chapter 5 Flashcards

1
Q

(blank) are actual privileged account ids and passwords

stored in (blank)

examples include:
domain admins
local admins
root accounts
service accounts

every account is associates with a single (blank)

A

accounts

safes

target account platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

how to add a linux account

  1. from account view select add account
  2. on the select system type choose (blank)
A

*NIX

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what are the steps in adding a linux account?
1
2
3
4

A
  1. select system type
  2. assign to a platform
  3. store in safe
  4. define properties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what does creating an account do?

A

It does not create an account on the target system, it registers information in the cyberark pam database about the created account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

the (blank) manages passwords and ssh keys on devices based on the polices set by the vault admins

A

central policy manager or CPM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what are the 3 actions performed by the cpm in order to manage privileged accounts
1
2
3

A

password verification - confirms the password stored in the vault matches the password on the target system

password change - changes the password automatically based upon an expiration period or by user intervention

reconciliation of unknow or lost passwords - process used when the password stored in the vault does not match the target system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the steps in the verify process?

cpm scans vault for account

vault sends account info and current passwords to cpm

cpm sends the login to the target system

target systems sends a success or failure message to the cpm

the cpm then notifies the vault of the success or failure

[none]

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

how is the password changed?

cpm scans vault for account

vault sends account info and current password to cpm

cpm uses credentials to login into target device

target sends cpm success or failure message

cpm generates password

cpm connects to target device and changes password

target sends back success or failure message

cpm logs into target with new credentials

target send success or failure to the cpm

cpm sends new password to vault for storage

A

blank

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly