CAD Access Controls 2 — Questions and Answers
Question 1: Which CyberArk component enforces the dual control workflow requiring a second approver before a password can be retrieved?
- Vault
- PVWA (Correct answer)
- CPM
- PSM
Correct answer: PVWA
The Password Vault Web Access (PVWA) enforces dual control workflows, requiring a designated approver to confirm a request before credentials are released.
Question 2: In CyberArk, what is the purpose of the 'Exclusive Access' safe setting?
- It allows only one user to access the safe at a time
- It prevents concurrent password retrievals, locking the account to a single active session (Correct answer)
- It restricts safe access to administrators only
- It encrypts all credentials with a unique key per user
Correct answer: It prevents concurrent password retrievals, locking the account to a single active session
Exclusive Access ensures only one user can check out and use a credential at a time, preventing concurrent use of shared privileged accounts.
Question 3: A user requests access to a Safe but their request remains in 'Pending' status. What is the most likely cause?
- The Safe is full and cannot accept new members
- Dual control requires an approver to confirm the access request (Correct answer)
- The CPM has suspended password rotation
- The user's AD account is disabled
Correct answer: Dual control requires an approver to confirm the access request
A pending request under dual control means no designated approver has yet confirmed the request within the configured approval workflow.
Question 4: Which Safe member permission allows a user to see the list of accounts in a Safe but NOT retrieve their passwords?
- Retrieve accounts
- List accounts (Correct answer)
- View Safe members
- Access Safe without confirmation
Correct answer: List accounts
The 'List accounts' permission lets users see account names within a Safe without granting them the ability to retrieve the actual credentials.
Question 5: When configuring time-based access in CyberArk, where are the allowed access time windows defined?
- In the Master Policy under 'Privileged Access Workflows' (Correct answer)
- In the Safe properties under 'Time Frame'
- In the user account settings in the Vault
- In the platform configuration under 'Connection Components'
Correct answer: In the Master Policy under 'Privileged Access Workflows'
Time-based access restrictions are configured within the Master Policy's Privileged Access Workflows section, defining when users are permitted to retrieve credentials.
Question 6: What happens to an exclusive account checkout if the user's session times out before they manually check it back in?
- The account remains checked out indefinitely until manually released by an admin
- The account is automatically released after the configured checkout duration expires (Correct answer)
- The CPM immediately rotates the password
- The PSM terminates the session and locks the account
Correct answer: The account is automatically released after the configured checkout duration expires
CyberArk automatically releases an exclusive checkout after the configured maximum checkout duration, preventing accounts from being indefinitely locked.
Question 7: Which of the following best describes the 'Access Safe without confirmation' permission in CyberArk?
- Lets a user bypass MFA when accessing the safe
- Allows the user to retrieve credentials without triggering the dual control approval workflow (Correct answer)
- Grants the user immediate safe member approval rights
- Enables direct vault access without PVWA
Correct answer: Allows the user to retrieve credentials without triggering the dual control approval workflow
The 'Access Safe without confirmation' permission exempts specific users from the dual control workflow, letting them retrieve credentials immediately.
Which CyberArk component enforces the dual control workflow requiring a second approver before a password can be retrieved?