โ† All CAD Flashcard Decks

CyberArk Cloud Entitlements Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CyberArk Cloud Entitlements flashcards as text
  1. In Azure, which identity type does CyberArk CEM primarily target when addressing non-human cloud entitlement risks?

    Answer: Managed Identities and Service Principals

    CEM focuses on Azure Managed Identities and Service Principals as the primary non-human identities that carry cloud workload permissions.

  2. What is the significance of 'cross-account access' risk in AWS as identified by CyberArk CEM?

    Answer: A compromised identity in one account can leverage permissions to access resources in other accounts

    Cross-account roles allow an identity compromised in one AWS account to pivot and access resources in other accounts, expanding the blast radius of a breach.

  3. How does CyberArk CEM handle multi-cloud environments when an organization uses AWS, Azure, and GCP simultaneously?

    Answer: It provides a unified dashboard with normalized risk views across all three clouds

    CEM offers a single unified interface that aggregates and normalizes entitlement data across AWS, Azure, and GCP for centralized visibility.

  4. Which AWS feature, when misconfigured, allows an attacker to escalate privileges by assuming roles beyond their intended scope?

    Answer: IAM role trust policies with overly broad Principal definitions

    An IAM role trust policy that allows any account or a wildcard principal to assume it can lead to privilege escalation across accounts or services.

  5. What remediation action does CyberArk CEM recommend when it detects an IAM user with long-standing unused access keys?

    Answer: Deactivate or delete the unused access keys to eliminate stale credential risk

    Stale, unused access keys represent persistent attack surfaces; CEM recommends deactivating or deleting them to reduce risk.

  6. In CyberArk CEM, what is the purpose of the 'Peer Group Analysis' feature?

    Answer: Benchmarking an identity's permissions against similar identities to detect anomalous over-provisioning

    Peer Group Analysis compares an identity's entitlements against similar identities in the same role or function to flag outliers with excessive permissions.

  7. When CyberArk CEM flags a finding as 'Critical,' what does this typically indicate about the cloud entitlement?

    Answer: The identity has permissions that could enable data exfiltration or full environment compromise

    Critical findings indicate entitlements that provide paths to catastrophic outcomes such as data theft, lateral movement, or complete cloud environment takeover.