PAM-DEF · Question #124
In the screenshot displayed, you just configured the usage in CyberArk and want to update its password. What is the least intrusive way to accomplish this?
The correct answer is B. Use the "change" button on the parent account's details page. In CyberArk, a "usage" is a dependent account linked to a parent account - the parent holds the actual credential that the usage references. Using the Change button on the parent account's details page is the least intrusive approach because it initiates a normal, controlled…
Question
In the screenshot displayed, you just configured the usage in CyberArk and want to update its password. What is the least intrusive way to accomplish this?
Exhibits
Options
- AUse the "change" button on the usage's details page.
- BUse the "change" button on the parent account's details page.
- CUse the "sync" button on the usage's details page.
- DUse the "reconcile" button on the parent account's details page.
How the community answered
(28 responses)- A11% (3)
- B79% (22)
- C4% (1)
- D7% (2)
Explanation
In CyberArk, a "usage" is a dependent account linked to a parent account - the parent holds the actual credential that the usage references. Using the Change button on the parent account's details page is the least intrusive approach because it initiates a normal, controlled password change at the source, which then propagates to the usage automatically as designed.
Why the distractors are wrong:
- A (Change on the usage): Triggering a change directly on the usage bypasses the proper parent-controlled workflow and can cause sync conflicts or unexpected behavior with the linked parent account.
- C (Sync on the usage): Sync is used to align the usage's stored password with what the parent already has - it doesn't change the password, it corrects a mismatch that already exists.
- D (Reconcile on the parent): Reconciliation is a corrective, more forceful action that overwrites the password on the target system to match the vault - it's reserved for remediation scenarios, not routine updates, making it more intrusive than a standard change.
Memory tip: Think "manage at the source" - since the usage depends on the parent, always act on the parent for password changes, just as you'd update a master template rather than each copy individually.
Topics
Community Discussion
No community discussion yet for this question.

