[Jan-2022] CAU201 Dumps are Available for Instant Access using Pass4sures [Q18-Q41]

Share

[Jan-2022] CAU201 Dumps are Available for Instant Access using Pass4sures

CAU201 Dumps 2022 - New CyberArk CAU201 Exam Questions


Who should take the CAU201 exam

Defender Exam is intended to certify an examinee's competence to fill one of the following roles within a Privileged Account Security Program:

  • Vault Administrator. The Vault Administrator is responsible for application administration and maintaining an operable PAS environment.
  • Data Administrator. The Data Administrator is responsible for provisioning safes and platforms, and for onboarding accounts.
  • Application Support. The Application Support Engineer provides first level support of the CyberArk applications within the customer organization.

For more info visit:

CyberArk CAU201 Exam Reference

 

NEW QUESTION 18
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by

  • A. Every person from that group
  • B. The number of persons specified by the Master Policy
  • C. That access cannot be granted to groups
  • D. Any one person from that group

Answer: B

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Dual- Control.htm#Confirmi

 

NEW QUESTION 19
Arrange the steps to restore a Vault using PARestore for a Backup in the correct sequence.

Answer:

Explanation:

 

NEW QUESTION 20
Which utilities could you use to change debugging levels on the vault without having to restart the vault. Select
all that apply.

  • A. PAR Agent
  • B. Setup.exe
  • C. PrivateArk Server Central Administration
  • D. Edit DBParm.ini in a text editor.

Answer: A

 

NEW QUESTION 21
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.

  • A. FALSE
  • B. TRUE

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/MESSAGES/Password
%20Vault%20Web%20Access%20Messages-%20General.htm

 

NEW QUESTION 22
What is the maximum number of levels of authorization you can set up in Dual Control?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 23
Which of the following properties are mandatory when adding accounts from a file? (Choose three.)

  • A. Address
  • B. Platform ID
  • C. All required properties specified in the Platform
  • D. Username
  • E. Hostname
  • F. Safe Name

Answer: B,C,F

 

NEW QUESTION 24
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.

  • A. FALS
  • B. TRUE

Answer: A

 

NEW QUESTION 25
What is the purpose of the Immediate Interval setting in a CPM policy?

  • A. To Control the maximum amount of time the CPM will wait for a password change to complete.
  • B. To control how often the CPM rests between password changes.
  • C. To control how often the CPM looks for System Initiated CPM work.
  • D. To control how often the CPM looks for User Initiated CPM work.

Answer: D

Explanation:
Explanation
When the Master Policy enforces check-in/check-out exclusive access, passwords are changed when the user clicks the Release button and releases the account. This is based on the ImmediateInterval parameter in the applied platform. If the user forgets to release the account, it is automatically released and changed by the CPM after a predetermined number of minutes, defined in the MinValidityPeriod parameter specified in the platform

 

NEW QUESTION 26
The Password upload utility can be used to create safes.

  • A. TRUE
  • B. FALSE

Answer: A

Explanation:
Explanation/Reference:
https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Password-Upload- Utility.htm

 

NEW QUESTION 27
What is the purpose of the CyberArk Event Notification Engine service?

  • A. It sends email messages from the Central Policy Manager (CPM)
  • B. It processes audit report messages
  • C. It makes Vault data available to components
  • D. It sends email messages from the Vault

Answer: C

 

NEW QUESTION 28
A user is receiving the error message "ITATS006E Station is suspended for User jsmith" when attempting to sign into the Password Vault Web Access (PVWA). Which utility would a Vault administrator use to correct this problem?

  • A. PrivateArk
  • B. PVWA
  • C. cavaultmanager.exe
  • D. createcredfile.exe

Answer: A

 

NEW QUESTION 29
Which CyberArk group does a user need to be part of to view recordings or live monitor sessions?

  • A. Vault Admin
  • B. DR Users
  • C. Operators
  • D. Auditors

Answer: D

 

NEW QUESTION 30
Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre-determined amount of time?

