โ† All CAD Flashcard Decks

Digital Vault Server Administration Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Vault Server Administration flashcards as text
  1. In CyberArk, which parameter in DBParm.ini controls the timeout period for idle Vault sessions?

    Answer: DisconnectIdleUserTimeout

    The DisconnectIdleUserTimeout parameter in DBParm.ini specifies the number of minutes before idle user sessions are automatically terminated by the Vault.

  2. Which CyberArk tool is used to export Vault audit logs to an external SIEM system?

    Answer: Vault Syslog integration via DBParm.ini syslog settings

    CyberArk supports syslog integration configured in DBParm.ini, allowing Vault audit events to be forwarded to external SIEM solutions in real time.

  3. What is the purpose of the 'Safes' directory within the Digital Vault installation path?

    Answer: Contains encrypted safe database files (.rdb) for all created safes

    The Safes directory contains the encrypted .rdb database files that hold the actual content of each safe created in the Vault.

  4. When the CyberArk Vault license expires, what is the immediate impact on Vault functionality?

    Answer: Existing accounts remain accessible but no new accounts or safes can be created

    Upon license expiry, CyberArk allows continued access to existing credentials but blocks creation of new accounts, safes, or users until the license is renewed.

  5. Which CyberArk administrative interface allows an administrator to manage Vault users and safes without a network connection to the Vault?

    Answer: CAVaultManager.exe command-line interface

    CAVaultManager.exe operates locally on the Vault server and can manage the Vault directly without requiring a network connection, useful for emergency administration.

  6. In a CyberArk DR failover scenario, which step must be completed on the DR Vault before it can accept production connections?

    Answer: Activate the DR Vault by running the activation procedure using CAVaultManager.exe

    During DR failover, the DR Vault must be activated using CAVaultManager.exe activate command, which promotes it to primary status so components can connect.

  7. What does the CyberArk Vault's 'Private Ark' security model prevent even a Vault administrator from doing by default?

    Answer: Directly reading or decrypting the contents of passwords stored in safes they do not own

    CyberArk's security architecture prevents even Vault administrators from directly reading password values in safes they are not explicitly authorized to access, ensuring separation of duties.