About the Exam

CyberArk Defender EPM is the Defender certification track for CyberArk Endpoint Privilege Manager administrators. It validates theoretical and hands-on expertise in the daily maintenance and operation of the Identity Security Solution, and CyberArk says the EPM administration course prepares participants to implement the EPM solution. Passing demonstrates practical ability to run and maintain CyberArk EPM for endpoint security use cases.

Exam Topics

  • Local Administrator Rights Removal25%
  • Least Privilege Enforcement25%
  • Ransomware Protection25%
  • Policy Audit and Compliance25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 3, 2026 at 5:39 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Ransomware Protection

Which threat-intelligence source requires that the suspected file be sent externally?

Explanation

VirusTotal performs file analysis after the sample is uploaded to the VirusTotal service; its API accepts a file upload for analysis. Therefore, using it requires transmitting the suspect file externally. WildFire can also be deployed as an appliance, allowing local analysis. VirusTotal: Upload a file Palo Alto Networks: WildFire API Resources

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Ransomware Protection

An EPM Administrator wants to exclude an application from every Threat Protection module. Where should the EPM Administrator make this change?

Explanation

The Authorized Applications application group provides the centralized application exclusion mechanism for CyberArk EPM Threat Protection modules, allowing the specified application to be excluded across those protections.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Ransomware Protection

Which type of user can be created by the Threat Deception LSASS Credential Lures feature?

Explanation

CyberArk Endpoint Privilege Manager’s Privilege Deception capability places local administrator deceptive accounts in an endpoint attack path as credential lures, enabling detection when an attacker attempts to use those credentials.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Policy Audit and Compliance

Which policy-targeting options are available when creating a policy?

Explanation

CyberArk Endpoint Privilege Manager policies can target EPM Sets, computers in Active Directory security groups, Active Directory users, and Active Directory security groups.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Ransomware Protection

An end user is having performance problems on their device after the EPM Agent was installed on their machine. What should the EPM Administrator do first to help resolve the issue?

Explanation

Mutual exclusions prevent CyberArk EPM and third-party security software from repeatedly scanning or intercepting each other’s files and processes, which can impair endpoint performance. The appropriate initial remediation is to place the third-party security solution in EPM’s Files To Be Ignored Always configuration and exclude CyberArk EPM from the third-party solution.

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home