[2022] New CAU201 exam dumps Use Updated CyberArk Exam [Q100-Q122]

Share

[2022] New CAU201 exam dumps Use Updated CyberArk Exam

Verified CAU201 Dumps Q&As - CAU201 Test Engine with Correct Answers


Certification Path

Valid Trustee Certification is prerequisite for this exam. Completion will give CyberArk Defender status.

 

NEW QUESTION 100
A Vault Administrator team member can log in to CyberArk, but for some reason, is not given Vault Admin rights.
Where can you check to verify that the Vault Admins directory mapping points to the correct AD group?

  • A. PVWA > User Provisioning > LDAP Integration > Mapping Criteria
  • B. PVWA > Administration > LDAP Integration > Mappings
  • C. PVWA > Administration > LDAP Integration > AD Groups
  • D. PVWA > User Provisioning > LDAP Integration > Map Name

Answer: B

 

NEW QUESTION 101
Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre- determined amount of time?

  • A. Enforce check-in/check-out exclusive access
  • B. Enforce one-time password access
  • C. Enforce check-in/check-out exclusive access & Enforce one-time password access
  • D. Require dual control password access Approval

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud/Latest/en/Content/Privilege%
20Cloud/privCloud-master-policy-rules.htm

 

NEW QUESTION 102
CyberArk recommends implementing object level access control on all Safes.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 103
Within the Vault each password is encrypted by:

  • A. the recovery public key
  • B. its own unique key
  • C. the server key
  • D. the recovery private key

Answer: B

 

NEW QUESTION 104
Users can be restricted through certain CyberArk interfaces (e.g. PVWA or PACLI).

  • A. FALSE
  • B. TRUE

Answer: B

 

NEW QUESTION 105
Which utilities could you use to change debugging levels on the vault without having to restart the vault. Select all that apply.

  • A. Setup.exe
  • B. PAR Agent
  • C. PrivateArk Server Central Administration
  • D. Edit DBParm.ini in a text editor.

Answer: B

 

NEW QUESTION 106
You are creating a Dual Control workflow for a team's safe.
Which safe permissions must you grant to the Approvers group?

  • A. List accounts, Authorize account request
  • B. List accounts, Unlock accounts
  • C. Retrieve accounts, Authorize account request
  • D. Retrieve accounts, Access Safe without confirmation

Answer: C

 

NEW QUESTION 107
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems

  • A. Windows
  • B. UNIX
  • C. Oracle
  • D. All of the above

Answer: A

Explanation:
Explanation/Reference: https://knowhow.tajco-group.com/knowledge-base/using-a-standard-rdp-client-application/

 

NEW QUESTION 108
Assuming a safe has been configured to be accessible during certain hours of the day, a Vault Admin may still access that safe outside of those hours.

  • A. TRUE
  • B. FALSE

Answer: B

Explanation:
Explanation/Reference: https://www.freshers360.com/wp-content/uploads/2019/05/Privileged-Account-Security- Implementation-Guide.pdf

 

NEW QUESTION 109
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.

  • A. FALS
  • B. TRUE

Answer: A

 

NEW QUESTION 110
A user has successfully conducted a short PSM session and logged off. However, the user cannot access the Monitoring tab to view the recordings.
What is the issue?

  • A. The PSM service is not running
  • B. The user must login as PSMAdminConnect
  • C. The user is not a member of the Auditors group
  • D. The user is not a member of the PVWAMonitor group

Answer: C

 

NEW QUESTION 111
Which one of the following reports is NOT generated by using the PVWA?

  • A. Application Inventory
  • B. Compliance Status
  • C. Account Inventory
  • D. Safes List

Answer: D

Explanation:
Explanation/Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/

 

NEW QUESTION 112
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? (Choose three.)

  • A. Store the server key in a Hardware Security Module (HSM) and copy the rest the keys from the CD to a folder on the Vault Server and secure it with NTFS permissions
  • B. Store the CD in a physical safe and mount the CD every time Vault maintenance is performed
  • C. Copy the entire contents of the CD to the system Safe on the Vault
  • D. Copy the entire contents of the CD to a folder on the Vault Server and secure it with NTFS permissions

Answer: A,B,D

 

NEW QUESTION 113
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?

  • A. Interval
  • B. Min Validity Period
  • C. Immediate Interval
  • D. Timeout

Answer: B

Explanation:
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced. This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."

 

NEW QUESTION 114
Which of the following options is not set in the Master Policy?

  • A. Enabling and Disabling of the Connection Through the PSM
  • B. Password Expiration Time
  • C. The use of "One-Time-Passwords"
  • D. Password Complexity

Answer: D

 

NEW QUESTION 115
Which utilities could you use to change debugging levels on the vault without having to restart the vault.
Select all that apply.

  • A. Setup.exe
  • B. PAR Agent
  • C. PrivateArk Server Central Administration
  • D. Edit DBParm.ini in a text editor.

Answer: B

 

NEW QUESTION 116
What is the primary purpose of Dual Control?

  • A. Reduced risk of credential theft
  • B. Non-repudiation (individual accountability)
  • C. More frequent password changes
  • D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.

Answer: D

 

NEW QUESTION 117
Match each key to its recommended storage location.

Answer:

Explanation:

 

NEW QUESTION 118
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?

  • A. Unmanaged privileged access
  • B. Over-Pass-The-Hash
  • C. Suspected credential theft
  • D. Golden Ticket

Answer: D

 

NEW QUESTION 119
SAFE Authorizations may be granted to____________.
Select all that apply.

  • A. Vault Users
  • B. LDAP Groups
  • C. Vault Group
  • D. LDAP Users

Answer: A,B,C,D

 

NEW QUESTION 120
Which of the following properties are mandatory when adding accounts from a file? (Choose three.)

  • A. Safe Name
  • B. All required properties specified in the Platform
  • C. Address
  • D. Platform ID
  • E. Hostname
  • F. Username

Answer: A,B,D

 

NEW QUESTION 121
Which report shows the accounts that are accessible to each user?

  • A. Entitlement report
  • B. Applications Inventory report
  • C. Activity report
  • D. Privileged Accounts Compliance Status report

Answer: A

 

NEW QUESTION 122
......

Pass Your CAU201 Dumps as PDF Updated on 2022 With 179 Questions: https://www.passsureexam.com/CAU201-pass4sure-exam-dumps.html

CyberArk CAU201 Real Exam Questions and Answers FREE: https://drive.google.com/open?id=1MEWA8cOLcKgjP9jGQMt-4wfHF_Ne69VY