CyberArk CAU201 Exam Questions

Questions for the CAU201 were updated on : Sep 09 ,2024

Page 1 out of 12. Viewing questions 1-15 out of 177

Question 1

If a user is a member of more than one group that has authorizations on a safe, by default that user is
granted________.

  • A. the vault will not allow this situation to occur.
  • B. only those permissions that exist on the group added to the safe first.
  • C. only those permissions that exist in all groups to which the user belongs.
  • D. the cumulative permissions of all groups to which that user belongs.
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

It is possible to control the hours of the day during which a user may log into the vault.

  • A. TRUE
  • B. FALSE
Answer:

A

User Votes:
A
50%
B
50%

Discussions
vote your answer:
A
B
0 / 1000

Question 3

VAULT authorizations may be granted to_____.

  • A. Vault Users
  • B. Vault Groups
  • C. LDAP Users
  • D. LDAP Groups
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

What is the purpose of the Interval setting in a CPM policy?

  • A. To control how often the CPM looks for System Initiated CPM work.
  • B. To control how often the CPM looks for User Initiated CPM work.
  • C. To control how long the CPM rests between password changes.
  • D. To control the maximum amount of time the CPM will wait for a password change to complete.
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of
the accounts in that safe. The members of the AD group UnixAdmins need to be able to use the
show, copy, and connect buttons on those passwords at any time without confirmation. The
members of the AD group Operations Staff need to be able to use the show, copy and connect
buttons on those passwords on an emergency basis, but only with the approval of a member of
Operations Managers never need to be able to use the show, copy or connect buttons themselves.
Which safe permission do you need to grant Operations Staff? Check all that apply.

  • A. Use Accounts
  • B. Retrieve Accounts
  • C. Authorize Password Requests
  • D. Access Safe without Authorization
Answer:

ABC

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

What is the purpose of the Immediate Interval setting in a CPM policy?

  • A. To control how often the CPM looks for System Initiated CPM work.
  • B. To control how often the CPM looks for User Initiated CPM work.
  • C. To control how often the CPM rests between password changes.
  • D. To Control the maximum amount of time the CPM will wait for a password change to complete.
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
When the Master Policy enforces check-in/check-out exclusive access, passwords are changed when
the user clicks the Release button and releases the account. This is based on the ImmediateInterval
parameter in the applied platform. If the user forgets to release the account, it is automatically
released and changed by the CPM after a predetermined number of minutes, defined in the
MinValidityPeriod parameter specified in the platform

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Which utilities could you use to change debugging levels on the vault without having to restart the
vault. Select all that apply.

  • A. PAR Agent
  • B. PrivateArk Server Central Administration
  • C. Edit DBParm.ini in a text editor.
  • D. Setup.exe
Answer:

AB

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
PAR-Private Ark Remote Control Agent allows you to perform several Vault admin tasks (without
restarting the Vault) and view machine statistics.

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

A Logon Account can be specified in the Master Policy.

  • A. TRUE
  • B. FALSE
Answer:

B

User Votes:
A
50%
B
50%

Discussions
vote your answer:
A
B
0 / 1000

Question 9

For an account attached to a platform that requires Dual Control based on a Master Policy exception,
how would you configure a group of users to access a password without approval.

  • A. Create an exception to the Master Policy to exclude the group from the workflow process.
  • B. Edith the master policy rule and modify the advanced Access safe without approval rule to include the group.
  • C. On the safe in which the account is stored grant the group the Access safe without audit authorization.
  • D. On the safe in which the account is stored grant the group the Access safe without confirmation authorization.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

As long as you are a member of the Vault Admins group, you can grant any permission on any safe
that you have access to.

  • A. TRUE
  • B. FALSE
Answer:

B

User Votes:
A
50%
B
50%

Explanation:
Being in Vault admins group only give you access to safes which are created during installation (safe
created in installation process ) -This is clearly mentioned in documents .

Discussions
vote your answer:
A
B
0 / 1000

Question 11

Which report provides a list of account stored in the vault.

  • A. Privileged Accounts Inventory
  • B. Privileged Accounts Compliance Status
  • C. Entitlement Report
  • D. Active Log
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

When on-boarding account using Accounts Feed, Which of the following is true?

  • A. You must specify an existing Safe where are account will be stored when it is on boarded to the Vault
  • B. You can specify the name of a new sale that will be created where the account will be stored when it is on-boarded to the Vault.
  • C. You can specify the name of a new Platform that will be created and associated with the account
  • D. Any account that is on boarded can be automatically reconciled regardless of the platform it is associated with.
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

Target account platforms can be restricted to accounts that are stored m specific Safes using the
Allowed Safes property.

  • A. TRUE
  • B. FALSE
Answer:

A

User Votes:
A
50%
B
50%

Discussions
vote your answer:
A
B
0 / 1000

Question 14

Which one the following reports is NOT generated by using the PVWA?

  • A. Accounts Inventory
  • B. Application Inventory
  • C. Sales List
  • D. Convince Status
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

PSM captures a record of each command that was executed in Unix.

  • A. TRIE
  • B. FALSE
Answer:

A

User Votes:
A
50%
B
50%

Discussions
vote your answer:
A
B
0 / 1000
To page 2