GUARD: CyberArk Guardian Practice Test — 58 Free Questions Online
QuestionQ1
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
That's the end of the preview
It's free
100% of the questions are free for all users. No strings attached.
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
At which stage is it appropriate to incorporate the C3 Alliance integrations?
ASince we already have integrations available and little development is required, they should all be completed in Stage 1.
BIntegrate the security tools in Stage 1 and other tools such as RPA in Stage 2.
CThey are less of a risk, so we should leave them until Stage 3 and focus on other privileged accounts first.
DThey should all be integrated prior to the actual ’go-live' of CyberArk PAM.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
0
Community Discussion
No comments yet. Be the first to start the discussion!
How can a Secondary PTA server be promoted to a Primary PTA Server?
AA manual procedure.
BAutomatically using the PTA Network Sensors.
CThis is not possible.
DAutomatically using a BASH script.
The customer currently has a Primary and DR vault. They have heard that another DR vault can be deployed for additional redundancy, so they order a physical server and rack and stack it in a Co-Iocation.
However, when installing the DR module on the new vault, the installation fails. What is the most likely cause?
ANone of the PVWAs can communicate with the new vault.
BThe customer does not have enough DR licenses.
CThe vault has not been hardened correctly.
DUnless the configuration is using the Distributed Vault architecture, you can only have 2 total vault servers.
Your customer has used CyberArk PAS for more than five years and has successfully onboarded over 35 local built-in administrator accounts.
A new CISO has assumed responsibility and wants to rapidly broaden privileged access management across the organization. Based on the use cases provided, prioritize them according to CyberArk's Blueprint methodology, from most critical first to least critical last.
Drag & Drop
Workstation built-in Administrators
Domain Administrators
Database Built-in Administrators
Server built-in Administrators
A new Vault is to be deployed in a highly regulated environment. Regulations require that every operating system on the network be updated regularly.
How does CyberArk recommend automatically updating hardened Vaults?
AUsing a dedicated WSUS server and install patches monthly.
DIntegrate the Vault with the domain for monthly updates.
QuestionQ6
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ8
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ9
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ10
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ11
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ12
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ13
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ14
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ15
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ16
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ17
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ18
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ19
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ20
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ21
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ22
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ23
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
QuestionQ24
No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which option listed below is an advanced Master Policy rule?
AAllow users to select a reason for access.
BAllow Manual Change.
CAllow Users to View Passwords.
DOnly Administrators can approve password access.
Which Secrets Manager component is recommended to be placed behind a load balancer for availability and redundancy?
AApplication Server Credential Provider
BCredential Provider
CCentral Credential Provider
DConjur Synchronizer
You want to be notified when a password is used. You configured NFNotifyOnPasswordUsed in the platform's Notification parameters.
Which two use cases result in the notification being sent?
Choose two
AWhen a user copies the password from the PVWA Ul.
BWhen the credential is first onboarded and assigned to the platform.
CWhen a user clicks 'Verify' to verify the password via the PVWA Ul.
DWhen user connects using PSM for SSH.
EWhen user logs on and clicks connect from the PVWA Ul.
The ‘LogRetention’ parameter in the DBParm.ini file specifies how long log records are retained.
When are the expired logs cleared?
AIt needs to be cleared manually.
BIt will not be cleared automatically. It will show warning.
CWhenever the Server is stopped.
DWhenever the Server is started.
In CyberArk Remote Access, match each persona to its job role:
Drag & Drop
Remote Access Administrator
Company Privileged Employee
3rd Party Vendor
Tenant Admin
The person who provisions access to PAS for 3rd party vendors or privileged employees.
An internal employee who can access company resources remotely through Remote Access.
A non-employee who can be provided remote access to company resources through Remote Access.
This is a company user who has permissions to manage Remote Access applications and invite vendors.
Communication is an integral component of any PAM program and includes these two elements.
Choose two
AGetting buy-in from leadership and communicating this from the first stakeholder meeting.
BAllowing each level to develop their own messaging so that we can build a specific message catered to each group's goals: leadership, management, different organizations, IT Administrators, etc..
CDeveloping a PAM sponsor to evangelize the project goals with the CTO and the entire technology organization.
D"One and Done" communication so we don't overwhelm users.
EDeveloping all training materials in Stage 2 of the program so that we can include 'lessons learned'.
In most cases, why should a failed CPM verification followed by a reconciliation action be considered a security incident?
AThe secret may have been changed outside of CyberArk and is compromised.
BThe secret is not configured for automatic reconciliation.
CThe CPM should not be performing automatic reconciliation actions.
DThe secret was rotated outside of an approved change-control window.
A customer has a large deployment that comprises 4 VAULTs, 6 PVWAs, 5 CPMs, and 6 PSMs. The support team has asked you to submit logs and configuration files for each component.
How would you obtain the files in the most efficient way?
AUse PAS Reporter to gather the logs and configuration files. Upload the PAS reporter database to the support ticket.
BUse CyberArk xRay.
CUse CyberArk zBang.
DGather the logs and configuration files from each server manually.
The following message appears in a log: PSMSV1230E: Vault files download completed with errors. Some of the files may be missing.
On which system would you most likely see this message?
APSM for SSH
BCPM
CPSM
DVault
A customer has a hybrid infrastructure that spans multiple cloud vendors and privately owned data centers. They deployed CyberArk PAM in AWS by using CyberArk-provided scripts. Eighty percent of the customer’s infrastructure is located in privately owned data centers. The customer is concerned about availability between the cloud provider and the data center. They are cloud-first and are gradually migrating their servers to the cloud.
Active Master Policy settings:
Require dual-control approval for password access
Enforce exclusive check-in/check-out access
Require password changes every 25 days
Require password verification every 7 days
What is the most appropriate recommendation for the customer?
AKeep the deployment as is in AWS.
BDeploy an active CPM to the privately owned Data Center.
CDeploy a separate infrastructure in another cloud vendor.
DMigrate the CPM to the privately owned Data Center.
When Dual Control is enabled for a platform in the Master Policy, exceptions may be configured in the following two locations.
Choose two
AExceptions can be configured in the safe permissions for specific users or groups.
BExceptions can be configured in the object level of individual vaulted accounts associated with that platform.
CExceptions can be configured for PSM connectivity at the platform level.
DExceptions can be configured for specific users or groups at the master policy level.
EExceptions can be configured in vault level permissions for specific users and groups.
What does a SCIM Server refer to?
ASecure for CyberArk Identity Manager.
BSystem for Cross Identity Management.
CSystem for CyberArk Identity Management.
DSecure Compute Information Manager.
Which type of approach is most important for driving the adoption and transformation of a successful Identity Security program?
ARisk based approach
BSecurity based approach
CTop-down approach
DBottom up approach
What are the three Guiding Principles of the CyberArk Blueprint?
ACredential Theft, Lateral and Vertical Movement, Privilege Escalation and Abuse.
BIdentity Security, Credential Theft, Lateral and Vertical Movement.
CAttack and Defend capability, Credential Theft, Least Privilege.
DQuick return on investment, Password Management, Credential Theft.
The organization wants to use a third-party account-discovery tool to add accounts to the Account Feed.
What is the preferred integration method?
AUse the Password Upload Utility (PUU) scripts to add the accounts to the Account Feed.
BConfigure the third party app or an intermediate script to use PACLI to add accounts objects to the PendingAccounts safe.
CConfigure the third party app or an intermediate script to use the "add discovered accounts" REST API method.
DConfigure the CACPMScanner.exe.config in the CPM folder to scan an additional data source.
The Active Directory manager asks you to temporarily enable Object Level Access Control (OLAC) on a Safe they own so they can control which users may use a particular Domain Admin account.
What OLAC limitation should you explain to them?
AOLAC does not enable granular control of which users can use a specific object.
BOnce enabled, object level access control cannot be disabled.
CWith object level access control enabled, PSM operations on the managed accounts are not supported.
DNew accounts cannot be added to the safe, once OLAC is enabled.
What is the greatest number of Conjur Standbys that can be deployed within an Auto-Failover cluster?
A3
B4
C5
D6
What is required for a Privilege Cloud Connector Server?
APublic Facing IP
BIIS Server 10
CIPv6 Address
DJoined to the domain
A customer must retain all privileged-access records for 7 years. The environment has approximately 2000 users who create nearly 100 GB of session recordings each day.
How should CyberArk PAS be designed to meet this requirement for PSM recordings?
ASet a low PSM Recording Retention period and use Secure Replicate to offload recordings for archival storage.
BConnect Vault servers to SAN storage and increase disk size whenever free disk space monitoring sends an alert.
CConnect external storage to PSM servers to more evenly distribute the storage requirements.
DSet Audit Retention Master Policy and PSMRecording Safe object retention to 2555 days (365 days * 7 years).
Community Discussion