If PTA is integrated with a supported SIEM solution, which detection becomes available?
A Reconcile Account can be specified in the Master Policy.
Answer : B
A Reconcile Account is not specified in the Master Policy, but in the Platform settings. The Master Policy defines the general password management settings for all the accounts in the Vault, such as the frequency of password rotation and verification. The Platform settings define the specific password management settings for each type of target system, such as the password complexity and the Reconcile Account.Reference:
Defender PAM course, Module 2: Password Management, Lesson 2: Master Policy and Platforms, slide 8
Defender PAM course, Module 2: Password Management, Lesson 3: Reconcile and Logon Accounts, slide 2
Defender PAM Sample Items Study Guide, Question 37
CyberArk Privileged Access Security Documentation, Password Management - Master Policy
CyberArk Privileged Access Security Documentation, Password Management - Platforms
Where can you check that the LDAP binding is using TCP/636?
In addition to add accounts and update account contents, which additional permission on the safe is required to add a single account?
During a High Availability node switch you notice an error and the Cluster Vault Manager Utility fails back to the original node.
Which log files should you check to investigate the cause of the issue? (Choose three.)
Answer : B, C, E
During a High Availability (HA) node switch, if an error occurs and the Cluster Vault Manager Utility fails back to the original node, you should check the following log files to investigate the cause of the issue:
CyberArk Docs - Troubleshooting High Availability issues1
CyberArk Docs - Monitoring the CyberArk Digital Cluster Vault Server2
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.
Answer : B
When creating an onboarding rule, it will be executed upon .