← All CAD Flashcard Decks

Mixed Deck — All CAD Topics Flashcards

100 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CAD Topics flashcards as text
  1. When PTA detects a threat and automatically responds by rotating a compromised account's password, this capability is known as:

    Answer: Automatic response

    PTA's automatic response feature triggers actions such as password rotation or account suspension when a threat is confirmed.

  2. Why should SSH keys be managed under a PAM solution in addition to passwords?

    Answer: SSH keys grant privileged access to servers and, if unmanaged, can persist indefinitely without rotation or accountability

    Unmanaged SSH keys often have no expiration, are rarely rotated, and can provide root-level access, making them high-risk privileged credentials that belong in a PAM vault.

  3. How is access to the Vault controlled?

    Answer: Access control lists and safe permissions

    Access to the CyberArk Vault and its contents is meticulously controlled through a combination of robust access control lists (ACLs) and granular safe permissions. These mechanisms precisely define which users or groups can access specific safes, view, retrieve, or manage credentials, ensuring strict adherence to the principle of least privilege and enhancing security.

  4. Which of the following is a fundamental principle of privileged session manager setup as it applies to CyberArk Defender Certification?

    Answer: Systematic evaluation and adherence to established industry standards

    A fundamental principle of privileged session manager setup in CyberArk Defender Certification is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.

  5. Which log file should an administrator review to investigate failed authentication attempts to the Digital Vault?

    Answer: vault.log

    The vault.log file records all Vault-level events including authentication successes and failures.

  6. A CyberArk administrator wants to prevent a specific user from deleting accounts in a Safe while still allowing them to manage passwords. Which permission should be withheld?

    Answer: Delete accounts

    The 'Delete accounts' permission is separate from password management permissions, so withholding it prevents deletion while other account management tasks remain available.

  7. Which Safe member permission is required to add new accounts to a CyberArk Safe?

    Answer: Add accounts

    The 'Add accounts' permission specifically allows a Safe member to onboard new privileged accounts into the Safe.

  8. Which Master Policy rule, when enabled, instructs the CPM to periodically rotate account passwords on a scheduled basis?

    Answer: Require periodic password change

    The 'Require periodic password change' Master Policy rule enables the CPM to automatically rotate account passwords at intervals defined in the associated platform settings.

  9. In CyberArk's Vault replication topology, what type of replication does CyberArk use between the primary and DR Vault?

    Answer: Synchronous one-way replication from primary to DR

    CyberArk uses synchronous, one-way replication from the primary Vault to the DR Vault, ensuring the DR always has an up-to-date copy.

  10. Which PAM concept ensures that each privileged session is recorded and can be audited later?

    Answer: Session monitoring

    Session monitoring records privileged sessions so security teams can review, audit, or replay them.

  11. Which quality assurance method is most commonly applied in digital vault server administration to verify that CAD professional standards are being met?

    Answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks

    Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in digital vault server administration, providing objective, measurable evidence that CAD standards are consistently met.

  12. A CAD professional encounters an unfamiliar situation while performing privileged session manager setup duties. What is the most appropriate first action?

    Answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding

    When facing unfamiliar situations in privileged session manager setup, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.

  13. In the CyberArk framework, what is an 'Account Group' and what use case does it serve?

    Answer: A logical grouping of accounts that must all be rotated together to maintain synchronization across clustered or replicated systems

    Account Groups synchronize password changes across multiple accounts simultaneously, ensuring that clustered or replicated systems remain consistent after rotation.

  14. What is 'dual control' in the context of CyberArk PAM?

    Answer: Requiring a second approver before a password is retrieved

    Dual control requires a second authorized user to approve a password retrieval request before it is granted.

  15. Which CyberArk Vault component handles encryption key management and is the most sensitive element of the Vault infrastructure?

    Answer: Vault Server with the Server Key

    The Vault Server holds and uses the Server Key (Master CD key) to protect all encrypted data; its compromise would expose the entire Vault.

  16. What is the maximum number of concurrent PSM sessions limited by in a CyberArk environment?

    Answer: PSM server capacity and the CyberArk license

    PSM concurrent session limits are governed by both the hardware capacity of the PSM server(s) and the session capacity defined in the CyberArk license.

  17. What is the significance of 'cross-account access' risk in AWS as identified by CyberArk CEM?

    Answer: A compromised identity in one account can leverage permissions to access resources in other accounts

    Cross-account roles allow an identity compromised in one AWS account to pivot and access resources in other accounts, expanding the blast radius of a breach.

  18. An auditor needs read-only access to view all activity logs across all Safes without being able to retrieve passwords. Which built-in group should they be added to?

    Answer: Auditors

    The built-in 'Auditors' group in CyberArk grants read-only visibility into Safe contents and audit logs without providing credential retrieval capabilities.

  19. Which setting can enforce session approval in CyberArk?

    Answer: Dual control

    Dual control is a critical security setting in CyberArk that enforces a 'four-eyes' principle, requiring a second authorized user to approve a privileged session request before it can be initiated. This significantly enhances security for highly sensitive operations by preventing a single point of failure or malicious activity, adding an extra layer of oversight.

  20. In CyberArk, which object type represents an individual set of credentials (username, password, and target details) stored inside a Safe?

    Answer: Account

    An Account (also called a password object) stores the actual credential — username, password, address, and platform association — inside a Safe.