← All CAD Flashcard Decks

Application Access Manager Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Application Access Manager flashcards as text
  1. In CyberArk AAM, what is the effect of setting 'AccessPermittedFrom' and 'AccessPermittedTo' on an application definition?

    Answer: Limits the time window during which the application can retrieve credentials

    AccessPermittedFrom/To enforces time-based access control, allowing credential retrieval only within specified hours.

  2. Which CyberArk tool is used to register a new application identity in the Vault for AAM purposes?

    Answer: PrivateArk Client or PVWA Applications page

    Applications are registered via the PVWA Applications page or the PrivateArk Client under the Applications node.

  3. An AAM application retrieves a credential but the password has just been rotated by CPM. What ensures the application always gets the current valid password?

    Answer: AAM always retrieves the current password directly from the Vault at request time

    AAM retrieves credentials live from the Vault at each request, so the application always receives the current, valid password.

  4. What is the purpose of the 'Application ID' field when making a CCP REST API call?

    Answer: It identifies which registered application definition should be used for authentication and authorization

    The Application ID tells CCP which registered application identity to evaluate, determining which authentication methods and Safe permissions apply.

  5. Which of the following is a supported authentication method for Conjur workload identities in a cloud environment?

    Answer: AWS IAM Role (authn-iam)

    Conjur's authn-iam authenticator validates AWS IAM roles, enabling EC2 instances and Lambda functions to authenticate natively.

  6. When the Credential Provider cannot reach the Vault, what behavior does the application experience by default?

    Answer: The retrieval request fails with an error

    If the CP cannot connect to the Vault, the API call returns an error — there is no automatic fallback to cached or local credentials.

  7. Which parameter in a CCP REST API request specifies the account to retrieve within the target Safe?

    Answer: Object

    The 'Object' parameter in the CCP REST API URL specifies the account object name within the Safe to retrieve.