a)

in the PTAAuthorizationGroups parameter, found in Administration > Options > PTA

b)

in the PTAAuthorizationGroups parameter, found in Administration > Options > General

c)

in the SecurityEventsAuthorizationGroups parameter, found in Administration > Security > Options

d)

in the SecurityEventsFeedAuthorizationGroups parameter, found in Administration > Options > General

42.

What is required to manage loosely connected devices?

a)

PSM for SSH

b)

EPM

c)

PSM

d)

PTA

43.

Your organization has a requirement to allow only one user to 'check out passwords' and connect through the PSM securely. What needs to be configured in the Master policy to ensure this will happen?

a)

Enforce check-in/check-out exclusive access = active; Require privileged session monitoring and isolation = active

b)

Enforce check-in/check-out exclusive access = inactive; Require privileged session monitoring and isolation = inactive

c)

Enforce check-in/check-out exclusive access = inactive; Record and save session activity = active

d)

Enforce check-in/check-out exclusive access = active; Record and save session activity = inactive

44.

When should vault keys be rotated?

a)

when it is copied to file systems outside the vault

b)

annually

c)

whenever a CyberArk user leaves the organization

d)

when migrating to a new data center

45.

Where can PTA be configured to send alerts?

a)

SIEM

b)

Email

c)

Google Analytics

d)

EVD

e)

PAReplicate

46.

In your organization the 'click to connect' button is not active by default. How can this feature be activated?

a)

Policies > Master Policy > Allow EPV transparent connections > Inactive

b)

Policies > Master Policy > Session Management > Require privileged session monitoring and isolation > Add Exception

c)

Policies > Master Policy > Allow EPV transparent connections > Active

d)

Policies > Master Policy > Password Management

47.

What are the mandatory fields when onboarding from Pending Accounts?

a)

Address

b)

Safe

c)

Account Description

d)

Platform

e)

CPM

48.

Match each permission to where it can be found

a)

Add Accounts

Add Accounts => Safe

b)

Initiate CPM

account

management

operations => Safe

c)

Add/Update

Users => Vault

d)

Add Safes

Add Safes => Vault

49.

Which accounts can be selected for use in the Windows discovery process? (Choose two.)

a)

an account stored in the Vault

b)

an account specied by the user

c)

the Vault Administrator

d)

any user with Auditor membership

e)

the PasswordManager user

50.

You are concerned about the Windows Domain password changes occurring during business hours. Which settings must be updated to ensure passwords are only rotated outside of business hours?

a)

In the platform policy - Automatic Password Management > Password Change > ToHour & FromHour

b)

in the Master Policy - Account Change Window > ToHour & From Hour

c)

Administration Settings - CPM Settings > ToHour & FromHour

d)

On each individual account - Edit > Advanced > ToHour & FromHour

51.

The Privileged Access Management solution provides an out-of-the-box target platform to manage SSH keys, called UNIX Via SSH Keys. How are these keys managed?

a)

CyberArk stores Private keys in the Vault and updates Public keys on target systems.

b)

CyberArk stores Public keys in the Vault and updates Private keys on target systems.

c)

CyberArk does not store Public or Private keys and instead uses a reconcile account to create keys on demand.

d)

CyberArk stores both Private and Public keys and can update target systems with either key.

52.

The Active Directory User configured for Windows Discovery needs which permission(s) or membership?

a)

Member of Domain Admin Group

b)

Member of LDAP Admin Group

c)

Read and Write Permissions

d)

Read Only Permissions

53.

Which command generates a full backup of the Vault?

a)

PAReplicate.exe Vault.ini /LogonFromFile user.ini /FullBackup

b)

PAPreBackup.exe C:\PrivateArk\Server\Conf\Vault.ini Backup/Asdf1234 /full

c)

PARestore.exe PADR ini /LogonFromFile vault.ini /FullBackup

d)

CAVaultManager.exe RecoverBackupFiles /BackupPoolName BkpSvr1

54.

You have been asked to create an account group and assign three accounts which belong to a cluster. When you try to create a new group, you receive an unauthorized error; however, you are able to edit other aspects of the account properties. Which safe permission do you need to manage account groups?

a)

create folders

b)

specify next account content

c)

rename accounts

d)

manage safe

55.

Match the connection component to the corresponding OS/Function *



(a)  

56.

A recently-hired colleague onboarded five new Local Accounts that are

used for five standalone Windows Servers. After attempting to connect to

the servers from PVWA, the colleague noticed that the "Connect" button

was greyed out for all five new accounts.

*

What can you do to help your colleague resolve this issue? (Choose two.)

a)

Verify that the address eld is populated with an IP or FQDN of each server.

b)

Verify that the correct PSM connection component appears within account

platform settings.

c)

Verify that the address eld is blank and that the correct PSM connection

component appears within account platform settings.

d)

Notify the Windows Team that created the new accounts that the CyberArk PAM

solution is not designed to manage local accounts on Windows Servers.

e)

Verify that the "Disable automatic management for this account" setting for each

account is not enabled.

57.

Before failing back to the production infrastructure after a DR exercise, what must you do to maintain audit history during the DR event?

a)

Ensure that the Production Instance replicates changes that occurred from the Disaster Recovery Instance.

b)

Briefly stop and start the Disaster Recovery Instance before attempting to fail components back to the Production Instance.

c)

Stop the CPM services before starting the production server.

d)

Perform an IIS Reset on all PVWA servers.

58.

You are configuring CyberArk to use HTML5 gateways exclusively for PSM connections. In the PVWA, where do you set DefaultConnectionMethod to HTML5?

a)

Options > Privileged Session Management UI

b)

Options > Privileged Session Management

c)

Options > Privileged Session Management Defaults

d)

Options > Privileged Session Management Interface

59.

You are onboarding an account that is not supported out of the box.

*What should you do first to obtain a platform to import?

a)

Create a service ticket in the customer portal explaining the requirements of

the custom platform.

b)

Search common community portals like stackoverow, reddit, github for an

existing platform.

c)

From the platforms page, uncheck the “Hide non-supported platforms” checkbox

and see if a platform meeting your needs appears.

d)

Visit the CyberArk marketplace and search for a platform that meets your needs.

60.

Which master policy settings ensure non-repudiation?

a)

Require password verification every X days and enforce one-time password access.

b)

Enforce check-in/check-out exclusive access and enforce one-time password access.

c)

Allow EPV transparent connections ('Click to connect') and enforce check-in/check-out exclusive access.

d)

Allow EPV transparent connections ('Click to connect') and enforce one-time password access.

61.

You have been asked to turn off the time access restrictions for a safe. Where is this setting found?

a)

PrivateArk Client

b)

RestAPI

c)

PVWA

d)

Vault

62.

You want to generate a license capacity report. Which tool accomplishes this?

a)

Password Vault Web Access

b)

PrivateArk Client

c)

DiagnoseDB Report

d)

RestAPI

63.

Match the Status of Service on a DR Vault to what is displayed when it is

operating normally in Replication mode.

a)

Cyber-Ark

Hardened

Windows

Firewal > Running

b)

PrivateArk

Database

PrivateArk

Databas > Running

c)

PrivateArk Server > Stoped

d)

CyberArk Vault

DR > Running

e)

CyberArk Event

Notication

Engine > Stoped

64.

Which parameters can be used to harden the Credential Files (CredFiles) while using CreateCredFile Utility?

a)

Host IP Address

b)

Operating System Username

c)

Client Hostname

d)

Operating System Type (Linux/Windows/HP-UX)

e)

Vault IP Address

65.

Match each automatic remediation to the correct PTA security event. *

a)

A

b)

B

66.

You notice an authentication failure entry for the DR user in the ITALog. What is the correct process to fix this error? (Choose two.)

a)

PrivateArk Client > Tools > Administrative Tools > Users and Groups > DR User >

Update > Authentication > Update Password.

b)

Create a new credential le, on the DR Vault, using the CreateCredFile utility and

the newly set password.

c)

Create a new credential le, on the Primary Vault, using the CreateCredFile utility

and the newly set password.

d)

PVWA > User Provisioning > Users and Groups > DR User > Update Password.

e)

PrivateArk Client > Tools > Administrative Tools > Users and Groups >

PAReplicate User > Update > Authentication > Update Password.

67.

To manage automated onboarding rules, a CyberArk user must be a member of which group?

a)

Vault Admins

b)

CPM User

c)

Auditors

d)

Administrators

68.

To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?

a)

List Accounts, Use Accounts

b)

List Accounts, Use Accounts, Retrieve Accounts

c)

Use Accounts

d)

List Accounts, Use Accounts, Retrieve Accounts, Access Safe without

conrmation

69.

Which CyberArk utility allows you to create lists of Master Policy Settings, owners and safes for output to text files or MSSQL databases?

a)

Export Vault Data

b)

Export Vault Information

c)

PrivateArk Client

d)

Privileged Threat Analytics

70.

You have been asked to secure a set of shared accounts in CyberArk

whose passwords will need to be used by end users. The account owner

wants to be able to track who was using an account at any given

moment.

Which security configuration should you recommend?

a)

Congure one-time passwords for the appropriate platform in Master Policy.

b)

Congure shared account mode on the appropriate safe.

c)

Congure both one-time passwords and exclusive access for the appropriate

platform in Master Policy.

d)

Congure object level access control on the appropriate safe.