Actual CAU201 Exam Recently Updated Questions with Free Demo [Q95-Q120]

Share

Actual CAU201 Exam Recently Updated Questions with Free Demo

Free CyberArk CAU201 Exam Questions Self-Assess Preparation


Understanding functional and technical aspects of CyberArk Security and Audit

The following will be discussed in the CAU-201 exam dumps:

  • Review a recording
  • Describe all reports and what information they give a user
  • Configure email alerts in PTA
  • Configure a Response to Credential Theft
  • Understand the purpose of EVD

CyberArk Defender certification exam is a vendor-neutral certification that demonstrates the candidate's knowledge and expertise in privileged access security best practices. CyberArk Defender certification is recognized globally and is highly valued by organizations seeking to protect their critical assets. The CyberArk Defender certification is an excellent opportunity for security professionals to advance their careers and enhance their skills in privileged access security.

 

NEW QUESTION # 95
Users can be resulted to using certain CyberArk interfaces (e.g.PVWA or PACLI).

  • A. FALS
  • B. TRUE

Answer: B


NEW QUESTION # 96
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by

  • A. The number of persons specified by the Master Policy
  • B. That access cannot be granted to groups
  • C. Any one person from that group
  • D. Every person from that group

Answer: A


NEW QUESTION # 97
As long as you are a member ofthe Vault Admins group you can grant any permission on any safe.

  • A. FALS
  • B. TRUE

Answer: B


NEW QUESTION # 98
It is possible to control the hours of the day during which a user may log into the vault.

  • A. FALSE
  • B. TRUE

Answer: B


NEW QUESTION # 99
In order to connect to a target device through PSM, the account credentials used for the connection must be stored in the vault?

  • A. True.
  • B. False. Because if credentials are not stored in the vault, the PSM will prompt for credentials.
  • C. False. Becauseif credentials are not stored in the vault, the PSM will log into the target device as PSM Connect.
  • D. False. Because the user can also enter credentials manually using Secure Connect.

Answer: C


NEW QUESTION # 100
The password upload utility must run from the CPM server

  • A. TRUE
  • B. FALSE

Answer: B

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Password- Upload-Utility.htm


NEW QUESTION # 101
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....

  • A. Log in to the system asroot,then change root's password
  • B. Noneofthese
  • C. Log in to the system as thelogon account,run the su command to loginas root, and then changeroot's password.
  • D. Log in to the system as the logon account, then change roofs password

Answer: B


NEW QUESTION # 102
Which option in the Private Ark client is used to update users' Vault group memberships?

  • A. Update > Group tab
  • B. Update > General tab
  • C. Update > Authorizations tab
  • D. Update > Member Of tab

Answer: B


NEW QUESTION # 103
For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.

  • A. On the safe in which the account is stored grant the group the' Access safe without confirmation' authorization.
  • B. Create an exception to the Master Policy to exclude the group from the workflow process.
  • C. On the safe in which the account is stored grant the group the' Access safe without audit' authorization.
  • D. Edith the master policy rule and modify the advanced' Access safe without approval' rule to include the group.

Answer: A


NEW QUESTION # 104
The password upload utility must run from the CPM server

  • A. TRUE
  • B. FALSE

Answer: B


NEW QUESTION # 105
Match the Status of Service on a DR Vault to what is displayed when it is operating normally in Replication mode.

Answer:

Explanation:


NEW QUESTION # 106
Which of the following Privileged Session Management (PSM) solutions support live monitoring of active sessions?

  • A. PSM (i.e., launching connections by clicking on the connect button in the Password Vault Web Access (PVWA)
  • B. PSM for Windows (previously known as RDP Proxy)
  • C. All of the above
  • D. PSM for SSH (previously known as PSM-SSH Proxy)

Answer: C


NEW QUESTION # 107
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems

  • A. All of the above
  • B. Windows
  • C. UNIX
  • D. Oracle

Answer: B


NEW QUESTION # 108
When Dual Control is enabled a user must first submit a request in the Password Vault Web Access (PVWA) and receive approval before being able to launch a secure connection via PSM for Windows (previously known as RDP Proxy).

  • A. True
  • B. False, a user can submit the request after the connection has already been initiated via the PSM for Windows

Answer: B


NEW QUESTION # 109
For an account attached to a platform that requires Dual Control based on a Master Policy exception, how would you configure a group of users to access a password without approval.

  • A. Create an exception to the Master Policy to exclude the group from the workflow process.
  • B. Edit the master policy rule and modify the advanced 'Access safe without approval' rule to include the group.
  • C. On the safe in which the account is stored grant the group the 'Access safe without confirmation' authorization.
  • D. On the safe in which the account is stored grant the group the 'Access safe without audit' authorization.

Answer: A

Explanation:
Explanation/Reference:
Reference: https://www.reddit.com/r/CyberARk/comments/6270zr/dual_control_on_specific_accounts/


NEW QUESTION # 110
A user has successfully conducted a short PSM session and logged off. However, the user cannot access the Monitoring tab to view the recordings.
What is the issue?

  • A. The user must login as PSMAdminConnect
  • B. The PSM service is not running
  • C. The user is not a member of the PVWAMonitor group
  • D. The user is not a member of the Auditors group

Answer: D


NEW QUESTION # 111
In accordance with best practice, SSH access is denied for root accounts on UNIX/LINUX system. What is the BEST way to allow CPM to manage root accounts.

  • A. Create a privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Reconcile account of the targetserver's root account.
  • B. Create a non-privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Logon account of the target server's root account.
  • C. Configure the Unix system to allow SSH logins.
  • D. Configure the CPM to allow SSH logins.

Answer: B


NEW QUESTION # 112
If a password is changed manually on a server, bypassing the CPM, how would you configure the account so
that the CPM could resume management automatically?

  • A. Configure the Provider to change the password to match the Vault's Password
  • B. Associate a reconcile account and configure the platform to reconcile automatically.
  • C. Associate a logon account and configure the platform to reconcile automatically.
  • D. Run the correct auto detection process to rediscover the password.

Answer: B


NEW QUESTION # 113
It is possible to restrict the time of day, or day of week that a [b]verify[/b] process can occur

  • A. FALSE
  • B. TRUE

Answer: B

Explanation:
Password verification can be restricted to specific days. This means that the CPM will only verify passwords on the days of the week specified in the VFExecutionDays parameter. The days of the week are represented by the first 3 letters of the name of the day. Sunday is represented by Sun, Monday by Mon, etc.


NEW QUESTION # 114
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?

  • A. No, it is not possible.
  • B. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
  • C. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
  • D. Yes, if a logon account is associated with the root account.

Answer: B


NEW QUESTION # 115
In PVWA, you are attempting to play a recording made of a session by user jsmith, but there is no option to "Fast Forward" within the video. It plays and only allows you to skip between commands instead. You are also unable to download the video.
What could be the cause?

  • A. The browser you are using is out of date and needs an update to be supported.
  • B. You do not have the "View Audit" permission on the safe where the account is stored.
  • C. You need to update the recorder settings in the platform to enable screen capture every 10000 ms or less.
  • D. Recording is of a PSM for SSH session.

Answer: A


NEW QUESTION # 116
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to change the root account's password the CPM will...

  • A. Log in to the system as the logon account, then change root's password
  • B. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
  • C. None of these.
  • D. Log in to the system as root, then change root's password.

Answer: D

Explanation:
Explanation/Reference:


NEW QUESTION # 117
What is the purpose of the Immediate Interval setting in a CPM policy?

  • A. To control how often the CPM rests between password changes.
  • B. To control how often the CPM looks for System Initiated CPM work.
  • C. To Control the maximum amount of time the CPM will wait for a password change to complete.
  • D. To control how often the CPM looks for User Initiated CPM work.

Answer: D

Explanation:
Explanation
When the Master Policy enforces check-in/check-out exclusive access, passwords are changed when the user clicks the Release button and releases the account. This is based on the ImmediateInterval parameter in the applied platform. If the user forgets to release the account, it is automatically released and changed by the CPM after a predetermined number of minutes, defined in the MinValidityPeriod parameter specified in the platform


NEW QUESTION # 118
A Logon Account can be specified in the Master Policy.

  • A. FALSE
  • B. TRUE

Answer: B


NEW QUESTION # 119
You have been asked to identify the up or down status of Vault services.
Which CyberArk utility can you use to accomplish this task?

  • A. Remote Control Agent
  • B. PAS Reporter
  • C. Syslog
  • D. Vault Replicator

Answer: A


NEW QUESTION # 120
......


The CAU201 certification exam is a valuable credential for cybersecurity professionals seeking to advance their careers in the field of privileged access management. CyberArk Defender certification demonstrates a high level of expertise in CyberArk solutions and provides a competitive edge in the job market. CyberArk Defender certified professionals are highly sought after by organizations looking to strengthen their cybersecurity posture and protect their critical assets from cyber threats.

 

CAU201 Free Sample Questions to Practice One Year Update: https://www.vce4plus.com/CyberArk/CAU201-valid-vce-dumps.html

Download CAU201 exam with CyberArk CAU201 Real Exam Questions: https://drive.google.com/open?id=1NuRrGbVes8K204wEKWDjhNDHQWPBP-O0