CAD CyberArk Architecture & Components 3 — Questions and Answers
Question 1: Which CyberArk component is specifically designed to detect anomalous privileged account behavior and generate risk-based alerts?
- CPM
- PSM
- PTA (Privileged Threat Analytics) (Correct answer)
- PVWA
Correct answer: PTA (Privileged Threat Analytics)
PTA analyzes behavioral data from CyberArk and external sources to detect and alert on suspicious privileged activity.
Question 2: What is the function of the CyberArk 'Reconcile Account' feature?
- It synchronizes Safe permissions between primary and DR Vault
- It resets a target account password when the CPM-managed password is out of sync (Correct answer)
- It merges duplicate account entries in the Vault
- It validates the PSM recording archive integrity
Correct answer: It resets a target account password when the CPM-managed password is out of sync
Reconciliation uses a separate privileged 'reconcile account' to reset a target account's password when normal CPM rotation fails due to a mismatch.
Question 3: CyberArk's EPM (Endpoint Privilege Manager) primarily addresses which security challenge?
- Securing SSH keys in the Digital Vault
- Removing local admin rights and controlling application execution on endpoints (Correct answer)
- Recording privileged sessions to cloud infrastructure
- Rotating service account passwords in Active Directory
Correct answer: Removing local admin rights and controlling application execution on endpoints
EPM enforces least-privilege on endpoints by removing unnecessary local admin rights and controlling which applications can execute.
Question 4: In CyberArk, which object defines the technical parameters (e.g., connection method, port, prompt patterns) used by the CPM to manage a specific type of target system?
- Safe
- Platform (Plugin) (Correct answer)
- Master Policy
- Connector
Correct answer: Platform (Plugin)
A Platform (also called a CPM plugin) defines how the CPM connects to and rotates credentials on a specific target system type.
Question 5: Which CyberArk Vault component handles encryption key management and is the most sensitive element of the Vault infrastructure?
- PVWA Application Server
- Vault Server with the Server Key (Correct answer)
- CPM Engine
- PSM Server
Correct answer: Vault Server with the Server Key
The Vault Server holds and uses the Server Key (Master CD key) to protect all encrypted data; its compromise would expose the entire Vault.
Question 6: How does PSM for SSH (PSMP) differ from standard PSM in a CyberArk deployment?
- PSMP stores SSH keys in a separate Safe from other credentials
- PSMP allows native SSH clients to connect through it as a transparent proxy (Correct answer)
- PSMP only records sessions and does not enforce isolation
- PSMP is deployed on Windows while PSM runs on Linux
Correct answer: PSMP allows native SSH clients to connect through it as a transparent proxy
PSMP acts as a transparent SSH proxy, allowing users to use native SSH clients while CyberArk still records and isolates the session.
Question 7: What is the significance of the CyberArk 'Operator CD' in Vault initialization?
- It contains the PVWA installation package
- It holds one portion of the Vault's master encryption key required during startup (Correct answer)
- It stores the DR replication certificate
- It is used to reset the PVWA admin password
Correct answer: It holds one portion of the Vault's master encryption key required during startup
The Operator CD contains a split portion of the Vault's encryption key; it must be present during Vault startup to decrypt the Vault data.
Which CyberArk component is specifically designed to detect anomalous privileged account behavior and generate risk-based alerts?