CAD Vault Management 3 — Questions and Answers
Question 1: In CyberArk's hierarchical permission model, which level takes the highest precedence when there is a conflict between Vault, Safe, and folder permissions?
- Vault-level permissions always win
- Safe-level permissions always win
- The most restrictive permission at any level wins (Correct answer)
- Folder-level permissions override Safe and Vault levels
Correct answer: The most restrictive permission at any level wins
CyberArk applies the most restrictive permission across all levels, so a deny or missing permission at any level blocks the action even if higher levels grant it.
Question 2: What is the role of the 'Owners' group within a CyberArk Safe?
- They are automatically notified of all password changes
- They have full control including the ability to manage Safe membership (Correct answer)
- They can view passwords but cannot modify Safe settings
- They serve as approvers in dual-control workflows only
Correct answer: They have full control including the ability to manage Safe membership
Safe Owners have full administrative rights over the Safe, including managing other members' permissions and configuring Safe properties.
Question 3: Which CyberArk Vault feature automatically backs up the entire Vault database to a secondary location at scheduled intervals?
- Vault replication
- Transparent Data Encryption
- Disaster Recovery Vault (Correct answer)
- Safe archiving
Correct answer: Disaster Recovery Vault
The Disaster Recovery (DR) Vault uses built-in replication to continuously or periodically sync the primary Vault's data to a secondary DR Vault server.
Question 4: When a CyberArk Safe has the 'Require reason for access' option enabled, where is the user-provided reason stored?
- In the password object's metadata
- In the Vault audit log linked to the access event (Correct answer)
- In the SIEM system via syslog forwarding
- In the user's Active Directory account attributes
Correct answer: In the Vault audit log linked to the access event
The reason entered by the user is captured and stored in the Vault's immutable audit log, associated with the specific access event.
Question 5: A security team wants to ensure that when a privileged account password is checked out, no other user can check it out simultaneously. Which Safe setting achieves this?
- Enable 'One-time password' mode
- Enable 'Exclusive access' mode (Correct answer)
- Set maximum concurrent sessions to 1 in the platform
- Require dual control approval for all access
Correct answer: Enable 'Exclusive access' mode
Enabling Exclusive Access on a Safe ensures that only one user can hold a checked-out password at a time, preventing concurrent checkouts.
Question 6: Which port does the CyberArk Vault use by default for communication with PVWA and CPM components?
- 443
- 1858 (Correct answer)
- 8080
- 3389
Correct answer: 1858
CyberArk Vault components communicate using port 1858 (TCP) by default for the proprietary CyberArk protocol between server components.
Question 7: What happens to a Safe's contents when the Safe retention period expires in CyberArk?
- All passwords are automatically rotated
- All objects in the Safe are permanently deleted (Correct answer)
- The Safe is archived and becomes read-only
- Access is suspended pending administrator review
Correct answer: All objects in the Safe are permanently deleted
When the retention period of a Safe expires, all objects stored within it are permanently and irreversibly deleted from the Vault.
In CyberArk's hierarchical permission model, which level takes the highest precedence when there is a conflict between Vault, Safe, and folder permissions?