CAD CyberArk Cloud Entitlements 3 — Questions and Answers
Question 1: In Azure, which identity type does CyberArk CEM primarily target when addressing non-human cloud entitlement risks?
- Azure AD Guest Users
- Managed Identities and Service Principals (Correct answer)
- Azure Active Directory Domain Services accounts
- External B2B collaboration users
Correct answer: Managed Identities and Service Principals
CEM focuses on Azure Managed Identities and Service Principals as the primary non-human identities that carry cloud workload permissions.
Question 2: What is the significance of 'cross-account access' risk in AWS as identified by CyberArk CEM?
- It increases S3 storage costs
- A compromised identity in one account can leverage permissions to access resources in other accounts (Correct answer)
- It automatically disables CloudTrail logging
- It prevents VPC peering from functioning
Correct answer: A compromised identity in one account can leverage permissions to access resources in other accounts
Cross-account roles allow an identity compromised in one AWS account to pivot and access resources in other accounts, expanding the blast radius of a breach.
Question 3: How does CyberArk CEM handle multi-cloud environments when an organization uses AWS, Azure, and GCP simultaneously?
- It requires separate installations per cloud
- It provides a unified dashboard with normalized risk views across all three clouds (Correct answer)
- It only supports AWS and Azure together
- It requires manual CSV exports from each cloud
Correct answer: It provides a unified dashboard with normalized risk views across all three clouds
CEM offers a single unified interface that aggregates and normalizes entitlement data across AWS, Azure, and GCP for centralized visibility.
Question 4: Which AWS feature, when misconfigured, allows an attacker to escalate privileges by assuming roles beyond their intended scope?
- S3 bucket policies
- IAM role trust policies with overly broad Principal definitions (Correct answer)
- CloudWatch metric alarms
- AWS Config rules
Correct answer: IAM role trust policies with overly broad Principal definitions
An IAM role trust policy that allows any account or a wildcard principal to assume it can lead to privilege escalation across accounts or services.
Question 5: What remediation action does CyberArk CEM recommend when it detects an IAM user with long-standing unused access keys?
- Rotate the keys every 24 hours automatically
- Deactivate or delete the unused access keys to eliminate stale credential risk (Correct answer)
- Move the keys to AWS Secrets Manager
- Convert the IAM user to a service account
Correct answer: Deactivate or delete the unused access keys to eliminate stale credential risk
Stale, unused access keys represent persistent attack surfaces; CEM recommends deactivating or deleting them to reduce risk.
Question 6: In CyberArk CEM, what is the purpose of the 'Peer Group Analysis' feature?
- Comparing cloud costs between departments
- Benchmarking an identity's permissions against similar identities to detect anomalous over-provisioning (Correct answer)
- Grouping users by geographic region
- Aggregating logs from multiple SIEM tools
Correct answer: Benchmarking an identity's permissions against similar identities to detect anomalous over-provisioning
Peer Group Analysis compares an identity's entitlements against similar identities in the same role or function to flag outliers with excessive permissions.
Question 7: When CyberArk CEM flags a finding as 'Critical,' what does this typically indicate about the cloud entitlement?
- The identity has exceeded its API rate limit
- The identity has permissions that could enable data exfiltration or full environment compromise (Correct answer)
- The identity's MFA device needs replacement
- The cloud account billing is overdue
Correct answer: The identity has permissions that could enable data exfiltration or full environment compromise
Critical findings indicate entitlements that provide paths to catastrophic outcomes such as data theft, lateral movement, or complete cloud environment takeover.
In Azure, which identity type does CyberArk CEM primarily target when addressing non-human cloud entitlement risks?