chapter 2 Flashcards

1
Q

what is a user?

A

people, or applications, that have been granted access to the system in order to access passwords, manage policies. they are defined by their domain credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are accounts? Where are they stored?
what are some examples?

A

the actual privileged account and passwords, they are stored in safes. ex: domain admins, local admins, root accounts and services accounts, etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are internal users and groups in cyberark?
How are they added?

A

users and groups that are created automatically in the vault, users and groups that are added manually to the vault

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what are transparent users and groups in LDAP?

  1. How are the provisioned?
  2. What color is their icon?

What happens if you delete a transparent user?

A

users and groups that are automatically provisioned from an external directory.
1. provisioned automatically in the vault when they authenticate via ldap for the first time
2. these users and groups are marked with a white LDAP users or groups icon
3. if you delete a transparent user within cyberark, it will be automatically re-created upon login if it still exists within ad and answers the mapping criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the master user?

How is it accessed?

How many factors of authorization?

What are they?

A

most powerful user, with full safe and vault authorizations that cannot be removed
1. accessed only through the private ark client
3. has 3 factor authentication
a. master user password, defined during installation
b. access to the recovery private key, recprvkey
c. access only from the vault console and one additional ip address (emergency station IP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you change the master password?

A

login with the master user and click on user > set password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do you manually add?

A

private ark client interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what are the authorized instances available when manually adding a user

A

EVD
GUI
HTTPGW
NAPI
PACLI
PIMSU
PVWA
WINCLIENT
XAPI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what can you do in the user management module in the web portal administration view (pvwa)

A

create and edit cyberark users
create groups and assign users to them
disable a user or activate a suspended user
reset a user’s password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

the (blank) communicates with LDAP compliant directory servers to obtain user identification and security information.

What does this enable?

A

vault

This enables automatic provisioning and creation of unique users based upon the external group membership and attributes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what are the first steps to LDAP integration?

What do you enter in order to connect to an LDAP server?

What kind of account do you need?

A

define the domain using the wizard

enter the domain name
in order to connect to an LDAP server

provide credentials of a bind account to authenticate to LDAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what are the second steps to LDAP integration?

What links a LDAP group with one of the built in cyberark groups?

A

define default directory mappings

a directory map links an LDAP group with one of the built in cyberark groups and determines how user accounts are created in the vault and the roles they will have

you can edit these directory mappings later or create customer mappings according to your needs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

users are provisioned (blank) in the vault the first time they authenticate via LDAP, receiving roles and attributes based on the directory mapping that applies to them.

LDAP users and groups that have been created in the vault are with a (blank) LDAP user or groups icon

A

automatically

white

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

if you delete a user within cyberark, it will be automatically (blank) upon login if it still exists in AD

to block an LDAP user or group from cyberark, (blank) them from all LDAP groups with an associated directory mapping, or disable/delete them in the external directory

a (blank) process checks which users map to the various queries

A

re-created

remove

daily

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

the parameter AutoSyncExternalObjects in the (blank) file determines if, how often and when the vault’s external users and groups will be synchronized with the external directory

What does the parameter look like?

AutoSyncExternal objects = yes, 24, 1,5

Which means

yes - determines whether or not to sync with the external directory

24 - the number of hours in one period cycle

1,5 - the hours during which the sync will take place

A

dbparm.ini

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what are the 2 categories of authorizations in the system?

A

vault and safe

17
Q

what are vault authorizations?

A

can only be assigned only to users, not groups

cannot be inherited via group membership

can be defined via the private ark client or pvwa

18
Q

what are safe authorizations?

A

assigned to users and or groups

can be inherited via group membership

can be defined in the privateark client or pvwa

19
Q

predefined users are assigned different (blank) authorizations based on their role and functions

the built in (blank) user has full vault authorizations by default

A

vault

administrator

20
Q

what authorizations does the built in auditor user have by default?

A

audit users

21
Q

what authorizations does the built in backup user have by default?

A

backup all safes

22
Q

most predefined users and groups are added to all newly created (blank) based on their role and function

users in the auditors’ group are automatically added to all (blank) with permission to
(blank)
(blank)
(blank)

A

safes

safes

list accounts

view safe members

view audit log

23
Q

you can modify the list of groups that are added automatically to newly created safes is controlled by a parameter in the (blank)

A

dbparm.ini file

24
Q

the tabs and buttons available in the <blank> depend on the logged in user's membership in a cyberark built in group</blank>

members of the vault admins have access to the (blank) tab

A

PVWA

administration

25
what tab do members of auditors have?
privleged sessions
26
what tab to members of security admins and security operators have access to?
security pane
27
a directory map determines whether a user account or group will be created in a vault and the roles they will have, what are the 2 kinds of directory maps?
user mapping - allows for authentication and defines user attributes, such as vault authorizations and location group mapping - makes LDAP groups searchable from within cyberark, allowing mapped groups to be granted safe authorizations and to be nested within built in cyberark groups
28
what groups need to be created in LDAP for cyberark to work?
cyberark auditors cyberark safe managers cyber ark users cyberark vault admins
29
the LDAP integration wizard is used to map what four AD groups to the four predefined cyber ark roles?
vault admins safe managers auditors users
30
the (blank) mapping is applied to any user who is a member of the LDAP group cyberark vault admins LDAP users are provisioned in the vault with the appropriate authorizations the first time the users log in
vault admins
31
in addition to the predefined mappings, you can create (blank) directory mappings via a simplified wizard on the (blank)
custom PVWA
32