CAD Enterprise Password Vault Policies 2 — Questions and Answers
Question 1: In CyberArk EPV, which platform policy setting controls how frequently the CPM automatically rotates a privileged account password?
- MinValidityPeriod
- ImmediateInterval
- ChangeFrequency (Correct answer)
- AllowedSafes
Correct answer: ChangeFrequency
ChangeFrequency (also called 'Interval') in the platform policy defines how often the CPM automatically changes the password.
Question 2: Which CyberArk policy setting prevents a user from checking out the same password twice in a row without an intervening checkout by another user?
- EnforceCheckinCheck
- RequireReason
- ExclusiveAccountMode (Correct answer)
- AllowMultipleChecks
Correct answer: ExclusiveAccountMode
Exclusive Account Mode ensures only one user holds a password at a time, preventing consecutive re-checkout by the same user.
Question 3: A CyberArk platform's 'OneTimePassword' policy is enabled. What happens to the password after the session ends?
- It expires after 24 hours
- It is immediately changed by the CPM (Correct answer)
- It is archived in the Vault
- The user must manually rotate it
Correct answer: It is immediately changed by the CPM
When OneTimePassword is enabled, the CPM immediately changes the password after the session is terminated or the account is checked in.
Question 4: Which EPV Safe member permission allows a user to retrieve account passwords but NOT modify the Safe's properties?
- Safe Manager
- Retrieve accounts (Correct answer)
- Authorize account requests
- Manage Safe
Correct answer: Retrieve accounts
'Retrieve accounts' grants the ability to view or copy passwords without granting administrative control over the Safe.
Question 5: In CyberArk, what is the purpose of the 'MinValidityPeriod' platform parameter?
- Sets the maximum age of a password before expiration
- Prevents password change for a minimum number of days after last change (Correct answer)
- Defines the minimum password length
- Controls how long a checkout session lasts
Correct answer: Prevents password change for a minimum number of days after last change
MinValidityPeriod ensures the CPM will not change a password again until the specified number of days have passed since the last change.
Question 6: Which component in the CyberArk solution is responsible for enforcing dual-control password access workflow?
- CPM
- PSM
- PVWA (Correct answer)
- EPM
Correct answer: PVWA
The PVWA (Password Vault Web Access) manages the dual-control access request and approval workflow for privileged accounts.
Question 7: A policy requires that passwords contain at least two uppercase letters, two digits, and one special character. Where in CyberArk is this complexity rule configured?
- Safe Properties
- Master Policy
- Platform Password Properties (Correct answer)
- LDAP Integration Settings
Correct answer: Platform Password Properties
Password complexity rules such as character requirements are defined in the Platform's Password Properties section.
In CyberArk EPV, which platform policy setting controls how frequently the CPM automatically rotates a privileged account password?