โ† All CAD Flashcard Decks

CAD Audit & Compliance Flashcards

6 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CAD Audit & Compliance flashcards as text
  1. In CyberArk, which built-in Safe is used to store all audit log files generated by the Vault server itself?

    Answer: VaultInternal

    The VaultInternal Safe stores core operational files including Vault audit logs, which are protected with the highest security.

  2. What does enabling 'Require reason' on a Safe in CyberArk accomplish from an audit perspective?

    Answer: Requires users to provide a justification that is recorded in the audit log when retrieving a password

    Enabling 'Require reason' forces users to submit a business justification at checkout time, which is then captured in the audit log for compliance review.

  3. Which CyberArk component sends email alerts to Safe owners or security teams when unauthorized or suspicious access is detected?

    Answer: Notification Engine

    The Notification Engine monitors Vault events and dispatches email alerts based on configured rules, supporting real-time audit notification.

  4. When performing a CyberArk compliance audit, which tool can be used to compare current Safe permissions against a security baseline?

    Answer: PVWA Entitlement Report export

    Exporting the Entitlement Report from PVWA and comparing it to a documented baseline is the standard approach for Safe permission compliance audits.

  5. In CyberArk, audit logs record which of the following details for each Vault activity? (Select the most complete answer)

    Answer: User, date/time, action, and target object

    CyberArk Vault audit logs capture the authenticated user, timestamp, action performed, and the target object (account or Safe) to ensure full traceability.

  6. Which CyberArk Master Policy setting helps ensure compliance by automatically disabling accounts that have not been used within a specified number of days?

    Answer: Inactive Account Management

    The Inactive Account Management setting in Master Policy automatically disables dormant accounts that exceed the inactivity threshold, reducing compliance risk.