โ† All CAD Flashcard Decks

Privileged Threat Analytics Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privileged Threat Analytics flashcards as text
  1. Which PTA deployment component is responsible for analyzing raw security events and generating risk-scored alerts?

    Answer: PTA Server

    The PTA Server is the core analytics engine that processes ingested data, applies behavioral models, and produces risk-scored security alerts.

  2. How does PTA handle the detection of SSH key-based authentication anomalies for privileged Unix/Linux accounts?

    Answer: PTA analyzes SSH session logs to detect keys used from new locations or at unusual times

    PTA ingests SSH session data to detect behavioral anomalies in key-based authentication, such as use from new source IPs or atypical times.

  3. After a PTA automatic response rotates a compromised account's password, where is the new credential securely stored?

    Answer: In the CyberArk Vault under the account's Safe

    When PTA rotates a password as an automatic response, the CPM generates the new credential and stores it in the CyberArk Vault Safe.

  4. Which metric does PTA use to prioritize which security alerts require the most immediate attention?

    Answer: Risk score assigned to the event based on account sensitivity and behavior severity

    PTA assigns a risk score to each alert by combining the privilege level of the involved account with the severity of the detected behavior to drive prioritization.

  5. What is the primary purpose of PTA's 'Unmanaged Privileged Accounts' report?

    Answer: To surface accounts with administrative rights that have not been onboarded into CyberArk for management

    The Unmanaged Privileged Accounts report helps organizations discover shadow admin accounts that operate outside Vault control and represent security gaps.

  6. During a PTA threat investigation, an analyst notices the alert chain shows Pass-the-Hash followed by lateral movement to a domain controller. What is the BEST immediate response?

    Answer: Isolate the source machine, trigger automatic password rotation for the compromised account, and escalate to the incident response team

    A lateral movement chain reaching a domain controller is a critical incident requiring immediate isolation, credential rotation, and IR escalation to prevent full domain compromise.

  7. Which CyberArk PTA capability allows it to detect threats even for accounts that are managed in the Vault but whose sessions are not recorded by PSM?

    Answer: PTA uses network traffic analysis and Windows Event Logs independently of PSM session recording

    PTA operates independently of PSM by analyzing network traffic and authentication logs, enabling threat detection regardless of whether session recording is active.