CAU201 Dumps Updated Nov 30, 2023 Practice Test and 179 unique questions [Q11-Q33]

Share

CAU201 Dumps Updated Nov 30, 2023 Practice Test and 179 unique questions

2023 Latest 100% Exam Passing Ratio - CAU201 Dumps PDF


CyberArk Defender certification exam (CAU201) is a popular certification exam for professionals who are looking to establish themselves as experts in CyberArk technology. CyberArk Defender certification is designed for individuals who have a deep understanding of CyberArk and its products and have the ability to implement and manage CyberArk solutions. CyberArk Defender certification exam is designed to test the knowledge and skills of individuals in various areas of CyberArk technology.


CyberArk Defender (CAU201) exam is an advanced certification that validates the skills and knowledge of individuals to protect privileged accounts and systems using CyberArk solutions. CAU201 exam is designed for professionals who work with CyberArk's Privileged Access Security solutions in various roles, such as security analysts, administrators, engineers, and consultants.

 

NEW QUESTION # 11
As long as you are a member of the Vault Admins group you can grant any permission on any safe.

  • A. FALSE
  • B. TRUE

Answer: A

Explanation:
Being in Vault admins group only give you access to safes which are created during installation (safe created in installation process ) -This is clearly mentioned in documents .


NEW QUESTION # 12
Customers who have the 'Access Safe without confirmation' safe permission on a safe where accounts are
configured for Dual control, still need to request approval to use the account.

  • A. FALSE
  • B. TRUE

Answer: A


NEW QUESTION # 13
Which of the following files must be created or configured m order to run Password Upload Utility? Select all that apply.

  • A. conf.ini
  • B. PACli.ini
  • C. Vault.ini
  • D. A comma delimited upload file

Answer: A,C,D


NEW QUESTION # 14
In the Private Ark client, how do you add an LDAP group to a CyberArk group?

  • A. Select Update on the CyberArk group, and then click Add > LDAP Group
  • B. Select Member Of on the LDAP group, and then click Add > LDAP Group
  • C. Select Update on the LDAP Group, and then click Add > LDAP Group
  • D. Select Member Of on the CyberArk group, and then click Add > LDAP Group

Answer: B


NEW QUESTION # 15
If a password is changed manually on a server, bypassing the CPM, how would you configure the account so
that the CPM could resume management automatically?

  • A. Associate a logon account and configure the platform to reconcile automatically.
  • B. Associate a reconcile account and configure the platform to reconcile automatically.
  • C. Run the correct auto detection process to rediscover the password.
  • D. Configure the Provider to change the password to match the Vault's Password

Answer: B


NEW QUESTION # 16
What is the purpose of a linked account?

  • A. To connect the CPNI to a target system.
  • B. To allow more than one account to work together as part of a password management process.
  • C. To ensure that a particular collection of accounts all have the same password.
  • D. To ensure a particular set of accounts all change at the same time.

Answer: B


NEW QUESTION # 17
It is possible to restrict the time of day, or day of week that a [b]reconcile[/b] process can occur

  • A. TRUE
  • B. FALS

Answer: A

Explanation:
Explanation
Password reconciliation can be restricted to specific days. This means that the CPM will only reconcile passwords on the days of the week specified in the RCExecutionDays parameter. The days of the week are represented by the first 3 letters of the name of the day. Sunday is represented by Sun, Mondayby Mon, etc.


NEW QUESTION # 18
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.

  • A. TRUE
  • B. FALS

Answer: A


NEW QUESTION # 19
What is the primary purpose of Dual Control?

  • A. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.
  • B. Non-repudiation (individual accountability)
  • C. More frequent password changes
  • D. Reduced risk of credential theft

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Dual-
Control.htm


NEW QUESTION # 20
When on-boarding account using Accounts Feed, which of the following is true?

  • A. You can specify the name of a new Platform that will be created and associated with the account.
  • B. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
  • C. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated with.
  • D. You can specify the name of a new safe that will be created where the account will be stored when it is on- boarded to the Vault.

Answer: A

Explanation:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/


NEW QUESTION # 21
When managing SSH keys, the CPM stores the Public Key

  • A. In the Vault
  • B. On the target server
  • C. Nowhere because the public key can always be generated from the private key.
  • D. A & B

Answer: B

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/SSHKM/Managing%
20SSH%20Keys.htm


NEW QUESTION # 22
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.

  • A. TRUE
  • B. FALSE

Answer: A


NEW QUESTION # 23
Which report provides a list of account stored in the vault.

  • A. Active Log
  • B. Entitlement Report
  • C. Privileged Accounts Compliance Status
  • D. Privileged Accounts Inventory

Answer: A


NEW QUESTION # 24
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. Yes, only if a logon account is associated with the root account and the user connects through the PSM- SSH connection component.
  • B. No, it is not possible.
  • C. Yes, if a logon account is associated with the root account.
  • D. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.

Answer: A

Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/7zx8w5/ssh_connection/


NEW QUESTION # 25
A logon account can be specified in the platform settings.

  • A. False
  • B. True

Answer: B


NEW QUESTION # 26
One can create exceptions to the Master Policy based on ____________________.

  • A. Platforms
  • B. Accounts
  • C. Safes
  • D. Policies

Answer: B


NEW QUESTION # 27
You want to generate a license capacity report.
Which tool accomplishes this?

  • A. Password Vault Web Access
  • B. PrivateArk Client
  • C. RestAPI
  • D. DiagnoseDB Report

Answer: B


NEW QUESTION # 28
Which statement is correct concerning accounts that are discovered, but cannot be added to the Vault by an automated onboarding rule?

  • A. They cannot be onboarded to the Password Vault.
  • B. They are not part of the Discovery Process.
  • C. They must be uploaded using third party tools.
  • D. They are added to the Pending Accounts list and can be reviewed and manually uploaded.

Answer: B


NEW QUESTION # 29
Which CyberArk group does a user need to be part of to view recordings or live monitor sessions?

  • A. Auditors
  • B. Vault Admin
  • C. Operators
  • D. DR Users

Answer: A


NEW QUESTION # 30
Which parameter controls how often the CPM looks for accounts that need to be changed from recently
completed Dual control requests.

  • A. ImmediateInterval
  • B. Interval
  • C. The CPM does not change the password under this circumstance
  • D. HeadStartInterval

Answer: B


NEW QUESTION # 31
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?

  • A. PSMMaster
  • B. PSMConnect
  • C. PSMGwUser
  • D. PSMAdminConnect

Answer: D


NEW QUESTION # 32
When Dual Control is enabled a user must first submit a request in the Password Vault Web Access (PVWA) and receive approval before being able to launch a secure connection via PSM for Windows (previously known as RDP Proxy).

  • A. False, a user can submit the request after the connection has already been initiated via the PSM for Windows
  • B. True

Answer: A


NEW QUESTION # 33
......


CyberArk Defender exam tests the candidate's proficiency in securing privileged access, securing application credentials, and implementing least privilege principles. CAU201 exam covers a broad range of topics, including CyberArk PAS architecture and components, account management, secure credential management, and implementing CyberArk solutions in different environments.

 

Verified CAU201 dumps Q&As - 100% Pass from Easy4Engine: https://www.easy4engine.com/CAU201-test-engine.html

Pass Exam With Full Sureness - CAU201 Dumps with 179 Questions: https://drive.google.com/open?id=1BheidL0D677SKY925F74Z0TtHaGj3__F