PAM-SEN Flashcards

1
Q

You are installing a CPM.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords and Manage Server File Categories, which Vault authorization(s) does a CyberArk user need to install the CPM?

A

B. Activate Users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In which configuration file do you add LoadBalancerClientAddressHeader when you enable x-forwarding on the PVWA loadbalancer?

A

B. web.config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

You are configuring SNMP remote monitoring for your organization’s Vault servers.
In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP traps?

A

A. SNMPHostIP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_Admin safes.
How do you set this in CyberArk?

A

A. In the CYBRWINDAD platform, under Automatic Password Management/General, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM.
Which file should you update to allow this to run?

A

A. PSMConfigureAppLocker.xml

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How should you configure PSM for SSH to support load balancing?

A

A. by using a network load balancer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?

A

A. PARAgent.ini

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A first PSM server has been installed.
What should you confirm before installing any additional PSM servers?

A

C. The user performing the installation is not a direct owner in the PSMUnmanagedSessionAccounts Safe.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

During the PSM installation process, Safes and a User are created.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords, and Activate Users, which authorization(s) does the Vault user installing the PSM need to enable them to be successfully created?

A

B. Manage Server File Categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Your customer wants to store the Safes Data on Vault Drive D instead of Drive C.
Which file should you edit?

A

A. TSparm.ini

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What must you do to prepare a Windows server for PVWA installation?

A

A. In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which statement about REST API is correct? (Choose two.)

A

A. When a user successfully authenticates to the Vault, an authentication token is returned.
D. Each REST API call requires that a valid authentication token be provided.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)

A

A. Red Hat Enterprise Linux 7.x
B. CentOS 7.x

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which utility should be used to register the Vault in Amazon Web Services?

A

A. CAVaultManager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

You are configuring the Vault to send syslog audit data to your organization’s SIEM solution.
What is a valid value for the SyslogServerProtocol parameter in DBPARM.INI file?

A

A. TLS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?

A

C. 6 - 1 primary and 5 satellite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence.

A
  1. Locate the CPM_Hardening.ps1 script in the installation media.
  2. Open Powershell as Administrator and run the script.
  3. Review these script logs: HardeningScript.log and CybrHardeningsecedit.log
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?

A

A. Add the FQDN & IP details for each LDAP host into the local hosts file of the Vault server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?

A

A. saml.config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

A customer is moving from an on-premises to a public cloud deployment.
What is the best and most cost-effective option to secure the server key?

A

C. Install the Vault using the native cloud images and secure the server key using native cloud Key Management Systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After setting the Authentication to SSH key and enabling MFA Caching from the PVWA interface, the Linux Team cannot connect successfully using the new MFA caching feature.
What is the most probable cause?

A

A. OpenSSH 7.8 or above is not installed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

You want to add an additional maintenance user on the PSM for SSH.
How can you accomplish this if InstallCyberarkSSHD is set to Yes or No?

A

B. Create a local user called proxymng<number>.</number>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which service must be set to Automatic (delayed start) after the Vault is installed and configured?

A

A. Windows Time service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation?

A

D. 1.1.1.1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

CyberArk User Neil is trying to connect to the Target Linux server 192.168.1.164 using a domain account ACME/linuxuser01 on domain acme.corp using PSM for SSH server 192.168.65.145.
What is the correct syntax?

A

C. ssh neil@linuxuser01@192.168.1.164@192.168.65.145

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?

A

A. retention period

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Which components can connect to a satellite Vault in a distributed Vault architecture?

A

B. PVWA, PSM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer.
Which additional packages do you need to install to meet the customer’s needs? (Choose two.)

A

A. CARKpsmp-infra
B. libssh

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which component should be installed on the Vault if Distributed Vaults are used with PSM?

A

A. RabbitMQ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is the default username for the PSM for SSH maintenance user when InstallCyberarkSSHD is set to yes?

A

A. proxymng

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?

