
Pass Your Exam With 100% Verified CAU301 Exam Questions
CAU301 Dumps PDF - CAU301 Real Exam Questions Answers
How to book the CAU301 Exam
These are following steps for registering the CAU301 exam.
- Step 1: Visit to Pearson VUE Exam Registration
- Step 2: Signup/Login to Pearson VUE account
- Step 3: Search for CyberArk CAU301 Certifications Exam
- Step 4: Select Date, time and confirm with payment method
Understanding functional and technical aspects of Securely managing and monitoring privileged account access
The following will be discussed in the CAU-301 exam dumps:
- Add Multi-Factor-Authentication (MFA) and Adaptive Authentication for your PAM access. This can help meet compliance requirements, such as PCI DSS Requirement 8.3. Many regulations such as PCI DSS require securing administrative access with tools like MFA.
- Make sure that privileged access is terminated automatically upon the employee leaving the organization. Again, this is often a compliance requirement, such as for PCI DSS. Not all PAM tools ensure this and-too often-IT departments don't de-provision ex-employees quickly enough. When that employee has access to privileged accounts, it can spell disaster.
- Provide a single user experience. By using your IAM as the interface to the PAM, you improve the user experience for privileged users, since they access the PAM from the same place that they access other corporate resources.
- Ensure that administrators are productive on day one. By using your IAM with PAM, you can automatically provision administrators to the PAM and grant them appropriate access on their very first day.
NEW QUESTION 24
Which file would you modify to configure your Vault Server to forward Activity Logs to a SIEM or SYSLOG server?
- A. PARagent.ini
- B. dbparm.ini
- C. ENEConf.ini
- D. padr.ini
Answer: C
NEW QUESTION 25
What are the operating system prerequisites for installing CPM?
- A. Windows 2008 R2 or higher.
- B. .NET 3.51 Framework Feature
- C. Web Services Role
- D. Remote Desktop Services Role
Answer: B
Explanation:
Explanation/Reference: https://www.cse-cst.gc.ca/en/system/files/pdf_documents/cyberark-v91-sec-eng.pdf (11)
NEW QUESTION 26
What is the purpose of the password Reconcile process?
- A. To allow CyberArk to manage unknown or lost credentials.
- B. To generate a new complex password.
- C. To change the password of an account according to organizationally defined password rules.
- D. To test that CyberArk is storing accurate credentials for accounts.
Answer: C
Explanation:
Explanation/Reference: https://www.cyberark.com/blog/securing-privileged-accounts-best-practices-guide-part-4/
NEW QUESTION 27
What is the best practice for storing the Master CD?
- A. Copy the contents of the CD to a Hardware Security Module and discard the CD.
- B. Store the CD in a secure location, such as a physical safe, and copy the contents of the CD to a folder (secured with NTFS permission) on the vault.
- C. Copy the files to the Vault server and discard the CD.
- D. Store the CD in a secure location, such as a physical safe.
Answer: B
NEW QUESTION 28
The security of the Vault Server is entirely dependent on the security of the network.
- A. FALSE
- B. TRUE
Answer: A
NEW QUESTION 29
In an SMTP integration it is possible to use the fully-qualified domain name (FQDN) when specifying the SMTP server address(es)
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 30
Which file would you modify to configure your Vault Server to forward Activity Logs to a SIEM or SYSLOG server?
- A. PARagent.ini
- B. dbparm.ini
- C. ENEConf.ini
- D. padr.ini
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 31
By default, the vault secure protocol uses which IP port and protocol.
- A. UDP/1858
- B. TCP/80
- C. TCP/443
- D. TCP/1858
Answer: D
Explanation:
Explanation/Reference: http://docplayer.net/53689072-The-cyberark-digital-vault-built-for-security.html
NEW QUESTION 32
What is the name of the account used to establish the initial RDP session from the end user client machine to the PSM server?
- A. The credentials the end user retrieved from the vault
- B. PSMAdminConnect
- C. PSM
- D. PSMConnect
Answer: B
NEW QUESTION 33
What would be a good use case for the Replicate module?
