CAD PAM Basics 2 — Questions and Answers
Question 1: Which CyberArk component is responsible for rotating credentials automatically after they are checked in?
- Central Policy Manager (CPM) (Correct answer)
- Privileged Session Manager (PSM)
- Password Vault Web Access (PVWA)
- Application Identity Manager (AIM)
Correct answer: Central Policy Manager (CPM)
The Central Policy Manager (CPM) automatically rotates credentials based on configured policies after they are checked in.
Question 2: In CyberArk, what term describes an account whose credentials are stored and managed inside the Digital Vault?
- Onboarded account (Correct answer)
- Discovered account
- Pending account
- Shadow account
Correct answer: Onboarded account
An onboarded account is one whose credentials have been brought under CyberArk Vault management.
Question 3: Which PAM concept ensures that each privileged session is recorded and can be audited later?
- Session monitoring (Correct answer)
- Dual control
- Just-in-time access
- Credential checkout
Correct answer: Session monitoring
Session monitoring records privileged sessions so security teams can review, audit, or replay them.
Question 4: What is 'dual control' in the context of CyberArk PAM?
- Requiring a second approver before a password is retrieved (Correct answer)
- Using two separate vaults for redundancy
- Encrypting credentials with two different keys
- Logging into the PVWA with two authentication factors
Correct answer: Requiring a second approver before a password is retrieved
Dual control requires a second authorized user to approve a password retrieval request before it is granted.
Question 5: Which of the following best describes 'standing privileges' in PAM terminology?
- Always-on privileged access that persists even when not needed (Correct answer)
- Temporary access granted for a specific task window
- Read-only access to audit logs
- Shared credentials stored in a password safe
Correct answer: Always-on privileged access that persists even when not needed
Standing privileges are persistent, always-active privileged accounts that pose a higher risk because they are available even when not in use.
Question 6: Which CyberArk feature allows applications to retrieve credentials without embedding them in code?
- Application Identity Manager (AIM) / Credential Provider (Correct answer)
- Central Policy Manager (CPM)
- Privileged Session Manager (PSM)
- Password Vault Web Access (PVWA)
Correct answer: Application Identity Manager (AIM) / Credential Provider
AIM / Credential Provider lets applications request credentials from the Vault at runtime, eliminating hardcoded passwords.
Question 7: In CyberArk's Vault, what is a 'Safe' used for?
- A logical container for storing and controlling access to privileged accounts (Correct answer)
- A physical hardware security module for key storage
- A network segment isolated from production
- A backup copy of the Vault database
Correct answer: A logical container for storing and controlling access to privileged accounts
A Safe is a logical vault partition that holds accounts and files, with its own access controls and audit trail.
Which CyberArk component is responsible for rotating credentials automatically after they are checked in?