PAM-SEN Flashcards
You are installing a CPM.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords and Manage Server File Categories, which Vault authorization(s) does a CyberArk user need to install the CPM?
B. Activate Users
In which configuration file do you add LoadBalancerClientAddressHeader when you enable x-forwarding on the PVWA loadbalancer?
B. web.config
You are configuring SNMP remote monitoring for your organization’s Vault servers.
In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP traps?
A. SNMPHostIP
You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_Admin safes.
How do you set this in CyberArk?
A. In the CYBRWINDAD platform, under Automatic Password Management/General, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).
Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM.
Which file should you update to allow this to run?
A. PSMConfigureAppLocker.xml
How should you configure PSM for SSH to support load balancing?
A. by using a network load balancer
In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?
A. PARAgent.ini
A first PSM server has been installed.
What should you confirm before installing any additional PSM servers?
C. The user performing the installation is not a direct owner in the PSMUnmanagedSessionAccounts Safe.
During the PSM installation process, Safes and a User are created.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords, and Activate Users, which authorization(s) does the Vault user installing the PSM need to enable them to be successfully created?
B. Manage Server File Categories
Your customer wants to store the Safes Data on Vault Drive D instead of Drive C.
Which file should you edit?
A. TSparm.ini
What must you do to prepare a Windows server for PVWA installation?
A. In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell.
Which statement about REST API is correct? (Choose two.)
A. When a user successfully authenticates to the Vault, an authentication token is returned.
D. Each REST API call requires that a valid authentication token be provided.
HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)
A. Red Hat Enterprise Linux 7.x
B. CentOS 7.x
Which utility should be used to register the Vault in Amazon Web Services?
A. CAVaultManager
You are configuring the Vault to send syslog audit data to your organization’s SIEM solution.
What is a valid value for the SyslogServerProtocol parameter in DBPARM.INI file?
A. TLS
When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
C. 6 - 1 primary and 5 satellite
Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence.
- Locate the CPM_Hardening.ps1 script in the installation media.
- Open Powershell as Administrator and run the script.
- Review these script logs: HardeningScript.log and CybrHardeningsecedit.log
To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?
A. Add the FQDN & IP details for each LDAP host into the local hosts file of the Vault server.
In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?
A. saml.config
A customer is moving from an on-premises to a public cloud deployment.
What is the best and most cost-effective option to secure the server key?
C. Install the Vault using the native cloud images and secure the server key using native cloud Key Management Systems.
Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After setting the Authentication to SSH key and enabling MFA Caching from the PVWA interface, the Linux Team cannot connect successfully using the new MFA caching feature.
What is the most probable cause?
A. OpenSSH 7.8 or above is not installed.
You want to add an additional maintenance user on the PSM for SSH.
How can you accomplish this if InstallCyberarkSSHD is set to Yes or No?
B. Create a local user called proxymng<number>.</number>
Which service must be set to Automatic (delayed start) after the Vault is installed and configured?
A. Windows Time service
Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation?
D. 1.1.1.1
CyberArk User Neil is trying to connect to the Target Linux server 192.168.1.164 using a domain account ACME/linuxuser01 on domain acme.corp using PSM for SSH server 192.168.65.145.
What is the correct syntax?
C. ssh neil@linuxuser01@192.168.1.164@192.168.65.145
In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?
A. retention period
Which components can connect to a satellite Vault in a distributed Vault architecture?
B. PVWA, PSM
You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer.
Which additional packages do you need to install to meet the customer’s needs? (Choose two.)
A. CARKpsmp-infra
B. libssh
Which component should be installed on the Vault if Distributed Vaults are used with PSM?
A. RabbitMQ
What is the default username for the PSM for SSH maintenance user when InstallCyberarkSSHD is set to yes?
A. proxymng
Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?
C. IdP “Audience” and “ServiceProviderName” in the PVWA saml.config file
All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The current PAM solution is:
2 distributed Vaults, the primary one in New York and a satellite in Tokyo
2 PVWA servers, both in New York with load balancing configured
2 PSM servers, both in New York without load balancing configured
1 CPM server in New York
All PVWA, PSM, and CPM servers are connected to the primary Vault
Which proposal optimally resolves the performance issue while minimizing the impact to production?
A. Install two new PVWA servers in Tokyo data center, configure load balancing, connect to the local satellite Vault and provide the URL of new PVWA servers to the local employees.
You have been asked to limit a platform called “Windows_Servers” to safes called “WindowsDC1” and “WindowsDC2”. The platform must not be assigned to any other safe.
What is the correct way to accomplish this?
A. Edit the “Windows_Servers” platform, expand “Automatic Password Management”, then select General and modify “AllowedSafes” to be (WindowsDC1)|(WindowsDC2).
The account used to install a PVWA must have ownership of which safes? (Choose two.)
A. VaultInternal
D. Notification Engine
DRAG DROP -
Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence.
PVWAPrerequisites.ps1 script, PVWAInstallation.ps1 script, PVWARegisterComponents.ps1 script then PVWA_Hardening.ps1
Which configuration file and Vault utility are used to migrate the server key to an HSM?
A. DBparm.ini and CAVaultManager.exe
There is a requirement for a password to change between 01:00 and 03:00 on Saturdays and Sundays; however, this does not work consistently.
Which platform setting may be the cause?
C. The DaysToRun setting for the platform is incorrect and must be set to Sat,Sun.
What must you do to synchronize a new Vault server with an organization’s NTP server?
A. Configure an AllowNonStandardFWAddresses rule for the organization’s NTP server in DBParm.ini on the Vault server.