Font size
WorksheetsCyberArk Def Exam Questions
Total questions: 70
Worksheet time: 38mins
What do you need on the Vault to support LDAP over SSL?
CA Certificate(s) used to sign the External Directory certificate
RECPRV.key
a private key for the external directory
self-signed Certificate(s) for the Vault
You are troubleshooting a PVWA slow response. Which log files should you analyze first? (Choose two.)
ITALog.log
web.config
CyberArk.WebApplication.log
CyberArk.WebConsole.log
What is the easiest way to duplicate an existing platform?
From PrivateArk, copy/paste the appropriate Policy.ini file; then rename it.
From the PVWA, navigate to the platforms page, select an existing platform that is similar to the new target account platform and then click Duplicate; name the new platform.
From PrivateArk, copy/paste the appropriate settings in PVConfiguration.xml; then update the policyName variable.
From the PVWA, navigate to the platforms page, select an existing platform that is similar to the new target account platform, manually update the platform settings and click "Save as" INSTEAD of save to duplicate and rename the platform.
Due to corporate storage constraints, you have been asked to disable session monitoring and recording for 500 testing accounts used for your lab environment. How do you accomplish this?
Master Policy>select Session Management>add Exceptions to the
platform(s)>disable Session Monitoring and Recording policies
Administration>Platform Management>select the platform(s)>disable Session
Monitoring and Recording
Polices>Access Control (Safes)>select the safe(s)>disable Session Monitoring
and Recording policies
Administration>Conguration Options>Options>select Privilege Session
Management>disable Session Monitoring and Recording policies
A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The Vault Admin has been asked to look at the account and identify who can approve their request. What is the correct location to identify users or groups who can approve?
PVWA > Administration > Platform Conguration > Edit Platform > UI & Workow
> Dual Control > Approvers
PVWA > Policies > Access Control (Safes) > Select the safe > Safe Members
> Workow > Authorize Password Requests
PVWA > Account List > Edit > Show Advanced Settings > Dual Control > Direct
Managers
PrivateArk > Admin Tools > Users and Groups > Auditors (Group Membership)
What must you specify when configuring a discovery scan for UNIX? (Choose two.)
Vault Administrator
CPM Scanner
root password for each machine
list of machines to scan
safe for discovered accounts
To change the safe where recordings are kept for a specific platform, which setting must you update in the platform configuration?
SessionRecorderSafe
SessionSafe
RecordingsPath
RecordingLocation
Which processes reduce the risk of credential theft? (Choose two.)
equire dual control password access approval
require password change every X days
enforce check-in/check-out exclusive access
enforce one-time password access
You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How can this be configured to allow for password management using least privilege?
Congure each CPM to use the correct logon account.
Congure each CPM to use the correct reconcile account.
Congure the UNIX platform to use the correct logon account.
Congure the UNIX platform to use the correct reconcile account.
ADR Vault became active due to a failure of the primary Vault. Service on the primary Vault has now been restored. Arrange the first steps to return the DR vault to its normal standby mode in the correct sequence.
Shutdown PrivateArk Service
ser Failover Mode = No
Start PrivateArk DR Service
Which methods can you use to add a user directly to the Vault Admin Group? (Choose three.)
Active Directory
PACLI
REST API
PrivateArk Client
PVWA
Which Automatic Remediation is configurable for a PTA detection of a "Suspected Credential Theft"?
Add to Pending
Rotate Credentials
Reconcile Credentials
Disable Account
Which item is an option for PSM recording customization?
Windows events text recorder with automatic play-back
Windows events text recorder and universal keystrokes recording simultaneously
Universal keystrokes text recorder with windows events text recorder disabled
Custom audio recording for windows events
You want to create a new onboarding rule. Where do you accomplish this?
In PVWA, click Reports > Unmanaged Accounts > Rules
In PVWA, click Options > Platform Management > Onboarding Rules
In PrivateArk, click Tools > Onboarding Rules
In PVWA, click Accounts > Onboarding Rules
What does the Export Vault Data (EVD) utility do?
exports data from the Vault to TXT or CSV les, or to MSSQL databases
generates a backup le that can be used as a cold backup
exports all passwords and imports them into another instance of CyberArk
keeps two active vaults in sync
When are external vault users and groups synchronized by default?
They are synchronized once every 24 hours between 1 AM and 5 AM.
They are synchronized once every 24 hours between 7 PM and 12 AM.
They are synchronized every 2 hours.
They are not synchronized according to a specic schedule.
You created a new safe and need to ensure the user group cannot see the password, but can connect through the PSM. Which safe permissions must you grant to the group? (Choose two.)
