
Updated Sep-2022 Exam Engine for PAM-DEF Exam Free Demo & 365 Day Updates
Exam Passing Guarantee PAM-DEF Exam with Accurate Quastions!
NEW QUESTION 77
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.
- A. FALS
- B. TRUE
Answer: B
NEW QUESTION 78
If a password is changed manually on a server, bypassing the CPM, how would you configure the account so that the CPM could resume management automatically?
- A. Associate a reconcile account and configure the platform to reconcile automatically
- B. Configure the Provider to change the password to match the Vault's Password
- C. Run the correct auto detection process to rediscover the password
- D. Associate a logon account and configure the platform to reconcile automatically
Answer: A
NEW QUESTION 79
You have been asked to identify the up or down status of Vault services.
Which CyberArk utility can you use to accomplish this task?
- A. Remote Control Agent
- B. PAS Reporter
- C. Vault Replicator
- D. Syslog
Answer: A
NEW QUESTION 80
Which PTA sensors are required to detect suspected credential theft?
- A. Logs, Network Sensor, EPM
- B. Logs, Vault Logs
- C. Logs, PSM Logs, CPM Logs
- D. Logs, Network Sensor, Vault Logs
Answer: B
NEW QUESTION 81
When a DR Vault Server becomes an active vault, it will automatically fail back to the original state once the Primary Vault comes back online.
- A. True; this is the default behavior
- B. True, if the AllowFailback setting is set to "yes" in the padr.ini file
- C. False; this is not possible
- D. True, if the AllowFailback setting is set to "yes" in the dbparm.ini file
Answer: C
NEW QUESTION 82
By default, members of which built-in groups will be able to view and configure Automatic Remediation and Session Analysis and Response in the PVWA?
- A. Auditors
- B. Security Admins
- C. Vault Admins
- D. Security Operators
Answer: B,C
NEW QUESTION 83
Time of day or day of week restrictions on when password verifications can occur configured in ____________________.
- A. The Account Details
- B. The Platform settings
- C. The Safe settings
- D. The Master Policy
Answer: B
NEW QUESTION 84
A newly created platform allows users to access a Linux endpoint. When users click to connect, nothing happens.
Which piece of the platform is missing?
- A. UnixPrompts.ini
- B. UnixProcess.ini
- C. PSM-SSH Connection Component
- D. PSM-RDP Connection Component
Answer: D
NEW QUESTION 85
When a DR Vault Server becomes an active vault, it will automatically revert back to DR mode once the Primary Vault comes back online.
- A. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the padr.ini file
- B. True; this is the default behavior
- C. True, if the AllowFailback setting is set to "yes" in the padr.ini file
- D. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the dbparm.ini file
Answer: A
NEW QUESTION 86
You received a notification from one of your CyberArk auditors that they are missing Vault level audit permissions. You confirmed that all auditors are missing the Audit Users Vault permission.
Where do you update this permission for all auditors?
- A. PVWA User Provisioning > LDAP integration > Vault Auditors Mapping > Vault Authorizations
- B. PVWA> Administration > Configuration Options > LDAP integration > Vault Auditors Mapping > Vault Authorizations
- C. Private Ark Client > Tools > Administrative Tools > Directory Mapping > Vault Authorizations
- D. Private Ark Client > Tools > Administrative Tools > Users and Groups > Auditors > Authorizations tab
Answer: D
NEW QUESTION 87
When running a "Privileged Accounts Inventory" Report through the Reports page in PVWA on a specific safe, which permission/s are required on that safe to show complete account inventory information?
- A. Manage Safe, View Audit
- B. List Accounts, Access Safe without confirmation
- C. List Accounts, View Safe Members
- D. Manage Safe Owners
Answer: C
NEW QUESTION 88
Which one the following reports is NOT generated by using the PVWA?
- A. Convince Status
- B. Application Inventory
- C. Accounts Inventory
- D. Sales List
Answer: D
NEW QUESTION 89
How does the Vault administrator apply a new license file?
- A. Upload the license.xml file to the system Safe and restart the PrivateArk Server service
- B. Upload the license.xml file to the Vault Internal Safe and restart the PrivateArk Server service
- C. Upload the license.xml file to the Vault Internal Safe
- D. Upload the license.xml file to the system Safe
Answer: D
NEW QUESTION 90
A user is receiving the error message "ITATS006E Station is suspended for User jsmith" when attempting to sign into the Password Vault Web Access (PVWA) .
Which utility would a Vault administrator use to correct this problem?
- A. PrivateArk
- B. PVWA
- C. createcredfile.exe
- D. cavaultmanager.exe
Answer: A
NEW QUESTION 91
Which of the following statements are NOT true when enabling PSM recording for a target Windows server? (Choose all that apply)
- A. RDP must be enabled on the target server
- B. The PSM software must be instated on the target server
- C. PSM must be enabled in the Master Policy (either directly, or through exception)
- D. PSMConnect must be added as a local user on the target server
Answer: B,C
NEW QUESTION 92
What is the purpose of the password change process?
- A. To allow CyberArk to manage unknown or lost credentials
- B. To test that CyberArk is storing accurate credentials for accounts
- C. To change the password of an account according to organizationally defined password rules
- D. To generate a new complex password
Answer: A
NEW QUESTION 93
What is the purpose of the HeadStartlnterval setting m a platform?
- A. It instructs the AIM Provider to 'skip the cache' during the defined time period
- B. It alerts users of upcoming password changes x number of days before expiration.
- C. It instructs the CPM to initiate the password change process X number of days before expiration.
- D. It determines how far in advance audit data is collected tor reports
Answer: C
NEW QUESTION 94
As long as you are a member of the Vault Admins group, you can grant any permission on any safe that you have access to.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 95
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? (Choose three.)
- A. Copy the entire contents of the CD to the system Safe on the Vault
- B. Copy the entire contents of the CD to a folder on the Vault Server and secure it with NTFS permissions
- C. Store the server key in a Hardware Security Module (HSM) and copy the rest the keys from the CD to a folder on the Vault Server and secure it with NTFS permissions
- D. Store the CD in a physical safe and mount the CD every time Vault maintenance is performed
Answer: A,B,C
NEW QUESTION 96
The vault supports Subnet Based Access Control.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 97
Platform settings are applied to _________.
- A. The entire vault.
- B. Individual Accounts
- C. Network Areas
- D. Safes
Answer: D
NEW QUESTION 98
Your organization requires all passwords be rotated every 90 days.
Where can you set this regulatory requirement?
- A. Master Policy
- B. PVWAConfig.xml
- C. Safe Templates
- D. Platform Configuration
Answer: A
NEW QUESTION 99
CyberArk recommends implementing object level access control on all Safes.
- A. True
- B. False
Answer: B
NEW QUESTION 100
PSM captures a record of each command that was executed in Unix.
- A. TRIE
- B. FALSE
Answer: A
NEW QUESTION 101
......
Exam Questions for PAM-DEF Updated Versions With Test Engine: https://2cram.actualtestsit.com/CyberArk/PAM-DEF-exam-prep-dumps.html