CAD CAD Audit & Compliance 2 — Questions and Answers
Question 1: When configuring CyberArk to meet SOX compliance requirements, which control ensures that no single user can both request and approve privileged access?
- One-Time Password
- Dual Control (Correct answer)
- Just-In-Time Access
- Safe Membership Restriction
Correct answer: Dual Control
Dual Control enforces separation of duties by requiring a separate authorizer to approve any privileged account checkout request.
Question 2: Which CyberArk report lists all Safe members and their assigned permissions, useful for access certification reviews?
- Privileged Accounts Inventory
- Entitlement Report (Correct answer)
- Activity Summary Report
- Password Rotation Report
Correct answer: Entitlement Report
The Entitlement Report details every Safe member and their permissions, enabling periodic access review and certification for compliance.
Question 3: In CyberArk, what is the purpose of the 'Access Keys for Accountability' feature during privileged session recording?
- Encrypts session recordings at rest
- Ties each session recording to a specific authenticated user for accountability (Correct answer)
- Allows session recordings to be exported to SIEM
- Restricts session length to a defined timeout
Correct answer: Ties each session recording to a specific authenticated user for accountability
Access Keys for Accountability links PSM recordings directly to the authenticated requester, ensuring clear attribution for audit trails.
Question 4: Which CyberArk PVWA report is specifically designed to show accounts whose passwords have not been changed in a user-defined number of days?
- Dormant Accounts Report
- Non-Compliant Accounts Report (Correct answer)
- Safe Activity Report
- Privileged Identity Report
Correct answer: Non-Compliant Accounts Report
The Non-Compliant Accounts Report identifies accounts that have exceeded the allowed password age, flagging them for remediation.
Question 5: To comply with PCI-DSS requirements for privileged account monitoring, CyberArk PSM recordings should be stored for a minimum of how long?
- 30 days
- 90 days
- 1 year (Correct answer)
- 7 years
Correct answer: 1 year
PCI-DSS requires audit logs and session recordings for privileged users to be retained for at least one year, with three months immediately available.
Question 6: Which CyberArk feature generates a SYSLOG-format stream of vault audit events that can be forwarded to a SIEM platform?
- SMTP Notifier
- SYSLOG Integration via Vault Parameters (Correct answer)
- Audit Bridge Connector
- Vault Event Exporter
Correct answer: SYSLOG Integration via Vault Parameters
CyberArk Vault supports SYSLOG integration configured via Vault parameters to forward audit events in real time to external SIEM tools.
When configuring CyberArk to meet SOX compliance requirements, which control ensures that no single user can both request and approve privileged access?