  • A. Enforce check-in/check-out exclusive access & Enforce one-time password access
  • B. Enforce check-in/check-out exclusive access
  • C. Require dual control password access Approval
  • D. Enforce one-time password access

Answer: B

 

NEW QUESTION 31
Accounts Discovery allows secure connections to domain controllers.

  • A. FALSE
  • B. TRUE

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 32
Match each key to its recommended storage location.

Answer:

Explanation:

 

NEW QUESTION 33
If the AccountUploader Utility is used to create accounts with SSH keys, which parameter do you use to set the full or relative path of the SSH private key file that will be attached to the account?

  • A. Address
  • B. KeyPath
  • C. KeyFile
  • D. ObjectName

Answer: C

 

NEW QUESTION 34
Which of the following Privileged Session Management solutions provide a detailed audit log of session
activities?

  • A. PSM for SSH (previously known as PSM SSH Proxy)
  • B. All of the above
  • C. PSM (i.e., launching connections by clicking on the "Connect" button in the PVWA)
  • D. PSM for Windows (previously known as RDP Proxy)

Answer: C

 

NEW QUESTION 35
Which command configures email alerts within PTA if settings need to be changed post install?

  • A. /opt/tomcat/utility/emailConfiguration.sh
  • B. /opt/tomcat/utility/emailSetup.sh
  • C. /opt/PTA/emailConfiguration.sh
  • D. /opt/PTA/utility/emailConfig.sh

Answer: A

 

NEW QUESTION 36
VAULT authorizations may be granted to ____________________.
Select all that apply.

  • A. LDAP Groups
  • B. LDAP Users
  • C. Vault Groups
  • D. Vault Users

Answer: B

 

NEW QUESTION 37
Which is the primary purpose of exclusive accounts?

  • A. Reduced risk of credential theft
  • B. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization
  • C. Non-repudiation (individual accountability)
  • D. More frequent password changes

Answer: C

 

NEW QUESTION 38
Which parameters can be used to harden the Credential Files (CredFiles) while using CreateCredFile Utility? (Choose three.)

  • A. Time Frame
  • B. Client Hostname
  • C. Operating System Username
  • D. Host IP Address
  • E. Vault IP Address
  • F. Operating System Type (Linux/Windows/HP-UX)

Answer: B,C,D

 

NEW QUESTION 39
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
  • B. Yes, if a logon account is associated with the root account.
  • C. No, it is not possible.
  • D. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.

Answer: D

 

NEW QUESTION 40
In accordance with best practice, SSH access is denied for root accounts on UNIXLINUX system.
What is the BEST way to allow CPM to manage root accounts?

  • A. Create a privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account of the target server's root account.
  • B. Configure the Unix system to allow SSH logins.
  • C. Create a non-privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Logon account of the target server's root account.
  • D. Configure the CPM to allow SSH logins.

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 41
......


CyberArk CAU201 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Setup text based or video based recordings on PSM
  • Identify and locate component configuration files
  • Explain the differences between a logon versus a reconcile account
Topic 2
  • Setup automatic verification, management, and reconciliation of passwords or SSH Keys
  • Maintain an appropriate chain of custody for Encryption Keys
Topic 3
  • Configure workflow processes to reduce the risk of credential theft
  • Restore an object to the vault from a PAReplicate Backup
Topic 4
  • Configure the Master Policy to create PSM recordings
  • Make a PSM for SSH Connection using an SSH Client
Topic 5
  • Perform a bulk upload of accounts using Password Upload Utility or REST
  • Resync a credential file by running createcredfile manually on the command line
Topic 6
  • Configure the Master Policy to enable the PSM
  • Configure workflow processes to ensure non-repudiation

 

CyberArk CAU201 Exam Practice Test Questions: https://www.pass4sures.top/CyberArk-Defender/CAU201-testking-braindumps.html