โ† All CAD Flashcard Decks

Setup Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Setup flashcards as text
  1. What happens if the CyberArk Vault's system clock drifts significantly from other components during setup?

    Answer: Authentication failures occur due to Kerberos and certificate timestamp mismatches

    Clock drift causes authentication failures because Kerberos tickets and TLS certificates are time-sensitive, requiring all components to be NTP-synchronized.

  2. During CyberArk installation, what is the purpose of the 'Vault.ini' parameter 'AllowNonStandardFWAddresses'?

    Answer: It permits Vault access from IP ranges outside the default firewall ruleset

    AllowNonStandardFWAddresses lets administrators specify IP ranges that are permitted to connect to the Vault beyond the built-in default firewall rules.

  3. Which CyberArk setup step must occur before the LDAP/AD integration can be used for user authentication?

    Answer: Configuring the LDAP integration in PVWA and binding with a service account

    LDAP/AD integration requires configuring the directory settings in PVWA including specifying the LDAP server, binding with a service account, and mapping user attributes.

  4. What is the role of the CyberArk 'Credential Provider' (CP) component installed on application servers?

    Answer: It allows applications to retrieve credentials from the Vault without storing them locally

    The Credential Provider allows applications to fetch secrets from the Vault at runtime using the AIM SDK or REST, eliminating hard-coded credentials in application configs.

  5. During PSM setup, what Windows configuration is required on the PSM server for session isolation?

    Answer: Remote Desktop Services (RDS) must be installed and configured in Session Host mode

    PSM relies on Windows Remote Desktop Services in Session Host mode to create isolated user sessions for each proxied privileged connection.

  6. When configuring CyberArk Safe permissions during initial setup, what does the 'Owner' permission level grant?

    Answer: Full control including the ability to manage Safe members and permissions

    The Owner permission level grants full control over the Safe including adding/removing members, modifying permissions, and managing all Safe-level settings.

  7. What is the recommended SSL/TLS configuration for the PVWA web server during CyberArk setup?

    Answer: A certificate from an internal or public CA trusted by client browsers should be installed

    PVWA should use a CA-signed certificate (internal or public) to ensure browsers trust the connection and to prevent man-in-the-middle attacks.