A

C. IdP “Audience” and “ServiceProviderName” in the PVWA saml.config file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The current PAM solution is:
2 distributed Vaults, the primary one in New York and a satellite in Tokyo
2 PVWA servers, both in New York with load balancing configured
2 PSM servers, both in New York without load balancing configured
1 CPM server in New York
All PVWA, PSM, and CPM servers are connected to the primary Vault
Which proposal optimally resolves the performance issue while minimizing the impact to production?

A

A. Install two new PVWA servers in Tokyo data center, configure load balancing, connect to the local satellite Vault and provide the URL of new PVWA servers to the local employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

You have been asked to limit a platform called “Windows_Servers” to safes called “WindowsDC1” and “WindowsDC2”. The platform must not be assigned to any other safe.
What is the correct way to accomplish this?

A

A. Edit the “Windows_Servers” platform, expand “Automatic Password Management”, then select General and modify “AllowedSafes” to be (WindowsDC1)|(WindowsDC2).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

The account used to install a PVWA must have ownership of which safes? (Choose two.)

A

A. VaultInternal
D. Notification Engine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

DRAG DROP -
Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence.

A

PVWAPrerequisites.ps1 script, PVWAInstallation.ps1 script, PVWARegisterComponents.ps1 script then PVWA_Hardening.ps1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Which configuration file and Vault utility are used to migrate the server key to an HSM?

A

A. DBparm.ini and CAVaultManager.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

There is a requirement for a password to change between 01:00 and 03:00 on Saturdays and Sundays; however, this does not work consistently.
Which platform setting may be the cause?

A

C. The DaysToRun setting for the platform is incorrect and must be set to Sat,Sun.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What must you do to synchronize a new Vault server with an organization’s NTP server?

A

A. Configure an AllowNonStandardFWAddresses rule for the organization’s NTP server in DBParm.ini on the Vault server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

You need to add a new PSM server to an existing CyberArk environment.
What is the best way to determine the sizing of this server?

A

A. Review the “Recommended Server Specifications” for PSMs in the CyberArk Documents website.

40
Q

Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?

A

C. psmpparms

41
Q

When integrating a Vault with HSM, which file is uploaded to the HSM device?

A

A. server.key

42
Q

What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?

A

B. In the RADIUS server, define the CyberArk Vault as a RADIUS client/agent.

43
Q

A customer wants to store PSM recordings for 100 days and estimates they will have 10 Windows sessions per day for 100 minutes each.
What is the minimum storage required for the Vault and PAReplicate for the PSM recordings?

A

B. 250 GB

44
Q

In large-scale environments, it is important to enable the CPM to focus its search operations on specific Safes instead of scanning all Safes it sees in the Vault.
How is this accomplished?

A

B. AllowedSafe Parameter on each platform policy

45
Q

In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA_Hardening.ps1 perform when run? (Choose two.)

A

A. performs IIS hardening
E. imports the CyberArk INF configuration

46
Q

When SAML authentication is used to sign in to the PVWA, which service performs the actual authentication?

A

B. Identity Provider (IdP)

47
Q

Which components support load balancing? (Choose two.)

A

B. PVWA
C. PSM

48
Q

Which method can be used to directly authenticate users to PSM for SSH? (Choose three.)

A

A. CyberArk authentication
B. LDAP authentication
C. RADIUS authentication

49
Q

You are designing the number of PVWAs a customer must deploy. The customer has three data centers with a distributed Vault in each, requires high availability, and wants to use all Vaults at all times.
How many PVWAs does the customer need?

A

A. six or more

50
Q

After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.2.2.2.
What should you do?

A

A. Edit DBParm.ini to add: AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2],Yes,123:outbound/udp.

51
Q

Which command should be executed to harden a Vault after registering it to Azure?

A

A. HardenAzureFW.ps1

52
Q

Which files does the Vault Installation Wizard prompt you for during the Vault install?

A

A. Operator CD and License

53
Q

Which statement is correct about a post-install hardening?

A

C. It is executed after Vault installation by running CAVaultHarden.exe and hardening options can be edited by changing the Hardening.ini file.

54
Q

As a member of a PAM Level-2 support team, you are troubleshooting an issue related to load balancing four PVWA servers at two data centers. You received a note from your Level-1 support team stating “When testing PVWA website from a workstation, we noticed that the “Source IP of last sign-in” was shown as the VIP (Virtual IP address) assigned to the four PVWA servers instead of the workstation IP where the PVWA site was launched from.”
Which step should you take?

