CyberArk CAU201 Premium Exam Engine pdf - Download Free Updated 114 Questions [Q15-Q37]

Share

CyberArk CAU201 Premium Exam Engine pdf - Download Free Updated 114 Questions

Verified CAU201 Bundle Real Exam Dumps PDF


Understanding functional and technical aspects of CyberArk Password Management Configuration

The following will be discussed in the CAU-201 dumps:

  • Configure Management of Workstation Passwords using Loosely Connected Devices
  • Add a User/Group to a safe in accordance with access control policies
  • Manage the password of a supported usage
  • Configure a reconcile account
  • Configure Safe Retention
  • Duplicate a Platform
  • Provision a Safe
  • Properly configure the “SearchForUsages” Platform parameter
  • Configure a logon account
  • Follow a safe naming convention
  • Configure workflow processes to reduce the risk of credential theft
  • Configure workflow processes to ensure non-repudiation
  • Import a Custom Platform from the Marketplace
  • Setup automatic verification, management, and reconciliation of passwords or SSH Keys
  • Configure a request/approval process
  • Configure workflow processes to comply with audit/regulatory policies
  • Use an OOB Platform to manage a device
  • Explain the differences between a logon versus a reconcile account

Understanding functional and technical aspects of CyberArk Security and Audit

The following will be discussed in the CAU-201 dumps:

  • Configure Automatic Session Termination
  • Grant appropriate permission to allow users to run reports
  • Understand the purpose of EVD
  • Search for a recording
  • Describe all reports and what information they give a user
  • Describe the various PTA detections
  • Utilize safe permissions to limit the scope of reports for specific users
  • Configure a Response to Unmanaged Credentials
  • Configure a Response to Credential Theft
  • Configure email alerts in PTA
  • Review a recording

 

NEW QUESTION 15
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?

  • A. Session suspension
  • B. Password reconciliation
  • C. Session termination
  • D. Password change

Answer: D

 

NEW QUESTION 16
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.

  • A. TRUE
  • B. FALSE

Answer: A

 

NEW QUESTION 17
What is the primary purpose of Dual Control?

  • A. Non-repudiation (individual accountability)
  • B. More frequent password changes
  • C. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.
  • D. Reduced risk of credential theft

Answer: C

 

NEW QUESTION 18
Which of the following options is not set in the Master Policy?

  • A. Enabling and Disabling of the Connection Through the PSM
  • B. Password Expiration Time
  • C. The use of "One-Time-Passwords"
  • D. Password Complexity

Answer: D

 

NEW QUESTION 19
Customers who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.

  • A. TRUE
  • B. FALSE

Answer: B

 

NEW QUESTION 20
When on-boarding account using Accounts Feed, which of the following is true?

  • A. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
  • B. You can specify the name of a new Platform that will be created and associated with the account.
  • C. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated
    with.
  • D. You can specify the name of a new safe that will be created where the account will be stored when it is on-
    boarded to the Vault.

Answer: B

Explanation:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/

 

NEW QUESTION 21
Which of the following logs contains information about errors related to PTA?

  • A. pm_error.log
  • B. diamond.log
  • C. WebApplication.log
  • D. ITAlog.log

Answer: B

 

NEW QUESTION 22
As long as you are a member of the Vault Admins group you can grant any permission on any safe.

  • A. TRUE
  • B. FALSE

Answer: B

 

NEW QUESTION 23
Which of the following statements are NOT true when enabling PSM recording for a target Windows server?
Choose all that apply.

  • A. PSMConnect must be added as a local user on the target server.
  • B. RDP must be enabled on the target server.
  • C. The PSM software must be installed on the target server.
  • D. PSM must be enabled in the Master Policy (either directly, or through exception).

Answer: A

 

NEW QUESTION 24
CyberArk implements license limits by controlling the number and types of users that can be provisioned in the
vault.

  • A. TRUE
  • B. FALSE

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Managing-the-
CyberArk-License.htm

 

NEW QUESTION 25
Which combination of Safe member permissions will allow end users to log in to a remote machine transparently but NOT show or copy the password?

  • A. List Accounts, Retrieve Accounts
  • B. Use Accounts, List Accounts
  • C. Use Accounts, Retrieve Accounts, List Accounts
  • D. Use Accounts

Answer: A

 

NEW QUESTION 26
Which CyberArk components products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.

  • A. Discovery and Audit (DNA)
  • B. Accounts Discovery
  • C. Auto Detection (AD)
  • D. Export Vault Data (EVD)
  • E. On Demand Privileges manager (OPM)

Answer: A,B

 

NEW QUESTION 27
Which report provides a list of account stored in the vault.

  • A. Privileged Accounts Compliance Status
  • B. Entitlement Report
  • C. Active Log
  • D. Privileged Accounts Inventory

Answer: C

 

NEW QUESTION 28
Which service should NOT be running on the DR Vault when the primary Production Vault is up?

  • A. CyberArk Vault Disaster Recovery (DR) service
  • B. PrivateArk Database
  • C. PrivateArk Server
  • D. CyberArk Logical Container

Answer: C

 

NEW QUESTION 29
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. Yes, if a logon account is associated with the root account.
  • B. Yes, only if a logon account is associated with the root account and the user connects through the PSM- SSH connection component.
  • C. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
  • D. No, it is not possible.

Answer: B

Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/7zx8w5/ssh_connection/

 

NEW QUESTION 30
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....

  • A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • B. Log in to the system as the logon account, then change roofs password
  • C. None of these
  • D. Log in to the system as root, then change root's password

Answer: A

 

NEW QUESTION 31
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.

  • A. TRUE
  • B. FALSE

Answer: B

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/MESSAGES/Password
%20Vault%20Web%20Access%20Messages-%20General.htm

 

NEW QUESTION 32
Which parameter controls how often the CPM looks for Soon-to-be-expired Passwords that need to be
changed.

  • A. ImmediateInterval
  • B. HeadStartInterval
  • C. Interval
  • D. The CPM does not change the password under this circumstance

Answer: A

 

NEW QUESTION 33
What is the purpose of the Interval setting in a CPM policy?

  • A. To control how often the CPM looks for System Initiated CPM work.
  • B. To control the maximum amount of time the CPM will wait for a password change to complete.
  • C. To control how often the CPM looks for User Initiated CPM work.
  • D. To control how long the CPM rests between password changes.

Answer: A

 

NEW QUESTION 34
Which Cyber Are components or products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.

  • A. On Demand Privileges Manager (OPM)
  • B. Discovery and Audit (DMA)
  • C. Accounts Discovery
  • D. Auto Detection (AD)
  • E. Export Vault Data (EVD)

Answer: B,C,D

 

NEW QUESTION 35
By default, members of which built-in groups will be able to view and configure Automatic Remediation and Session Analysis and Response in the PVWA?

  • A. Security Operators
  • B. Security Admins
  • C. Vault Admins
  • D. Auditors

Answer: B

 

NEW QUESTION 36
When managing SSH keys, the CPM stored the Private Key

  • A. On the target server
  • B. Nowhere because the private key can always be generated from the public key.
  • C. A & B
  • D. In the Vault

Answer: D

 

NEW QUESTION 37
......

Pass Your CyberArk Exam with CAU201 Exam Dumps: https://www.lead2passexam.com/CyberArk/valid-CAU201-exam-dumps.html

CAU201 Dumps PDF New [2021] Ultimate Study Guide: https://drive.google.com/open?id=11UqgyDzROwQcvtcAjCpPcnTl8XpuvRWZ