โ† All CAD Flashcard Decks

Enterprise Password Vault Policies Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Enterprise Password Vault Policies flashcards as text
  1. Which CyberArk component stores the Master Policy and enforces it across all Safes by default?

    Answer: Digital Vault Server

    The Digital Vault Server (Vault) is the authoritative source that stores and enforces the Master Policy governing all Safes.

  2. In CyberArk, what is the role of the 'Logon Account' associated with a platform?

    Answer: A credential the CPM uses to authenticate to the target before performing a password change

    A Logon Account provides the CPM with credentials to authenticate to the remote target system so it can perform password management tasks.

  3. Which Safe member permission is required to add new accounts to a CyberArk Safe?

    Answer: Add accounts

    The 'Add accounts' permission specifically allows a Safe member to onboard new privileged accounts into the Safe.

  4. A CyberArk platform is configured with 'ImmediateInterval' set to 5 minutes. What does this control?

    Answer: The grace period before an immediate change request is executed

    ImmediateInterval defines how many minutes the CPM waits before executing an 'immediate change' request that was triggered manually or by policy.

  5. When configuring a CyberArk Safe, which setting restricts access to accounts stored in the Safe to a specific time window each day?

    Answer: Time-based restrictions in the Safe member permissions

    CyberArk allows Safe member permissions to include time-based access restrictions, limiting when a user can retrieve passwords from the Safe.

  6. What happens in CyberArk when a Safe's 'Number of days retention' setting expires for an activity log?

    Answer: Activity log entries older than the retention period are purged from the Vault

    Activity log entries that exceed the configured retention period are automatically purged to manage storage and comply with data retention policies.

  7. A CyberArk security team wants to ensure that every password change on a Unix platform is verified immediately after rotation. Which platform setting enables this?

    Answer: VerifyPassword

    Setting VerifyPassword (or EnableVerification) in the platform instructs the CPM to confirm the new password works on the target immediately after each change.