Valid Defender - Sentry (Combined) CAU302 Dumps Ensure Your Passing
CAU302 Dumps Real Exam Questions Test Engine Dumps Training
CAU302 Exam topics
Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our CAU-302 practice test will include the following topics:
- Monitoring Privileged Account Access
- Target Hosts Using Privileged Session Manager
- Securely Managing
- Defining the CyberArk Privileged Account Security Solution Architecture
How to study the CAU302 Exam
CAU-302 practice test is a great way to prepare for the certification. If you have some experience regarding CyberArk then our CAU-302 practice exams will help you to find a great way to understand the important topics and recurring questions asked in the exam. These have been written by our expert team and both of these will help you a lot to clear this exam with good marks.
What is the duration of the CAU302 Exam
- Number of Questions: 40
- Passing Score: 70%
- Format: Multiple choices, multiple answers
- Length of Examination: 90 minutes
NEW QUESTION 57
The vault does not support Subnet Based Access Control.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 58
In accordance with best practice, SSH access is denied for root accounts on UNIX/LINUX systems. What is the BEST way to allow CPM to manage root accounts?
- A. Create a privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Reconcile account of the target server's root account.
- B. Create a non-privileged account on the target server. Allow this account the ability to SSH directly from the CPM machine. Configure this account as the Logon account of the target server's root account.
- C. Configure the CPM to allow SSH logins.
- D. Configure the Unix system to allow SSH logins.
Answer: B
Explanation:
Explanation
NEW QUESTION 59
In the vault each password is encrypted with a unique encryption key.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 60
A SIEM integration allows you to forward ITALOG records to a monitoring solution.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 61
Match the log file name with the CyberArk Component that generates the log.
Answer:
Explanation:

NEW QUESTION 62
When a DR Vault Server becomes an active vault, it will automatically revert back to DR mode once the Primary Vault comes back online.
- A. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the padr.ini file.
- B. False, the Vault administrator must manually set the DR Vault to DR mode by setting "FailoverMode=no" in the dbparm.ini file.
- C. True, this is the default behavior.
- D. True, if the AllowFailback setting is set to "yes" in the padr.ini file.
Answer: A
NEW QUESTION 63
Assuming a safe has been configured to be accessible during certain hours of the day, a Vault Admin may still access that safe outside of those hours.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 64
Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? Choose all that apply.
- A. Store the CD in a physical safe and mount the CD every time vault maintenance is performed.
- B. Store the server key in the Provider cache.
- C. Copy the contents of the CD to the System Safe on the vault.
- D. Store the server key in a Hardware Security Module.
- E. Copy the contents of the CD to a folder on the vault server and secure it with NTFS permissions.
Answer: D,E
NEW QUESTION 65
When accessing the Vault via PVWA, is it possible, is it possible to configure multiple Dual Authentication Methods?
- A. Yes, all authentication methods will be configured to use the IIS integrated authentication flow.
- B. Yes, all authentication methods will be configured to use the Vault integrated authentication flow.
- C. Yes, authentication methods will be configured to use the combination of IIS and Vault integrated authentication flow.
- D. No, dual authentication methods are not supported.
Answer: C
NEW QUESTION 66
HA, DR, Replicate are mutually exclusive and cannot be used in the same environment.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 67
When using multiple Central Policy Managers (CPM), which one of the following Safes is shared by all CPMs?
- A. PasswordManager_ADInternal
- B. PasswordManager_workspace
- C. PasswordManager_Pending
- D. PasswordManager
Answer: D
Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PAS%20INST/The- Central-Policy-Manager-Environment.htm
NEW QUESTION 68
What is the proper way to allow the Vault to resolve host names?
- A. Define a WINS server.
- B. Define the local hosts file.
- C. The Vault cannot resolve host names due to security standards.
- D. Define a DNS server.
Answer: D
NEW QUESTION 69
During ENE integration you should specify the Fully-Qualified Domain Name (FQDN) of the SMTP Gateway server.
- A. TRUE
- B. FALSE
Answer: B
NEW QUESTION 70
It is possible to leverage DNA to provide discovery functions that are not available with auto-detection.
- A. TRUE
- B. FALSE
Answer: A
NEW QUESTION 71
Which is the purpose of the HeadStartInterval setting in a platform?
- A. It instructs the CPM to initiate the password change process certain number of days before expiration.
- B. It determines how far in advance audit data is collected for reports.
- C. It instructs the AIM provider to 'skip the cache' during the defined time period.
- D. It alerts users of upcoming password changes a certain number of days before expiration.
Answer: A
NEW QUESTION 72
A Vault Administrator wants to change the PSM Server ID to comply with a naming standard. What is the
process for changing the PSM Server ID?
- A. Options A and B above is the correct procedure.
- B. First, login to the PVWA, browse to Administration, System Configuration, Options, Privileged Session
Management, Configured PSM Servers and select the PSM Server you need to change from the list of
servers. In the properties pane, set the value of the ID property to the new Server ID, click Apply and
OK. Next, edit the basic_psm.ini file located on the PSM server in the PSM root directory and update
the PSMServerID parameter with the new Server ID, save the file and restart the "CyberArk Privileged
Session Manager" service on the PSM server. - C. First, logon to the PrivateArk Client as Administrator and open the PVWAConfig safe. Retrieve and edit
the PVConfiguration.xml file. Search for the PSMServer Name and update the ID of the server you
want to rename. Save the file and copy back to the PWAConfig safe. Restart the "CyberArk Privileged
Session Manager" service on the PSM server. - D. Login to the PVWA, then change the PSMServer ID in Administration, System Configuration, Options,
Privileged Session Management, Configured PSM Servers. Run an IISRESET on all PVWA servers.
Answer: D
NEW QUESTION 73
Which report shows the accounts that are accessible to each user?
- A. Privileged Accounts Compliance Status Report
- B. Entitlement Report
- C. Activity Report
- D. Applications Inventory Report
Answer: B
NEW QUESTION 74
......
CyberArk CAU302: Selling Defender - Sentry (Combined) Products and Solutions: https://www.preppdf.com/CyberArk/CAU302-prepaway-exam-dumps.html