List Accounts
Use Accounts
Access Safe without Conrmation
Retrieve Files
Conrm Request
During a High Availability node switch you notice an error and the Cluster Vault Manager Utility fails back to the original node. Which log files should you check to investigate the cause of the issue? (Choose three.)
PM_Error.log
ClusterVault.console.log
ITALog.log
CyberArk Webconsole.log
VaultDB.log
Where can a user with the appropriate permissions generate a report? (Choose two.)
PVWA > Reports
PrivateArk Client
Cluster Vault Manager
PrivateArk Server Monitor
PARClient
Users are unable to launch Web Type Connection components from the PSM server. Your manager asked you to open the case with CyberArk Support. Which logs will be most useful for the CyberArk Support Team to debug the issue? (Choose three.)
PSMConsole.log
PSMDebug.log
PMconsole.log
PSMTrace.log
You have been asked to identify the up or down status of Vault Services. Which CyberArk utility can you use to accomplish this task?
PrivateArk Central Administration Console
PAS Reporter
PrivateArk Remote Control Agent
Syslog
A new colleague created a directory mapping between the Active Directory groups and the Vault. Where can the newly Configured directory mapping be tested?
Connect to the Active Directory and ensure the organizational unit exists.
Connect to Sailpoint (or similar tool) to ensure the organizational unit is correctly
named; log in to the PVWA with "Administrator" and conrm authentication
succeeds.
Search for members that exist only in the mapping group to grant them safe
permissions through the PVWA.
Connect to the PrivateArk Client with the Administrator Account to see if there is
a user in the Vault Admin Group.
A user needs to view recorded sessions through the PVWA.
Without giving auditor access, which safes does a user need access to
view PSM recordings? (Choose two.)
Recordings safe
Safe the account is in
System safe
PVWAConguration safe
VaultInternal safe
Without giving auditor access, which safes does a user need access to view PSM recordings?
Recordings safe
Safe the account is in
System safe
PVWAConfiguration safe
VaultInternal safe
Which file must be edited on the Vault to configure it to send data to PTA?
dbparm.ini
PARAgent.ini
my.ini
padr.ini
You want to build a connector that connects to a website through the Web applications for PSM framework. Which default connector do you duplicate and modify?
PSM-ChromeSample
PSM-WebForm
PSM-WebApp
PSM-WebAppSample
A new HTML5 Gateway has been deployed in your organization. From the PVWA, arrange the first steps to configure a PSM host to use the HTML5 Gateway in the correct sequence.
Administration>Options
Administration>Options
Privileged Session
Management
Congured PSM Server
and select existing
PSM host
Congured PSM Server
and select existing
PSM host
Connection Details
Add PSM gateway
Add PSM gatewa
When an account is unable to change its own password, how can you ensure that password reset with the reconcile account is performed each time instead of a change?
Set the parameter RCAllowManualReconciliation to Yes.
Set the parameter ChangePasswordinResetMade to Yes.
Set the parameter IgnoreReconcileOnMissingAccount to No.
Set the UnlockUserOnReconcile to Yes.
In a default CyberArk installation, which group must a user be a member of to view the 'reports' page in PVWA?
PVWAMonitor
ReportUsers
PVWAReports
Operators
Your organization requires all passwords be rotated every 90 days. Where can you set this requirement?
Master Policy
Safe Templates
PVWAConfiguration.xml
Platform Configuration
According to CyberArk, which issues most commonly cause installed components to display as disconnected in the System Health Dashboard? (Choose two.)
network instabilities/outages
vault license expiry
credential de-sync
browser compatibility issues
installed location file corruption
Where can reconcile and/or logon accounts be linked to an account? (Choose two.)
account settings
platform settings
master policy
safe settings
service account settings
You are running a 'Privileged Accounts Inventory' Report through the Reports page in PVWA on a specific safe. To show complete account inventory information, which permission/s are needed on that safe?
List Accounts, View Safe Members
Manage Safe Owners
List Accounts, Access Safe without confirmation
Manage Safe, View Audit
Which dependent accounts does the CPM support out-of-the-box?
Windows Registry
Solaris Configuration file
Windows Scheduled Tasks
Windows DCOM Applications
Windows Services
A password compliance audit found: 1) One-time password access of 20 domain accounts that are members of Domain Admins group in Active Directory are not being enforced. 2) All the sessions of connecting to domain controllers are not being recorded by CyberArk PSM. What should you do to address these findings?
Edit the Master Policy and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.
Edit safe properties and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.
Edit CPM Settings and add two policy exceptions: enable 'Enforce one-time password access', enable 'Record and save session activity'.
Contact the Windows Administrators and request them to add two policy exceptions at Active Directory Level: enable 'Enforce one-time password access', enable 'Record and save session activity'.
