New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the CyberArk Defender PAM-DEF Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account.

How should this be configured to allow for password management using least privilege?

Options:

A.

Configure each CPM to use the correct logon account.


B.

Configure each CPM to use the correct reconcile account.


C.

Configure the UNIX platform to use the correct logon account.


D.

Configure the UNIX platform to use the correct reconcile account.


Expert Solution
Questions # 42:

All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of the accounts in that safe. The members of the AD group UnixAdmins need to be able to use the show, copy, and connect buttons on those passwords at any time without confirmation. The members of the AD group Operations Staff need to be able to use the show, copy and connect buttons on those passwords on an emergency basis, but only with the approval of a member of Operations Managers never need to be able to use the show, copy or connect buttons themselves.

Which safe permission do you need to grant Operations Staff? Check all that apply.

Options:

A.

Use Accounts


B.

Retrieve Accounts


C.

Authorize Password Requests


D.

Access Safe without Authorization


Expert Solution
Questions # 43:

You are concerned about the Windows Domain password changes occurring during business hours.

Which settings must be updated to ensure passwords are only rotated outside of business hours?

Options:

A.

In the platform policy -

Automatic Password Management > Password Change > ToHour & FromHour


B.

in the Master Policy

Account Change Window > ToHour & From Hour


C.

Administration Settings -

CPM Settings > ToHour & FromHour


D.

On each individual account -

Edit > Advanced > ToHour & FromHour


Expert Solution
Questions # 44:

A password compliance audit found:

1) One-time password access of 20 domain accounts that are members of Domain Admins group in Active Directory are not being enforced.

2) All the sessions of connecting to domain controllers are not being recorded by CyberArk PSM.

What should you do to address these findings?

Options:

A.

Edit the Master Policy and add two policy exceptions: enable "Enforce one-time password access", enable "Record and save session activity".


B.

Edit safe properties and add two policy exceptions: enable "Enforce one-time password access", enable "Record and save session activity".


C.

Edit CPM Settings and add two policy exceptions: enable "Enforce one-time password access", enable "Record and save session activity".


D.

Contact the Windows Administrators and request them to add two policy exceptions at Active Directory Level: enable "Enforce one-time password access", enable "Record and save session activity".


Expert Solution
Questions # 45:

Refer to the exhibit.

Question # 45

Why is user "EMEALevel2Support" unable to change the password for user "Operator"?

Options:

A.

EMEALevel2Support’s hierarchy level is not the same or higher than Operator.


B.

EMEALevel2Support does not have the "Manage Directory Mapping" role.


C.

Operator can only be reset by the Master user.


D.

EMEALevel2Support does not have rights to reset passwords for other users.


Expert Solution
Questions # 46:

For Digital Vault Cluster in a high availability configuration, how does the cluster determine if a node is down?

Options:

A.

The heartbeat s no longer detected on the private network.


B.

The shared storage array is offline.


C.

An alert is generated in the Windows Event log.


D.

The Digital Vault Cluster does not detect a node failure.


Expert Solution
Questions # 47:

Assuming a safe has been configured to be accessible during certain hours of the day, a Vault Admin may still access that safe outside of those hours.

Options:

A.

TRUE


B.

FALSE


Expert Solution
Questions # 48:

Which service should NOT be running on the DR Vault when the primary Production Vault is up?

Options:

A.

PrivateArk Database


B.

PrivateArk Server


C.

CyberArk Vault Disaster Recovery (DR) service


D.

CyberArk Logical Container


Expert Solution
Questions # 49:

In the screenshot displayed, you just configured the usage in CyberArk and want to update its password.

What is the least intrusive way to accomplish this?

Question # 49

Options:

A.

Use the “change” button on the usage’s details page.


B.

Use the “change” button on the parent account’s details page.


C.

Use the “sync” button on the usage’s details page.


D.

Use the “reconcile” button on the parent account’s details page.


Expert Solution
Questions # 50:

Match each key to its recommended storage location.

Question # 50


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions