Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CyberArk Defender - PAM PAM-DEF Exam Questions

Page: 1 / 16 Total 239 questions

Want more questions? Get Premium Access.

Question 1

You need to recover an account localadmin02 for target server 10.0.123.73 stored in Safe Team1.

What do you need to recover and decrypt the object? (Choose three.)

Correct Answer: A. Recovery Private Key; B. Recover.exe; C. Vault data
Explanation:

To recover and decrypt an account that is stored in a Safe, you need the following items:

Recovery Private Key: This is a key that is used to decrypt the data stored in the Vault. It is located on the Master CD, which is a physical CD that contains the Private Recovery Key, a file named RecPrv.key.

Recover.exe: This is a utility that is used to recover information from a Safe's external files in case of loss or corruption of that Safe. The files are decrypted and saved as readable files. The utility can be run from the command line or the graphical user interface.

Vault data: This is the data that is stored in the Vault, such as accounts, safes, platforms, policies, users, groups, and audit records. The Vault data is encrypted using the Recovery Public Key, which is a key that is used to encrypt the data stored in the Vault. The Vault data can be recovered from the Vault server disk drive or from a backup file.


Question 2

PTA can automatically suspend sessions if suspicious activities are detected in a privileged session, but only if the session is made via the CyberArk PSM.

Correct Answer: B. False, the PTA can suspend sessions whether the session is made via the PSM or not
Explanation:

The PTA can automatically suspend sessions if suspicious activities are detected in a privileged session, regardless of the session method. The PTA can suspend sessions that are made via the PSM, the PVWA, or directly to the target system. The PTA can also suspend sessions that are made via SSH, RDP, or other protocols.Reference:

Defender PAM Sample Items Study Guide, page 24

PTA User Guide, page 17


Question 3

Question 4

For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.

Correct Answer: D. On the safe in which the account is stored grant the group the' Access safe without confirmation' authorization.
Explanation:

Dual Control is a feature that requires the approval of another user before accessing a password. It is based on a Master Policy rule that applies to all accounts attached to platforms that have this rule enabled. However, there may be situations where a group of users needs to access a password without approval, such as in an emergency or for troubleshooting purposes. In this case, an exception can be made by granting the group the 'Access safe without confirmation' authorization on the safe in which the account is stored. This authorization bypasses the Dual Control workflow and allows the group to retrieve the password without waiting for approval. However, the password retrieval will still be audited and recorded in the Vault.


Question 5

A recently-hired colleague onboarded five new Local Accounts that are used for five standalone Windows Servers. After attempting to connect to the servers from PVWA, the colleague noticed that the "Connect" button was greyed out for all five new accounts.

What can you do to help your colleague resolve this issue? (Choose two.)

Correct Answer: A. Verify that the address field is populated with an IP or FQDN of each server.; B. Verify that the correct PSM connection component appears within account platform settings.; E. Verify that the 'Disable automatic management for this account' setting for each account is not enabled.
Explanation:

Verify Server Address: Ensure that theaddress fieldis populated with the correctIP or FQDNfor each server (Option A).

Check PSM Settings: Confirm that the correctPSM connection componentis specified within theaccount platform settings(Option B).

Automatic Management: Check if the ''Disable automatic management for this account'' setting isnot enabled(Option E).

These steps should help in troubleshooting the connection issue in the CyberArk Privileged Access Management (PAM) solution.


Question 6

Question 7

When on-boarding account using Accounts Feed, Which of the following is true?

Correct Answer: B. You can specify the name of a new sale that will be created where the account will be stored when it is on-boarded to the Vault.
Explanation:

When on-boarding accounts using Accounts Feed, you can either select an existing safe or create a new one to store the accounts. You can also specify the platform, policy, and owner for each account. However, you cannot create a new platform using Accounts Feed, and not all platforms support automatic reconciliation.Reference:

Accounts Feed - CyberArk

CyberArk University

[Defender-PAM Sample Items Study Guide]


Question 8

Question 9

Question 10

As long as you are a member of the Vault Admins group, you can grant any permission on any safe that you have access to.

Correct Answer: B. FALSE
Explanation:

Being a member of the Vault Admins group does not automatically grant you any permission on any safe that you have access to. The Vault Admins group is a predefined group that is created during the installation or upgrade of the vault.This group has the Vault Admin authorization, which allows its members to perform administrative tasks on the vault, such as managing users, groups, platforms, policies, and safes1.However, this authorization does not include any safe member authorizations, such as View, Retrieve, Use, or Manage Safe2. Therefore, to grant any permission on a safe, you need to be added as a safe member with the appropriate authorizations, either directly or through another group. The Vault Admins group can be added to safes with all safe member authorizations, but this is not done automatically for all safes.By default, this group is only added to a number of system safes, such as the Password Manager Safe, the PVWAConfig Safe, and the Notification Methods Safe3.For other safes, the Vault Admins group can be added manually by the safe owner or another user with the Manage Safe authorization4.Reference:

1:Predefined users and groups, Predefined groups subsection

2: [CyberArk Privileged Access Security Implementation Guide], Chapter 3: Managing Safes, Section: Safe Authorizations, Table 2-1: Safe Authorizations

3:What default groups can be automatically added to Safes when they are created?

4: [CyberArk Privileged Access Security Administration Guide], Chapter 3: Managing Safes, Section: Adding Safe Members


Question 11

Question 12

Question 13

A Vault Administrator team member can log in to CyberArk, but for some reason, is not given Vault Admin rights.

Where can you check to verify that the Vault Admins directory mapping points to the correct AD group?

Question 14

Question 15

You receive this error:

''Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied.''

Which root cause should you investigate?

Correct Answer: A. The account does not have sufficient permissions to change its own password.
Explanation:

The error message ''Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied'' suggests that the account attempting to change the password does not have the necessary permissions to do so. This could be due to several reasons, such as the account not being part of the appropriate group with password change privileges, or specific restrictions set on the account that prevent password changes. It's important to verify the account's permissions and ensure it has the ability to change its own password within the domain.