リアルなCAU201最新試験PassTest 2023年最新ののCAU201練習テスト問題集を提供しています
全問CAU201問題集でandCyberArk Defenderトレーニングコース受験生を学習してパスさせるCyberArk Defender試験無料問題集!
CyberArk CAU201 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
質問 69
The vault supports Subnet Based Access Control.
- A. TRUE
- B. FALSE
正解: A
質問 70
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
- B. No, it is not possible.
- C. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
- D. Yes, if a logon account is associated with the root account.
正解: A
質問 71
Which one of the following reports is NOT generated by using the PVWA?
- A. Application Inventory
- B. Compliance Status
- C. Account Inventory
- D. Safes List
正解: D
解説:
Explanation/Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/
質問 72
By default, members of which built-in groups will be able to view and configure Automatic Remediation and
Session Analysis and Response in the PVWA?
- A. Security Operators
- B. Security Admins
- C. Auditors
- D. Vault Admins
正解: B
解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/Security-
Configuration.htm
質問 73
A user is receiving the error message "ITATS006E Station is suspended for User jsmith" when attempting to sign into the Password Vault Web Access (PVWA). Which utility would a Vault administrator use to correct this problem?
- A. PVWA
- B. cavaultmanager.exe
- C. createcredfile.exe
- D. PrivateArk
正解: D
質問 74
The System safe allows access to the Vault configuration files.
- A. TRUE
- B. FALSE
正解: B
質問 75
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Timeout
- B. Interval
- C. Min Validity Period
- D. Immediate Interval
正解: C
解説:
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced. This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."
質問 76
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to
change the root account's password the CPM will...
- A. None of these.
- B. Log in to the system as root, then change root's password.
- C. Log in to the system as the logon account, run the su command to log in as root, and then change root's
password. - D. Log in to the system as the logon account, then change root's password
正解: B
質問 77
In a rule using "Privileged Session Analysis and Response" in PTA, which session options are available to configure as responses to activities?
- A. Suspend, Terminate
- B. Suspend, Terminate, None
- C. Suspend, Terminate, Lock Account
- D. Pause, Terminate, None
正解: A
質問 78
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems
- A. Oracle
- B. All of the above
- C. Windows
- D. UNIX
正解: C
質問 79
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?
- A. Over-Pass-The-Hash
- B. Golden Ticket
- C. Suspected credential theft
- D. Unmanaged privileged access
正解: B
質問 80
Which Cyber Are components or products can be used to discover Windows Services or Scheduled Tasks that use privileged accounts? Select all that apply.
- A. Discovery and Audit (DMA)
- B. On Demand Privileges Manager (OPM)
- C. Auto Detection (AD)
- D. Export Vault Data (EVD)
- E. Accounts Discovery
正解: A,C,E
質問 81
For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.
- A. On the safe in which the account is stored grant the group the' Access safe without confirmation' authorization.
- B. On the safe in which the account is stored grant the group the' Access safe without audit' authorization.
- C. Edith the master policy rule and modify the advanced' Access safe without approval' rule to include the group.
- D. Create an exception to the Master Policy to exclude the group from the workflow process.
正解: A
質問 82
For a safe with Object Level Access enabled you can turn off Object Level Access Control when it no longer needed on the safe.
- A. TRUE
- B. FALSE
正解: B
質問 83
Platform settings are applied to______________.
- A. Network Areas
- B. The entire vault.
- C. Individual Accounts
- D. Safes
正解: D
解説:
Explanation
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/avxnxz/safes_and_platform_association/
質問 84
A Logon Account can be specified in the Master Policy.
- A. TRUE
- B. FALSE
正解: B
質問 85
If a user is a member of more than one group that has authorizations on a safe, by default that user is
granted____________________.
- A. only those permissions that exist on the group added to the safe first.
- B. the vault will not allow this situation to occur.
- C. only those permissions that exist in all groups to which the user belongs.
- D. the cumulative permissions of all the groups to which that user belongs.
正解: A
質問 86
You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account.
How should this be configured to allow for password management using least privilege?
- A. Configure each CPM to use the correct logon account.
- B. Configure the UNIX platform to use the correct reconcile account.
- C. Configure each CPM to use the correct reconcile account.
- D. Configure the UNIX platform to use the correct logon account.
正解: D
質問 87
Target account platforms canbe restricted to accounts that are stored m specific Safes using the AllowedSafes property.
- A. TRUE
- B. FALSE
正解: A
質問 88
Which is the primary purpose of exclusive accounts?
- A. Non-repudiation (individual accountability)
- B. More frequent password changes
- C. Reduced risk of credential theft
- D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization
正解: A
質問 89
For each listed prerequisite, identify if it is mandatory or not mandatory to run the PSM Health Check.
正解:
解説:
質問 90
The Password upload utility can be used to create safes.
- A. TRUE
- B. FALSE
正解: B
質問 91
......
有効な学習方法でCyberArkのCAU201試験をパス:https://www.passtest.jp/CyberArk/CAU201-shiken.html
無料テストエンジンCyberArk Defender認定試験:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK