CAD Enterprise Password Vault Policies 3 — Questions and Answers
Question 1: In CyberArk EPV, what does enabling 'Require dual control password access approval' in the Master Policy accomplish?
- Forces two CPM nodes to confirm rotation
- Requires two approvers before a password can be retrieved (Correct answer)
- Mandates MFA for all Vault logins
- Prevents PSM sessions without a second admin present
Correct answer: Requires two approvers before a password can be retrieved
Dual-control approval requires at least two authorized users to approve a password request before it can be checked out.
Question 2: Which CyberArk policy exception allows a specific account to bypass the global Master Policy rotation interval?
- Safe-level override
- Platform-level exception
- Account-level override via account properties (Correct answer)
- LDAP group exception
Correct answer: Account-level override via account properties
Account-level overrides in the account's properties can override platform defaults (and Master Policy exceptions) for individual accounts.
Question 3: A CyberArk administrator wants to ensure that service accounts are NEVER automatically changed by the CPM. Which platform setting achieves this?
- Set ChangePassword to 'No' (Correct answer)
- Set ChangeFrequency to 0
- Disable the CPM entirely
- Set OneTimePassword to 'No'
Correct answer: Set ChangePassword to 'No'
Setting the platform's ChangePassword property to 'No' instructs the CPM to skip automatic password rotation for accounts under that platform.
Question 4: What is the effect of setting 'Enforce check-in/check-out exclusive access' in a CyberArk Safe's Master Policy?
- Prevents concurrent logins to the PVWA
- Locks the password so only one user can hold it at a time (Correct answer)
- Forces PSM to terminate sessions after checkout
- Requires a ticket number before password retrieval
Correct answer: Locks the password so only one user can hold it at a time
Exclusive access check-in/check-out ensures only one user holds a given account credential at any moment, preventing simultaneous use.
Question 5: In which CyberArk configuration file are the default platform policy parameters defined for new platforms?
- dbparm.ini
- PVConfiguration.xml (Correct answer)
- basic_ini.ini
- PlatformDefault.ini
Correct answer: PVConfiguration.xml
PVConfiguration.xml contains global Vault configuration settings, while individual platform XML files define their own parameters inheriting from platform defaults.
Question 6: A security policy mandates that all password retrievals require a ticket number from the ITSM system. Which CyberArk feature enforces this?
- Dual control
- Ticketing system integration with reason requirement (Correct answer)
- PSM session recording
- CPM verification plug-in
Correct answer: Ticketing system integration with reason requirement
CyberArk's ticketing system integration (ServiceNow, Remedy, etc.) can mandate a valid ticket number before granting password access.
Question 7: Which EPV policy setting defines the maximum number of minutes a password checkout session may last before the account is automatically checked back in?
- SessionTimeout
- MaxCheckoutDuration (Correct answer)
- AllowedRequestedContent
- ExclusiveTimeout
Correct answer: MaxCheckoutDuration
MaxCheckoutDuration sets an upper limit on how long a user may hold an exclusive checkout before the system auto-checks it back in.
In CyberArk EPV, what does enabling 'Require dual control password access approval' in the Master Policy accomplish?