PAM-SEN V2 Flashcards
After a PSM session is complete, the PSM server uploads the recording to the Vault for long-term
storage.
A. TRUE
By default, the vault secure protocol uses which IP port and protocol.
A. TCP/1858
What is the best practice for storing the Master CD?
C. Store the CD in a secure location, such as a physical safe.
What utility is used to create or update a credential file?
A. CreateCredFile.exe
You are successfully managing passwords in the alpha.cyberark.com domain; however, when you
attempt to manage a password in the beta.cyberark.com domain, you receive the ‘network path not
found’ error. What should you check first?
B. That the CPM can successfully resolve addresses in the beta.cyberark.com domain.
What is the name of the account used to establish the initial RDP session from the end user client
machine to the PSM server?
A. PSMConnect
To apply a new license file you must:
A. Upload the license.xml file to the System Safe.
At what point is a transparent user provisioned in the vault?
C. The first time the user logs in.
Which of the following are supported authentication methods for CyberArk? Check all that apply.
A. CyberArk Password (SRP)
B. LDAP
C. SAML
D. PKI
E. RADIUS
F. OracleSSO
The security of the Vault Server is entirely dependent on the security of the network.
B. FALSE
What would be a good use case for the Disaster Recovery module?
C. Off site replication is required.
Which of the correct order of installation for PAS components?
A. Vault, CPM, PVWA, PSM
The RemoteApp feature of PSM allows seamless Application windows (i.e the Desktop of the PSM
server will not be visible.)
A. TRUE
Does CyberArk need service accounts on each server to change passwords?
D. No, the CPM uses the account information stored in the vault to login and change the account’s
password using its own credentials.
Which of the following protocols need to be installed on a standalone vault server? Check all that apply.
D. Internet Protocol version 4 (TCP/IPv4)
Which of the following are prerequisites for installing PVWA.
A. Web Services Role
In order to retrieve data from the vault a user MUST use an interface provided by CyberArk.
A. TRUE
Name two ways of viewing the ITAlog:
A. Log into the vault locally and navigate to the Server folder under the PrivateArk install location.
C. Access the System Safe from the PrivateArk client.
Which CyberArk component changes passwords on Target Devices?
B. CPM
In an SMTP integration it is possible to use the fully-qualified domain name (FQDN) when specifying theSMTP server address(es).
B. FALSE
The PrivateArk clients allows a user to view the contents of the vault like a filesystem.
A. TRUE
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? Choose all that apply.
A. Store the CD in a physical safe and mount the CD every time vault maintenance is performed
C. Copy the contents of the CD to a folder on the vault server and secure it with NTFS permissions.
D. Store the server key in a Hardware Security Module.
The Remote Desktop Services role must be properly licensed by Microsoft.
A. TRUE
Which file would you modify to configure your Vault Server to forward Activity Logs to a SIEM or
SYSLOG server?
A. dbparm.ini
Which keys are required to be present in order to start the PrivateArk Server Service?
A. Server Key
You are installing a CPM.
In addition to Add Safes, Add/Update Users, Reset Users?Passwords and Manage Server File
Categories, which Vault authorization(s) does a CyberArk user need to install the CPM?
B. Activate Users
You are configuring SNMP remote monitoring for your organization?s Vault servers.
In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP traps?
A. SNMPHostIP
In which configuration file do you add LoadBalancerClientAddressHeader when you enable x-forwardingon the PVWA loadbalancer?
B. web.config
You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform toonly the WINDEMEA and WINDEMEA_Admin safes. How do you set this in CyberArk?
A. In the CYBRWINDAD platform, under Automatic Password Management/General, configure
AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).
Before the hardening process, your customer identified a PSM Universal Connector executable that will
be required to run on the PSM. Which file should you update to allow this to run?
A. PSMConfigureAppLocker.xml
How should you configure PSM for SSH to support load balancing?
A. by using a network load balancer
In which configuration file on the Vault can filters be configured to either include or exclude log
messages that are sent through SNMP?
A. PARAgent.ini
A first PSM server has been installed. What should you confirm before installing any additional PSM servers?
C. The user performing the installation is not a direct owner in the PSMUnmanagedSessionAccounts
Safe
During the PSM installation process, Safes and a User are created.
In addition to Add Safes, Add/Update Users, Reset Users?Passwords, and Activate Users, which
authorization(s) does the Vault user installing the PSM need to enable them to be successfully created?
B. Manage Server File Categories
Your customer wants to store the Safes Data on Vault Drive D instead of Drive C. Which file should you edit?
A. TSparm.ini
What must you do to prepare a Windows server for PVWA installation?
A. In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in
Powershell.
Which statement about REST API is correct? (Choose two.)
A. When a user successfully authenticates to the Vault, an authentication token is returned.
D. Each REST API call requires that a valid authentication token be provided.
HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)
A. Red Hat Enterprise Linux 7.x
B. CentOS 7.x
C. Ubuntu 20.x
Which utility should be used to register the Vault in Amazon Web Services?
A. CAVaultManager
You are configuring the Vault to send syslog audit data to your organization?s SIEM solution. What is a valid value for the SyslogServerProtocol parameter in DBPARM.INI file?
A. TLS
When creating a distributed Vault environment architecture, what is the maximum number of Vault
servers that can be deployed?
C. 6 - 1 primary and 5 satellite
Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence
2 - a. Open Powershell as Administrator and run the script
3 - b. Review these script logs: HardeniningScript.log and CYBRHardeningsecedit.log.
1 - c. Locate the CPM_Hardening.ps1 script in the installation media.
To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?
A. Add the FQDN & IP details for each LDAP host into the local hosts file of the Vault server.
In which file must the attribute ?SignAuthnRequest=?true??be added to the PartnerIdentityProvider
element to support signed SAML requests?
A. saml.config
A customer is moving from an on-premises to a public cloud deployment. What is the best and most cost-effective option to secure the server key?
C. Install the Vault using the native cloud images and secure the server key using native cloud Key
Management Systems.
Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching
feature. The PSM for SSH was installed with default configuration settings. After setting the
Authentication to SSH key and enabling MFA Caching from the PVWA interface, the Linux Team cannot
connect successfully using the new MFA caching feature. What is the most probable cause?
A. OpenSSH 7.8 or above is not installed.
Which service must be set to Automatic (delayed start) after the Vault is installed and configured?
A. Windows Time service
You want to add an additional maintenance user on the PSM for SSH.
How can you accomplish this if InstallCyberarkSSHD is set to Yes or No?
B. Create a local user called proxymng<number>.</number>