โ† All CAD Flashcard Decks

Access Controls Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Controls flashcards as text
  1. In CyberArk's Master Policy, which setting controls whether users must provide a reason when checking out a privileged account?

    Answer: Require users to specify reason for access

    The 'Require users to specify reason for access' Master Policy rule forces users to document a justification that is logged with every credential retrieval.

  2. A Vault admin needs to grant a new security team member the ability to manage Safe memberships but NOT retrieve passwords. Which permission set is appropriate?

    Answer: Manage Safe members only

    Granting only 'Manage Safe members' allows the user to add/remove Safe members and adjust permissions without giving them access to the stored credentials.

  3. Which CyberArk feature allows a SOC analyst to gain temporary elevated privileges to a target system for a defined period without permanently owning the account?

    Answer: Just-In-Time Access through the PVWA request workflow

    CyberArk's Just-In-Time (JIT) access workflow in PVWA allows temporary, time-boxed privilege grants that expire automatically, reducing standing access.

  4. When a platform has 'One Time Password' (OTP) enabled, what occurs after the privileged session ends?

    Answer: The CPM immediately rotates the password to a new random value

    With One Time Password enabled, the CPM automatically changes the credential immediately after the session ends, ensuring each use produces a unique password.

  5. What is the role of the 'Authorizer' Safe member permission in a dual control workflow?

    Answer: To approve or reject access requests submitted by other Safe members

    The Authorizer permission designates a user as an approver who can confirm or deny credential access requests in the dual control workflow.

  6. An organization wants to ensure that all privileged SSH sessions to Linux servers are recorded and cannot be bypassed. Which CyberArk component enforces this?

    Answer: PSM with SSH Proxy connection component

    The PSM SSH Proxy forces all SSH connections through CyberArk, recording the session and preventing direct access that would bypass auditing.

  7. In CyberArk, which object type stores the connection parameters, password policy rules, and plugin configurations for a specific account type?

    Answer: Platform

    A Platform in CyberArk is a template that defines how passwords are managed, rotated, and connected for a specific target system type (e.g., Windows Domain, Oracle DB).