If PTA is integrated with a supported SIEM solution, which detection becomes available?
unmanaged privileged account
privileged access to the Vault during irregular days
riskySPN
exposed credentials
Which change could CyberArk make to the REST API that could cause existing scripts to fail?
adding optional parameters in the request
adding additional REST methods
removing parameters
returning additional values in the response
You created a new platform by duplicating the out-of-box Linux through the SSH platform. Without any change, which Text Recorder Type(s) will the new platform support?
SSH Text Recorder
Universal Keystrokes Text Recorder
Events Text Recorder
SQL Text Recorder
Telnet Commands Text Recorder
You are creating a Dual Control workflow for a team's safe. Which safe permissions must you grant to the Approvers group?
List accounts, Authorize account request
Retrieve accounts, Access Safe without confirmation
Retrieve accounts, Authorize account request
List accounts, Unlock accounts
In addition to add accounts and update account contents, which additional permission on the safe is required to add a single account?
Upload Accounts Properties
Rename Accounts
Update Account Properties
Manage Safe
You want to give a newly-created group rights to review security events under the Security pane. You also want to be able to update the status of these events. Where must you update the group to allow this?
in the PTAAuthorizationGroups parameter, found in Administration > Options > PTA
in the PTAAuthorizationGroups parameter, found in Administration > Options > General
in the SecurityEventsAuthorizationGroups parameter, found in Administration > Security > Options
in the SecurityEventsFeedAuthorizationGroups parameter, found in Administration > Options > General
What is required to manage loosely connected devices?
PSM for SSH
EPM
PSM
PTA
Your organization has a requirement to allow only one user to 'check out passwords' and connect through the PSM securely. What needs to be configured in the Master policy to ensure this will happen?
Enforce check-in/check-out exclusive access = active; Require privileged session monitoring and isolation = active
Enforce check-in/check-out exclusive access = inactive; Require privileged session monitoring and isolation = inactive
Enforce check-in/check-out exclusive access = inactive; Record and save session activity = active
Enforce check-in/check-out exclusive access = active; Record and save session activity = inactive
When should vault keys be rotated?
when it is copied to file systems outside the vault
annually
whenever a CyberArk user leaves the organization
when migrating to a new data center
Where can PTA be configured to send alerts?
SIEM
Google Analytics
EVD
PAReplicate
In your organization the 'click to connect' button is not active by default. How can this feature be activated?
Policies > Master Policy > Allow EPV transparent connections > Inactive
Policies > Master Policy > Session Management > Require privileged session monitoring and isolation > Add Exception
Policies > Master Policy > Allow EPV transparent connections > Active
Policies > Master Policy > Password Management
What are the mandatory fields when onboarding from Pending Accounts?
Address
Safe
Account Description
Platform
CPM
Match each permission to where it can be found
Add Accounts
Add Accounts => Safe
Initiate CPM
account
management
operations => Safe
Add/Update
Users => Vault
Add Safes
Add Safes => Vault
Which accounts can be selected for use in the Windows discovery process? (Choose two.)
an account stored in the Vault
an account specied by the user
the Vault Administrator
any user with Auditor membership
the PasswordManager user
You are concerned about the Windows Domain password changes occurring during business hours. Which settings must be updated to ensure passwords are only rotated outside of business hours?
In the platform policy - Automatic Password Management > Password Change > ToHour & FromHour
in the Master Policy - Account Change Window > ToHour & From Hour
Administration Settings - CPM Settings > ToHour & FromHour
On each individual account - Edit > Advanced > ToHour & FromHour
The Privileged Access Management solution provides an out-of-the-box target platform to manage SSH keys, called UNIX Via SSH Keys. How are these keys managed?
CyberArk stores Private keys in the Vault and updates Public keys on target systems.
CyberArk stores Public keys in the Vault and updates Private keys on target systems.
CyberArk does not store Public or Private keys and instead uses a reconcile account to create keys on demand.
CyberArk stores both Private and Public keys and can update target systems with either key.
The Active Directory User configured for Windows Discovery needs which permission(s) or membership?
Member of Domain Admin Group
Member of LDAP Admin Group
Read and Write Permissions
Read Only Permissions
Which command generates a full backup of the Vault?
PAReplicate.exe Vault.ini /LogonFromFile user.ini /FullBackup
PAPreBackup.exe C:\PrivateArk\Server\Conf\Vault.ini Backup/Asdf1234 /full
PARestore.exe PADR ini /LogonFromFile vault.ini /FullBackup
CAVaultManager.exe RecoverBackupFiles /BackupPoolName BkpSvr1
You have been asked to create an account group and assign three accounts which belong to a cluster. When you try to create a new group, you receive an unauthorized error; however, you are able to edit other aspects of the account properties. Which safe permission do you need to manage account groups?
create folders
specify next account content
rename accounts
manage safe
Match the connection component to the corresponding OS/Function *
(a)
A recently-hired colleague onboarded five new Local Accounts that are
used for five standalone Windows Servers. After attempting to connect to
the servers from PVWA, the colleague noticed that the "Connect" button
was greyed out for all five new accounts.
