CAD Access Controls 3 — Questions and Answers
Question 1: In CyberArk's Master Policy, which setting controls whether users must provide a reason when checking out a privileged account?
- Require dual control password access approval
- Enforce check-in/check-out exclusive access
- Require users to specify reason for access (Correct answer)
- Allow EPV transparent connections
Correct answer: Require users to specify reason for access
The 'Require users to specify reason for access' Master Policy rule forces users to document a justification that is logged with every credential retrieval.
Question 2: A Vault admin needs to grant a new security team member the ability to manage Safe memberships but NOT retrieve passwords. Which permission set is appropriate?
- Retrieve accounts + Manage Safe
- Manage Safe members only (Correct answer)
- List accounts + Retrieve accounts
- Authorize account requests + Retrieve accounts
Correct answer: Manage Safe members only
Granting only 'Manage Safe members' allows the user to add/remove Safe members and adjust permissions without giving them access to the stored credentials.
Question 3: Which CyberArk feature allows a SOC analyst to gain temporary elevated privileges to a target system for a defined period without permanently owning the account?
- Just-In-Time (JIT) provisioning via CyberArk Conjur
- On-demand privileges via CyberArk Privilege Cloud
- Just-In-Time Access through the PVWA request workflow (Correct answer)
- Dynamic privilege assignment via the CPM
Correct answer: Just-In-Time Access through the PVWA request workflow
CyberArk's Just-In-Time (JIT) access workflow in PVWA allows temporary, time-boxed privilege grants that expire automatically, reducing standing access.
Question 4: When a platform has 'One Time Password' (OTP) enabled, what occurs after the privileged session ends?
- The password is deleted from the Vault
- The CPM immediately rotates the password to a new random value (Correct answer)
- The user is prompted to create a new password manually
- The account is disabled in Active Directory
Correct answer: The CPM immediately rotates the password to a new random value
With One Time Password enabled, the CPM automatically changes the credential immediately after the session ends, ensuring each use produces a unique password.
Question 5: What is the role of the 'Authorizer' Safe member permission in a dual control workflow?
- To retrieve passwords on behalf of other users
- To approve or reject access requests submitted by other Safe members (Correct answer)
- To unlock accounts that have been locked by the CPM
- To audit access logs and generate compliance reports
Correct answer: To approve or reject access requests submitted by other Safe members
The Authorizer permission designates a user as an approver who can confirm or deny credential access requests in the dual control workflow.
Question 6: An organization wants to ensure that all privileged SSH sessions to Linux servers are recorded and cannot be bypassed. Which CyberArk component enforces this?
- CPM with SSH key rotation plugin
- PSM with SSH Proxy connection component (Correct answer)
- PVWA with transparent connection enabled
- AIM with SSH credential provider
Correct answer: PSM with SSH Proxy connection component
The PSM SSH Proxy forces all SSH connections through CyberArk, recording the session and preventing direct access that would bypass auditing.
Question 7: In CyberArk, which object type stores the connection parameters, password policy rules, and plugin configurations for a specific account type?
- Safe
- Account
- Platform (Correct answer)
- Policy
Correct answer: Platform
A Platform in CyberArk is a template that defines how passwords are managed, rotated, and connected for a specific target system type (e.g., Windows Domain, Oracle DB).
In CyberArk's Master Policy, which setting controls whether users must provide a reason when checking out a privileged account?