← All CAD Flashcard Decks

Vault Management Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vault Management flashcards as text
  1. In CyberArk's hierarchical permission model, which level takes the highest precedence when there is a conflict between Vault, Safe, and folder permissions?

    Answer: The most restrictive permission at any level wins

    CyberArk applies the most restrictive permission across all levels, so a deny or missing permission at any level blocks the action even if higher levels grant it.

  2. What is the role of the 'Owners' group within a CyberArk Safe?

    Answer: They have full control including the ability to manage Safe membership

    Safe Owners have full administrative rights over the Safe, including managing other members' permissions and configuring Safe properties.

  3. Which CyberArk Vault feature automatically backs up the entire Vault database to a secondary location at scheduled intervals?

    Answer: Disaster Recovery Vault

    The Disaster Recovery (DR) Vault uses built-in replication to continuously or periodically sync the primary Vault's data to a secondary DR Vault server.

  4. When a CyberArk Safe has the 'Require reason for access' option enabled, where is the user-provided reason stored?

    Answer: In the Vault audit log linked to the access event

    The reason entered by the user is captured and stored in the Vault's immutable audit log, associated with the specific access event.

  5. A security team wants to ensure that when a privileged account password is checked out, no other user can check it out simultaneously. Which Safe setting achieves this?

    Answer: Enable 'Exclusive access' mode

    Enabling Exclusive Access on a Safe ensures that only one user can hold a checked-out password at a time, preventing concurrent checkouts.

  6. Which port does the CyberArk Vault use by default for communication with PVWA and CPM components?

    Answer: 1858

    CyberArk Vault components communicate using port 1858 (TCP) by default for the proprietary CyberArk protocol between server components.

  7. What happens to a Safe's contents when the Safe retention period expires in CyberArk?

    Answer: All objects in the Safe are permanently deleted

    When the retention period of a Safe expires, all objects stored within it are permanently and irreversibly deleted from the Vault.