[Q12-Q29] Use the best ways of preparing for CAU201 Exam Dumps with TestkingPass CyberArk CAU201 PDF Dumps [2021]

Share

Use the best ways of preparing for CAU201 Exam Dumps with TestkingPass CyberArk CAU201 dump PDF [2021]

CyberArk CAU201 exam candidates will surely pass the Exam if they consider the CAU201 dumps learning material presented by TestkingPass.

NEW QUESTION 12
Within the Vault each password is encrypted by:

  • A. the recovery private key
  • B. its own unique key
  • C. the server key
  • D. the recovery public key

Answer: B

 

NEW QUESTION 13
For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.

  • A. On the safe in which the account is stored grant the group the 'Access safe without audit' authorization.
  • B. Edit the master policy rule and modify the advanced 'Access safe without approval' rule to include the group.
  • C. Create an exception to the Master Policy to exclude the group from the workflow process.
  • D. On the safe in which the account is stored grant the group the 'Access safe without confirmation' authorization.

Answer: C

Explanation:
Explanation/Reference:
Reference: https://www.reddit.com/r/CyberARk/comments/6270zr/dual_control_on_specific_accounts/

 

NEW QUESTION 14
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to [b]change [/b] the root account's password the CPM will.....

  • A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • B. None of these
  • C. Log in to the system as root, then change root's password
  • D. Log in to the system as the logon account, then change roofs password

Answer: A

 

NEW QUESTION 15
SAFE Authorizations may be granted to____________.
Select all that apply.

  • A. LDAP Users
  • B. Vault Group
  • C. Vault Users
  • D. LDAP Groups

Answer: D

 

NEW QUESTION 16
PSM captures a record of each command that was executed in Unix.

  • A. TRIE
  • B. FALSE

Answer: A

 

NEW QUESTION 17
Accounts Discovery allows secure connections to domain controllers.

  • A. TRUE
  • B. FALSE

Answer: B

 

NEW QUESTION 18
All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of the
accounts in that safe. The members of the AD group UnixAdmins need to be able to use the show, copy, and
connect buttons on those passwords at any time without confirmation. The members of the AD group
OperationsStaff need to be able to use the show, copy and connect buttons on those passwords on an
emergency basis, but only with the approval of a member of OperationsManagers. The members of
OperationsManagers never need to be able to use the show, copy or connect buttons themselves.
Which safe permissions do you need to grant to OperationsStaff? Check all that apply.

  • A. Access Safe without Authorization
  • B. Retrieve Accounts
  • C. Authorize Password Requests
  • D. List Accounts
  • E. Use Accounts

Answer: E

Explanation:
Explanation/Reference:

 

NEW QUESTION 19
When on-boarding account using Accounts Feed, which of the following is true?

  • A. You can specify the name of a new safe that will be created where the account will be stored when it is on-
    boarded to the Vault.
  • B. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
  • C. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated
    with.
  • D. You can specify the name of a new Platform that will be created and associated with the account.

Answer: D

Explanation:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/

 

NEW QUESTION 20
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?

  • A. Timeout
  • B. Interval
  • C. Min Validity Period
  • D. Immediate Interval

Answer: C

Explanation:
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced. This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."

 

NEW QUESTION 21
Which one of the following reports is NOT generated by using the PVWA?

  • A. Account Inventory
  • B. Compliance Status
  • C. Application Inventory
  • D. Safes List

Answer: D

Explanation:
Explanation/Reference:
Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/

 

NEW QUESTION 22
Which of the following files must be created or configured m order to run Password Upload Utility? Select all that apply.

  • A. conf.ini
  • B. PACli.ini
  • C. Vault.ini
  • D. A comma delimited upload file

Answer: A,C,D

 

NEW QUESTION 23
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to change the root account's password the CPM will...

  • A. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • B. None of these.
  • C. Log in to the system as root, then change root's password.
  • D. Log in to the system as the logon account, then change root's password

Answer: C

 

NEW QUESTION 24
As long as you are a member of the Vault Admins group you can grant any permission on any safe.

  • A. TRUE
  • B. FALSE

Answer: B

Explanation:
Explanation
Being in Vault admins group only give you access to safes which are created during installation (safe created in installation process ) -This is clearly mentioned in documents .

 

NEW QUESTION 25
In order to connect to a target device through PSM, the account credentials used for the connection must be stored in the vault?

  • A. False. Because the user can also enter credentials manually using Secure Connect.
  • B. True.
  • C. False. Because if credentials are not stored in the vault, the PSM will prompt for credentials.
  • D. False. Because if credentials are not stored in the vault, the PSM will log into the target device as PSMConnect.

Answer: A

 

NEW QUESTION 26
The vault supports Role Based Access Control.

  • A. TRUE
  • B. FALSE

Answer: B

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Object-Level- Access-Control.htm

 

NEW QUESTION 27
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. Yes, if a logon account is associated with the root account.
  • B. No, it is not possible.
  • C. Yes, only if a logon account is associated with the root account and the user connects through the PSM- SSH connection component.
  • D. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.

Answer: C

Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/7zx8w5/ssh_connection/

 

NEW QUESTION 28
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?

  • A. PSMGwUser
  • B. PSMMaster
  • C. PSMConnect
  • D. PSMAdminConnect

Answer: D

 

NEW QUESTION 29
......

Full CAU201 Practice Test and 114 unique questions with explanations waiting just for you, get it now: https://drive.google.com/open?id=1zL-yjNy_iYNDyl6b6QNms15QpCwBxLFT

Accurate & Verified Answers As Seen in the Real Exam here: https://www.testkingpass.com/CAU201-testking-dumps.html