A customer has five main data centers with one PVWA in each center under different URLs.
How can you make this setup fault tolerant?
AThis setup is already fault tolerant.
BInstall more PVWAs in each data center.
CContinuously monitor PVWA status and send users the link to another PVWA if issues are encountered.
DLoad balance all PVWAs under same URL.
A customer has three data centers distributed globally and wants highly-available PSM connections in each segmented zone. In addition, the customer needs a highly-available PSM connection for the CyberArk Admins.
What will best satisfy this customer's needs?
Aone PSM per zone with a load balancer and two PSMs for Admins with a load balancer
Bsix PSMs in the mam data center with a load balancer and one PSM for Admins
Ctwo PSMs per zone with a load balancer and two PSMs for Admins with a dedicated load balancer
Dthree PSMs per zone with CyberArk built-in load balancing
DRAG DROP -
Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence.
What is the recommended method to determine if a PVWA is unavailable and should be disabled in a load balancing pool?
AMonitor Port 443 on the PVWA server
BMonitor Port 1858 on the PVWA server
CPing the PVWA server
DMonitor Port 3389 on the PVWA server
Question 6
Architecture & Component Overview
0
Question 7
Installation & Configuration
Question 8
Installation & Configuration
Question 9
Central Policy Manager Operations
Question 10
Installation & Configuration
Question 11
Privileged Session Manager (PSM)
Question 12
Installation & Configuration
Question 13
Architecture & Component Overview
Question 14
Privileged Session Manager (PSM)
Question 15
Installation & Configuration
Question 16
Installation & Configuration
Question 17
Safe Management
Question 18
Installation & Configuration
Question 19
Installation & Configuration
Question 20
Installation & Configuration
Question 21
Installation & Configuration
Question 22
Privileged Session Manager (PSM)
Question 23
Architecture & Component Overview
Question 24
Installation & Configuration
Question 25
Installation & Configuration
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
If a customer has one data center and requires fault tolerance, how many PVWAs should be deployed?
Atwo or more
Bone PVWA cluster
Cone
Dtwo PVWA clusters
You are installing a CPM.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords and Manage Server File Categories, which Vault authorization(s) does a CyberArk user need to install the CPM?
AManage Directory Mapping
BActivate Users
CBackup All Safes, Restore All Safes
DAudit Users, Add Network Areas
You are configuring SNMP remote monitoring for your organization’s Vault servers.
In the PARAgent.ini, which parameter specifies the destination of the Vault SNMP traps?
ASNMPHostIP
BSNMPTrapPort
CSNMPCommunity
DSNMPVersion
You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_Admin safes.
How do you set this in CyberArk?
AIn the CYBRWINDAD platform, under Automatic Password Management/General, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).
BIn the settings for Configuration/CPM assigned to the WINDEMEA and WINDEMEAADMIN safes, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEAADMIN).
CIn the CYBRWINDAD platform, under UI&Workflows/Properties/Optional, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).
DModify cpm.ini on the relevant CPM/s and add the setting AllowedSafesCYBRWINDAD and set to (WINDEMEA)|(WINDEMEAADMIN).
Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM.
Which file should you update to allow this to run?
APSMConfigureAppLocker.xml
BPSMHardening.xml
CPSMAppConfig.xml
DPSMConfigureHardening.xml
How should you configure PSM for SSH to support load balancing?
Dby editing sshd.config on the all the PSM for SSH servers
Which utility should be used to register the Vault in Amazon Web Services?
ACAVaultManager
BStorageManager
CCloudVaultManager
DCACert
When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
A5 - number of primary and satellite Vaults can be specified during installation
B3 - all primary
C6 - 1 primary and 5 satellite
D10 - 2 primary and 8 satellite
A first PSM server has been installed.
What should you confirm before installing any additional PSM servers?
AThe PSM ID of the first installed PSM server was changed and the additional PSM server can use the same PSM ID.
BThe user performing the installation is a direct owner in the PSMUnmanagedSessionAccounts Safe, PSM safe and member of PVWAMonitor group.
CThe user performing the installation is not a direct owner in the PSMUnmanagedSessionAccounts Safe.
DThe path of the Recordings Folder must be different on all PSM installations.
What must you do to prepare a Windows server for PVWA installation?
AIn the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell.
BInstall the PrivateArk client.
CVerify the user performing the installation is Domain Administrator and has logon access to the Vault server.
DEnable IPv6.
In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?
Asaml.config
Bsamlconfig.ini
CPVWAConfig.xml
DPVConfiguration.xml
The account used to install a PVWA must have ownership of which safes? (Choose two.)
AVaultInternal
BPVWAConfig
CSystem
DNotification Engine
EPVWAReports
Which configuration file and Vault utility are used to migrate the server key to an HSM?
ADBparm.ini and CAVaultManager.exe
BVaultKeys.ini and CAVaultManager.exe
CDBparm.ini and ChangeServerKeys.exe
DVaultKeys.ini and ChangeServerKeys.exe
Your customer wants to store the Safes Data on Vault Drive D instead of Drive C.
Which file should you edit?
ATSparm.ini
BVault.ini
CDBparm.ini
Duser.ini
In which configuration file do you add LoadBalancerClientAddressHeader when you enable x-forwarding on the PVWA loadbalancer?
APVconfiguration.xml
Bweb.config
Capigw.ini
DCyberArkScheduledTasks.exe.config
In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?
APARAgent.ini
BDBParm.ini
CTSParm.ini
DCyberArkv2 MIB file
During the PSM installation process, Safes and a User are created.
In addition to Add Safes, Add/Update Users, Reset Users’ Passwords, and Activate Users, which authorization(s) does the Vault user installing the PSM need to enable them to be successfully created?
AManage Vault File Categories
BManage Server File Categories
CManage Directory Mapping, Manage Server File Categories
Which statement about REST API is correct? (Choose two.)
AWhen a user successfully authenticates to the Vault, an authentication token is returned.
BREST API Windows authentication method allows skipping the logon API by using the Windows default credentials with a Kerberos ticket.
CTo allow High Availability, REST API can be configured to support Session Load Balancing by editing the PVConfiguration.xml and setting the AllowPVWASessionRedandancy=Yes.
DEach REST API call requires that a valid authentication token be provided.
EREST calls are directly sent to the currently active Vault using Port 1858.
HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)
ARed Hat Enterprise Linux 7.x
BCentOS 7.x
CUbuntu 20.x
DAK 7.x
EAndroid 11.x
You are configuring the Vault to send syslog audit data to your organization’s SIEM solution.
What is a valid value for the SyslogServerProtocol parameter in DBPARM.INI file?