CyberArk Cloud Entitlements Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CyberArk Cloud Entitlements flashcards as text
Which attack technique is directly mitigated by CyberArk CEM's detection of identities with `iam:PassRole` permission combined with unrestricted service trust?
Answer: IAM privilege escalation via role passing
The `iam:PassRole` permission, when combined with broad service trust, allows attackers to escalate privileges by passing powerful roles to services they control.
CyberArk CEM can integrate with which of the following to automatically create tickets for entitlement remediation?
Answer: ITSM tools such as ServiceNow or Jira
CEM integrates with ITSM platforms like ServiceNow and Jira to automatically open remediation tickets, enabling workflow-driven least-privilege enforcement.
What does the CyberArk CEM metric 'Unused Permission Ratio' represent?
Answer: The proportion of granted permissions that have never been exercised within the analysis period
The Unused Permission Ratio shows how much of what an identity can do it never actually does, directly indicating over-provisioning severity.
In the context of CyberArk CEM, what is an 'identity risk' associated with federated users accessing cloud environments?
Answer: External identity provider compromise could grant attackers cloud access without direct cloud credential theft
Federated access links cloud permissions to an external IdP, meaning a compromised IdP can yield cloud access to attackers without needing cloud-native credentials.
Which CyberArk CEM feature helps identify when an AWS EC2 instance profile grants more permissions than the application running on that instance requires?
Answer: Workload identity analysis with usage-based right-sizing
CEM's workload identity analysis examines the API calls made by EC2 instance profiles and recommends policies scoped to only what the workload actually uses.
What is the primary reason CyberArk recommends remediating 'toxic combinations' of cloud permissions flagged by CEM?
Answer: Certain permission combinations together enable dangerous attack paths that neither permission enables alone
Toxic combinations are permission pairings (e.g., `iam:CreatePolicy` + `iam:AttachUserPolicy`) that together enable privilege escalation paths neither permission creates individually.
When CyberArk CEM is used in an organization practicing DevSecOps, at which stage should cloud entitlement checks ideally be integrated?
Answer: Within the CI/CD pipeline so IaC permissions are validated before deployment
Integrating CEM checks into CI/CD pipelines enables shift-left security by catching over-permissive IAM policies in IaC templates before they reach production.