Deploy and configure CyberArk’s Identity Security solution
When running a “Privileged Accounts inventory” report from the Reports page in PVWA for a specific safe, which permission(s) are required on that safe to display complete account inventory information?
AList Accounts, View Safe Members
BManage Safe Owners
CList Accounts, Access Safe without confirmation
DManage Safe, View Audit
0
Community Discussion
No comments yet. Be the first to start the discussion!
Deploy and configure CyberArk’s Identity Security solution
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Prior to the hardening process, your customer identified a PSM Universal Connector executable that must run on the PSM. Which file should be updated to permit it to run?
APSMConfigureAppLocker.xml
BPSMHardening.xml
CPSMAppConfig.xml
DPSMConfigureHardening.xml
As Vault Admin, you have been asked to set up LDAP authentication for your organization’s CyberArk users. Which permissions are required to complete this task?
AAudit Users and Add Network Areas
BAudit Users and Manage Directory Mapping
CAudit Users and Add/Update Users
DAudit Users and Activate Users
Arrange the steps for completing CPM Hardening for an Out-of-Domain Deployment in the correct order.
Drag & Drop
Open Powershell as Administrator and run the script
Review the script log called HardeningScript log
Locate the CPM_Hardening.ps1 script in the installation media
Review the script log called CYBRHardeningsecedit.log
For each listed prerequisite, identify whether it is mandatory or not mandatory for running the PSM Health Check.
Drag & Drop
Mandatory
Not Mandatory
PSM service installed on Windows 2008 R2, Windows 2012 R2, or Windows 2016
PSM service installed on Windows 2012 R2, Windows 2016, or Windows 2019
A valid SSL certificate is installed on the Web Server
Web Server (IIS 8.5) role is installed
What is required for a PVWA installation?
AA DNS entry for the PVWA url must be created.
BA company-signed TLS certificate must be imported into the server.
CA Vault Administrative User must be used to register the PVWA.
DData Execution Prevention must be disabled.
In a PTA rule that uses Privileged Session Analysis and Response, which session options can be configured as responses to activities?
ASuspend, Terminate, None
BSuspend, Terminate, Lock Account
CPause, Terminate, None
DSuspend, Terminate
Besides disabling Windows services or features that PVWA operations do not require, which tasks does PVWA_Hardening.ps1 carry out when it runs?
Aperforms IIS hardening; imports the CyberArk INF configuration
Bperforms IIS hardening; configures all group policy settings
Cperforms IIS hardening; renames the local Administrator Account
Dconfigures Windows Firewall; removes all installation files
A customer operates two data centers and requires a single PVWA URL.
Which deployment delivers the fastest access to the PVWA and the greatest redundancy?
ADeploy two PVWAs behind a global traffic manager.
BDeploy one PVWA only.
CDeploy two PVWAs in an active/standby mode.
DDeploy two PVWAs using DNS round robin.
What is the recommended way to determine whether a PVWA is unavailable and needs to be removed from the load-balancing pool?
AMonitor port 443 on the PVWA server.
BMonitor port 1858 on the PVWA server.
CPing the PVWA server
DMonitor port 3389 on the PVWA server.
CyberArk user Neil is attempting to connect to the target Linux server 192.168.1.164 with the domain account ACME/linuxuser01 on domain acme.corp, using PSM for SSH server 192.168.65.145.
Users cannot launch Web Type Connection components from the PSM server. Your manager has asked you to open a case with CyberArk Support.
Which logs will help the CyberArk Support Team troubleshoot the issue?
Choose three
APSMConsole.log
BPSMDebug.log
CPSMTrace.log
D<Session_ID>.Component.log
EPMconsole.log
FITAlog.log
You are configuring the Vault to send syslog audit data to your organization’s SIEM solution.
What is a valid value for the SyslogServerProtocol parameter in the DBPARM.INI file?
ATLS
BSSH
CSMTP
DSNMP
In the displayed screenshot, you have just configured the usage in CyberArk and now want to update its password. What is the least intrusive way to do this?
AUse the "change" button on the usage’s details page
BUse the "change" button on the parent account’s details page
CUse the "sync" button on the usage's details page.
DUse the "reconcile" button on the parent account's details page.
Which usage can be added as a service-account platform?
AKerberos Tokens
BIIS Application Pools
CPowerShell Libraries
DLoosely Connected Devices
To enable the Automatic response “Add to Pending” within PTA when unmanaged credentials are detected, what are the minimum permissions required by PTAUser for the PasswordManager_pending safe?
Community Discussion