โ† All CAD Flashcard Decks

Setup Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Setup flashcards as text
  1. Which CyberArk component should be installed in the DMZ to facilitate RDP and SSH session proxying?

    Answer: PSM

    The Privileged Session Manager (PSM) is typically deployed in the DMZ to act as a jump server for proxying RDP and SSH sessions to target systems.

  2. What is the significance of the 'Operator' CD in a CyberArk Vault installation?

    Answer: It holds the Vault encryption keys used for disaster recovery

    The Operator CD (or USB) contains the Vault's master encryption keys, which are essential for disaster recovery and Vault restoration scenarios.

  3. During CyberArk setup, Safe creation for CPM operations requires which minimum permission for the CPM user?

    Answer: Add Accounts

    The CPM user needs at minimum 'Add Accounts' and related permissions on the Safe to store and manage the passwords it is responsible for rotating.

  4. What is the recommended network placement for the CyberArk Vault server itself?

    Answer: In an isolated network segment with strictly controlled access

    The Vault should be placed in a highly restricted, isolated network segment with minimal open firewall rules to reduce its attack surface.

  5. When setting up CyberArk with high availability, what role does a 'DR Vault' play?

    Answer: It serves as a hot standby that can take over if the primary Vault fails

    A DR (Disaster Recovery) Vault continuously replicates data from the primary Vault and can be promoted to take over operations if the primary becomes unavailable.

  6. Which file on the CyberArk Vault server controls the maximum number of concurrent Vault connections?

    Answer: Vault.ini

    The Vault.ini file contains configuration parameters including connection limits that control how many concurrent client connections the Vault accepts.

  7. After installing PSM, which CyberArk configuration step enables users to connect through it via the PVWA?

    Answer: Enabling PSM in the PVWA System Configuration and linking it to a PSM Server Safe

    The PSM must be enabled in PVWA's System Configuration settings and associated with the correct PSM Server Safe so PVWA can route connection requests through it.