QuestionQ41

Daily maintenance and operation to support the on-going performance of the CyberArk Identity Security solution

Match each PTA alert category to the PTA sensors that collect data for it.

Drag & Drop
Vault
Logs, Vault, AWS (optional), Azure (optional)
Logs, Vault, AD (optional), AWS (optional), Azure(Optional)
Network Sensor, PTA Windows Agent
unmanaged privileged account
anomalous access to multiple machines
suspicious activities detected in a privileged session
suspected credentials theft
Explanation

CyberArk PTA detects suspicious activity within a privileged session from Vault data. Suspected credential theft correlates logs with Vault credential activity and can use optional AWS and Azure sources. Unmanaged privileged-account detection also uses optional Active Directory data to determine whether a privileged account is managed. Anomalous access across many machines is detected from network or domain-controller activity collected by the Network Sensor or PTA Windows Agent.

Community Discussion

No comments yet. Be the first to start the discussion!