
CyberArk CAU201 Premium Exam Engine pdf - Download Free Updated 114 Questions
Verified CAU201 Bundle Real Exam Dumps PDF
Understanding functional and technical aspects of CyberArk Password Management Configuration
The following will be discussed in the CAU-201 dumps:
- Configure Management of Workstation Passwords using Loosely Connected Devices
- Add a User/Group to a safe in accordance with access control policies
- Manage the password of a supported usage
- Configure a reconcile account
- Configure Safe Retention
- Duplicate a Platform
- Provision a Safe
- Properly configure the âSearchForUsagesâ Platform parameter
- Configure a logon account
- Follow a safe naming convention
- Configure workflow processes to reduce the risk of credential theft
- Configure workflow processes to ensure non-repudiation
- Import a Custom Platform from the Marketplace
- Setup automatic verification, management, and reconciliation of passwords or SSH Keys
- Configure a request/approval process
- Configure workflow processes to comply with audit/regulatory policies
- Use an OOB Platform to manage a device
- Explain the differences between a logon versus a reconcile account
Understanding functional and technical aspects of CyberArk Security and Audit
The following will be discussed in the CAU-201 dumps:
- Configure Automatic Session Termination
- Grant appropriate permission to allow users to run reports
- Understand the purpose of EVD
- Search for a recording
- Describe all reports and what information they give a user
- Describe the various PTA detections
- Utilize safe permissions to limit the scope of reports for specific users
- Configure a Response to Unmanaged Credentials
- Configure a Response to Credential Theft
- Configure email alerts in PTA
- Review a recording
NEW QUESTION 15
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?
- A. Session suspension
- B. Password reconciliation
- C. Session termination
- D. Password change
Answer: D
NEW QUESTION 16
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 17
What is the primary purpose of Dual Control?
- A. Non-repudiation (individual accountability)
- B. More frequent password changes
- C. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.
- D. Reduced risk of credential theft
Answer: C
NEW QUESTION 18
Which of the following options is not set in the Master Policy?
- A. Enabling and Disabling of the Connection Through the PSM
- B. Password Expiration Time
- C. The use of "One-Time-Passwords"
- D. Password Complexity
Answer: D
NEW QUESTION 19
Customers who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 20
When on-boarding account using Accounts Feed, which of the following is true?
- A. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
- B. You can specify the name of a new Platform that will be created and associated with the account.
- C. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated
with. - D. You can specify the name of a new safe that will be created where the account will be stored when it is on-
boarded to the Vault.
Answer: B
Explanation:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/
NEW QUESTION 21
Which of the following logs contains information about errors related to PTA?
- A. pm_error.log
- B. diamond.log
- C. WebApplication.log
- D. ITAlog.log
Answer: B
NEW QUESTION 22
As long as you are a member of the Vault Admins group you can grant any permission on any safe.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 23
Which of the following statements are NOT true when enabling PSM recording for a target Windows server?
Choose all that apply.
- A. PSMConnect must be added as a local user on the target server.
- B. RDP must be enabled on the target server.
- C. The PSM software must be installed on the target server.
- D. PSM must be enabled in the Master Policy (either directly, or through exception).
Answer: A
NEW QUESTION 24
CyberArk implements license limits by controlling the number and types of users that can be provisioned in the
vault.
- A. TRUE
- B. FALSE
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Managing-the-
CyberArk-License.htm
NEW QUESTION 25
Which combination of Safe member permissions will allow end users to log in to a remote machine transparently but NOT show or copy the password?
- A. List Accounts, Retrieve Accounts
- B. Use Accounts, List Accounts
- C. Use Accounts, Retrieve Accounts, List Accounts
- D. Use Accounts
Answer: A
NEW QUESTION 26
Which CyberArk components products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.
- A. Discovery and Audit (DNA)
- B. Accounts Discovery
- C. Auto Detection (AD)
- D. Export Vault Data (EVD)
- E. On Demand Privileges manager (OPM)
Answer: A,B
NEW QUESTION 27
Which report provides a list of account stored in the vault.
- A. Privileged Accounts Compliance Status
- B. Entitlement Report
- C. Active Log
- D. Privileged Accounts Inventory
Answer: C
NEW QUESTION 28
Which service should NOT be running on the DR Vault when the primary Production Vault is up?
- A. CyberArk Vault Disaster Recovery (DR) service
- B. PrivateArk Database
- C. PrivateArk Server
- D. CyberArk Logical Container
Answer: C
NEW QUESTION 29
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. Yes, if a logon account is associated with the root account.
- B. Yes, only if a logon account is associated with the root account and the user connects through the PSM- SSH connection component.
- C. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
- D. No, it is not possible.
Answer: B
Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/7zx8w5/ssh_connection/
NEW QUESTION 30
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- B. Log in to the system as the logon account, then change roofs password
- C. None of these
- D. Log in to the system as root, then change root's password
Answer: A
NEW QUESTION 31
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.
- A. TRUE
- B. FALSE
Answer: B
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/MESSAGES/Password
%20Vault%20Web%20Access%20Messages-%20General.htm
NEW QUESTION 32
Which parameter controls how often the CPM looks for Soon-to-be-expired Passwords that need to be
changed.
- A. ImmediateInterval
- B. HeadStartInterval
- C. Interval
- D. The CPM does not change the password under this circumstance
Answer: A
NEW QUESTION 33
What is the purpose of the Interval setting in a CPM policy?
- A. To control how often the CPM looks for System Initiated CPM work.
- B. To control the maximum amount of time the CPM will wait for a password change to complete.
- C. To control how often the CPM looks for User Initiated CPM work.
- D. To control how long the CPM rests between password changes.
Answer: A
NEW QUESTION 34
Which Cyber Are components or products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.
- A. On Demand Privileges Manager (OPM)
- B. Discovery and Audit (DMA)
- C. Accounts Discovery
- D. Auto Detection (AD)
- E. Export Vault Data (EVD)
Answer: B,C,D
NEW QUESTION 35
By default, members of which built-in groups will be able to view and configure Automatic Remediation and Session Analysis and Response in the PVWA?
- A. Security Operators
- B. Security Admins
- C. Vault Admins
- D. Auditors
Answer: B
NEW QUESTION 36
When managing SSH keys, the CPM stored the Private Key
- A. On the target server
- B. Nowhere because the private key can always be generated from the public key.
- C. A & B
- D. In the Vault
Answer: D
NEW QUESTION 37
......
Pass Your CyberArk Exam with CAU201 Exam Dumps: https://www.lead2passexam.com/CyberArk/valid-CAU201-exam-dumps.html
CAU201 Dumps PDF New [2021] Ultimate Study Guide: https://drive.google.com/open?id=11UqgyDzROwQcvtcAjCpPcnTl8XpuvRWZ