CAU201無料試験問題と解答PDF最新問題2022年11月 [Q72-Q93]

Share

CAU201無料試験問題と解答PDF最新問題2022年11月

最新CAU201試験問題集で最近更新された179問題

質問 72
Target account platforms can be restricted to accounts that are stored in specific Safes using the AllowedSafes property.

  • A. FALSE
  • B. TRUE

正解: A

 

質問 73
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems

  • A. Windows
  • B. UNIX
  • C. Oracle
  • D. All of the above

正解: A

 

質問 74
The vault supports Role Based Access Control.

  • A. FALSE
  • B. TRUE

正解: A

解説:
Reference https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Object-Level-Access-Control.htm

 

質問 75
A new domain controller has been added to your domain. You need to ensure the CyberArk infrastructure can use the new domain controller for authentication.
Which locations must you update?

  • A. on the Vault server in the certificate store and on the PVWA server in the certificate store
  • B. on the Vault server in Windows\System32\Etc\Hosts and in the PVWA Application under Administration > LDAP Integration > Directories > Hosts
  • C. in the Private Ark client under Tools > Administrative Tools > Directory Mapping
  • D. on the Vault server in Windows\System32\Etc\Hosts and on the PVWA server in Windows\System32\Etc\Hosts

正解: C

解説:
Reference:
%20user%20management%20using%20LDAP%7C_____2

 

質問 76
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?

  • A. Timeout
  • B. Interval
  • C. Immediate Interval
  • D. Min Validity Period

正解: B

 

質問 77
Assuming a safe has been configured to be accessible during certain hours of the day, a Vault Admin may still access that safe outside of those hours.

  • A. FALSE
  • B. TRUE

正解: A

 

質問 78
Which CyberArk utility allows you to create lists of Master Policy Settings, owners and safes for output to text files or MSSQL databases?

  • A. Export Vault Data
  • B. Export Vault Information
  • C. Privileged Threat Analytics
  • D. PrivateArk Client

正解: A

 

質問 79
Which of the following files must be created or configured m order to run Password Upload Utility? Select all that apply.

  • A. conf.ini
  • B. PACli.ini
  • C. A comma delimitedupload file
  • D. Vault.ini

正解: C

 

質問 80
The vault supports Subnet Based Access Control.

  • A. TRUE
  • B. FALSE

正解: A

 

質問 81
When managing SSH keys, the CPM stored the Private Key

  • A. A & B
  • B. On the target server
  • C. In the Vault
  • D. Nowhere because the private key can always be generated from the public key.

正解: C

 

質問 82
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?

  • A. PSMAdminConnect
  • B. PSMMaster
  • C. PSMGwUser
  • D. PSMConnect

正解: A

 

質問 83
Users can be restricted through certain CyberArk interfaces (e.g. PVWA or PACLI).

  • A. TRUE
  • B. FALSE

正解: A

 

質問 84
A Reconcile Account can be specified in the Master Policy.

  • A. TRUE
  • B. FALS

正解: A

 

質問 85
What is the purpose of the HeadStartlnterval setting m a platform?

  • A. It instructs the AIM Provider to 'skip the cache' during the defined time period
  • B. It determines how far in advance audit data is collected tor reports
  • C. It instructs the CPM to initiate the password change process X number of days before expiration.
  • D. It alerts users of upcoming password changes x number of days before expiration.

正解: C

解説:
Explanation
The number of days before the password expires (according to the ExpirationPeriod parameter) that the CPM will initiate a password change process. This parameter is not relevant if the policy will be applied to a member of an account group.

 

質問 86
Which of the following statements are NOT true when enabling PSM recording for a target Windows server? (Choose all that apply)

  • A. RDP must be enabled on the target server
  • B. The PSM software must be instated on the target server
  • C. PSM must be enabled in the Master Policy (either directly, or through exception)
  • D. PSMConnect must be added as a local user on the target server

正解: B,C

 

質問 87
Match the connection component to the corresponding OS/Function.

正解:

解説:

 

質問 88
Your organization has a requirement to allow users to "check out passwords" and connect to targets with the same account through the PSM.
What needs to be configured in the Master policy to ensure this will happen?

  • A. Enforce check-in/check-out exclusive access = active; Record and save session activity = inactive
  • B. Enforce check-in/check-out exclusive access = inactive; Require privileged session monitoring and isolation = inactive
  • C. Enforce check-in/check-out exclusive access = active; Require privileged session monitoring and isolation = active
  • D. Enforce check-in/check-out exclusive access = inactive; Record and save session activity = active

正解: D

 

質問 89
The password upload utility must run from the CPM server

  • A. FALSE
  • B. TRUE

正解: A

 

質問 90
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....

  • A. None of these
  • B. Log in to the system as the logon account, then change roofs password
  • C. Log in to the system as root, then change root's password
  • D. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.

正解: D

 

質問 91
PSM captures a record of each command that was executed in Unix.

  • A. TRUE
  • B. FALSE

正解: A

 

質問 92
A Vault administrator have associated a logon account to one of their Unix root accounts in the vault. When attempting to verify the root account's password the Central Policy Manager (CPM) will:

  • A. ignore the logon account and attempt to log in as root
  • B. none of these
  • C. log in first with the logon account, then run the SU command to log in as root using the password in the Vault
  • D. prompt the end user with a dialog box asking for the login account to use

正解: D

 

質問 93
......


CyberArk CAU201 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • マスターポリシーを構成してPSM記録を作成する
  • SSHクライアントを使用してSSH接続用のPSMを作成する
トピック 2
  • マスターポリシーを構成してPSMを有効にし、ワークフロープロセスを構成して否認防止を確実にします
トピック 3
  • パスワードまたはSSHキーの自動検証、管理、および調整をセットアップします
  • 暗号化キーの適切な管理過程を維持します
トピック 4
  • 緩く接続されたデバイスを使用してワークステーションパスワードの管理を構成する
  • 適切な説明と重大度でサポートケースを開く
トピック 5
  • Password UploadUtilityまたはRESTを使用してアカウントの一括アップロードを実行します
  • コマンドラインでcreatecredfileを手動で実行して資格情報ファイルを再同期します
トピック 6
  • クレデンシャルの盗難のリスクを軽減するようにワークフロープロセスを構成します
  • PAReplicateバックアップからオブジェクトをボールトに復元します

 

CyberArk CAU201リアル2022年最新のブレーン問題集で模擬試験問題集:https://www.passtest.jp/CyberArk/CAU201-shiken.html

CAU201試験問題リアルCAU201練習問題集:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK