โ† All CAD Flashcard Decks

CyberArk Cloud Entitlements Flashcards

7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CyberArk Cloud Entitlements flashcards as text
  1. What AWS managed policy is considered particularly dangerous by CyberArk CEM due to its broad permissions scope?

    Answer: AdministratorAccess

    AdministratorAccess grants unrestricted access to all AWS services and resources, making it one of the highest-risk policies CEM identifies.

  2. CyberArk CEM integrates with cloud providers' native logging services to analyze usage. Which AWS service does it primarily leverage for this?

    Answer: AWS CloudTrail

    CEM uses AWS CloudTrail event logs to determine which API calls each identity actually makes, enabling accurate least-privilege recommendations.

  3. What is 'privilege creep' in the context of cloud entitlements, and how does CEM address it?

    Answer: The gradual accumulation of permissions over time beyond operational needs; CEM identifies and recommends removal of unused rights

    Privilege creep occurs as identities accumulate permissions through role changes and project needs without cleanup; CEM continuously monitors and recommends right-sizing.

  4. Which CyberArk CEM capability allows security teams to simulate the impact of removing permissions before applying changes?

    Answer: What-if analysis / impact simulation

    CEM's what-if analysis lets administrators model the effects of permission removals on workloads before committing changes, reducing the risk of operational disruption.

  5. In GCP, which permission scope does CyberArk CEM flag as highest risk when assigned to a Service Account?

    Answer: roles/editor or roles/owner at the project level

    Project-level editor or owner roles grant broad read/write or administrative access across all GCP services in that project, representing extreme over-provisioning.

  6. How does CyberArk CEM help organizations demonstrate compliance with the principle of least privilege during security audits?

    Answer: By generating detailed reports showing entitlement risk posture and remediation actions taken

    CEM produces audit-ready reports documenting current entitlement risks, historical trends, and remediation activities to support compliance evidence.

  7. What is the recommended CyberArk CEM workflow when onboarding a new cloud account for monitoring?

    Answer: Connect the account via read-only role, allow CEM to complete discovery, then review findings before any remediation

    Best practice is to connect CEM with read-only access first, complete a full discovery scan, and review findings before executing any remediation actions.