
100% Pass Top-selling CAU201 Exams - New 2021 CyberArk Pratice Exam
CyberArk Defender Dumps CAU201 Exam for Full Questions - Exam Study Guide
NEW QUESTION 43
Secure Connect provides the following. Choose all that apply.
- A. Real-time live session monitoring.
- B. Session Recording
- C. PSM connections to target devices that are not managed by CyberArk.
- D. PSM connections from a terminal without the need to login to the PVWA
Answer: B,C
NEW QUESTION 44
It is possible to restrict the time of day, or day of week that a [b]verify[/b] process can occur
- A. TRUE
- B. FALSE
Answer: A
Explanation:
Explanation
Password verification can be restricted to specific days. This means that the CPM will only verify passwords on the days of the week specified in the VFExecutionDays parameter. The days of the week are represented by the first 3 letters of the name of the day. Sunday is represented by Sun, Monday by Mon, etc.
NEW QUESTION 45
Within the Vault each password is encrypted by:
- A. the recovery private key
- B. its own unique key
- C. the server key
- D. the recovery public key
Answer: B
NEW QUESTION 46
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 47
Via Password Vault Web Access (PVWA), a user initiates a PSM connection to the target Linux machine using RemoteApp. When the client's machine makes an RDP connection to the PSM server, which user will be utilized?
- A. Credentials stored in the Vault for the target machine
- B. Shadowuser
- C. PSMAdminConnect
- D. PSMConnect
Answer: D
NEW QUESTION 48
What is the maximum number of levels of authorizations you can set up in Dual Control?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 49
Which of the following PTA detections are included in the Core PAS offering?
- A. Golden Ticket
- B. Over-Pass-The Hash
- C. Unmanaged Privileged Access
- D. Suspected Credential Theft
Answer: C
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/What-Does-PTA- Detect.htm
NEW QUESTION 50
An auditor initiates a live monitoring session to PSM server to view an ongoing live session. When the auditor's machine makes an RDP connection the PSM server, which user will be used?
- A. Credentials stored in the Vault for the target machine
- B. Shadowuser
- C. PSMConnect
- D. PSMAdminConnect
Answer: D
NEW QUESTION 51
All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of the accounts in that safe. The members of the AD group UnixAdmins need to be able to use the show, copy, and connect buttons on those passwords at any time without confirmation. The members of the AD group OperationsStaff need to be able to use the show, copy and connect buttons on those passwords on an emergency basis, but only with the approval of a member of OperationsManagers. The members of OperationsManagers never need to be able to use the show, copy or connect buttons themselves.
Which safe permissions do you need to grant to OperationsStaff? Check all that apply.
- A. Access Safe without Authorization
- B. Retrieve Accounts
- C. Authorize Password Requests
- D. List Accounts
- E. Use Accounts
Answer: E
Explanation:
Explanation/Reference:
NEW QUESTION 52
The Password upload utility can be used to create safes.
- A. FALS
- B. TRUE
Answer: B
NEW QUESTION 53
Which one the following reports is NOT generated by using the PVWA?
- A. Sales List
- B. Accounts Inventory
- C. Convince Status
- D. Application Inventory
Answer: C
NEW QUESTION 54
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. Yes, if a logon account is associated with the root account.
- B. No, it is not possible.
- C. Yes, only if a logon account is associated with the root account and the user connects through the PSM- SSH connection component.
- D. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
Answer: C
Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/7zx8w5/ssh_connection/
NEW QUESTION 55
A logon account can be specified in the platform settings.
- A. True
- B. False
Answer: A
NEW QUESTION 56
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- B. None of these
- C. Log in to the system as root, then change root's password
- D. Log in to the system as the logon account, then change roofs password
Answer: A
NEW QUESTION 57
SAFE Authorizations may be granted to _________________.
Select all that apply.
- A. LDAP Users
- B. LDAP Groups
- C. Vault Groups
- D. Vault Users
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 58
Accounts Discovery allows secure connections to domain controllers.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 59
What is the purpose of the Immediate Interval setting in a CPM policy?
- A. To control how often the CPM looks for System Initiated CPM work.
- B. To control how often the CPM rests between password changes.
- C. To Control the maximum amount of time the CPM will wait for a password change to complete.
- D. To control how often the CPM looks for User Initiated CPM work.
Answer: A
NEW QUESTION 60
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. Yes, if a logon account is associated with the root account.
- B. No, it is not possible.
- C. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
- D. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
Answer: C
NEW QUESTION 61
What is the purpose of the HeadStartlnterval setting m a platform?
- A. It instructs the CPM to initiate the password change process X number of days before expiration.
- B. It instructs the AIM Provider to 'skip the cache' during the defined time period
- C. It alerts users of upcoming password changes x number of days before expiration.
- D. It determines how far in advance audit data is collected tor reports
Answer: A
Explanation:
Explanation
The number of days before the password expires (according to the ExpirationPeriod parameter) that the CPM will initiate a password change process. This parameter is not relevant if the policy will be applied to a member of an account group.
NEW QUESTION 62
......
Authentic Best resources for CAU201 Online Practice Exam: https://www.certkingdompdf.com/CAU201-latest-certkingdom-dumps.html