A

A. Verify the “LoadBalancerClientAddressHeader” parameter setting in PVWA configuration file Web.config is set to “X-Forwarded-For”.

55
Q

You are installing the HTML5 gateway on a Linux host using the RPM provided.
After installing the Tomcat webapp, what is the next step in the installation process?

A

A. Deploy the HTML5 service (guacd).

56
Q

What is required before the first CPM can be installed?

A

A. The environment must have at least one Vault and one PVWA installed.

57
Q

When configuring RADIUS authentication, which utility is used to create a file containing an encrypted version of the RADIUS secret?

A

A. CAVaultManager

58
Q

What is the purpose of the CPM_Preinstallation.ps1 script included with the CPM installation package?

A

D. It verifies the NET version installed on the server and sets the IIS SSL TLS server configuration.

59
Q

Which tools are used during a CPM renaming process? (Choose two.)

A

A. APIKeyManager Utility
B. CreateCredFile Utility

60
Q

When performing “In Domain” hardening of a PSM server, which steps must be performed? (Choose two.)

A

A. Import CyberArk policy settings from the provided file into a new GPO.
C. Link GPO to a dedicated OU containing CyberArk PSM servers.

61
Q

Which step is required to register a Vault manually in Amazon Web Services using CAVaultManager?

A

C. Specify the Cloud region using the /CloudRegion flag

62
Q

What authentication methods can be implemented to enforce Two-Factor Authentication (2FA) for users authenticating to CyberArk using both the PVWA (through the browser) and the PrivateArk Client?

A

A. LDAP and RADIUS

63
Q

Which pre-requisite step must be completed before installing a Vault?

A

B. Install a clean operating system.

64
Q

Which browser is supported for PSM Web Connectors developed using the CyberArk Plugin Generator Utility (PGU)?

A

B. Google Chrome

65
Q

What is a valid combination of primary and secondary layers of authentication to a company’s two-factor authentication policy?

A

A. RSA SecurID Authentication (in PVWA) and LDAP Authentication

66
Q

You want to add an additional maintenance user on the PSM for SSH.

A

C. Create a local user and add it to group configured for the parameter AllowGroups in the /etc/sshd_config file.

67
Q

Which authentication methods does PSM for SSH support?

A

D. CyberArk Password, LDAP, RADIUS

68
Q

Which statement is correct about CPM behavior in a distributed Vault environment?

A

A. CPMs should only access the primary Vault. When it is unavailable, CPM cannot access any Vault until another Vault is promoted as the new primary Vault.

69
Q

What is the purpose of the PSM health check hardening?

A

A. Remove IIS settings which can be considered security vulnerabilities.

70
Q

A customer’s environment has three data centers consisting of 5,000 servers in Germany, 10,000 servers in Canada, and 1,500 servers in Singapore. You want to manage target servers and avoid complex firewall rules. How many CPMs should you deploy?

A

D. 6 total, 2 per data center

71
Q

What is a step to enable NTP synchronization on a stand-alone Vault?

A

C. Edit dbparm.ini and add a Firewall rule for the NTP address.

72
Q

What are the basic network requirements to deploy a CPM server?

A

A. Port 1858 to Vault and Port 443 to PVWA

73
Q

You want to change the name of the PVWAappuser of the second PVWA server.

A

D. Rename user in PrivateArk
E. Create new cred file for user

74
Q

Which statements are correct about the PSM HTML5 gateway? (Choose two.)

A

B. It does not support connections to target system where NLA is enabled on the PSM server
D. Printer redirection cannot be enabled

75
Q

A customer has five PVWA servers. Three are located at the primary data center and the remaining two are at a satellite data center.

What is important to consider about the load balancer? (Choose two.)

A

A. It must not alter page content, or should include a mechanism to prevent pages from being altered.
B. It must support “sticky sessions”.

76
Q

A new domain controller has been added to your domain. You need to ensure the CyberArk infrastructure can use the new domain controller for authentication.

Which locations must you update?

