โ† All CAD Flashcard Decks

Application Access Manager Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Application Access Manager flashcards as text
  1. A developer wants to integrate an application with CyberArk AAM without installing any agent on the app server. Which retrieval method should they use?

    Answer: Central Credential Provider (CCP) REST API

    CCP's REST API is the agentless method, allowing any application to retrieve credentials via HTTPS without a local agent.

  2. In CyberArk Conjur, which entity represents the non-human identity of an application requesting a secret?

    Answer: Host

    In Conjur, a 'Host' represents a machine or application identity that can authenticate and retrieve secrets.

  3. Which CyberArk AAM feature allows Kubernetes pods to retrieve secrets without storing credentials in the pod specification?

    Answer: Conjur Secrets Provider for Kubernetes

    The Conjur Secrets Provider runs as an init or sidecar container to inject secrets into pods at runtime.

  4. What must be configured in the Vault for an AAM application to access accounts in a specific Safe?

    Answer: The AAM provider user must be added to the Safe with Retrieve permission

    The provider user representing the AAM application must be granted at minimum 'Retrieve Accounts' permission on the target Safe.

  5. Which AAM authentication method is MOST resistant to credential theft from the application server itself?

    Answer: Hash-based authentication

    Hash-based authentication ties credential access to the exact, unmodified binary, so a stolen executable or spoofed process cannot authenticate.

  6. A CI/CD pipeline needs to inject database credentials at build time using CyberArk. Which integration approach is BEST aligned with CyberArk best practices?

    Answer: Use AAM CCP REST API to pull credentials dynamically at runtime

    Calling the CCP REST API at runtime eliminates hardcoded secrets and keeps credentials current without pipeline changes.

  7. What is the default port used by the Central Credential Provider (CCP) web service for HTTPS requests?

    Answer: 443

    CCP listens on the standard HTTPS port 443 by default when hosted in IIS.