Vault Management Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vault Management flashcards as text
Which CyberArk Vault feature allows administrators to define a time window during which a Safe can be accessed, restricting access outside business hours?
Answer: Safe access schedule
Safe access schedules allow administrators to restrict when a Safe can be accessed, enforcing time-based access controls aligned with business hours or maintenance windows.
What is the primary purpose of the CyberArk 'Transparent Data Encryption' (TDE) feature for the Vault?
Answer: It encrypts the Vault's data files on disk at the operating system level
TDE encrypts the Vault's underlying database files on disk, providing protection against unauthorized access to the physical storage media.
An administrator runs the PrivateArk Client and attempts to create a new Safe but the option is grayed out. What is the most likely cause?
Answer: The administrator lacks the 'Add Safes' Vault-level permission
The ability to create Safes requires the 'Add Safes' permission at the Vault level, which is separate from Safe-level or user-level permissions.
In CyberArk, which process validates that a target account's actual password on the remote system matches what is stored in the Vault?
Answer: CPM password verification
The Central Policy Manager (CPM) performs periodic password verification by connecting to the target system and confirming the stored password is still valid.
When a CyberArk Safe is configured with the 'Object-level access control' option, what additional granularity is provided?
Answer: Users can be granted permissions on individual password objects within the Safe rather than the entire Safe
Object-level access control allows administrators to assign different permissions to individual accounts or files within a single Safe, enabling fine-grained access management.
What is the recommended CyberArk best practice for the number of Vault administrators to minimize risk while maintaining operational capability?
Answer: Two to four administrators with clearly defined roles
CyberArk recommends maintaining two to four Vault administrators to ensure availability while limiting the number of highly privileged accounts as a security best practice.
Which CyberArk Vault mechanism prevents an attacker who has stolen a Vault backup file from extracting stored credentials offline?
Answer: All Vault data is encrypted with the Server Key, which is never stored with the data
The Vault's Server Key encrypts all stored data but is kept separately from the database files, making offline decryption of stolen backup files infeasible without the Server Key.