PAM Basics Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 PAM Basics flashcards as text
What is 'password reconciliation' in CyberArk's CPM?
Answer: The process of resynchronizing the Vault's stored password with the actual password on the target system when they diverge
Password reconciliation uses a reconciliation account to reset the target system password back to what the Vault expects when they get out of sync.
Which type of privileged account typically has the highest risk because it can administer the entire directory infrastructure?
Answer: Domain Administrator account
Domain Administrator accounts control Active Directory and therefore all objects within it, making them the highest-value target in an enterprise.
What is the difference between a 'logon account' and a 'reconciliation account' in CyberArk platform configuration?
Answer: A logon account authenticates to perform rotation; a reconciliation account resets passwords when synchronization is lost
The logon account has permissions to change passwords on the target, while the reconciliation account has permissions to forcibly reset passwords that have drifted out of sync.
In CyberArk, which Safe member permission allows a user to retrieve the actual password value?
Answer: Retrieve accounts
The 'Retrieve accounts' permission specifically grants the ability to view and copy the actual credential value from the Vault.
Which PAM control helps detect insider threats by alerting when a privileged user accesses systems outside their normal behavior pattern?
Answer: User and Entity Behavior Analytics (UEBA) integrated with PAM
UEBA analyzes behavioral baselines and flags anomalous privileged activity that may indicate an insider threat or compromised account.
What does 'transparent mode' in PSM refer to?
Answer: Users connect directly to the target system via PSM without seeing a separate jump-host interface
Transparent mode allows PSM to proxy the connection invisibly so users authenticate normally to the target system while PSM records the session behind the scenes.
Which CyberArk concept describes grouping multiple related privileged accounts so they are rotated in a coordinated sequence?
Answer: Account group / linked accounts
Account groups (linked accounts) allow the CPM to coordinate rotation across dependent accounts (e.g., a service account and its scheduled-task entry) so they stay in sync.