
2021 Realistic Verified CAU201 exam dumps Q&As - CAU201 Free Update
Use Real CAU201 Dumps - 100% Free CAU201 Exam Dumps
CyberArk CAU201 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION 62
Which one the following reports is NOT generated by using the PVWA?
- A. Accounts Inventory
- B. Application Inventory
- C. Sales List
- D. Convince Status
Answer: D
NEW QUESTION 63
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by
- A. Any one person from that group
- B. That access cannot be granted to groups
- C. The number of persons specified by the Master Policy
- D. Every person from that group
Answer: C
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Dual- Control.htm#Confirmi
NEW QUESTION 64
Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre-determined amount of time?
- A. Enforce check-in/check-out exclusive access & Enforce one-time password access
- B. Enforce one-time password access
- C. Require dual control password access Approval
- D. Enforce check-in/check-out exclusive access
Answer: D
NEW QUESTION 65
It is possible to restrict the time of day, or day of week that a [b]verify[/b] process can occur
- A. FALSE
- B. TRUE
Answer: B
Explanation:
Password verification can be restricted to specific days. This means that the CPM will only verify passwords on the days of the week specified in the VFExecutionDays parameter. The days of the week are represented by the first 3 letters of the name of the day. Sunday is represented by Sun, Monday by Mon, etc.
NEW QUESTION 66
For a safe with Object Level Access enabled you can turn off Object Level Access Control when it no longer needed on the safe.
- A. FALSE
- B. TRUE
Answer: A
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Object-Level- Access-Control.htm
NEW QUESTION 67
What is the name of the Platform parameters that controls how long a password will stay valid when One Time Passwords are enabled via the Master Policy?
- A. Immediate Interval
- B. Timeout
- C. Interval
- D. Min Validity Period
Answer: D
Explanation:
Min Validity Period -The number of minutes to wait from the last retrieval of the password until it is replaced. This gives the user a minimum period to be able to use the password before it is replaced. Use -1 to ignore this property. This parameter is also used to release exclusive accounts automatically Interval -" The number of minutes that the Central Policy Manager waits between running periodic searches for the platform. Note: It is recommended to leave the default value of 1440. If a change/verify policy has been configured, the Central Policy Manager will automatically align the periodic searches with the start of the defined timeframes."
NEW QUESTION 68
A Simple Mail Transfer Protocol (SMTP) integration is critical for monitoring Vault activity and facilitating workflow processes, such as Dual Control.
- A. True
- B. False
Answer: B
NEW QUESTION 69
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....
- A. None of these
- B. Log in to the system as the logon account, run the su command to log in as root, and then change root's password.
- C. Log in to the system as the logon account, then change roofs password
- D. Log in to the system as root, then change root's password
Answer: A
NEW QUESTION 70
Which type of automatic remediation can be performed by the PTA in case of a suspected credential theft security event?
- A. Password change
- B. Session suspension
- C. Password reconciliation
- D. Session termination
Answer: A
NEW QUESTION 71
Which user is automatically added to all Safes and cannot be removed?
- A. Operator
- B. Administrator
- C. Auditor
- D. Master
Answer: D
NEW QUESTION 72
What is the chief benefit of PSM?
- A. Automatic password management
- B. Privileged session recording
- C. Privileged session isolation
- D. 'Privileged session isolation' and 'Privileged session recording'
Answer: B
NEW QUESTION 73
VAULT authorizations may be granted to ____________________.
Select all that apply.
- A. Vault Groups
- B. LDAP Users
- C. LDAP Groups
- D. Vault Users
Answer: B
NEW QUESTION 74
SAFE Authorizations may be granted to____________.
Select all that apply.
- A. Vault Group
- B. LDAP Groups
- C. LDAP Users
- D. Vault Users
Answer: B
NEW QUESTION 75
As long as you are a member of the Vault Admins group you can grant any permission on any safe.
- A. FALSE
- B. TRUE
Answer: A
Explanation:
Being in Vault admins group only give you access to safes which are created during installation (safe created in installation process ) -This is clearly mentioned in documents .
