Base Flashcards

1
Q

Can the CPM be installed on the same server as the Vault?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s the different between User and Account?

A

User is the person accessing CyberArk, the Accounts are the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s the benifit for using the HTML5 GW vs RDP through firewall for remote users?

A

HTML5 GW is not Client specific. Win, Mac, Unix..etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What locations should you install the CPM?

A

Closest to the Target Systems, as it resembles user password change events. Better Performace.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What network conditions should you concider when installing the Vault Sever?

A

Never in a Domain
Seperate VLAN
No Thrid Party Software
Physical Servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Should the CPM and PSM be mebers of your Domain?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Durring Vault installation, there is the option to ‘NOT Harden the Server’, when would you use that?

A

Durring installing Vault into AWS, hardening would be after Vault install.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many Windows Services, after a Vault Install?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Vault server hardending is following which standard?

A

Microsoft Security Center Manager (SCM) *Validate This

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What port does the Remote Control Agent (on the Vault Server) communicate on?

A

Port: 9022

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What other service does the Remote Control Agent provide, hint auditing?

A

SMNP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What do you install on the Vault server, beore CyberArk?

A

HSM software (Hardware Security Module) to store the keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tool can you use to test Hardware Security Module communication?

A

nCipher *validate, many vendors possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How do you ENROLL the Vault in the HSM server?

A

Add Port 9004 to dbparm.ini to allow Hardware Security Module (HSM) in the FireWall rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

On Vault install, what 3 default Safes are created?

A

System, VaultInternal, Notification Engine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What Cyberark component MUST be installed directly after the Vault server?

A

PVWA

17
Q

What’s special about when the CPM communicates with the PVWA?

A

All communication is done through the Vault !!!

18
Q

Can the CPM component server be installed directly after the Vault install?

A

No, you need at least 1 PVWA server