100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
PAM/ DEFENDER CERTIFICATE STUDY GUIDE $12.49   Add to cart

Exam (elaborations)

PAM/ DEFENDER CERTIFICATE STUDY GUIDE

 0 view  0 purchase
  • Course
  • Institution

1. Which permissions are needed for the Active Directory user required by the Windows Discovery process? a. Domain Admin b. Ldap Admin c. Read/Write d. Read - Answer- Answer: A 2. Match each component to its respective Log File location. - Answer- PTA /opt/tomcat/logs PSM for SSH (PSM...

[Show more]

Preview 3 out of 25  pages

  • September 12, 2023
  • 25
  • 2023/2024
  • Exam (elaborations)
  • Questions & answers
avatar-seller
PAM/ DEFENDER CERTIFICATE STUDY GUIDE
1. Which permissions are needed for the Active Directory user required by the Windows
Discovery process?

a. Domain Admin
b. Ldap Admin
c. Read/Write
d. Read - Answer- Answer: A

2. Match each component to its respective Log File location. - Answer- PTA
/opt/tomcat/logs

PSM for SSH (PSMP) /var/opt/CARKpsmp/logs

Disaster RecoveryC:\Program Files (x86)\PrivateArk\Server\PADR

You Received this Error: "Error in changepass to user domain\user on domain server (\
domain)winRC=50 Access is denied"

Which root cause should you investigate?


a. The account does not have sufficient permissions to change its own password

b. The domain controller is unreachable

c. The password has been changed recently and minimum password age is preventing
the change.

d. The CPM service is disabled and will need to be restarted. - Answer- Answer: A

4. As vault Admin you have been asked to configure LDAP authentication for your
organization's CyberArk users. Which permissions do you need to complete this task?

a. Audit Users and Add Network Areas
b. Audit Users and Manage Directory Mapping
c. Audit Users and Add/Update Users
d. Audit Users and Activate Users - Answer- Answer: B

5. Which PTA sensors are required to detect suspected credential theft.

a. Logs, Vault Logs
b. Logs, Network Sensor, Vault Logs
c. Logs, PSM Logs, CPM Logs
d. Logs, Network Sensor, EPM - Answer- Answer: A

,6. You are installing HTML5 gateway on a Linux host using the RPM provided. After
installing the Tomcat webapp, what is the next step in the installation process?

a. Deploy the HTML5 service (guacd)
b. Secure the connection between the guacd and the webapp
c. Secure the webapp and JWT validation endpoint
d. Configure ASLR - Answer- Answer: B

7. To enable automatic response "Add to Pending" within PTA when unmanaged
credentials are found, what are the minimum permissions required by PTAUser for the
PasswordManager_Pending safe?

a. List Accounts, View Safe Members, Add Accounts (includes update properties),
Update Account Content, Update Account Properties.

b. List Accounts, Add Accounts (includes update properties), Delete Accounts, Manage
Safe

c. Add Accounts (includes update properties), Update Account Content, Update
Account properties, View Audit.

d. View Accounts, Update Account Content, Update Account Properties, Access Safe
without Confirmation, Mange Safe, View Audit. - Answer- Answer: A

8. A customer's environment three data centers, consisting of 5,000 servers in
Germany, 10,000 servers in Canada, 1,500 servers in Singapore. You want to manage
target servers and avoid complex firewall rules. How many CPM's should you deploy?

a. 1
b. 3, total, 1 per data center
c. 15
d. 6, total, 2 per data center - Answer- Answer: B

9. What is a prerequisite step before CyberArk can be configured to support RADIUS
authentication?

a. Log on to the PrivateArk Client, display the user properties of the user to configure,
run the Authentication method drop-down list, and select RADIUS authentication.

b. In the RADIUS server, define the CyberArk Vault as RADIUS client/agent.

c. In the Vault Installation folder, run CAVaultManger as Administrator with the
SecureSecretFiles command.

d. Navigate to /Server/Conf and open DBParms.ini and set the RadiusServersInfo
parameter. - Answer- Answer: B

, 10. Which components can connect to a satellite Vault in distributed Vault architecture?

a. CPM, EPM, PTA
b. PVWA, PSM
c. CPM,PVWA, PSM
d. CPM, PSM - Answer- Answer: B

11. You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You
discover that the CPM is unable to log in directly with the root account and will need to
use a secondary account. How should this be configured to allow for password
management using least privilege?

a. Configure each CPM to use the correct logon account

b. Configure each CPM to use the correct reconcile account

c. Configure the UNIX Platform to use the correct logon account

d. Configure the UNIX Platform to use the correct reconcile account - Answer- Answer:
C

12. Match the built-in Vault user with the correct definition.

a. This user appears on the highest level of the user hierarchy and has all the possible
permissions. As such, it can create and manage other Users on any level on the Users'
hierarchy.

b. This user appears at the to of the User hierarchy, enabling it to view all the Users in
the Safe. The user can produce reports of Safe activities and User activities, which
enables it to keep track of activity in the Safe and User requirements.

c. This user is an internal user that cannot be logged onto and carries out internal tasks,
such as automatically clearing expired user and Safe History.

d. This user has all available Safe member authorizations except Authorize password
requests. This user has complete system control, manages a full recovery when
necessary and cannot be removed from any Safe. - Answer- A: Administrator
B: Auditor
C: Batch
D: Master

13. A new HTML5 Gateway has been deployed in your organization. Where do you
configure the PSM to use the HTML5 Gateway?

a. Administration > Options > Privileged Session Management > Configured PSM
Servers > Connection Details > Add PSM Gateway

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Greaterheights. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $12.49. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

77254 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$12.49
  • (0)
  Add to cart