โ† All CAD Flashcard Decks

Access Controls Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Access Controls flashcards as text
  1. Which CyberArk access control concept ensures that the team that manages Safe membership is different from the team that uses the credentials stored in that Safe?

    Answer: Separation of duties

    Separation of duties in CyberArk is enforced by granting Safe management rights (add/remove members) to one group while credential retrieval rights go to a separate group.

  2. A user can connect to a target server through PSM but cannot see the password in PVWA. Which permission configuration explains this?

    Answer: The user has 'Use accounts' but not 'Retrieve accounts' permission

    The 'Use accounts' permission allows PSM transparent connections (where the password is injected automatically) without granting 'Retrieve accounts' which would show the cleartext password.

  3. In CyberArk, what is a 'Vault Exception' in the context of the Master Policy?

    Answer: A platform-level or Safe-level override that deviates from the global Master Policy rules

    Vault Exceptions allow specific platforms or Safes to override Master Policy rules, enabling different access controls for different environments without changing the global policy.

  4. Which CyberArk feature allows applications to retrieve credentials from the Vault without storing them in configuration files?

    Answer: Application Identity Manager (AIM) / Credential Provider

    The Application Identity Manager (AIM) Credential Provider allows applications to query the CyberArk Vault at runtime, eliminating hardcoded credentials in config files.

  5. When reviewing Safe membership, an administrator notices a user has the 'Manage Safe' permission. What does this specifically allow?

    Answer: Adding and removing Safe members and changing their permissions

    The 'Manage Safe' permission specifically grants the ability to add/remove Safe members and modify their permission sets, not to retrieve credentials or delete the Safe.

  6. A privileged user checks out an exclusive account but their workstation crashes before they check it in. What is the recommended administrative action?

    Answer: Manually release the account checkout from the PVWA as an administrator

    Administrators can manually release an exclusive account checkout from PVWA when the user cannot do so themselves, freeing it for the next requester.

  7. Which CyberArk access control mechanism specifically addresses the risk of a privileged user accessing a system outside the approved change window?

    Answer: Dual control approval workflow with time-based restrictions

    Combining dual control (requiring approver sign-off) with time-based Master Policy restrictions ensures privileged accounts can only be checked out during approved windows.

Access Controls Flashcards โ€” CAD Study Cards with Answers