
CAU201 Pre-Exam Practice Tests | (Updated 114 Questions)
Valid CAU201 Exam Q&A PDF - One Year Free Update
NEW QUESTION 56
Which parameter controls how often the CPM looks for Soon-to-be-expired Passwords that need to be changed.
- A. The CPM does not change the password under this circumstance
- B. ImmediateInterval
- C. HeadStartInterval
- D. Interval
Answer: B
NEW QUESTION 57
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. Yes, if a logon account is associated with the root account.
- B. No, it is not possible.
- C. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
- D. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
Answer: C
NEW QUESTION 58
What is the purpose of the password change process?
- A. To test that CyberArk is storing accurate credentials for accounts
- B. To change the password of an account according to organizationally defined password rules
- C. To allow CyberArk to manage unknown or lost credentials
- D. To generate a new complex password
Answer: B
NEW QUESTION 59
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Timeout
- B. Interval
- C. Immediate Interval
- D. Min Validity Period
Answer: B
NEW QUESTION 60
What is the purpose of the HeadStartlnterval setting m a platform?
- A. It instructs the CPM to initiate the password change process X number of days before expiration.
- B. It instructs the AIM Provider to 'skip the cache' during the defined time period
- C. It alerts users of upcoming password changes x number of days before expiration.
- D. It determines how far in advance audit data is collected tor reports
Answer: A
Explanation:
The number of days before the password expires (according to the ExpirationPeriod parameter) that the CPM will initiate a password change process. This parameter is not relevant if the policy will be applied to a member of an account group.
NEW QUESTION 61
It is possible to control the hours of the day during which a user may long into the vault.
- A. TRUE
- B. FALSE
Answer: A
Explanation:
Explanation/Reference: https://isecurenet.net/wp-content/uploads/2016/06/user-sb-cyberark_privileged_threat_analytics-
030916-final-en-web.pdf
NEW QUESTION 62
Which of the following statements are NOT true when enabling PSM recording for a target Windows server? (Choose all that apply)
- A. PSMConnect must be added as a local user on the target server
- B. The PSM software must be instated on the target server
- C. PSM must be enabled in the Master Policy (either directly, or through exception)
- D. RDP must be enabled on the target server
Answer: B,C
NEW QUESTION 63
Which of the following PTA detections require the deployment of a Network Sensor or installing the PTA Agent on the domain controller?
- A. Unmanaged privileged access
- B. Over-Pass-The-Hash
- C. Golden Ticket
- D. Suspected credential theft
Answer: C
NEW QUESTION 64
In order to connect to a target device through PSM, the account credentials used for the connection must be stored in the vault?
- A. False. Because the user can also enter credentials manually using Secure Connect.
- B. True.
- C. False. Because if credentials are not stored in the vault, the PSM will prompt for credentials.
- D. False. Because if credentials are not stored in the vault, the PSM will log into the target device as PSMConnect.
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 65
Which report shows the accounts that are accessible to each user?
- A. Activity report
- B. Applications Inventory report
- C. Privileged Accounts Compliance Status report
- D. Entitlement report
Answer: D
NEW QUESTION 66
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems
- A. Oracle
- B. UNIX
- C. All of the above
- D. Windows
Answer: D
Explanation:
Explanation/Reference: https://knowhow.tajco-group.com/knowledge-base/using-a-standard-rdp-client-application/
NEW QUESTION 67
Time of day or day of week restrictions on when password verifications can occur configured in
____________________.
- A. The Platform settings
- B. The Master Policy
- C. The Safe settings
- D. The Account Details
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Verifying-
Passwords.htm
NEW QUESTION 68
Users can be resulted to using certain CyberArk interfaces (e.g.PVWA or PACLI).
- A. FALS
- B. TRUE
Answer: B
NEW QUESTION 69
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- B. Log in to the system as root, then change root's password
- C. Log in to the system as the logon account, then change roofs password
- D. None of these
Answer: D
NEW QUESTION 70
What is the purpose of the Immediate Interval setting in a CPM policy?
- A. To control how often the CPM looks for System Initiated CPM work.
- B. To control how often the CPM rests between password changes.
- C. To Control the maximum amount of time the CPM will wait for a password change to complete.
- D. To control how often the CPM looks for User Initiated CPM work.
Answer: A
NEW QUESTION 71
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?
- A. Session suspension
- B. Password reconciliation
- C. Password change
- D. Session termination
Answer: C
NEW QUESTION 72
Which utilities could you use to change debugging levels on the vault without having to restart the vault. Select all that apply.
- A. PrivateArk Server Central Administration
- B. Edit DBParm.ini in a text editor.
- C. Setup.exe
- D. PAR Agent
Answer: D
NEW QUESTION 73
Which parameter controls how often the CPM looks for accounts that need to be changed from recently completed Dual control requests.
- A. The CPM does not change the password under this circumstance
- B. Interval
- C. ImmediateInterval
- D. HeadStartInterval
Answer: B
NEW QUESTION 74
It is possible to control the hours of the day during which a user may log into the vault.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 75
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as thelogon account,run the su command to loginas root, and then changeroot's password.
- B. Log in to the system asroot,then change root's password
- C. Log in to the system as the logon account, then change roofs password
- D. Noneofthese
Answer: D
NEW QUESTION 76
Accounts Discovery allows secure connections to domain controllers.
- A. TRUE
- B. FALSE
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 77
Which of the following files must be created or configured in order to run Password Upload Utility? Select all that apply.
- A. Vault.ini
- B. conf.ini
- C. PACli.ini
- D. A comma delimited upload file
Answer: B
Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/84gfsb/password_upload_utility_error/
NEW QUESTION 78
PSM captures a record of each command that was executed in Unix.
- A. TRIE
- B. FALSE
Answer: A
NEW QUESTION 79
......
CyberArk Defender Free Update Certification Sample Questions: https://www.itcertmagic.com/CyberArk/real-CAU201-exam-prep-dumps.html
Trend for CyberArk CAU201 pdf dumps before actual exam: https://drive.google.com/open?id=1SoArhS4BoLNCWgiZ6uelxxsF5m-2dZoX