CyberArk Defender - PAM PAM-DEF Exam Questions

Page: 1 / 14
Total 239 questions
Question 1

VAULT authorizations may be granted to_____.



Answer : A, C

Vault Authorizations

* Can be assigned only to users (not groups).

* Cannot be inherited via group membership.

* Defined only via the Private Ark Client.

Safe Auth

* Assigned to users and/or groups.

* Can be inherited via group membership.

* Can be defined in the Private Ark Client or PVWA


Question 2

Where can a user with the appropriate permissions generate a report? (Choose two.)



Answer : A, B

A user with the appropriate permissions can generate a report in thePVWA (Privileged Vault Web Access)under theReportssection1. Users who belong to the group specified in theManageReportsGroupparameter in the Reports section of the Web Access Options in the System Configuration page are able to generate reports in the PVWA.By default, this group is thePVWAMonitorgroup1.Additionally, reports can be generated using thePrivateArk Client, which is a desktop application that provides a direct interface to manage the CyberArk Vault and its contents, including the generation of reports2.


CyberArk Docs - Reports in PVWA1

CyberArk Docs - Generate the Report2

Question 3

A logon account can be specified in the platform settings.



Answer : A

A logon account can be specified in the platform settings of CyberArk, a security software that manages privileged accounts and credentials.According to the CyberArk documentation1, 'In the Account Details window, in the CPM pane, in the accounts section, you can associate either a logon account or a reconciliation account. If a default logon account has been configured for the platform that manages this account, that account is listed.You can associate another logon account or leave the default account as it is.'1A logon account is an account that is used to log on to a target system and perform password management operations on other accounts. A reconciliation account is an account that is used to restore access to a target system when the logon account fails.


Question 4

Which parameter controls how often the CPM looks for accounts that need to be changed from recently completed Dual control requests.



Answer : B

This parameter controls how often the CPM looks for accounts that need to be changed from recently completed Dual control requests. It is set in the Master Policy under the Dual Control section. The value of this parameter determines the frequency of the CPM's verification process for accounts that have been accessed by users who have received confirmation from authorized Safe owners. The CPM will change the password of these accounts according to the value of this parameter.Reference:

Dual Control - CyberArk

Dual control in V10 Interface - docs.cyberark.com

PAM-DEF CyberArk Defender -- PAM Questions and Answers - Marks4sure


Question 5

Which of the Following can be configured in the Master Poky? Choose all that apply.



Answer : A, B, C, H

The Master Policy is a centralized overview of the security and compliance policy of privileged accounts in the organization. It allows the administrator to configure compliance driven rules that are defined as the baseline for the enterprise.The Master Policy includes the following main concepts1:

Basic policy rules: These rules allow the administrator to define specific aspects of privileged account management, such as privileged access workflows, password management, session monitoring and auditing.

Advanced policy rules: Some basic policy rules have related advanced settings that provide more granular control over the policy enforcement.

Exceptions: These are policy rules that differ from the overall Master Policy for a specific scope of accounts, such as accounts associated with a specific platform.

The Master Policy rules are divided into four sections2:

Privileged Access Workflows: These rules define how the organization manages access to privileged accounts, such as requiring dual control, one-time passwords, exclusive passwords, transparent connections, reason for access, etc.

Password Management: These rules determine how passwords are managed, such as requiring password change, password verification, password reconciliation, ticketing integration, required properties, custom connection components, etc.

Session Management: These rules determine whether or not privileged sessions are recorded and how they are monitored, such as requiring session isolation, session recording, session audit, etc.

Audit: This rule determines how Safe audits are retained, such as specifying the audit retention period.

Based on the above information, the following options can be configured in the Master Policy:

A .Dual Control: This is a basic policy rule in the Privileged Access Workflows section that determines whether users need to get approval from authorized users before accessing a privileged account2.

B .One Time Passwords: This is a basic policy rule in the Privileged Access Workflows section that determines whether users can only use a password once before it is changed2.

C .Exclusive Passwords: This is a basic policy rule in the Privileged Access Workflows section that determines whether users need to check out a password and prevent other users from accessing it until it is checked in2.

H .Password Aging Rules: This is a basic policy rule in the Password Management section that determines how often passwords need to be changed2.

The following options cannot be configured in the Master Policy:

D .Password Reconciliation: This is not a policy rule, but a process that restores the password of a privileged account to the value that is stored in the Vault, in case it is changed or out of sync3.

E . Ticketing Integration: This is not a policy rule, but a feature that enables the integration of the Vault with external ticketing systems, such as ServiceNow, Jira, etc.

F . Required Properties: This is not a policy rule, but a platform setting that determines which properties are mandatory for adding accounts to a platform.

G . Custom Connection Components: This is not a policy rule, but a platform setting that determines which connection components are used to connect to target systems, such as PVWA, PSM, PSMP, etc.


1:The Master Policy

2:Master Policy Rules

3: Password Reconciliation

: Ticketing Integration

: Required Properties

: Custom Connection Components

Question 6

PSM captures a record of each command that was executed in Unix.



Answer : A

PSM captures a record of each command that was executed in Unix by using the SSH text recorder. This is a feature that enables PSM to record all the keystrokes that are typed during privileged sessions on SSH connections, including Unix systems. The SSH text recorder can be configured in the Platform Management settings for each platform that uses the SSH protocol. The text recordings are stored and protected in the Vault server and are accessible to authorized auditors.The text recordings can also be used for auditing and compliance purposes, as they provide a detailed trace of the actions performed by the users on the target systems1.Reference:

1:Introduction to PSM for SSH, How it works subsection, Text recordings paragraph


Question 7

What is the purpose of the PrivateArk Database service?



Answer : D

The purpose of the PrivateArk Database service is to maintain the Vault metadata, which includes the information about the Safes, accounts, policies, users, groups, and audit records that are stored in the Vault. The PrivateArk Database service is a Windows service that manages the database files that contain the Vault data.The PrivateArk Database service is responsible for creating, updating, deleting, and backing up the database files, as well as performing encryption and compression operations on the data1.The PrivateArk Database service is installed automatically as part of the Vault server installation and can be configured using the DBParm.ini file2.

The other options are not the purpose of the PrivateArk Database service, although they may be related to other services or components of the Vault.The PrivateArk Server service is the service that communicates with the components, such as the PVWA, the CPM, the PSM, and the PTA, and handles the requests from the clients and components3.The Event Notification Engine service is the service that sends email alerts from the Vault, based on predefined events and recipients4. The Central Policy Manager component is the component that executes password changes, verifications, and reconciliations for the accounts that are managed by the Vault.Reference:

Server Components - CyberArk, section ''The PrivateArk Server process (Dbmain)''

DBParm.ini - CyberArk, section ''Main parameters''

Server Components - CyberArk, section ''The PrivateArk Server process (Dbmain)''

Event Notification Engine - CyberArk, section ''Event Notification Engine''

[Change Passwords - CyberArk], section ''Change Passwords''


Page:    1 / 14   
Total 239 questions