nerdexam
CyberArk

PAM-DEF · Question #150

You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How should…

The correct answer is C. Configure the UNIX platform to use the correct logon account. The logon account can be defined on the target account level or on the platform level, making it available to all accounts associated with the platform. Note: Logon accounts can also be defined for PSM and PSM for SSH connections. In this case, they can be retrieved from the…

Managing and Protecting Privileged Accounts and Credentials

Question

You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary account. How should this be configured to allow for password management using least privilege?

Options

  • AConfigure each CPM to use the correct logon account.
  • BConfigure each CPM to use the correct reconcile account.
  • CConfigure the UNIX platform to use the correct logon account.
  • DConfigure the UNIX platform to use the correct reconcile account.

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    14% (6)
  • C
    74% (32)
  • D
    7% (3)

Explanation

The logon account can be defined on the target account level or on the platform level, making it available to all accounts associated with the platform. Note: Logon accounts can also be defined for PSM and PSM for SSH connections. In this case, they can be retrieved from the account level only. https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/13.0/en/Content/PASIMP/Linked-PAS- Accounts.htm#Overview

Topics

#UNIX root account#CPM logon account#platform configuration#least privilege

Community Discussion

No community discussion yet for this question.

Full PAM-DEF Practice