
Authentic Best resources for CAU302 Test Engine Practice Exam
[2021] CAU302 PDF Questions - Perfect Prospect To Go With Lead2PassExam Practice Exam
NEW QUESTION 109
Which credentials does CyberArk use when managing a target account?
- A. A Domain Administrator account created for this purpose
- B. Those of the service account for the CyberArk Password Manager service
- C. The credentials of the target account
- D. An account assigned by the Master Policy
Answer: B
NEW QUESTION 110
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?
- A. Session suspension
- B. Password reconciliation
- C. Password change
- D. Session termination
Answer: C
NEW QUESTION 111
Via Password Vault Web Access (PVWA), a user initiates a PSM connection to the target Linux machine using RemoteApp. When the client's machine makes an RDP connection to the PSM server, which user will be utilized?
- A. Credentials stored in the Vault for the target machine
- B. Shadowuser
- C. PSMAdminConnect
- D. PSMConnect
Answer: D
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/MESSAGES/RDP%
20file%20and%20RemoteApp%20connections.htm
NEW QUESTION 112
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 113
Which parameter controls how often the Central Policy Manager (CPM) looks for exclusive passwords that need to be changed?
- A. The CPM does not change the password under this circumstance
- B. ImmediateInterval
- C. HeadStartInterval
- D. Interval
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 114
Which user is automatically added to all Safes and cannot be removed?
- A. Operator
- B. Master
- C. Administrator
- D. Auditor
Answer: A
NEW QUESTION 115
Which is the purpose of the HeadStartInterval setting in a platform?
- A. It instructs the AIM provider to 'skip the cache' during the defined time period.
- B. It alerts users of upcoming password changes a certain number of days before expiration.
- C. It instructs the CPM to initiate the password change process certain number of days before expiration.
- D. It determines how far in advance audit data is collected for reports.
Answer: C
NEW QUESTION 116
When working with the CyberArk High Availability Cluster, which services are running on the passive node?
- A. Cluster Vault Manager, PrivateArk Database and Remote Control Agent
- B. Cluster Vault Manager and PrivateArk Database
- C. Cluster Vault Manager and Remote Control Agent
- D. Cluster Vault Manager
Answer: B
NEW QUESTION 117
When using multiple Central Policy Managers (CPM), which one of the following Safes is shared by all CPMs?
- A. PasswordManager_Pending
- B. PasswordManagerSharedSafe
- C. PasswordManager_ADInternal
- D. PasswordManager_workspace
Answer: B
NEW QUESTION 118
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.D18912E1457D5D1DDCBD40AB3BF70D5D
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 119
Which service should NOT be running on the DR Vault when the primary production Vault is up?
- A. CyberArk Logical Container
- B. PrivateArk Server
- C. PrivateArk Database
- D. CyberArk Vault Disaster Recovery Service
Answer: B
NEW QUESTION 120
Which one of the built-in Vault users is not automatically added to the safe when it is first created in PVWA?
- A. Operator
- B. Master
- C. Administrator
- D. Auditor
Answer: A
NEW QUESTION 121
When a DR Vault Server becomes an active vault, it will automatically revert back to DR mode once the Primary Vault comes back online.
- A. True, this is the default behavior.
- B. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the dbparm.ini file.
- C. True, if the AllowFailback setting is set to "yes" in the padr.ini file.
- D. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the padr.ini file.
Answer: D
NEW QUESTION 122
What is the primary purpose of One Time Passwords?
- A. Reduced risk of credential theft
- B. More frequent password changes
- C. Non-repudiation (individual accountability)
- D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization
Answer: A
Explanation:
Explanation
NEW QUESTION 123
What is the purpose of the PrivateArk Database service?
- A. Executes password changes.
- B. Maintains Vault metadata.
- C. Communicates with components.
- D. Sends email alerts from the vault.
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 124
Name two ways of viewing the ITAlog:
- A. Log into the PVWA and go to the Reports tab.
- B. Go to the Thirdpary log directory on the CPM
- C. Log into the vault locally and navigate to the Server folder under the PrivateArk install location.
- D. Access the System Safe from the PrivateArk client.
Answer: C,D
NEW QUESTION 125
An SMTP integration allows you to forward audit records to a monitoring solution.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 126
The Vault administrator can change the Vault license by uploading the new license to the system Safe.
- A. True
- B. False
Answer: A
Explanation:
Explanation/Reference: https://cyberark-customers.force.com/s/article/00002945
NEW QUESTION 127
Which CyberArk components or products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.
- A. Auto Detection (AD)
- B. Discovery and Audit (DNA)
- C. On Demand Privileges Manager (OPM)
- D. Export Vault Data (EVD)
- E. Accounts Discovery
Answer: C,D,E
Explanation:
Explanation/Reference:
NEW QUESTION 128
PTA can automatically suspend sessions in case of suspicious activities detected in a privileged session, only if the session is made via the CyberArk PSM.
- A. False, the PTA can suspend sessions whether the session is made via the PSM or not
- B. True
Answer: A
NEW QUESTION 129
Which report could show all accounts that are past their expiration dates?
- A. Privileged Account Compliance Status report
- B. Applications Inventory report
- C. Privileged Account Inventory report
- D. Activity log
Answer: A
NEW QUESTION 130
PSM generates recordings on the Vault server in real time.
- A. True
- B. False
Answer: A
NEW QUESTION 131
A Vault Administrator wants to change the PSM Server ID to comply with a naming standard. What is the process for changing the PSM Server ID?
- A. Options A and B above is the correct procedure.
- B. First, logon to the PrivateArk Client as Administrator and open the PVWAConfig safe. Retrieve and edit the PVConfiguration.xml file. Search for the PSMServer Name and update the ID of the server you want to rename. Save the file and copy back to the PWAConfig safe. Restart the "CyberArk Privileged Session Manager" service on the PSM server.
- C. Login to the PVWA, then change the PSMServer ID in Administration, System Configuration, Options, Privileged Session Management, Configured PSM Servers. Run an IISRESET on all PVWA servers.
- D. First, login to the PVWA, browse to Administration, System Configuration, Options, Privileged Session Management, Configured PSM Servers and select the PSM Server you need to change from the list of servers. In the properties pane, set the value of the ID property to the new Server ID, click Apply and OK.
Next, edit the basic_psm.ini file located on the PSM server in the PSM root directory and update the PSMServerID parameter with the new Server ID, save the file and restart the "CyberArk Privileged Session Manager" service on the PSM server.
Answer: C
NEW QUESTION 132
SAFE Authorizations may be granted to ________________.
Select all that apply.
- A. LDAP Users
- B. Vault Users
- C. Vault Groups
- D. LDAP Groups
Answer: D
NEW QUESTION 133
......
Best updated resource for CAU302 Online Practice Exam: https://www.lead2passexam.com/CyberArk/valid-CAU302-exam-dumps.html