CAD CAD Audit & Compliance 1 — Questions and Answers
Question 1: Which CyberArk component is responsible for recording and storing all audit logs generated by the Digital Vault?
- Vault Audit Log (Correct answer)
- Central Policy Manager
- Privileged Session Manager
- Password Manager
Correct answer: Vault Audit Log
The Vault Audit Log captures every action taken on the Digital Vault, providing a tamper-evident record for compliance purposes.
Question 2: In CyberArk, which report helps administrators verify that accounts have had their passwords rotated within a defined compliance window?
- Privileged Accounts Inventory Report
- Compliance Status Report (Correct answer)
- Entitlement Report
- Activity Log Report
Correct answer: Compliance Status Report
The Compliance Status Report shows whether passwords have been changed within required intervals, supporting audit and regulatory needs.
Question 3: What CyberArk feature allows auditors to watch a live or recorded privileged session without interrupting the active user?
- Dual Control
- Transparent Mode
- Session Monitoring (Correct answer)
- Safe Audit
Correct answer: Session Monitoring
Session Monitoring in PSM lets authorized auditors view live sessions or play back recordings for compliance review.
Question 4: Which Safe permission must be granted to allow a user to view audit activity logs for a specific Safe in CyberArk?
- List Accounts
- View Audit Log (Correct answer)
- Retrieve Accounts
- Manage Safe
Correct answer: View Audit Log
The 'View Audit Log' permission grants a user the ability to see all audit activity recorded for a given Safe.
Question 5: In CyberArk PVWA, which section allows administrators to generate reports showing all accounts that have never been accessed?
- Policies tab
- Reports tab (Correct answer)
- Accounts tab
- Administration tab
Correct answer: Reports tab
The Reports tab in PVWA provides built-in reports including inactive and never-accessed account listings for compliance auditing.
Question 6: What CyberArk mechanism ensures that audit records stored in the Vault cannot be deleted or modified by any user, including administrators?
- Safe Quota Limit
- Immutable Audit Trail (Correct answer)
- Dual Control Workflow
- Master Policy Lock
Correct answer: Immutable Audit Trail
CyberArk's immutable audit trail ensures all vault activity logs are tamper-proof and cannot be altered or deleted, even by vault admins.
Which CyberArk component is responsible for recording and storing all audit logs generated by the Digital Vault?