A

A. on the Vault server in C:\Windows\System32\drivers\etc\hosts and in the PVWAApplication under Administration > LDAP Integration > Directories > Hosts

77
Q

You are beginning the post-install process after a manual PSM installation is completed.

What must you do?

A

A. Disable screen saver for the PSM local users.

78
Q

As Vault Admin, you have been asked to enable your organization’s CyberArk users to authenticate using LDAP.

In addition to Audit Users, which permission do you need to complete this task?

A

B. Manage Directory Mapping

79
Q

Which user is enabled when replicating data between active and stand-by Vaults?

A

A. DR

80
Q

This value needs to be added to the PVWA configuration file:

Assuming all CyberArk PVWA servers were installed using default paths/folders, which configuration file should you locate and edit to accomplish this?

A

A. c:\inetpub\wwwroot\passwordvault\web.config

81
Q

A customer has five main data centers with one PVWA in each center under different URLs.

How can you make this setup fault tolerant?

A

D. Load balance all PVWAs under same URL.

82
Q

What is the recommended method to determine if a PVWA is unavailable and should be disabled in a load balancing pool?

A

A. Monitor Port 443 on the PVWA server

83
Q

For redundancy, you want to add a secondary RADIUS server.

What must you do to accomplish this?

A

C. Open the DBParm.ini on the Vault server. Add the second RADIUS server configuration settings after the first one, separated by a comma.

84
Q

Which parameter must be provided when registering a primary Vault in Azure, but not in Amazon Web Services?

A

D. /RDPGateway

85
Q

Which component must be installed before the first CPM installation?

A

C. PVWA

86
Q

You are setting up a Linux host to act as an HTML 5 gateway for PSM sessions.

Which servers need to be trusted by the Linux host to secure communications through the gateway?

A

A. PSM and PVWA

87
Q

What is a requirement for setting fault tolerance for PSMs?

A

A. Use a load balancer

88
Q

A customer asked you to help scope the company’s PSM deployment.

What should be included in the scoping conversation?

A

C. Recordings retention period

89
Q

A customer has three data centers distributed globally and wants highly-available PSM connections in each segmented zone. In addition, the customer needs a highly-available PSM connection for the CyberArk Admins.

What will best satisfy this customer’s needs?

A

C. two PSMs per zone with a load balancer and two PSMs for Admins with a dedicated load balancer

90
Q

The installCyberArkSSHD parameter on the PSM for SSH can be set to multiple values.

Match each value to the correct condition.

A

Yes - Override the local SSHD service with a CyberArk customized SSHD service to benefit from full PSM for SSH functionality.
No - Do not install the CyberArk SSHD service. Significant functional limitations apply.
Integrated - The local SSHD service is configured to work through the PAM (Pluggable Authentication Module), which is deployed as part of the PSM for SSH installation. This is the default value.

91
Q

A customer has two data centers and requires a single PVWA url.

Which deployment provides the fastest time to reach the PVWA and the most redundancy?

A

A. Deploy two PVWAs behind a global traffic manager.

92
Q

What is determined by the “MaxConcurrentConnections” setting within a platform?

A

A. maximum number of concurrent connections that can be opened between the CPM and the remote machines for the platform

93
Q

If a customer has one data center and requires fault tolerance, how many PVWAs should be deployed?

A

A. two or more

94
Q

You are installing multiple PVWAs behind a load balancer.

Which statement is correct?

A

C. The load balancer must support “sticky sessions”.

95
Q

What is a prerequisite step before installing the Vault on Windows 2019?

A

B. Check that the server IP address is correctly configured and that it is static

96
Q

After installing the first PSM server and before installing additional PSM servers, you must ensure the user performing the installation is not a direct owner of which safe?

A

A. PSMUnmanagedSessionAccounts Safe

97
Q

A. PSMUnmanagedSessionAccounts Safe

A
  1. Validate that the Primary CPM’s services are stopped and set to manual.
  2. On the DR CPM, confirm details in the Vault.ini configuration file, reset the password to the CPM user, and recreate the credential file.
  3. Enable the CPM services on the DR CPM.
  4. Review logs to confirm the DR CPM services are running as expected.