CyberArk Defender - PAM (PAM-DEF日本語版) - PAM-DEF日本語 FREE EXAM DUMPS QUESTIONS & ANSWERS
次の PTA 検出のうち、ネットワーク センサーの展開またはドメイン コントローラーへの PTA エージェントのインストールが必要なものはどれですか?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
ワンタイム パスワードの主な目的は何ですか?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
CyberArk をアカウント プロビジョニング プロセスに統合するには、どのオンボーディング方法を使用しますか?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
各コンポーネント サーバーが動作していることを確認するにはどうすればよいでしょうか?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
PAReplicate 用にサーバーに必要なディスク容量はどれくらいですか?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
アカウントがデュアル コントロール用に構成されている金庫で、「確認なしで金庫にアクセスする」金庫のアクセス許可を持っているお客様は、アカウントを使用するための承認を要求する必要があります。
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Private Ark クライアントの [ツール] メニュー > [管理ツール] > [ユーザーとグループ] で、ユーザーの Vault グループ メンバーシップを更新するにはどのオプションを使用しますか?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
マスター ポリシーでワンタイム パスワードが有効になっている場合、パスワードの有効期間を制御するプラットフォーム パラメータの名前は何ですか?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
ユーザーのロックを解除する権利を Tier 1 サポートに委任するように求められました。Tier 1 サポート チームには、メンバー用の LDAP グループがすでにあります。
これを行うための手順を正しい順序で配置します。

これを行うための手順を正しい順序で配置します。

Correct Answer:

Explanation
The correct sequence to delegate the rights to unlock users to Tier 1 support with an existing LDAP group is as follows:
* Sign into the PWA (V10) as a local user with the "Manage Directory Mapping" privilege.
* Open LDAP Integration view.
* Add Mapping to the existing LDAP integration.
* Name the new mapping and set the mapping order.
* Select required LDAP group and assign authorization "Activate Users".
Comprehensive Explanation: To delegate the rights to unlock users, you must first access the Privileged Web Access (PWA) with the appropriate privileges to manage directory mappings. Then, navigate to the LDAP Integration view to add a new mapping to the existing LDAP integration. This mapping should be named and ordered correctly. Finally, select the LDAP group that represents Tier 1 support and assign the specific authorization needed to unlock users, which is "Activate Users" in this context12.
References:
* CyberArk Docs: LDAP Integration in V102
* CyberArk Knowledge Article: How to delegate permissions to unlock Active Directory accounts1
Vault の完全バックアップを生成するコマンドはどれですか?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
「資格情報の盗難の疑い」を PTA が検出するために構成できる自動修復はどれですか?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
DR Vault の Status of Service を、レプリケーション モードで正常に動作しているときに表示されるものと一致させます。


Correct Answer:

Explanation
CyberArk Hardened Windows Firewall -> Running
PrivateArk Database -> Running
PrivateArk Server -> Stopped
CyberArk Vault Disaster Recovery -> Running
CyberArk Event Notification Engine -> Stopped
* Comprehensive Explanation: A DR Vault is a Vault that acts as a standby replica of the Primary Vault and is ready to take its place when the Primary Vault is unavailable. The DR Vault operates in Replication mode, which means it continuously replicates the data and metadata from the Primary Vault.
In Replication mode, the following services have the following status on the DR Vault:
* Cyber-Ark Hardened Windows Firewall: This service provides firewall protection for the Vault server.
It should be running on the DR Vault to ensure security.
* PrivateArk Database: This service manages the database that stores the metadata of the Vault. It should be stopped on the DR Vault, because the database is not active in Replication mode. The database is only activated when the DR Vault switches to Production mode.
* PrivateArk Server: This service manages the Vault server and its communication with other components. It should be stopped on the DR Vault, because the Vault server is not active in Replication mode. The Vault server is only activated when the DR Vault switches to Production mode.
* CyberArk Vault Disaster Recovery: This service manages the replication process between the Primary Vault and the DR Vault. It should be running on the DR Vault to ensure data synchronization and readiness for failover.
* Cyber-Ark Event Notification Engine: This service manages the event notifications and alerts for the
* Vault. It should be stopped on the DR Vault, because the event notifications are not relevant in Replication mode. The event notifications are only activated when the DR Vault switches to Production mode.
References: Primary-DR environment - CyberArk, Replicate the Primary Vault to the Satellite Vaults - CyberArk
SSH キーを管理するとき、CPM は秘密キーを保存しました
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
ターゲット アカウント プラットフォームは、Allowed Safes プロパティを使用して、特定の Safe に保存されているアカウントに制限できます。
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).