QuestionQ33

No official GUARD exam topic/domain breakdown or percentage weightings were publicly available on CyberArk’s official certification pages I could verify

You deployed your Primary Vault on a CyberArk-supported cloud platform by using a CyberArk-provided image, and deployed a DR Vault in a privately owned data center.

What is the best method for securing the Server Key on the DR Vault?

Explanation

An on-premises DR Vault should protect its Server Key with an HSM. The HSM keeps the cryptographic key in dedicated, tamper-resistant hardware and can perform key operations without exposing the key material to the Vault host. Cloud KMS or Azure Key Vault choices are tied to supported cloud-provider integrations, whereas the DR Vault is located in a privately owned data center.

Community Discussion

No comments yet. Be the first to start the discussion!