โ† All CAD Flashcard Decks

CyberArk Cloud Entitlements Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CyberArk Cloud Entitlements flashcards as text
  1. Which CyberArk component specifically addresses the challenge of ephemeral cloud credentials that are short-lived and automatically rotated?

    Answer: Cloud Entitlements Manager (CEM)

    CEM is designed to discover, analyze, and remediate cloud entitlements including short-lived ephemeral credentials across cloud environments.

  2. In AWS, what is the primary risk associated with overly permissive IAM roles attached to Lambda functions?

    Answer: Excessive access if the function is compromised or misconfigured

    Overly permissive IAM roles on Lambda functions can allow an attacker to pivot across AWS services if the function is exploited.

  3. CyberArk Cloud Entitlements Manager uses what methodology to determine the minimum permissions a cloud identity actually requires?

    Answer: Usage analytics and activity monitoring

    CEM analyzes actual usage patterns and activity logs to calculate the effective minimum permissions needed, enabling least-privilege enforcement.

  4. What is a 'shadow permission' in the context of CyberArk Cloud Entitlements Manager?

    Answer: An effective permission derived indirectly through role chaining or group membership

    Shadow permissions are effective access rights that arise indirectly through role chaining, group memberships, or policy inheritance rather than direct assignment.

  5. When CyberArk CEM generates a 'right-sized' policy recommendation, what should an administrator do before applying it in production?

    Answer: Review the recommendation and test it in a non-production environment first

    Right-sized policy recommendations should always be reviewed and tested in a staging environment before production deployment to avoid unintended access disruptions.

  6. Which cloud provider's concept of 'service accounts' does CyberArk CEM specifically analyze for excessive permissions in GCP environments?

    Answer: GCP Service Accounts

    In GCP, Service Accounts are the primary non-human identity type, and CEM analyzes their permissions to identify and remediate excess access.

  7. What does CyberArk CEM's 'Entitlement Risk Score' primarily measure?

    Answer: The combination of excessive permissions and the likelihood of exploitation

    The Entitlement Risk Score combines the breadth of excessive permissions with contextual factors like identity exposure to quantify overall risk.