Pass the CyberArk Defender PAM-DEF Questions and answers with CertsForce

Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions
Questions # 31:

When Dual Control is enabled a user must first submit a request in the Password Vault Web Access (PVWA) and receive approval before being able to launch a secure connection via PSM for Windows (previously known as RDP Proxy).

Options:

A.

True


B.

False, a user can submit the request after the connection has already been initiated via the PSM for Windows


Expert Solution
Questions # 32:

The Password upload utility can be used to create safes.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 33:

You created a new safe and need to ensure the user group cannot see the password, but can connect through the PSM.

Which safe permissions must you grant to the group? (Choose two.)

Options:

A.

List Accounts Most Voted


B.

Use Accounts Most Voted


C.

Access Safe without Confirmation


D.

Retrieve Files


E.

Confirm Request


Expert Solution
Questions # 34:

What is required to manage loosely connected devices?

Options:

A.

PSM for SSH


B.

EPM


C.

PSM


D.

PTA


Expert Solution
Questions # 35:

Vault admins must manually add the auditors’ group to newly created safes so auditors will have sufficient access to run reports.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 36:

You receive this error:

“Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied.”

Which root cause should you investigate?

Options:

A.

The account does not have sufficient permissions to change its own password.


B.

The domain controller is unreachable.


C.

The password has been changed recently and minimum password age is preventing the change.


D.

The CPM service is disabled and will need to be restarted.


Expert Solution
Questions # 37:

The primary purpose of exclusive accounts is to ensure non-repudiation (Individual accountability).

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 38:

Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre-determined amount of time?

Options:

A.

Require dual control password access Approval


B.

Enforce check-in/check-out exclusive access


C.

Enforce one-time password access


D.

Enforce check-in/check-out exclusive access & enforce one-time password access


Expert Solution
Questions # 39:

Which authorizations are required in a recording safe to allow a group to view recordings?

Question # 39


Expert Solution
Questions # 40:

Which master policy settings ensure non-repudiation?

Options:

A.

Require password verification every X days and enforce one-time password access.


B.

Enforce check-in/check-out exclusive access and enforce one-time password access.


C.

Allow EPV transparent connections ('Click to connect') and enforce check-in/check-out exclusive access.


D.

Allow EPV transparent connections ('Click to connect') and enforce one-time password access.


Expert Solution
Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions