Application Access Manager Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Application Access Manager flashcards as text
Which CyberArk component serves as the authentication broker when using the Central Credential Provider?
Answer: CCP IIS Web Service
The CCP is deployed as an IIS-hosted web service that authenticates applications and proxies credential requests to the Vault.
In CyberArk AAM, what does 'OS User' authentication rely on to verify an application's identity?
Answer: The operating system account running the application process
OS User authentication validates the Windows or Unix account under which the requesting process is executing.
An application is registered in CyberArk AAM with three authentication methods: IP, OS User, and Path. How many methods must match for the request to succeed?
Answer: All three must match
By default, when multiple authentication methods are configured, ALL must be satisfied for the application to receive credentials.
What is the role of the 'AppProviderUser' in the CyberArk AAM architecture?
Answer: The Vault account used by the CP/CCP service to authenticate to the Vault on behalf of applications
AppProviderUser is the Vault identity that the AAM provider uses to authenticate and perform retrievals on behalf of registered applications.
Which file on the Credential Provider server stores its configuration, including Vault address and authentication details?
Answer: appProvider.ini
The appProvider.ini file contains the CP's configuration including the Vault IP and authentication parameters.
What type of credential does CyberArk AAM support retrieving for SSH-based applications?
Answer: Passwords and SSH private keys
AAM can retrieve both passwords and SSH private keys stored in the Vault for applications that need SSH authentication.
When troubleshooting a failed AAM credential retrieval, which log file on the Credential Provider server should you check first?
Answer: AppProvider.log
AppProvider.log records all Credential Provider activity including authentication failures and retrieval errors.