chparter 15 Flashcards
vault backup solution
the safes in the vault are stored in the (blank) sub-directory
information about users, network areas, safes, log records, and all activities that occur between them is stored in a database. Database files are stored in the (blank) sub-directory
these 2 folders are extremely important and it is imperative to back them up regularly
the cyberark vault enables you to backup and restore a single safe to a vault, as well as a complete vault’s data and metadata
Data
Metadata
backup considerations
vault backup can be implemented in two ways:
(blank) backup (not recommended) - third party backup software is installed on the vault and the application has access to the backup folders. this introduces an external application to the vault and potentially reduces the level of security
(blank) backup (recommended) - the privateark replicate utility is installed on another server on the network, typically a server hosting another cyberark PAM component
The replicate utility pulls vault data as encrypted files to the server. Enterprise backup software can them backup these files
direct
indirect
before installing the replicator utility
make sure the backup server has the following features and capabilities
at least the same disk space as the vault database on an NTFS volume
Accessibility by your enterprise backup system
Physical security that only permits authorized users to access it
Set the password on the primary (blank)
vault
install the utility
install the replicator module and specify
a path to a backup folder for the replicated data
blank
replicator configuration
edit the (blank) file to give the replicator utility the network address of the vault server
vault.ini
the (blank) file is used by the replicator utility to authenticate to the vault and should be hardened.
The password for the (blank) user is changed in the vault and the credential file is updated after every successful login
credential
backup
the backup is launched at a command line using the (blank) executable file.
The syntax of the command:
(blank) vault.ini /logonfromfile user.ini /fullbackup
specifies the vault.ini file and uses the logonfromfile and fullbackup switches
PAReplicate
PAReplicate
the (blank) command enables you to restore safes that have previously been backed up.
Only users with the (blank) authorization in the vault can restore a safe
PARestore
Restore All Safes
(blank) can be used to launch backups at predetermined intervals
c:\program files (x86)\privateark\replicate\pareplicate.exe vault.ini /logonfromfile user.cred /fullbackup
scheduled tasks
you should create (blank) scheduled tasks
one full backup running every week
a daily incremental backup
logs cab be found in the root of the (blank) folder
2
replicate