Privileged Access Management Concepts Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Privileged Access Management Concepts flashcards as text
What is 'lateral movement' in the context of a privileged access attack?
Answer: An attacker using compromised credentials to access additional systems within the network
Lateral movement is the technique attackers use to progressively move through a network after gaining initial access, often leveraging stolen privileged credentials.
Which CyberArk component enforces password policies and performs automatic password changes on target systems?
Answer: CPM (Central Policy Manager)
The CPM is responsible for enforcing platform-specific password policies and executing automated credential rotation on managed accounts.
What is 'dual control' in CyberArk PAM?
Answer: A workflow where a second authorized user must approve a password request before it is granted
Dual control requires an approver to authorize a requestor's access before the Vault releases the credential, enforcing four-eyes verification.
What is the difference between authentication and authorization in PAM?
Answer: Authentication verifies identity; authorization determines what resources the verified identity may access
Authentication confirms identity (who you are), while authorization enforces permissions (what you are allowed to do) after identity is confirmed.
In CyberArk, what is a 'platform' in the context of account management?
Answer: A template that defines how CyberArk manages and interacts with a specific type of account or system
A CyberArk platform is a policy template that specifies connection methods, password rules, and management settings for a particular account type or target system.
Which of the following best describes 'privileged access workstations (PAWs)'?
Answer: Hardened endpoints reserved exclusively for performing privileged administrative tasks
PAWs are dedicated, hardened devices from which admins perform privileged tasks, reducing the risk of credential theft from general-purpose endpoints.
What risk does an unmanaged 'local administrator' account on endpoints pose?
Answer: It provides attackers with a persistent, often shared credential to move laterally across endpoints
Shared local admin accounts (e.g., same password across many machines) enable lateral movement once an attacker compromises any single endpoint.