CyberArk Architecture & Components Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CyberArk Architecture & Components flashcards as text
Which CyberArk component is specifically designed to detect anomalous privileged account behavior and generate risk-based alerts?
Answer: PTA (Privileged Threat Analytics)
PTA analyzes behavioral data from CyberArk and external sources to detect and alert on suspicious privileged activity.
What is the function of the CyberArk 'Reconcile Account' feature?
Answer: It resets a target account password when the CPM-managed password is out of sync
Reconciliation uses a separate privileged 'reconcile account' to reset a target account's password when normal CPM rotation fails due to a mismatch.
CyberArk's EPM (Endpoint Privilege Manager) primarily addresses which security challenge?
Answer: Removing local admin rights and controlling application execution on endpoints
EPM enforces least-privilege on endpoints by removing unnecessary local admin rights and controlling which applications can execute.
In CyberArk, which object defines the technical parameters (e.g., connection method, port, prompt patterns) used by the CPM to manage a specific type of target system?
Answer: Platform (Plugin)
A Platform (also called a CPM plugin) defines how the CPM connects to and rotates credentials on a specific target system type.
Which CyberArk Vault component handles encryption key management and is the most sensitive element of the Vault infrastructure?
Answer: Vault Server with the Server Key
The Vault Server holds and uses the Server Key (Master CD key) to protect all encrypted data; its compromise would expose the entire Vault.
How does PSM for SSH (PSMP) differ from standard PSM in a CyberArk deployment?
Answer: PSMP allows native SSH clients to connect through it as a transparent proxy
PSMP acts as a transparent SSH proxy, allowing users to use native SSH clients while CyberArk still records and isolates the session.
What is the significance of the CyberArk 'Operator CD' in Vault initialization?
Answer: It holds one portion of the Vault's master encryption key required during startup
The Operator CD contains a split portion of the Vault's encryption key; it must be present during Vault startup to decrypt the Vault data.