100%の合格率を試そう!更新されたのはCAU201試験問題 [2022]
合格させるCAU201試験にはリアル問題解答
CyberArk CAU201 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
質問 40
The Password upload utility can be used to create safes.
- A. FALS
- B. TRUE
正解: B
質問 41
To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?
- A. List Accounts, Use Accounts, Retrieve Accounts
- B. Use Accounts
- C. List Accounts, Use Accounts, Retrieve Accounts, Access Safe without confirmation
- D. List Accounts, Use Accounts
正解: B
質問 42
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by
- A. The number of persons specified by the Master Policy
- B. Any one person from that group
- C. That access cannot be granted to groups
- D. Every person from that group
正解: A
質問 43
You receive this error:
"Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied." Which root cause should you investigate?
- A. The CPM service is disabled and will need to be restarted.
- B. The password has been changed recently and minimum password age is preventing the change.
- C. The domain controller is unreachable.
- D. The account does not have sufficient permissions to change its own password.
正解: D
質問 44
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?
- A. PSMGwUser
- B. PSMAdminConnect
- C. PSMMaster
- D. PSMConnect
正解: B
質問 45
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Timeout
- B. Interval
- C. Immediate Interval
- D. Min Validity Period
正解: D
解説:
Explanation
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced.
This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."
質問 46
The Accounts Feed contains:
- A. All users added to CyberArk in the last 30 days
- B. Accounts that were discovered by CyberArk in the last 30 days
- C. Accounts that were discovered by CyberArk that have not yet been onboarded
- D. All accounts added to the vault in the last 30 days
正解: B
解説:
Explanation
質問 47
Which parameter controls how often the CPM looks for Soon-to-be-expired Passwords that need to be
changed.
- A. Interval
- B. ImmediateInterval
- C. The CPM does not change the password under this circumstance
- D. HeadStartInterval
正解: B
質問 48
If a user is a member of more than one group that has authorizations on a safe, by default that user is
granted____________________.
- A. only those permissions that exist in all groups to which the user belongs.
- B. the cumulative permissions of all the groups to which that user belongs.
- C. the vault will not allow this situation to occur.
- D. only those permissions that exist on the group added to the safe first.
正解: D
質問 49
SAFE Authorizations may be granted to _________________.
Select all that apply.
- A. Vault Groups
- B. LDAP Groups
- C. LDAP Users
- D. Vault Users
正解: D
質問 50
You are onboarding an account that is not supported out of the box.
What should you do first to obtain a platform to import?
- A. Create a service ticket in the customer portal explaining the requirements of the custom platform.
- B. Search common community portals like stackoverflow, reddit, github for an existing platform.
- C. From the platforms page, uncheck the "Hide non-supported platforms" checkbox and see if a platform meeting your needs appears.
- D. Visit the CyberArk marketplace and search for a platform that meets your needs.
正解: A
質問 51
When managing SSH keys, the CPM stores the Public Key
- A. In the Vault
- B. On the target server
- C. A & B
- D. Nowhere because the public key can always be generated from the private key.
正解: B
解説:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/SSHKM/Managing%
20SSH%20Keys.htm
質問 52
What is the name of the Platform parameter that controls how long a password will stay valid when One Time
Passwords are enabled via the Master Policy?
- A. Timeout
- B. Interval
- C. MinValidityPeriod
- D. ImmediateInterval
正解: A
質問 53
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? (Choose three.)
- A. Copy the entire contents of the CD to a folder on the Vault Server and secure it with NTFS permissions
- B. Copy the entire contents of the CD to the system Safe on the Vault
- C. Store the CD in a physical safe and mount the CD every time Vault maintenance is performed
- D. Store the server key in a Hardware Security Module (HSM) and copy the rest the keys from the CD to a folder on the Vault Server and secure it with NTFS permissions
正解: A,C,D
質問 54
Which values are acceptable in the address field of an Account?
- A. It must be a Fully Qualified Domain Name (FQDN)
- B. Any name that is resolvable on the Central Policy Manager (CPM) server is acceptable
- C. It must be an IP address
- D. It must be NetBIOS name
正解: B
質問 55
Which usage can be added as a service account platform?
- A. PowerShell Libraries
- B. IIS Application Pools
- C. Loosely Connected Devices
- D. Kerberos Tokens
正解: C
質問 56
In a default CyberArk installation, which group must a user be a member of to view the "reports" page in PVWA?
- A. ReportUsers
- B. Operators
- C. PVWAMonitor
- D. PVWAReports
正解: C
質問 57
The System safe allows access to the Vault configuration files.
- A. TRUE
- B. FALSE
正解: B
解説:
Explanation/Reference:
質問 58
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as the logon account, then change roofs password
- B. Log in to the system as root, then change root's password
- C. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- D. None of these
正解: C
質問 59
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?
- A. Suspected credential theft
- B. Golden Ticket
- C. Over-Pass-The-Hash
- D. Unmanaged privileged access
正解: B
質問 60
Accounts Discovery allows secure connections to domain controllers.
- A. TRUE
- B. FALSE
正解: B
解説:
Explanation/Reference:
質問 61
Which utilities could you use to change debugging levels on the vault without having to restart the vault. Select all that apply.
- A. Setup.exe
- B. PrivateArk Server Central Administration
- C. PAR Agent
- D. Edit DBParm.ini in a text editor.
正解: C
質問 62
SAFE Authorizations may be granted to____________.
Select all that apply.
- A. Vault Group
- B. LDAP Users
- C. LDAP Groups
- D. Vault Users
正解: A,B,C,D
質問 63
Match each PTA alert category with the PTA sensors that collect the data for it.
正解:
解説:
質問 64
......
CAU201試験問題を最新版を今すぐ試そうの[2022年最新] 正解回答付き:https://www.passtest.jp/CyberArk/CAU201-shiken.html
無料CyberArk CAU201テスト練習問題試験問題集:https://drive.google.com/open?id=1cmSivVnei270OrXrqq9O_9laCyAnEHqK