リアルなCAU201最新試験は2023年最新のCAU201練習テスト問題集を提供しています [Q69-Q91]

Share

リアルなCAU201最新試験PassTest 2023年最新ののCAU201練習テスト問題集を提供しています

全問CAU201問題集でandCyberArk Defenderトレーニングコース受験生を学習してパスさせるCyberArk Defender試験無料問題集!


CyberArk CAU201 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • 緩く接続されたデバイスを使用してワークステーションパスワードの管理を構成する
  • 適切な説明と重大度でサポートケースを開く
トピック 2
  • Password UploadUtilityまたはRESTを使用してアカウントの一括アップロードを実行します
  • コマンドラインでcreatecredfileを手動で実行して資格情報ファイルを再同期します
トピック 3
  • パスワードまたはSSHキーの自動検証、管理、および調整をセットアップします
  • 暗号化キーの適切な管理過程を維持します
トピック 4
  • マスターポリシーを構成してPSMを有効にし、ワークフロープロセスを構成して否認防止を確実にします
トピック 5
  • PSMでのテキストベースまたはビデオベースの記録のセットアップ
  • コンポーネント構成ファイルの識別と検索
  • ログオンとアカウントの調整の違いを説明する
トピック 6
  • 接続ボタンを有効にするようにマスターポリシーを構成します
  • Cyber​​Arkアプリケーションの状態を監視するために使用できるツールを説明します
トピック 7
  • クレデンシャルの盗難のリスクを軽減するようにワークフロープロセスを構成します
  • PAReplicateバックアップからオブジェクトをボールトに復元します

 

質問 69
The vault supports Subnet Based Access Control.

  • A. TRUE
  • B. FALSE

正解: A

 

質問 70
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
  • B. No, it is not possible.
  • C. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
  • D. Yes, if a logon account is associated with the root account.

正解: A

 

質問 71
Which one of the following reports is NOT generated by using the PVWA?

  • A. Application Inventory
  • B. Compliance Status
  • C. Account Inventory
  • D. Safes List

正解: D

解説:
Explanation/Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/

 

質問 72
By default, members of which built-in groups will be able to view and configure Automatic Remediation and
Session Analysis and Response in the PVWA?

  • A. Security Operators
  • B. Security Admins
  • C. Auditors
  • D. Vault Admins

正解: B

解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Security-
Configuration.htm

 

質問 73
A user is receiving the error message "ITATS006E Station is suspended for User jsmith" when attempting to sign into the Password Vault Web Access (PVWA). Which utility would a Vault administrator use to correct this problem?

  • A. PVWA
  • B. cavaultmanager.exe
  • C. createcredfile.exe
  • D. PrivateArk

正解: D

 

質問 74
The System safe allows access to the Vault configuration files.

  • A. TRUE
  • B. FALSE

正解: B

 

質問 75
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?

  • A. Timeout
  • B. Interval
  • C. Min Validity Period
  • D. Immediate Interval

正解: C

解説:
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced. This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."

 

質問 76
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to
change the root account's password the CPM will...

  • A. None of these.
  • B. Log in to the system as root, then change root's password.
  • C. Log in to the system as the logon account, run the su command to log in as root, and then change root's
    password.
  • D. Log in to the system as the logon account, then change root's password

正解: B

 

質問 77
In a rule using "Privileged Session Analysis and Response" in PTA, which session options are available to configure as responses to activities?

  • A. Suspend, Terminate
  • B. Suspend, Terminate, None
  • C. Suspend, Terminate, Lock Account
  • D. Pause, Terminate, None

正解: A

 

質問 78
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems

  • A. Oracle
  • B. All of the above
  • C. Windows
  • D. UNIX

正解: C

 

質問 79
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?

  • A. Over-Pass-The-Hash
  • B. Golden Ticket
  • C. Suspected credential theft
  • D. Unmanaged privileged access

正解: B

 

質問 80
Which Cyber Are components or products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.

  • A. Discovery and Audit (DMA)
  • B. On Demand Privileges Manager (OPM)
  • C. Auto Detection (AD)
  • D. Export Vault Data (EVD)
  • E. Accounts Discovery

正解: A,C,E

 

質問 81
For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.

  • A. On the safe in which the account is stored grant the group the' Access safe without confirmation' authorization.
  • B. On the safe in which the account is stored grant the group the' Access safe without audit' authorization.
  • C. Edith the master policy rule and modify the advanced' Access safe without approval' rule to include the group.
  • D. Create an exception to the Master Policy to exclude the group from the workflow process.

正解: A

 

質問 82
For a safe with Object Level Access enabled you can turn off Object Level Access Control when it no longer needed on the safe.

  • A. TRUE
  • B. FALSE

正解: B

 

質問 83
Platform settings are applied to______________.

  • A. Network Areas
  • B. The entire vault.
  • C. Individual Accounts
  • D. Safes

正解: D

解説:
Explanation
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/avxnxz/safes_and_platform_association/

 

質問 84
A Logon Account can be specified in the Master Policy.

  • A. TRUE
  • B. FALSE

正解: B

 

質問 85
If a user is a member of more than one group that has authorizations on a safe, by default that user is
granted____________________.

  • A. only those permissions that exist on the group added to the safe first.
  • B. the vault will not allow this situation to occur.
  • C. only those permissions that exist in all groups to which the user belongs.
  • D. the cumulative permissions of all the groups to which that user belongs.

正解: A

 

質問 86
You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account.
How should this be configured to allow for password management using least privilege?

  • A. Configure each CPM to use the correct logon account.
  • B. Configure the UNIX platform to use the correct reconcile account.
  • C. Configure each CPM to use the correct reconcile account.
  • D. Configure the UNIX platform to use the correct logon account.

正解: D

 

質問 87
Target account platforms canbe restricted to accounts that are stored m specific Safes using the AllowedSafes property.

  • A. TRUE
  • B. FALSE

正解: A

 

質問 88
Which is the primary purpose of exclusive accounts?

  • A. Non-repudiation (individual accountability)
  • B. More frequent password changes
  • C. Reduced risk of credential theft
  • D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization

正解: A

 

質問 89
For each listed prerequisite, identify if it is mandatory or not mandatory to run the PSM Health Check.

正解:

解説:

 

質問 90
The Password upload utility can be used to create safes.

  • A. TRUE
  • B. FALSE

正解: B

 

質問 91
......

有効な学習方法でCyberArkのCAU201試験をパス:https://www.passtest.jp/CyberArk/CAU201-shiken.html

無料テストエンジンCyberArk Defender認定試験:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK