
[Aug-2021] Pass CyberArk CAU302 Exam in First Attempt Guaranteed!
Full CAU302 Practice Test and 230 unique questions with explanations waiting just for you, get it now!
NEW QUESTION 34
Multiple Vault Servers can be load balanced.
- A. True
- B. False
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/11.4/en/Content/PAS%20INST/Optional- Installing-Multiple-PSM-Servers.htm
NEW QUESTION 35
In accordance with best practice. SSH access is denied for root accounts on UNIX/LINUX systems. What is the BEST way to allow CPM to manage root accounts.
- A. Create a non-privileged account on the target server Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Logon account of the target server's root account
- B. Configure the CPM to allow SSH logins
- C. Create a privileged account on the target server Allow this account the ability to SSHdirectly from the CPM machineConfigure this account as the Reconcile account of the target server's root account.
- D. Configure the Unix system to allow SSH logins.
Answer: A
NEW QUESTION 36
Which one of the following reports is NOT generated by using the PVWA?
- A. Active/Non-Active Users
- B. Compliance Status
- C. Accounts Inventory
- D. Application Inventory
Answer: A
NEW QUESTION 37
What is the purpose of the password Change process?
- A. To test that CyberArk is storing accurate credentials for accounts
- B. To change the password of an account according to organizationally defined password rules
- C. To allow CyberArk to manage unknown or lost credentials
- D. To generate a new complex password
Answer: B
NEW QUESTION 38
The vault does not support Role Based Access Control
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 39
Which of the following is NOT a use case for installing multiple CPMS?
- A. Reduce network traffic across WAN links
- B. A single CPM cannot accommodate the total number of accounts managed
- C. Accounts are managed in multiple sites or VLANs protected by firewall
- D. Provide load balancing capabilities when managing passwords on target devices
Answer: D
NEW QUESTION 40
Within the Vault each password is encrypted by
- A. Its own unique key.
- B. The Recovery Public Key
- C. The Server Key
- D. The Recovery Private Key
Answer: A
Explanation:
Explanation
NEW QUESTION 41
What are the chief benefits of PSM? Choose all that apply
- A. Automatic Password Management
- B. A & C
- C. Privileged Session Isolation
- D. Privileged Session Recording
Answer: B
NEW QUESTION 42
When using multiple Central Policy Managers (CPM), which one of the following Safes is shared by all CPMs?
- A. PasswordManager_Pending
- B. PasswordManagerSharedSafe
- C. PasswordManager_ADInternal
- D. PasswordManager_workspace
Answer: B
NEW QUESTION 43
What is the primary purpose of One Time Passwords?
- A. Reduced risk of credential theft
- B. More frequent password changes
- C. Non-repudiation (individual accountability)
- D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization
Answer: A
NEW QUESTION 44
When working with the CyberArk High Availability Cluster, which services are running on the passive node?
- A. Cluster Vault Manager, PrivateArk Database and Remote Control Agent
- B. Cluster Vault Manager and PrivateArk Database
- C. Cluster Vault Manager and Remote Control Agent
- D. Cluster Vault Manager
Answer: B
NEW QUESTION 45
After the Vault Server is installed, the Microsoft Windows Firewall is now commandeered by the Vault Can the administrator change these firewall rules?
- A. Yes, the administrator can still modify Firewall rules via the Windows Firewall interface
- B. Yes, but the administrator can only modify the firewall rules by editing the dbparm.ini file and the restarting the vault
- C. No, the Vault does not permit any changes to the Firewall due to security requirements
- D. Yes, but the administrator can only modify the firewall rules by editing the FirewallRuIes mi file and the restarting the vault
Answer: B
NEW QUESTION 46
If a user is a member of more than one group that has authorizations on a safe, by default that user is granted
__________________.
- A. only those permissions that exist in all groups to which the user belongs.
- B. the vault will not allow this situation to occur.
- C. only those permissions that exist on the group added to the safe first.
- D. the cumulative permissions of all the groups to which that user belongs
Answer: D
NEW QUESTION 47
A Simple Mail Transfer Protocol (SMTP) integration is critical for monitoring Vault activity and facilitating workflow processes, such as Dual Control.
- A. False
- B. True
Answer: A
NEW QUESTION 48
A vault admin received an email notification that a password verification process has failed Which service sent the message?
- A. The CyberArk Privileged Session Manager service on the Vault.
- B. The PrivateArk Server Service on the Vault.
- C. The CyberArk Event Notification Engine Service on the Vault
- D. The CyberArk Password Manager service on the Components Server.
Answer: C
NEW QUESTION 49
......
Get Latest CAU302 Dumps Exam Questions in here: https://www.braindumpspass.com/CyberArk/CAU302-practice-exam-dumps.html