Access Rights Manager (ARM) Flashcards

1
Q

How can you restrict access to a directory that contains information about an upcoming company merge?

a) Disable inheritances
b) Assign one resource owner
c) Configure SAP properties
d) Disable the automatic list rights management

A

a) Disable Inheritances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What file types are supported for configuring scripts?

A
.ps (PowerShell)*
.vbs (VisualBasic)
.bat
.cmd
.js (nodejs.exe)
.exe
  • PowerShell files are .ps1, but the admin guide says .ps as of the authoring of this deck.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A user has been losing access rights for several months, but does not know which rights are lost. The user has been running ARM for one year. How can you troubleshoot this issue? Select all that apply.

a) You compare the Where has a user/group access report against a current scan and a 6 months old scan
b) Run a scan comparison report for the user and another user who has no issues and compare them to search for issues
c) Review the logbook and search for issues
d) Run AD Logga report with the member removed event type, and set the report start date to the previous year and filter the report for the user

A

A, C, D

a) You compare the Where has a user/group access report against a current scan and a 6 months old scan
c) Review the logbook and search for issues
d) Run AD Logga report with the member removed event type, and set the report start date to the previous year and filter the report for the user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You configured ARM to send file server reports to Data Owners every quarter. What are possible reasons why you did not receive a report this quarter? Select all that apply.

a) The administrator deleted the Exchange Online mailbox
b) The SMTP server sending options changed
c) The 25 without SSL port was opened on the SMTP server
d) The SMTP server was offline when ARM attempted to run the report

A

B, D

b) The SMTP server sending options changed
d) The SMTP server was offline when ARM attempted to run the report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

After installation, the Basic Configuration page launches automatically and asks you to do which two steps before anything else can be configured?

a) Define the credentials for the ARM Server to run Active Directory requests
b) Install missing components listed in the install Report
c) Activate your license
d) Define the SQL Server database

A

A, D

a) Define the credentials for the ARM Server to run Active Directory requests
d) Define the SQL Server database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where can you run web components/WebAPI? Select all that apply.

a) ARM server with IIS installed
b) Apache server
c) Standalone Microsoft IIS server
d) GWS server

A

A, C

a) ARM server with IIS installed
c) Standalone Microsoft IIS server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is required when you configure FS Logga for a Windows failover cluster? Select all that apply.

a) Install and run the collector service on all nodes
b) Restart the file server after you install FS Logga
c) Install .net in all cases manually
d) Install the FS Logga filter driver on all nodes

A

A, D

a) Install and run the collector service on all nodes
d) Install the FS Logga filter driver on all nodes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What helps automate the process of disabling a user in ARM? Select all that apply.

a) Scripts
b) Reports
c) GrantMa
d) Templates

A

A, C

a) Scripts
c) GrantMa

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can you improve filer server scan performance?

a) Configure $-Shares to see all shares
b) Increase scan depth and remove all shares
c) Configure Storage of Scans to store unnecessary data
d) Use the correct file server type

A

D

d) Use the correct file server type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What can you do to balance the load on your ARM server?

a) Install additional collector
b) Use NTFS
c) Defrag hard disks
d) Use a dedicated drive for Pagefile

A

A

a) Install additional collector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What SQL rights do you need to install an ARM instance’s database?

A

If an ARM DB already exists, you need dbowner. Otherwise, you need dbcreator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What kinds of mailbox permissions can be managed in ARM?

A

Full Access, Send As, and Receive As

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the requirements for a service account for FS Logga?

A

FS Logga does not require a service account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the requirements for a service account for AD Logga?

A

Event Log Reader

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the requirements for a service account for Exchange Logga?

A

Organization Management and Records Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the default port used between the ARM server and GUI?

A

55555

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are some reasons to install an Additional Collector?

A

Connecting remote resources to reduce WAN footprint

FS Logga for Windows FS requires a collector

Load Balancing

To incorporate foreign domains (non-trusted)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Describe how to find broken/corrupted inheritance in ARM.

A

Under resources, choose the appropriate file server, click on “Report” and choose “report on all paths (or sub-directories) with different access rights.” Save the report as a spreadsheet, and filter on “inheritance corrupted = yes”

19
Q

What causes a “maximum number of ARM queue messages exceeded error? How do you fix it?

A

It is caused by the FS/AD Logga not being reachable or being uninstalled or renamed. It will fix itself if the connector is just unreachable, but if it has been uninstalled or renamed, it must be manually removed by logging into RabbitMQ and deleting the Queue.

20
Q

How do you find and fix directories (not users) with corrupted inheritance?

A

Analysis > Directories > Directories with Corrupted Inheritance; select the ones you want to fix and choose “Enforce Inheritance”

21
Q

Who can allocate Manager in AD Attributes?

A

ARM Administrator

22
Q

Describe how to create a protected directory on a file server

A

Create directory, remove all inherited rights, add new access rights for selected users

23
Q

What causes an unresolved SID? How do you find them? Remove them?

A

Users or groups with direct access rights on file servers are deleted in AD. They can be found by running a “Where has User/Group Access” report and modifying the access rights of the resources that show in that report.

24
Q

What are 4 thresholds that would cause a server health check to show as warning/yellow or critical/red?

A
  • Database size
  • Database free disk space
  • Free disk space on archive disk
  • Message count in queuing services
25
Q

Where are logs stored in ARM?

A

%ProgramData%\protected-networks.com\8MAN\log

26
Q

What log file would you use to see issues with Logga?

A

pnTracer

27
Q

Where are scripts stored in ARM?

A

%ProgramData%\protected-networks.com\8MAN\scripts\analyze

28
Q

How do you prevent an ARM database from filling up (or fix it when it has filled up)?

A

Shrink DB, Reduce scan frequency, disable FS Logga Alerts

29
Q

What file formats are supported by Easy Connect?

A

.csv and .sql

30
Q

True or false: It is possible to import/export Data Owner configurations in ARM

A

True

31
Q

What is a way to identify over-privileged users in ARM?

A

Kerberos Token size

32
Q

What port is used for LDAP?

A

TCP/389

33
Q

What port is used for NetBIOS?

A

TCP/139

34
Q

What port is used for MS Directory Services?

A

TCP/445

35
Q

What port is used for WMI/DCOM/RPC?

A

TCP/135 (dynamic)

36
Q

What port is used for SQL?

A

TCP/1433

37
Q

What port is used for Kerberos?

A

88

38
Q

What port is used between ARM components?

A

55555; dynamic

39
Q

What port is used for RabbitMQ?

A

5671

40
Q

If you have 4000 users, can you still use an ARM1000 license? If so, how?

A

Yes; ARM licenses are assigned - you can have only 1000 licensed users but still 3000 unlicensed users.

41
Q

Is it best practice to use a hostname or FQDN for Exchange Scans?

A

Hostname

42
Q

What are Purpose Groups used for?

A

They are used as aliases / friendly names within ARM only.

43
Q

What is the cause of permissions not propagating down?

A

Broken ACLs

44
Q

Info on which Logga(s) can be found in the Logbook?

A

AD and Exchange Only (not FS Logga, etc.)