nerdexam
CyberArk

ACCESS-DEF · Question #5

Which statement is correct about the CyberArk Identity Windows Device Trust enrollment process?

The correct answer is C. You can define the maximum number of joinable endpoints.. Option C is correct because CyberArk Identity's Windows Device Trust enrollment settings allow administrators to configure a maximum number of endpoints that can be joined/enrolled - this is a security control to prevent unchecked device sprawl within a tenant. Why the distractor

Access Policy Management

Question

Which statement is correct about the CyberArk Identity Windows Device Trust enrollment process?

Options

  • AAn enrollment code is optional.
  • BThe endpoint does not need to be a domain-joined machine.
  • CYou can define the maximum number of joinable endpoints.
  • DYou can define the minimum number of joinable endpoints.

How the community answered

(36 responses)
  • A
    3% (1)
  • C
    94% (34)
  • D
    3% (1)

Explanation

Option C is correct because CyberArk Identity's Windows Device Trust enrollment settings allow administrators to configure a maximum number of endpoints that can be joined/enrolled - this is a security control to prevent unchecked device sprawl within a tenant.

Why the distractors are wrong:

  • A - An enrollment code is required, not optional; it's the mechanism that authenticates and authorizes a device during enrollment.
  • B - The endpoint must be a domain-joined machine; Device Trust enrollment for Windows specifically requires domain membership as a prerequisite.
  • D - There is no setting for a minimum number of joinable endpoints - that concept doesn't apply to enrollment policy; you cap the ceiling, not set a floor.

Memory tip: Think of it as a "guest list with a cap" - CyberArk lets you set the maximum seats at the party (max endpoints), not a minimum attendance requirement. Max = security boundary; min = nonsensical for enrollment.

Topics

#Device Trust enrollment#endpoint configuration#enrollment limits#CyberArk Identity

Community Discussion

No community discussion yet for this question.

Full ACCESS-DEF Practice