*
What can you do to help your colleague resolve this issue? (Choose two.)
Verify that the address eld is populated with an IP or FQDN of each server.
Verify that the correct PSM connection component appears within account
platform settings.
Verify that the address eld is blank and that the correct PSM connection
component appears within account platform settings.
Notify the Windows Team that created the new accounts that the CyberArk PAM
solution is not designed to manage local accounts on Windows Servers.
Verify that the "Disable automatic management for this account" setting for each
account is not enabled.
Before failing back to the production infrastructure after a DR exercise, what must you do to maintain audit history during the DR event?
Ensure that the Production Instance replicates changes that occurred from the Disaster Recovery Instance.
Briefly stop and start the Disaster Recovery Instance before attempting to fail components back to the Production Instance.
Stop the CPM services before starting the production server.
Perform an IIS Reset on all PVWA servers.
You are configuring CyberArk to use HTML5 gateways exclusively for PSM connections. In the PVWA, where do you set DefaultConnectionMethod to HTML5?
Options > Privileged Session Management UI
Options > Privileged Session Management
Options > Privileged Session Management Defaults
Options > Privileged Session Management Interface
You are onboarding an account that is not supported out of the box.
*What should you do first to obtain a platform to import?
Create a service ticket in the customer portal explaining the requirements of
the custom platform.
Search common community portals like stackoverow, reddit, github for an
existing platform.
From the platforms page, uncheck the “Hide non-supported platforms” checkbox
and see if a platform meeting your needs appears.
Visit the CyberArk marketplace and search for a platform that meets your needs.
Which master policy settings ensure non-repudiation?
Require password verification every X days and enforce one-time password access.
Enforce check-in/check-out exclusive access and enforce one-time password access.
Allow EPV transparent connections ('Click to connect') and enforce check-in/check-out exclusive access.
Allow EPV transparent connections ('Click to connect') and enforce one-time password access.
You have been asked to turn off the time access restrictions for a safe. Where is this setting found?
PrivateArk Client
RestAPI
PVWA
Vault
You want to generate a license capacity report. Which tool accomplishes this?
Password Vault Web Access
PrivateArk Client
DiagnoseDB Report
RestAPI
Match the Status of Service on a DR Vault to what is displayed when it is
operating normally in Replication mode.
Cyber-Ark
Hardened
Windows
Firewal > Running
PrivateArk
Database
PrivateArk
Databas > Running
PrivateArk Server > Stoped
CyberArk Vault
DR > Running
CyberArk Event
Notication
Engine > Stoped
Which parameters can be used to harden the Credential Files (CredFiles) while using CreateCredFile Utility?
Host IP Address
Operating System Username
Client Hostname
Operating System Type (Linux/Windows/HP-UX)
Vault IP Address
Match each automatic remediation to the correct PTA security event. *
A
B
You notice an authentication failure entry for the DR user in the ITALog. What is the correct process to fix this error? (Choose two.)
PrivateArk Client > Tools > Administrative Tools > Users and Groups > DR User >
Update > Authentication > Update Password.
Create a new credential le, on the DR Vault, using the CreateCredFile utility and
the newly set password.
Create a new credential le, on the Primary Vault, using the CreateCredFile utility
and the newly set password.
PVWA > User Provisioning > Users and Groups > DR User > Update Password.
PrivateArk Client > Tools > Administrative Tools > Users and Groups >
PAReplicate User > Update > Authentication > Update Password.
To manage automated onboarding rules, a CyberArk user must be a member of which group?
Vault Admins
CPM User
Auditors
Administrators
To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?
List Accounts, Use Accounts
List Accounts, Use Accounts, Retrieve Accounts
Use Accounts
List Accounts, Use Accounts, Retrieve Accounts, Access Safe without
conrmation
Which CyberArk utility allows you to create lists of Master Policy Settings, owners and safes for output to text files or MSSQL databases?
Export Vault Data
Export Vault Information
PrivateArk Client
Privileged Threat Analytics
You have been asked to secure a set of shared accounts in CyberArk
whose passwords will need to be used by end users. The account owner
wants to be able to track who was using an account at any given
moment.
Which security configuration should you recommend?
Congure one-time passwords for the appropriate platform in Master Policy.
Congure shared account mode on the appropriate safe.
Congure both one-time passwords and exclusive access for the appropriate
platform in Master Policy.
Congure object level access control on the appropriate safe.
