
ExamcollectionPass CAU201 Dumps Real Exam Questions Test Engine Dumps Training
CyberArk CAU201 exam dumps and online Test Engine
Understanding functional and technical aspects of CyberArk Password Management Configuration
The following will be discussed in the CAU-201 dumps:
- Configure Safe Retention
- Import a Custom Platform from the Marketplace
- Provision a Safe
- Add a User/Group to a safe in accordance with access control policies
- Configure a request/approval process
- Configure a logon account
- Manage the password of a supported usage
- Configure workflow processes to comply with audit/regulatory policies
- Properly configure the âSearchForUsagesâ Platform parameter
- Configure workflow processes to ensure non-repudiation
- Configure workflow processes to reduce the risk of credential theft
- Follow a safe naming convention
- Explain the differences between a logon versus a reconcile account
- Configure a reconcile account
- Duplicate a Platform
- Setup automatic verification, management, and reconciliation of passwords or SSH Keys
- Use an OOB Platform to manage a device
- Configure Management of Workstation Passwords using Loosely Connected Devices
Understanding functional and technical aspects of CyberArk User Management Configuration
The following will be discussed in the CAU-201 exam dumps:
- Configure Safe Level Permissions on a User or Group
- Configure Vault Level Permissions on a User
- Configure additional LDAP hosts
- Add an LDAP User/Group to a Local Group
- Describe the purpose of each Built-In Vault User
- Verify an LDAP Configuration is using SSL
- Be able to describe the difference between safe and vault level permissions without the GUI (web or PA client)
- Validate Proper Function of Pre-Configured Directory Mappings
- Provision an internally authenticated user in the vault
- Login as the Master user
- Set/Reset a Vault Userâs Password
- Add a User to a Vault Group
NEW QUESTION 34
Within the Vault each password is encrypted by:
- A. the recovery private key
- B. the recovery public key
- C. its own unique key
- D. the server key
Answer: C
NEW QUESTION 35
As long as you are a member ofthe Vault Admins group you can grant any permission on any safe.
- A. TRUE
- B. FALS
Answer: A
NEW QUESTION 36
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Immediate Interval
- B. Timeout
- C. Interval
- D. Min Validity Period
Answer: D
Explanation:
Explanation
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced.
This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."
NEW QUESTION 37
Users who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 38
It a password is changed manually on a server, bypassing the CPM, how would you configure the account so that the CPM could resume management automatically?
- A. Associate a reconcile account and configure the platform to reconcile automatically
- B. Run the correct auto detection process to rediscover the password
- C. Associate a logon account and configure the platform to reconcile automatically
- D. Configure the Provider to change the password to match the Vault's Password
Answer: D
NEW QUESTION 39
PSM captures a record of each command that was executed in Unix.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 40
You have associated a logon account to one of your UNIX root accounts in the vault. When attempting to
change the root account's password the CPM will...
- A. Log in to the system as the logon account, run the su command to log in as root, and then change root's
password. - B. None of these.
- C. Log in to the system as root, then change root's password.
- D. Log in to the system as the logon account, then change root's password
Answer: C
NEW QUESTION 41
The password upload utility must run from the CPM server
- A. TRUE
- B. FALSE
Answer: B
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Password-
Upload-Utility.htm
NEW QUESTION 42
Which of the Following can be configured in the Master Policy? Choose all that apply.
- A. Ticketing Integration
- B. Password Reconciliation
- C. One Time Passwords
- D. Dual Control
- E. Required Properties
- F. Custom Connection Components
- G. Exclusive Passwords
- H. Password Aging Rules
Answer: B,C,D,H
NEW QUESTION 43
Users can be restricted through certain CyberArk interfaces (e.g. PVWA or PACLI).
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 44
What is the purpose of a linked account?
- A. To allow more than one account to work together as part of a password management process.
- B. To ensure that a particular collection of accounts all have the same password.
- C. To ensure a particular set of accounts all change at the same time.
- D. To connect the CPNI to a target system.
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Linked-
Accounts.htm
NEW QUESTION 45
The Password upload utility can be used to create safes.
- A. TRUE
- B. FALS
Answer: A
NEW QUESTION 46
CyberArk implements license limits by controlling the number and types of users that can be provisioned in the
vault.
- A. TRUE
- B. FALSE
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Managing-the-
CyberArk-License.htm
NEW QUESTION 47
In order to connect to a target device through PSM, the account credentials used for the connection must be
stored in the vault?
- A. False. Because if credentials are not stored in the vault, the PSM will log into the target device as
PSMConnect. - B. False. Because if credentials are not stored in the vault, the PSM will prompt for credentials.
- C. False. Because the user can also enter credentials manually using Secure Connect.
- D. True.
Answer: C
NEW QUESTION 48
SAFE Authorizations may be granted to____________.
Select all that apply.
- A. LDAP Users
- B. LDAP Groups
- C. Vault Group
- D. Vault Users
Answer: B
NEW QUESTION 49
An auditor needs to login to the PSM in order to live monitor an active session. Which user ID is used to establish the RDP connection to the PSM server?
- A. PSMGwUser
- B. PSMMaster
- C. PSMConnect
- D. PSMAdminConnect
Answer: D
NEW QUESTION 50
One can create exceptions to the Master Policy based on ____________________.
- A. Policies
- B. Accounts
- C. Platforms
- D. Safes
Answer: B
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/The-Master-
Policy.htm
NEW QUESTION 51
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Immediate Interval
- B. Timeout
- C. Min Validity Period
- D. Interval
Answer: D
NEW QUESTION 52
......
How to book the CAU201 Exam
These are following steps for registering the CyberArk CAU201 exam.
- Step 1: Visit to Pearson VUE Exam Registration
- Step 2: Signup/Login to Pearson VUE account
- Step 3: Search for CyberArk CAU201 Exam Certifications Exam
- Step 4: Select Date, time and confirm with payment method
CyberArk CAU201: Selling CyberArk Defender Products and Solutions: https://www.examcollectionpass.com/CyberArk/CAU201-practice-exam-dumps.html