CyberArk
PAM-DEF · Question #200
A password compliance audit found: 1) One-time password access of 20 domain accounts that are members of Domain Admins group in Active Directory are not being enforced. 2) All the sessions of…
The correct answer is A. Edit the Master Policy and add two policy exceptions: enable "Enforce one-time password access". https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/13.0/en/Content/PASIMP/Working-with- Rules.htm?tocpath=Administrator%7CPrivileged%20Accounts%7CSecurity%20Policy%7C_____ 2#MasterPolicyrules
Managing and Monitoring Privileged Sessions
Question
A password compliance audit found: 1) One-time password access of 20 domain accounts that are members of Domain Admins group in Active Directory are not being enforced. 2) All the sessions of connecting to domain controllers are not being recorded by CyberArk PSM. What should you do to address these findings?
Options
- AEdit the Master Policy and add two policy exceptions: enable "Enforce one-time password access",
- BEdit safe properties and add two policy exceptions: enable "Enforce one-time password access",
- CEdit CPM Settings and add two policy exceptions: enable "Enforce one-time password access",
- DContact the Windows Administrators and request them to add two policy exceptions at Active
How the community answered
(24 responses)- A75% (18)
- B4% (1)
- C8% (2)
- D13% (3)
Explanation
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/13.0/en/Content/PASIMP/Working-with- Rules.htm?tocpath=Administrator%7CPrivileged%20Accounts%7CSecurity%20Policy%7C_____ 2#MasterPolicyrules
Topics
#Master Policy#one-time password#PSM recording#policy exceptions
Community Discussion
No community discussion yet for this question.