CyberArk EPM-DEF Cert Guide PDF 100% Cover Real Exam Questions [Q37-Q61]

Share

CyberArk EPM-DEF Cert Guide PDF 100% Cover Real Exam Questions

Pass EPM-DEF Exam - Real Questions and Answers

NEW QUESTION # 37
When working with credential rotation/loosely connected devices, what additional CyberArk components are required?

  • A. PVWA
  • B. PTA
  • C. DAP
  • D.

Answer: A


NEW QUESTION # 38
What are valid policy options for JIT and elevation policies?

  • A. Grant temporary access for, Policy name, Terminate administrative processes when the policy expires, Collect audit information
  • B. Grant temporary access for all users, Policy name, Restart administrative processes in admin approval mode, Collect audit information
  • C. Terminate administrative services, Grant policy access for, Policy name, Collect audit reports
  • D. Grant administrative access, Policy name, Log off to apply policy, Collect policy violation information

Answer: D


NEW QUESTION # 39
What EPM component is responsible for communicating password changes in credential rotation?

  • A. EPM Discovery
  • B. EPM Agent
  • C. EPM API
  • D. EPM Server

Answer: D


NEW QUESTION # 40
An end user is experiencing performance issues on their device after the EPM Agent had been installed on their machine. What should the EPM Administrator do first to help resolve the issue?

  • A. Uninstall or disable any anti-virus software prohibiting the EPM Agent functionalities.
  • B. Verify any 3rd party security solutions have been added to EPM's Files To Be Ignored Always configuration and CyberArk EPM has also been excluded from the 3rd party security solutions.
  • C. Rerun the agent installation on the user's machine to repair the installation.
  • D. Enable the Default Policy's Privilege Management Control, Unhandled Privileged Applications in Elevate mode.

Answer: A


NEW QUESTION # 41
An end user is reporting that an application that needs administrative rights is crashing when selecting a certain option menu item. The Application is part of an advanced elevate policy and is working correctly except when using that menu item.
What could be the EPM cause of the error?

  • A. The Elevate Child Processes option is not enabled.
  • B. The Users defined in the advanced policy do not include the end user running the application.
  • C. The Advanced: Time options are not set correctly to include the time that the user is running the application at.
  • D. The Specify permissions to be set for selected Services on End-user Computers is set to Allow Start/Stop

Answer: A


NEW QUESTION # 42
Match the Trusted Source to its correct definition:

Answer:

Explanation:


NEW QUESTION # 43
Match the Application Groups policy to their correct description.

Answer:

Explanation:


NEW QUESTION # 44
CyberArk's Privilege Threat Protection policies are available for which Operating Systems? (Choose two.)

  • A. Windows Servers
  • B. Windows Workstations
  • C. MacOS
  • D. Linux

Answer: A,B


NEW QUESTION # 45
When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)

  • A. Add trusted software to the Allow Application Group
  • B. Add additional files, folders, and/or file extensions to be included to Ransomware Protection
  • C. Add trusted software to the Authorized Applications (Ransomware protection) Application Group
  • D. Enable Detect privileged unhandled applications under Default Policies

Answer: B,C


NEW QUESTION # 46
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?

  • A. Default Policies
  • B. Anti-tampering Protection
  • C. Authorized Applications (Ransomware Protection)
  • D. Files to be Ignored Always

Answer: C


NEW QUESTION # 47
What unauthorized change can CyberArk EPM Ransomware Protection prevent?

  • A. Certificates in the Certificate Store
  • B. Website Data
  • C. Local Administrator Passwords
  • D. Windows Registry Keys

Answer: A


NEW QUESTION # 48
What are the policy targeting options available for a policy upon creation?

  • A. EPM Sets, Computers in AD Security Groups, AD Users and AD Security Groups
  • B. AD Users and Groups, Computers in AD Security Groups, Servers
  • C. OS Computers, EPM Sets, AD Users
  • D. Computers in this set, Computers in AD Security Groups, Users and Groups

Answer: A


NEW QUESTION # 49
Which policy can be used to improve endpoint performance for applications commonly used for software development?

  • A. Developer Applications
  • B. Trusted Source
  • C. Software Updater
  • D. Trusted Application

Answer: D


NEW QUESTION # 50
Which user or group will not be removed as part of CyberArk EPM's Remove Local Administrators feature?

  • A. Built-in Local Administrator
  • B. Admin Users
  • C. Power Users
  • D. Domain Users

Answer: A


NEW QUESTION # 51
A Helpdesk technician needs to provide remote assistance to a user whose laptop cannot connect to the Internet to pull EPM policies. What CyberArk EPM feature should the Helpdesk technician use to allow the user elevation capabilities?

  • A. Loosely Connected Devices Credential Management
  • B. Elevate Trusted Application If Necessary
  • C. Just In Time Access and Elevation
  • D. Offline Policy Authorization Generator

Answer: C


NEW QUESTION # 52
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?

  • A. Event Queue Flush Period
  • B. Condition Timeout
  • C. Heartbeat Timeout
  • D. Policy Update Rate

Answer: A


NEW QUESTION # 53
When working with credential rotation at the EPM level, what is the minimum time period that can be set between connections?

  • A. 24 hours
  • B. 5 hours
  • C. 72 hours
  • D. 1 hour

Answer: C


NEW QUESTION # 54
A company is looking to manage their Windows Servers and Desktops with CyberArk EPM. Management would like to define different default policies between the Windows Servers and Windows Desktops.
What should the EPM Administrator do?

  • A. Create Advanced Policies to apply different policies between Windows Servers and Windows Desktops.
  • B. In the Default Policies, exclude either the Windows Servers or the Windows Desktops.
  • C. CyberArk does not recommend installing EPM Agents on Windows Servers.
  • D. Create a separate Set for Windows Servers and Windows Desktops.

Answer: A


NEW QUESTION # 55
What feature is designed to exclude applications from CyberArk EPM's Ransomware Protection, without whitelisting the application launch?

  • A. Threat Intelligence
  • B. Trusted Sources
  • C. Policy Recommendations
  • D. Authorized Applications (Ransomware Protection)

Answer: D


NEW QUESTION # 56
An EPM Administrator would like to enable a Threat Protection policy, however, the policy protects an application that is not installed on all endpoints.
What should the EPM Administrator do?

  • A. Enable the Threat Protection policy only in Detect mode.
  • B. Do not enable the Threat Protection policy.
  • C. Enable the Threat Protection policy and configure the Policy Targets.
  • D. Split up the endpoints in to separate Sets and enable Threat Protection for only one of the Sets.

Answer: D


NEW QUESTION # 57
What are the predefined application groups?

  • A. Block Only
  • B. Elevate, Allow, Block, Developer Applications
  • C. Run as Administrator, Run as Developer, Block
  • D. Developer group, Administrator group

Answer: B


NEW QUESTION # 58
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?

  • A. An EPM admin can create an authorization token for each application needed by running:
    EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
    -action run
  • B. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours and Terminate administrative processes when the policy expires option unchecked
  • C. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
  • D. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours

Answer: B


NEW QUESTION # 59
If you want to diagnose agent EPM agent connectivity issues, what is the agent executable that can be used from the command line?

  • A. epm_agent.exe
  • B. vault_agent.exe
  • C. vf_agent.exe
  • D. db_agent.exe

Answer: A


NEW QUESTION # 60
An application has been identified by the LSASS Credentials Harvesting Module.
What is the recommended approach to excluding the application?

  • A. Add the application to the Files to be Ignored Always in Agent Configurations.
  • B. In Agent Configurations, add the application to the Threat Protection Exclusions
  • C. Add the application to an Advanced Policy or Application Group with an Elevate policy action.
  • D. Exclude the application within the LSASS Credentials Harvesting module.

Answer: B


NEW QUESTION # 61
......


CyberArk Defender - EPM certification exam is a rigorous test that covers a wide range of topics, including endpoint security, privileged access management, and CyberArk Endpoint Privilege Manager deployment and configuration. EPM-DEF exam is designed to test an individual's understanding of best practices for securing endpoints and managing privileged access, as well as their ability to deploy and configure the CyberArk EPM solution effectively.

 

100% Free EPM-DEF Daily Practice Exam With 62 Questions: https://surepass.actualtests4sure.com/EPM-DEF-practice-quiz.html