chapter 3 Flashcards

1
Q

the (blank) enables an organization to define a baseline for managing accounts in the organization

it is used for managing global policy settings

exceptions to the (blank) rules allow sets of accounts to vary from the policy rule

A

master policy

master policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the 5 rules of the privileged access workflows for the master policy

A

dual control

exclusive passwords

one-time passwords

allow transparent connections

require reason for access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what are the 2 rules of the password management rules for the master policy

A

require password change every x days

require password verification every x days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what are the 2 rules of the session management rules

A

require privileged session monitoring and isolation

record and save session activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what is the rule of the audit policy

A

activities and retention period

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is a platform?

A

technical settings for managing passwords and connecting to target systems, basis for exceptions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the 2 types of platforms?

A

targets

dependents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what does the target platform do?

A

define the technical settings that determine how the system manages accounts on different types of servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what does the dependents platform do?

A

also known as usages, define additional services accounts such as windows services or scheduled tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what are the three main functions of platforms?

A

define the technical settings required to manage passwords - password policy settings such as minimum length, forbidden characters and so on

point to the relevant plug-ins and connection components - how you login and change a password on a unix server is very different than how you do the same things on a windows server. different plug-ins must be used for different target systems

the basis for exceptions to the master policy - exceptions can be made to the master policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

where is the option for platform management?

A

under the administration tab in the pvwa

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what are some of the default platforms?

A

windows
*nix
cloud services
database
security applications
network device
application
directory
website
operating system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

how do you create a new platform when accounts of the same system type require different policies?

A

duplicate command under … menu

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

when duplicating platforms, use a logical naming convention, and make the name unique. what would be a good platform name for linux accounts using a SSH connection with passwords that are rotated every 30 days

A

LIN SSH 30

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

select (blank) to modify the platform settings under the … menu

A

edit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

platforms are divided into 2 broad sections, (blank) and (blank). the settings for managing passwords can be found in the automatic password management section

A

UI and Workflows

Automatic password management

17
Q

in the create platform screen, under automatic password management, the (blank) section controls the password creation policy
1. length,
2. complexity
3. forbidden characters

A

generate password

18
Q

why would you deactivate platforms that are not currently relevant to you implementation

A

better administration - inactive platforms are hidden from users when they add accounts

better performance - the cpm does not need to manage inactive platforms

19
Q

if you have a system that is not supported by one of the default platforms, you can either create a new one or import one from the (blank)

A

cyberark marketplace

20
Q

when you need to have different settings than is provided by the master policy, you will create (blank) to the master policy by platform

A

exceptions

21
Q

in the (blank) page, we can view the password management policies that are applied to the different platforms

A

platform management