โ† All CAD Flashcard Decks

Enterprise Password Vault Policies Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Enterprise Password Vault Policies flashcards as text
  1. When a CyberArk CPM fails to verify a password on a remote target, what status is assigned to the account?

    Answer: Exception

    When the CPM cannot verify or change a password, the account is placed in 'Exception' status, alerting administrators to the failure.

  2. In CyberArk, what is the function of the 'Reconcile' operation performed by the CPM?

    Answer: Resets a password using a reconcile account when the current password is unknown

    Reconciliation allows the CPM to reset an account's password using a separate reconcile account when the current password is out of sync or unknown.

  3. Which CyberArk platform property must be configured to allow the CPM to log on to a target Windows server and change a local account password?

    Answer: ManageAs

    The ManageAs property (or associated reconcile/logon account) tells the CPM which privileged account to use when connecting to the target to perform the change.

  4. A CyberArk policy requires passwords to be at least 14 characters. An application hard-codes a 12-character password. What should the CyberArk administrator do?

    Answer: Create a platform exception allowing 12-character passwords for that account

    A platform exception or account-level override can lower the minimum password length for specific accounts without affecting the global policy.

  5. What does the 'PasswordNeverExpires' flag in CyberArk account properties indicate to the CPM?

    Answer: The CPM should not automatically rotate the password based on schedule

    Setting PasswordNeverExpires tells the CPM to skip scheduled automatic rotation while still allowing manual changes.

  6. In the CyberArk Master Policy, which rule setting controls whether users can connect through the PSM to targets without first viewing the password?

    Answer: Allow transparent connections through PSM

    'Allow transparent connections through PSM' permits users to launch PSM sessions without ever seeing the underlying credential.

  7. A CyberArk Safe has 'Enforce one-time password' enabled in the Master Policy. A user retrieves the password and does NOT use it. What does the CPM do?

    Answer: Changes the password immediately after check-in, regardless of use

    With OTP enforced, the CPM rotates the password upon check-in regardless of whether the password was actually used, ensuring each checkout yields a unique credential.