PAM-DEF Exam Questions
233 real PAM-DEF exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51
The Accounts Feed contains:
- Question #52
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems
- Question #53
What is the primary purpose of One Time Passwords?
- Question #54
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.
- Question #55
Ad-Hoc Access (formerly Secure Connect) provides the following features. Choose all that apply.
- Question #56
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by
- Question #57
When managing SSH keys, the CPM stored the Private Key
- Question #58
When managing SSH keys, the CPM stores the Public Key
- Question #59
Accounts Discovery allows secure connections to domain controllers.
- Question #60
Which parameter controls how often the CPM looks for Soon-to-be-expired Passwords that need to be changed.
- Question #61
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.
- Question #62
Which of the following Privileged Session Management solutions provide a detailed audit log of session activities?
- Question #63
What is the primary purpose of Dual Control?
- Question #64
Time of day or day of week restrictions on when password verifications can occur configured in ____________________.
- Question #65
Which parameter controls how often the CPM looks for accounts that need to be changed from recently completed Dual control requests.
- Question #66
According to the DEFAULT Web Options settings, which group grants access to the REPORTS page?
- Question #67
Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre-determined amount of time?
- Question #68
The password upload utility must run from the CPM server
- Question #69
For a safe with Object Level Access enabled you can turn off Object Level Access Control when it no longer needed on the safe.
- Question #70
The vault supports Subnet Based Access Control.
- Question #71
When creating an onboarding rule, it will be executed upon .
- Question #72
How does the Vault administrator apply a new license file?
- Question #73
When Dual Control is enabled a user must first submit a request in the Password Vault Web Access (PVWA) and receive approval before being able to launch a secure connection via PSM...
- Question #74
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?
- Question #75
Via Password Vault Web Access (PVWA), a user initiates a PSM connection to the target Linux machine using RemoteApp. When the client's machine makes an RDP connection to the PSM se...
- Question #76
Which report shows the accounts that are accessible to each user?
- Question #77
The Vault administrator can change the Vault license by uploading the new license to the system Safe.
- Question #78
A Vault administrator have associated a logon account to one of their Unix root accounts in the vault. When attempting to verify the root account's password the Central Policy Mana...
- Question #79
Which is the primary purpose of exclusive accounts?
- Question #80
What is the chief benefit of PSM?
- Question #81
A Simple Mail Transfer Protocol (SMTP) integration is critical for monitoring Vault activity and facilitating workflow processes, such as Dual Control.
- Question #82
CyberArk recommends implementing object level access control on all Safes.
- Question #83
Which of the following logs contains information about errors related to PTA?
- Question #84
An auditor initiates a live monitoring session to PSM server to view an ongoing live session. When the auditor's machine makes an RDP connection the PSM server, which user will be...
- Question #85
Which keys are required to be present in order to start the PrivateArk Server service?
- Question #86
Which of the following Privileged Session Management (PSM) solutions support live monitoring of active sessions?
- Question #87
Within the Vault each password is encrypted by:
- Question #88
When a DR Vault Server becomes an active vault, it will automatically revert back to DR mode once the Primary Vault comes back online.
- Question #89
Which user(s) can access all passwords in the Vault?
- Question #90
Which report could show all accounts that are past their expiration dates?
- Question #91
Which values are acceptable in the address field of an Account?
- Question #92
tsparm.ini is the main configuration file for the Vault.
- Question #93
Which combination of Safe member permissions will allow end users to log in to a remote machine transparently but NOT show or copy the password?
- Question #94
A logon account can be specified in the platform settings.
- Question #95
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?
- Question #96
dbparm.ini is the main configuration file for the Vault.
- Question #97
A user has successfully conducted a short PSM session and logged off. However, the user cannot access the Monitoring tab to view the recordings. What is the issue?
- Question #98
Which of the following components can be used to create a tape backup of the Vault?
- Question #99
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? (Choose thre...
- Question #100
Which of these accounts onboarding methods is considered proactive?