โ† All CAD Flashcard Decks

Privileged Access Management Concepts Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privileged Access Management Concepts flashcards as text
  1. What is the 'Vault' in CyberArk's architecture, and what makes it secure?

    Answer: A hardened server with a proprietary protocol (PVWA), layered encryption, and strict firewall rules that stores all privileged credentials

    The CyberArk Vault uses a proprietary protocol, multiple encryption layers, and hardened OS configuration to protect credentials stored within it.

  2. Which of the following is a key benefit of session recording in PAM?

    Answer: It provides a full audit trail of privileged activity for forensic investigation and compliance

    Session recordings create an immutable audit trail of all privileged activity, supporting incident response, forensics, and regulatory compliance requirements.

  3. What is 'shadow IT' in the context of privileged access management risks?

    Answer: Unauthorized applications, systems, or cloud accounts created outside IT governance, often with unmanaged privileged credentials

    Shadow IT refers to technology resources deployed without IT approval, which typically contain unmanaged privileged accounts outside the PAM program's scope.

  4. What is 'break-glass access' in PAM, and when is it used?

    Answer: Emergency access to highly privileged accounts that bypasses normal approval workflows when critical systems fail

    Break-glass access provides emergency credentials that can be used when normal PAM workflows are unavailable, with all usage strictly logged for post-incident review.

  5. Why should SSH keys be managed under a PAM solution in addition to passwords?

    Answer: SSH keys grant privileged access to servers and, if unmanaged, can persist indefinitely without rotation or accountability

    Unmanaged SSH keys often have no expiration, are rarely rotated, and can provide root-level access, making them high-risk privileged credentials that belong in a PAM vault.

  6. In the CyberArk framework, what is an 'Account Group' and what use case does it serve?

    Answer: A logical grouping of accounts that must all be rotated together to maintain synchronization across clustered or replicated systems

    Account Groups synchronize password changes across multiple accounts simultaneously, ensuring that clustered or replicated systems remain consistent after rotation.

  7. Which PAM principle does 'time-limited access' directly enforce?

    Answer: Least privilege (limiting both scope and duration of access)

    Time-limited access enforces least privilege by ensuring elevated rights are granted only for the minimum duration necessary, not indefinitely.