โ† All CAD Flashcard Decks

Privileged Access Management Concepts Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privileged Access Management Concepts flashcards as text
  1. What is the primary purpose of a Privileged Session Manager (PSM) in CyberArk?

    Answer: To proxy and record privileged sessions without exposing credentials to end users

    PSM acts as a proxy between users and target systems, recording sessions while keeping credentials hidden from the end user.

  2. Which PAM control ensures that a privileged account password is changed immediately after each use?

    Answer: One-time password (OTP) rotation

    One-time password rotation changes credentials after every checkout, preventing reuse and limiting the window of exposure.

  3. In CyberArk, what is a 'Safe' used for?

    Answer: A logical container within the Vault that stores accounts and applies access policies

    A Safe is the primary organizational and access-control unit inside the CyberArk Vault, grouping accounts with shared policies.

  4. What does 'least privilege' mean in the context of PAM?

    Answer: Granting users the minimum level of access required to perform their job functions

    Least privilege limits each user or process to only the permissions needed for their specific tasks, reducing the attack surface.

  5. What is 'credential theft' in the context of privileged access risks?

    Answer: An attacker obtaining and misusing valid privileged account credentials

    Credential theft occurs when an attacker acquires legitimate privileged credentials and uses them to move laterally or escalate privileges.

  6. Which component in CyberArk is responsible for automatically discovering privileged accounts across the network?

    Answer: Account Discovery (DNA / PVWA scan)

    CyberArk's Discovery and Audit (DNA) tool and PVWA account discovery scans identify unmanaged privileged accounts across the environment.

  7. Why is it important to manage service accounts under a PAM solution?

    Answer: Service accounts often have broad privileges and static passwords, making them high-value targets

    Service accounts frequently have excessive privileges and rarely-rotated passwords, making them prime targets for attackers seeking persistent access.