- A. Recovery Time Objectives or Recovery Point Objectives are at or near zero
- B. Integration with an Enterprise Backup Solution is required.
- C. PSM is used
- D. Off site replication is required.
Answer: A
NEW QUESTION 34
Which of the following protocols need to be installed on a standalone vault server?
- A. QoS Packet Scheduler
- B. Client for Microsoft Networks
- C. NIC Teaming Driver, if applicable
- D. File and Printer Sharing for Microsoft Networks
- E. Check all that apply
- F. Internet Protocol Version 4 (TCP/IPv4)
Answer: D
NEW QUESTION 35
Which of the following protocols need to be installed on a standalone vault server? Check all that apply.
- A. NIC Teaming Driver, if applicable
- B. Internet Protocol version 4 (TCP/IPv4)
- C. File and Printer Sharing for Microsoft Networks
- D. QoS Packet Scheduler
- E. Client for Microsoft Networks
Answer: B,C,D,E
NEW QUESTION 36
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? Choose all that apply.
- A. Copy the contents of the CD to a folder on the vault server and secure it with NTFS permissions.
- B. Store the server key in a Hardware Security Module.
- C. Copy the contents of the CD to the System Safe on the vault.
- D. Store the server key in the Provider cache.
- E. Store the CS in a physical safe and mount the CD every time vault maintenance is performed.
Answer: A,B
NEW QUESTION 37
What utility is used to create or update a credential file?
- A. CreateCredFile exe
- B. Central Policy Manager
- C. CAVaultManager.exe
- D. Password Vault Web Access
Answer: A
NEW QUESTION 38
When a DR vault server becomes an active vault, it will automatically fail back to the original state once the primary vault comes back online.
- A. True, if the 'AllowFailback' setting is set to yes in the PADR.ini file.
- B. True, this is the default behavior.
- C. False, this is not possible.
- D. True, if the 'AllowFailback' setting is set to yes in the dbparm.ini file.
Answer: A
NEW QUESTION 39
What would be a good use case for the Disaster Recovery module?
- A. Integration with an Enterprise Backup Solution is required.
- B. Recovery Time Objectives or Recovery Point Objectives are at or near zero.
- C. PSM is used.
- D. Off site replication is required.
Answer: D
NEW QUESTION 40
In order to retrieve data from the vault a user MUST use an interface provided by CyberArk.
- A. TRUE
- B. FALSE
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 41
Which of the following are supported authentication methods for CyberArk? Check all that apply.
- A. PKI
- B. LDAP
- C. OracleSSO
- D. CyberArk Password (SRP)
- E. Biometric
- F. RADIUS
- G. SAML
Answer: A,B,F
Explanation:
Explanation/Reference: https://training.cyberark.com/instructor-led-training/cyberark-privileged-account-security-pas-install- and-configure
NEW QUESTION 42
Which CyberArk component changes passwords on Target Devices?
- A. PrivateArk
- B. Vault
- C. PSM
- D. PVWA
- E. CPM
- F. AIM
- G. OPM
Answer: C,D,E
NEW QUESTION 43
Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?
- A. paragent.ini
- B. dbparm.ini
- C. padr.ini
- D. ENEConf.ini
Answer: A
NEW QUESTION 44
Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?
- A. dbparm ini
- B. padr ini
- C. ENEConf.ini I
- D. paragent.ini
Answer: A
NEW QUESTION 45
Which keys are required to be present in order to start the PrivateArk Server Service? Select all that apply.
- A. Server Key
- B. Safe Key
- C. Recovery Public Key
- D. Recovery Private Key
Answer: D
NEW QUESTION 46
......
Certification Path
The CyberArk Certified Sentry Certification Level 2: Defender exam as pre-requisite exam and the completion grants certified Cyberark Sentry status.
CAU301 Dumps 100 Pass Guarantee With Latest Demo: https://practicetorrent.exam4pdf.com/CAU301-dumps-torrent.html

