Pass the CyberArk Defender PAM-DEF Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? (Choose three.)

Options:

A.

Store the CD in a physical safe and mount the CD every time Vault maintenance is performed


B.

Copy the entire contents of the CD to the system Safe on the Vault


C.

Copy the entire contents of the CD to a folder on the Vault Server and secure it with NTFS permissions


D.

Store the server key in a Hardware Security Module (HSM) and copy the rest the keys from the CD to a folder on the Vault Server and secure it with NTFS permissions


Expert Solution
Questions # 12:

Which is the primary purpose of exclusive accounts?

Options:

A.

Reduced risk of credential theft


B.

More frequent password changes


C.

Non-repudiation (individual accountability)


D.

To force a ‘collusion to commit’ fraud ensuring no single actor may use a password without authorization


Expert Solution
Questions # 13:

Your customer, ACME Corp, wants to store the Safes Data in Drive D instead of Drive C.

Which file should you edit?

Options:

A.

TSparm.ini


B.

Vault.ini


C.

DBparm.ini


D.

user.ini


Expert Solution
Questions # 14:

You want to create a new onboarding rule.

Where do you accomplish this?

Options:

A.

In PVWA, click Reports > Unmanaged Accounts > Rules


B.

In PVWA, click Options > Platform Management > Onboarding Rules


C.

In PrivateArk, click Tools > Onboarding Rules


D.

In PVWA, click Accounts > Onboarding Rules


Expert Solution
Questions # 15:

Time of day or day of week restrictions on when password verifications can occur configured in ____________________.

Options:

A.

The Master Policy


B.

The Platform settings


C.

The Safe settings


D.

The Account Details


Expert Solution
Questions # 16:

In a rule using “Privileged Session Analysis and Response” in PTA, which session options are available to configure as responses to activities?

Options:

A.

Suspend, Terminate, None


B.

Suspend, Terminate, Lock Account


C.

Pause, Terminate, None


D.

Suspend, Terminate


Expert Solution
Questions # 17:

What do you need on the Vault to support LDAP over SSL?

Options:

A.

CA Certificate(s) used to sign the External Directory certificate Most Voted


B.

RECPRV.key


C.

a private key for the external directory


D.

self-signed Certificate(s) for the Vault


Expert Solution
Questions # 18:

When managing SSH keys, the CPM stored the Private Key

Options:

A.

In the Vault


B.

On the target server


C.

A & B


D.

Nowhere because the private key can always be generated from the public key.


Expert Solution
Questions # 19:

Which CyberArk utility allows you to create lists of Master Policy Settings, owners and safes for output to text files or MSSQL databases?

Options:

A.

Export Vault Data


B.

Export Vault Information


C.

PrivateArk Client


D.

Privileged Threat Analytics


Expert Solution
Questions # 20:

When an account is unable to change its own password, how can you ensure that password reset with the reconcile account is performed each time instead of a change?

Options:

A.

Set the parameter RCAllowManualReconciliation to Yes.


B.

Set the parameter ChangePasswordinResetMade to Yes.


C.

Set the parameter IgnoreReconcileOnMissingAccount to No.


D.

Set the UnlockUserOnReconcile to Yes.


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions