Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free CyberArk CPC-CDE-RECERT Practice Exam with Questions & Answers | Set: 3

Questions 21

Which ports do the CyberArk Identity Connector require to be opened to support using Active Directory for LDAP authentication to Privileged Cloud Shared Services? (Choose two.)

Options:
A.

TCP 636 from the connector host to the domain controller

B.

TCP 443 from the connector host to the CyberArk Tenant

C.

TCP 636 from the CyberArk Tenant to the domain controller

D.

TCP 443 from the CyberArk Tenant to the connector host

E.

TCP 636 from the domain controller to the CyberArk Tenant

CyberArk CPC-CDE-RECERT Premium Access
Questions 22

Which group has only View Audit and View Safe permissions?

Options:
A.

Operators

B.

Auditors

C.

Privileged Cloud Admins

D.

Backup Users

Questions 23

Before you can delete a Safe, you must first delete all of its content (accounts and files) permanently. What else must also be achieved before the Safe can be successfully deleted?

Options:
A.

The Safe owners have been removed from the Safe membership.

B.

The version retention period has expired for all files.

C.

The associated CPM user has been removed from the Safe.

D.

The “Save account versions for a period of:” has been set to 0 within the Safe version retention settings.

Questions 24

Arrange the steps to failover to the passive CPM in the correct sequence.

CPC-CDE-RECERT Question 24

Options:
Questions 25

After correctly configuring reconciliation parameters in the Prod-AIX-Root-Accounts Platform, this error message appears in the CPM log: CACPM410E Ending password policy Prod-AIX-Root-Accounts since the reconciliation task is active but the AllowedSafes parameter was not updated What caused this situation?

Options:
A.

The reconciliation account defined in the Platform is in a locked state and is not accessible.

B.

The CPM is currently configured to use to an unsigned engine.

C.

The AllowedSafes parameter does not include the safe containing the reconciliation account defined in the Platform.

D.

A second CPM is incorrectly configured to manage the reconciliation account's safe which is causing a deadlock situation between the two CPMs.

Questions 26

To disable the PSM default Support for Browser Sessions, which option should be set to 'No* before running Hardening?

Options:
A.

SupportWebApplications

B.

SupportBrowsers

C.

SupportWebBrowsers

D.

SupportHTML5Content

Questions 27

When performing “In Domain” hardening of a PSM server, which steps are recommended? (Choose two.)

Options:
A.

Import CyberArk policy settings from the provided file into a new GPO.

B.

Apply advanced audit on the PSM server.

C.

Apply GPO to the CyberArk PSM servers.

D.

Import an INF file to the local machine.

E.

Configure AppLocker rules to block running unknown executables.

Questions 28

When installing PSM on a Windows 2019 Server, under which circumstances should the PSMConnect and PSMAdminConnect users be moved to the domain? (Choose two.)

Options:
A.

When RDS CAL Per User licenses are in use

B.

When the RDS session broker has a value > 1

C.

When you want to extend PSM sessions beyond one hour

D.

When you want to load balance the PSM installation

E.

When you need to enable PSM for Web Support

Questions 29

What is recommended when applying GPO (Group Policy Object) hardening for in-domain PSM servers?

Options:
A.

Apply the GPO provided by CyberArk onto the servers after other GPOs.

B.

Apply the GPO hardening to all hosts that end-users will connect to through the PSM.

C.

After installation, remove the PSM servers from the domain to maximize security.

D.

Place the servers which have PSM installed into a dedicated organizational unit (OU).