Access Controls Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Access Controls flashcards as text
Which built-in CyberArk Vault group has full administrative access to all Safes and is equivalent to a 'super admin' role?
Answer: Master
The 'Master' user in CyberArk Vault has unrestricted access and is the highest privilege account, used only for disaster recovery and initial setup.
A company policy requires that privileged accounts used for database administration cannot be used outside business hours. How is this enforced in CyberArk?
Answer: By configuring time-frame restrictions in the Master Policy for the relevant platform
Time-frame restrictions in the Master Policy allow administrators to define specific hours and days during which privileged credentials can be retrieved.
What is the effect of enabling 'Enforce check-in/check-out exclusive access' in the Master Policy?
Answer: Users must check out credentials before use and check them back in when done, preventing concurrent access
This policy enforces an exclusive checkout model where only one user can hold a credential at a time, and it must be explicitly returned when no longer needed.
When a user's Active Directory account is used to authenticate to PVWA, which CyberArk component handles the directory integration?
Answer: LDAP Integration configured in the Vault
CyberArk Vault's LDAP integration connects to Active Directory to authenticate users, allowing AD credentials to be used for PVWA login.
An auditor needs read-only access to view all activity logs across all Safes without being able to retrieve passwords. Which built-in group should they be added to?
Answer: Auditors
The built-in 'Auditors' group in CyberArk grants read-only visibility into Safe contents and audit logs without providing credential retrieval capabilities.
What does CyberArk's 'Object Level Access Control' (OLAC) feature provide?
Answer: Allows access permissions to be set at the individual account level within a Safe, overriding Safe-level permissions
OLAC enables granular permission assignment at the individual account level within a Safe, allowing fine-grained control beyond Safe-wide permissions.
A CyberArk administrator wants to prevent a specific user from deleting accounts in a Safe while still allowing them to manage passwords. Which permission should be withheld?
Answer: Delete accounts
The 'Delete accounts' permission is separate from password management permissions, so withholding it prevents deletion while other account management tasks remain available.