NEW QUESTION 76
PSM for Windows (previously known as "RDP Proxy") supports connections to the following target systems
- A. Oracle
- B. All of the above
- C. UNIX
- D. Windows
Answer: D
NEW QUESTION 77
Vault admins must manually add the auditors group to newly created safes so auditors will have sufficient access to run reports.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 78
Accounts Discovery allows secure connections to domain controllers.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 79
You have associated a logon account to one your UNIX cool accounts in the vault. When attempting to
[b]change [/b] the root account's password the CPM will.....
- A. Log in to the system as thelogon account,run the su command to loginas root, and then changeroot's password.
- B. Log in to the system asroot,then change root's password
- C. Log in to the system as the logon account, then change roofs password
- D. Noneofthese
Answer: D
NEW QUESTION 80
All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of the accounts in that safe. The members of the AD group UnixAdmins need to be able to use the show, copy, and connect buttons on those passwords at any time without confirmation. The members of the AD group OperationsStaff need to be able to use the show, copy and connect buttons on those passwords on an emergency basis, but only with the approval of a member of OperationsManagers. The members of OperationsManagers never need to be able to use the show, copy or connect buttons themselves.
Which safe permissions do you need to grant to OperationsStaff? Check all that apply.
- A. Access Safe without Authorization
- B. Use Accounts
- C. List Accounts
- D. Retrieve Accounts
- E. Authorize Password Requests
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 81
Can the 'Connect' button be used to initiate an SSH connection, as root, to a Unix system when SSH access for root is denied?
- A. No, it is not possible.
- B. Yes, when using the connect button, CyberArk uses the PMTerminal.exe process which bypasses the root SSH restriction.
- C. Yes, only if a logon account is associated with the root account and the user connects through the PSM-SSH connection component.
- D. Yes, if a logon account is associated with the root account.
Answer: C
NEW QUESTION 82
Which of the Following can be configured in the Master Policy? Choose all that apply.
- A. Exclusive Passwords
- B. Required Properties
- C. One Time Passwords
- D. Dual Control
- E. Custom Connection Components
- F. Ticketing Integration
- G. Password Reconciliation
- H. Password Aging Rules
Answer: C,D,G,H
NEW QUESTION 83
Ifa password is changed manually on a server, bypassing the CPM, how would you configure theaccount so that the CPM could resume management automatically?
- A. Configure the Provider to change the password to match the Vault's Password
- B. Associate a reconcile account and configure the platform to reconcile automatically
- C. Associate a logonaccount and configure the platform to reconcile automatically
- D. Run the correct auto detection process to rediscover the password
Answer: B
NEW QUESTION 84
A Reconcile Account can be specified in the Master Policy.
- A. FALS
- B. TRUE
Answer: B
NEW QUESTION 85
What is the purpose of the PrivateArk Server service?
- A. Makes Vault data accessible to components
- B. Sends email alerts from the Vault
- C. Maintains Vault metadata
- D. Executes password changes
Answer: A
NEW QUESTION 86
......
Understanding functional and technical aspects of CyberArk Ongoing Maintenance
The following will be discussed in the CAU-201 dumps:
- Identify the log files for each component
- Backup Vault Data with PAReplicate
- Open a support case with appropriate description and severity
- Resync a credential file by running createcredfile manually on the command line
- Identify and locate component configuration files
Understanding functional and technical aspects of CyberArk Password Management Configuration
The following will be discussed in the CAU-201 dumps:
- Setup automatic verification, management, and reconciliation of passwords or SSH Keys
- Follow a safe naming convention
- Configure Safe Retention
- Use an OOB Platform to manage a device
- Duplicate a Platform
- Properly configure the âSearchForUsagesâ Platform parameter
- Configure a reconcile account
- Configure workflow processes to comply with audit/regulatory policies
- Provision a Safe
- Configure workflow processes to ensure non-repudiation
- Import a Custom Platform from the Marketplace
- Configure a request/approval process
- Configure Management of Workstation Passwords using Loosely Connected Devices
- Manage the password of a supported usage
- Configure a logon account
Pass CAU201 exam Updated 179 Questions: https://www.test4sure.com/CAU201-pass4sure-vce.html
CAU201 Exam Dumps, Test Engine Practice Test Questions: https://drive.google.com/open?id=1qNUFQf6Ni3Y3CHQ2ZBJXks912ENXog8T