ACCESS-DEF · Question #5
Which statement is correct about the CyberArk Identity Windows Device Trust enrollment process?
The correct answer is C. You can define the maximum number of joinable endpoints.. Option C is correct because CyberArk Identity's Windows Device Trust enrollment settings allow administrators to configure a maximum number of endpoints that can be joined/enrolled - this is a security control to prevent unchecked device sprawl within a tenant. Why the distractor
Question
Options
- AAn enrollment code is optional.
- BThe endpoint does not need to be a domain-joined machine.
- CYou can define the maximum number of joinable endpoints.
- DYou can define the minimum number of joinable endpoints.
How the community answered
(36 responses)- A3% (1)
- C94% (34)
- D3% (1)
Explanation
Option C is correct because CyberArk Identity's Windows Device Trust enrollment settings allow administrators to configure a maximum number of endpoints that can be joined/enrolled - this is a security control to prevent unchecked device sprawl within a tenant.
Why the distractors are wrong:
- A - An enrollment code is required, not optional; it's the mechanism that authenticates and authorizes a device during enrollment.
- B - The endpoint must be a domain-joined machine; Device Trust enrollment for Windows specifically requires domain membership as a prerequisite.
- D - There is no setting for a minimum number of joinable endpoints - that concept doesn't apply to enrollment policy; you cap the ceiling, not set a floor.
Memory tip: Think of it as a "guest list with a cap" - CyberArk lets you set the maximum seats at the party (max endpoints), not a minimum attendance requirement. Max = security boundary; min = nonsensical for enrollment.
Topics
Community Discussion
No community discussion yet for this question.