[2022年01月] 最新のCyberArk Defender CAU201試験解答豪華セット問題集 [Q94-Q111]

Share

[2022年01月] 最新のCyberArk Defender CAU201試験解答豪華セット問題集

CyberArkコンテンツをマスターしてCAU201試験合格保証つき問題集!


CyberArk CAU201 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Configure the Master Policy to create PSM recordings
  • Make a PSM for SSH Connection using an SSH Client
トピック 2
  • Setup automatic verification, management, and reconciliation of passwords or SSH Keys
  • Maintain an appropriate chain of custody for Encryption Keys
トピック 3
  • Perform a bulk upload of accounts using Password Upload Utility or REST
  • Resync a credential file by running createcredfile manually on the command line
トピック 4
  • Configure the Master Policy to enable the connect button
  • Describe tools that could be used to monitor CyberArk Application Health
トピック 5
  • Configure workflow processes to reduce the risk of credential theft
  • Restore an object to the vault from a PAReplicate Backup
トピック 6
  • Configure the PSM to utilize the HTML5 Gateway
  • Describe how each component communicates with others or devices on network at a high level
トピック 7
  • Setup text based or video based recordings on PSM
  • Identify and locate component configuration files
  • Explain the differences between a logon versus a reconcile account

 

質問 94
Which of the following Privileged Session Management solutions provide a detailed audit log of session
activities?

  • A. All of the above
  • B. PSM (i.e., launching connections by clicking on the "Connect" button in the PVWA)
  • C. PSM for Windows (previously known as RDP Proxy)
  • D. PSM for SSH (previously known as PSM SSH Proxy)

正解: B

 

質問 95
What is the purpose of the Interval setting in a CPM policy?

  • A. To control how often the CPM looks for User Initiated CPM work.
  • B. To control how long the CPM rests between password changes.
  • C. To control the maximum amount of time the CPM will wait for a password change to complete.
  • D. To control how often the CPM looks for System Initiated CPM work.

正解: B

 

質問 96
What is the primary purpose of Dual Control?

  • A. More frequent password changes
  • B. Non-repudiation (individual accountability)
  • C. Reduced risk of credential theft
  • D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.

正解: D

解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Dual-
Control.htm

 

質問 97
When on-boarding account using Accounts Feed, which of the following is true?

  • A. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
  • B. You can specify the name of a new Platform that will be created and associated with the account.
  • C. You can specify the name of a new safe that will be created where the account will be stored when it is on-
    boarded to the Vault.
  • D. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated
    with.

正解: B

解説:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/

 

質問 98
Which of the following statements are NOT true when enabling PSM recording for a target Windows server?
Choose all that apply.

  • A. The PSM software must be installed on the target server.
  • B. RDP must be enabled on the target server.
  • C. PSMConnect must be added as a local user on the target server.
  • D. PSM must be enabled in the Master Policy (either directly, or through exception).

正解: C

 

質問 99
Which of the following options is not set in the Master Policy?

  • A. Password Complexity
  • B. The use of "One-Time-Passwords"
  • C. Enabling and Disabling of the Connection Through the PSM
  • D. Password Expiration Time

正解: A

 

質問 100
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....

  • A. Log in to the system as the logon account, then change roofs password
  • B. Log in to the system as root, then change root's password
  • C. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • D. None of these

正解: C

 

質問 101
The Vault administrator can change the Vault license by uploading the new license to the system Safe.

  • A. True
  • B. False

正解: A

 

質問 102
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to change the root account's password the CPM will...

  • A. Log in to the system as root, then change root's password.
  • B. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • C. None of these.
  • D. Log in to the system as the logon account, then change root's password

正解: A

 

質問 103
Which one of the following reports is NOT generated by using the PVWA?

  • A. Compliance Status
  • B. Account Inventory
  • C. Safes List
  • D. Application Inventory

正解: C

解説:
Explanation/Reference:
Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/

 

質問 104
The Accounts Feed contains:

  • A. All users added to CyberArk in the last 30 days
  • B. Accounts that were discovered by CyberArk in the last 30 days
  • C. Accounts that were discovered by CyberArk that have not yet been onboarded
  • D. All accounts added to the vault in the last 30 days

正解: B

解説:
Explanation

 

質問 105
CyberArk implements license limits by controlling the number and types of users that can be provisioned in the vault.

  • A. TRUE
  • B. FALSE

正解: A

解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Managing-the- CyberArk-License.htm

 

質問 106
Which of the Following can be configured in the Master Poky? Choose all that apply.

  • A. One Time Passwords
  • B. Dual Control
  • C. Exclusive Passwords
  • D. Password Reconciliation
  • E. Required Properties
  • F. Custom Connection Components
  • G. Ticketing Integration
  • H. Password Aging Rules

正解: A,B,C,H

 

質問 107
SAFE Authorizations may be granted to____________.
Select all that apply.

  • A. LDAP Users
  • B. Vault Group
  • C. Vault Users
  • D. LDAP Groups

正解: D

 

質問 108
As long as you are a member of the Vault Admins group, you can grant any permission on any safe that you have access to.

  • A. FALS
  • B. TRUE

正解: B

 

質問 109
You receive this error:
"Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied." Which root cause should you investigate?

  • A. The CPM service is disabled and will need to be restarted.
  • B. The password has been changed recently and minimum password age is preventing the change.
  • C. The domain controller is unreachable.
  • D. The account does not have sufficient permissions to change its own password.

正解: D

 

質問 110
Match the log file name with the CyberArk Component that generates the log.

正解:

解説:

 

質問 111
......

あなたを合格させるCyberArk CAU201試験専門問題集はここにある:https://www.passtest.jp/CyberArk/CAU201-shiken.html

最新CyberArk Defender CAU201練習テストに最速準備問題をゲットせよ:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK