QuestionQ15

No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify

A customer has a hybrid infrastructure that spans multiple cloud vendors and privately owned data centers. They deployed CyberArk PAM in AWS by using CyberArk-provided scripts. Eighty percent of the customer’s infrastructure is located in privately owned data centers. The customer is concerned about availability between the cloud provider and the data center. They are cloud-first and are gradually migrating their servers to the cloud.

Active Master Policy settings:

  • Require dual-control approval for password access
  • Enforce exclusive check-in/check-out access
  • Require password changes every 25 days
  • Require password verification every 7 days

What is the most appropriate recommendation for the customer?

Explanation

An active CPM in the privately owned data center can manage the large on-premises portion of the environment locally, including the required periodic password changes and verifications. Keeping the AWS CPM while adding this CPM provides resiliency and reduces reliance on potentially unavailable AWS-to-data-center connectivity during the cloud migration.

Community Discussion

No comments yet. Be the first to start the discussion!