PAM-DEF Exam Questions
233 real PAM-DEF exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #101
When a DR Vault Server becomes an active vault, it will automatically fail back to the original state once the Primary Vault comes back online.
- Question #102
What is the purpose of the password change process?
- Question #103
What is the purpose of the CyberArk Event Notification Engine service?
- Question #104
PTA can automatically suspend sessions if suspicious activities are detected in a privileged session, but only if the session is made via the CyberArk PSM.
- Question #105
Which service should NOT be running on the DR Vault when the primary Production Vault is up?
- Question #106
Which user is automatically added to all Safes and cannot be removed?
- Question #107
What is the purpose of the PrivateArk Database service?
- Question #108
A user is receiving the error message "ITATS006E Station is suspended for User jsmith" when attempting to sign into the Password Vault Web Access (PVWA). Which utility would a Vaul...
- Question #109
What is the purpose of the PrivateArk Server service?
- Question #110
Select the best practice for storing the Master CD.
- Question #111
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?
- Question #112
Which CyberArk group does a user need to be part of to view recordings or live monitor sessions?
- Question #113
To ensure all sessions are being recorded, a CyberArk administrator goes to the master policy and makes configuration changes. Which configuration is correct?
- Question #114
Which certificate type do you need to configure the vault for LDAP over SSL?
- Question #115
You are onboarding an account that is not supported out of the box. What should you do first to obtain a platform to import?
- Question #116
You have been asked to identify the up or down status of Vault services. Which CyberArk utility can you use to accomplish this task?
- Question #117
You are logging into CyberArk as the Master user to recover an orphaned safe. Which items are required to log in as Master?
- Question #118
Your organization requires all passwords be rotated every 90 days. Where can you set this regulatory requirement?
- Question #119
To enable the Automatic response "Add to Pending" within PTA when unmanaged credentials are found, what are the minimum permissions required by PTAUser for the PasswordManager_pend...
- Question #120
You have been asked to turn off the time access restrictions for a safe. Where is this setting found?
- Question #121
What is the configuration file used by the CPM scanner when scanning UNIX/Linux devices?
- Question #122
You have been asked to secure a set of shared accounts in CyberArk whose passwords will need to be used by end users. The account owner wants to be able to track who was using an a...
- Question #123
In your organization the "click to connect" button is not active by default. How can this feature be activated?
- Question #124
In the screenshot displayed, you just configured the usage in CyberArk and want to update its password. What is the least intrusive way to accomplish this?
- Question #125
A Vault Administrator team member can log in to CyberArk, but for some reason, is not given Vault Admin rights. Where can you check to verify that the Vault Admins directory mappin...
- Question #126
A newly created platform allows users to access a Linux endpoint. When users click to connect, nothing happens. Which piece of the platform is missing?
- Question #127
Which CyberArk utility allows you to create lists of Master Policy Settings, owners and safes for output to text files or MSSQL databases?
- Question #128
Which PTA sensors are required to detect suspected credential theft?
- Question #129
When running a "Privileged Accounts Inventory" Report through the Reports page in PVWA on a specific safe, which permission/s are required on that safe to show complete account inv...
- Question #130
Which usage can be added as a service account platform?
- Question #131
You need to recover an account localadmin02 for target server 10.0.123.73 stored in Safe Team1. What do you need to recover and decrypt the object? (Choose three.)
- Question #132
What is the easiest way to duplicate an existing platform?
- Question #133
The Privileged Access Management solution provides an out-of-the-box target platform to manage SSH keys, called UNIX Via SSH Keys. How are these keys managed?
- Question #134
You want to generate a license capacity report. Which tool accomplishes this?
- Question #135
You need to enable the PSM for all platforms. Where do you perform this task?
- Question #136
How much disk space do you need on the server for a PAReplicate?
- Question #137
In the Private Ark client, how do you add an LDAP group to a CyberArk group?
- Question #138
For Digital Vault Cluster in a high availability configuration, how does the cluster determine if a node is down?
- Question #139
In a rule using "Privileged Session Analysis and Response" in PTA, which session options are available to configure as responses to activities?
- Question #140
A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The Vault Admin has been asked to look at the acco...
- Question #141
You are creating a Dual Control workflow for a team's safe. Which safe permissions must you grant to the Approvers group?
- Question #142
You receive this error: "Error in changepass to user domain\user on domain server(\domain.(winRc=5) Access is denied." Which root cause should you investigate?
- Question #143
You are creating a shared safe for the help desk. What must be considered regarding the naming convention?
- Question #144
Due to network activity, ACME Corp's PrivateArk Server became active on the OR Vault while the Primary Vault was also running normally. All the components continued to point to the...
- Question #145
Which parameters can be used to harden the Credential Files (CredFiles) while using CreateCredFile Utility? (Choose three.)
- Question #146
A new HTML5 Gateway has been deployed in your organization. Where do you configure the PSM to use the HTML5 Gateway?
- Question #147
Which built-in report from the reports page in PVWA displays the number of days until a password is due to expire?
- Question #148
To use PSM connections while in the PVWA, what are the minimum safe permissions a user or group will need?
- Question #149
In a default CyberArk installation, which group must a user be a member of to view the "reports" page in PVWA?
- Question #150
You are onboarding 5,000 UNIX root accounts for rotation by the CPM. You discover that the CPM is unable to log in directly with the root account and will need to use a secondary a...