[2022年01月] 最新のCyberArk Defender CAU201試験解答豪華セット問題集
CyberArkコンテンツをマスターしてCAU201試験合格保証つき問題集!
CyberArk CAU201 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
質問 94
Which of the following Privileged Session Management solutions provide a detailed audit log of session
activities?
- A. All of the above
- B. PSM (i.e., launching connections by clicking on the "Connect" button in the PVWA)
- C. PSM for Windows (previously known as RDP Proxy)
- D. PSM for SSH (previously known as PSM SSH Proxy)
正解: B
質問 95
What is the purpose of the Interval setting in a CPM policy?
- A. To control how often the CPM looks for User Initiated CPM work.
- B. To control how long the CPM rests between password changes.
- C. To control the maximum amount of time the CPM will wait for a password change to complete.
- D. To control how often the CPM looks for System Initiated CPM work.
正解: B
質問 96
What is the primary purpose of Dual Control?
- A. More frequent password changes
- B. Non-repudiation (individual accountability)
- C. Reduced risk of credential theft
- D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.
正解: D
解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Dual-
Control.htm
質問 97
When on-boarding account using Accounts Feed, which of the following is true?
- A. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
- B. You can specify the name of a new Platform that will be created and associated with the account.
- C. You can specify the name of a new safe that will be created where the account will be stored when it is on-
boarded to the Vault. - D. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated
with.
正解: B
解説:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/
質問 98
Which of the following statements are NOT true when enabling PSM recording for a target Windows server?
Choose all that apply.
- A. The PSM software must be installed on the target server.
- B. RDP must be enabled on the target server.
- C. PSMConnect must be added as a local user on the target server.
- D. PSM must be enabled in the Master Policy (either directly, or through exception).
正解: C
質問 99
Which of the following options is not set in the Master Policy?
- A. Password Complexity
- B. The use of "One-Time-Passwords"
- C. Enabling and Disabling of the Connection Through the PSM
- D. Password Expiration Time
正解: A
質問 100
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as the logon account, then change roofs password
- B. Log in to the system as root, then change root's password
- C. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- D. None of these
正解: C
質問 101
The Vault administrator can change the Vault license by uploading the new license to the system Safe.
- A. True
- B. False
正解: A
質問 102
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to change the root account's password the CPM will...
- A. Log in to the system as root, then change root's password.
- B. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- C. None of these.
- D. Log in to the system as the logon account, then change root's password
正解: A
質問 103
Which one of the following reports is NOT generated by using the PVWA?
- A. Compliance Status
- B. Account Inventory
- C. Safes List
- D. Application Inventory
正解: C
解説:
Explanation/Reference:
Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/
質問 104
The Accounts Feed contains:
- A. All users added to CyberArk in the last 30 days
- B. Accounts that were discovered by CyberArk in the last 30 days
- C. Accounts that were discovered by CyberArk that have not yet been onboarded
- D. All accounts added to the vault in the last 30 days
正解: B
解説:
Explanation
質問 105
CyberArk implements license limits by controlling the number and types of users that can be provisioned in the vault.
- A. TRUE
- B. FALSE
正解: A
解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Managing-the- CyberArk-License.htm
質問 106
Which of the Following can be configured in the Master Poky? Choose all that apply.
- A. One Time Passwords
- B. Dual Control
- C. Exclusive Passwords
- D. Password Reconciliation
- E. Required Properties
- F. Custom Connection Components
- G. Ticketing Integration
- H. Password Aging Rules
正解: A,B,C,H
質問 107
SAFE Authorizations may be granted to____________.
Select all that apply.
- A. LDAP Users
- B. Vault Group
- C. Vault Users
- D. LDAP Groups
正解: D
質問 108
As long as you are a member of the Vault Admins group, you can grant any permission on any safe that you have access to.
- A. FALS
- B. TRUE
正解: B
質問 109
You receive this error:
"Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied." Which root cause should you investigate?
- A. The CPM service is disabled and will need to be restarted.
- B. The password has been changed recently and minimum password age is preventing the change.
- C. The domain controller is unreachable.
- D. The account does not have sufficient permissions to change its own password.
正解: D
質問 110
Match the log file name with the CyberArk Component that generates the log.
正解:
解説:
質問 111
......
あなたを合格させるCyberArk CAU201試験専門問題集はここにある:https://www.passtest.jp/CyberArk/CAU201-shiken.html
最新CyberArk Defender CAU201練習テストに最速準備問題をゲットせよ:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK