Ultimate Guide to Prepare Free CyberArk EPM-DEF Exam Questions and Answer
Pass CyberArk EPM-DEF Tests Engine pdf - All Free Dumps
NEW QUESTION # 24
What is a valid step to investigate an EPM agent that is unable to connect to the EPM server?
- A. Restart the end point
- B. Ping the server from the endpoint.
- C. Ping the endpoint from the EPM server.
- D. On the end point, open a browser session to the URL of the EPM server.
Answer: B
NEW QUESTION # 25
In EPM, creation of which user type is required to use SAML?
- A. Azure AD User
- B. SQL User
- C. AD User
- D. Local CyberArk EPM User
Answer: A
NEW QUESTION # 26
What is required to configure SAML authentication on EPM?
- A. Signed Authentication Request
- B. Signed SAML Response
- C. Encrypted Assertion
- D. OAuth token
Answer: B
NEW QUESTION # 27
How does a Trusted Source policy affect an application?
- A. Applications will be allowed to run always in elevated mode.
- B. Applications will be allowed to run and will inherit the process token from the EPM agent.
- C. Application from the defined trusted sources must be configured on a per application basis, in order to define run and elevation parameters.
- D. Applications will be allowed to run and will only elevate if required.
Answer: C
NEW QUESTION # 28
For Advanced Policies, what can the target operating system users be set to?
- A. AD Groups, Azure AD Groups
- B. Local or AD users and groups
- C. Local or AD users, Azure AD Users
- D. Local or AD users and groups, Azure AD User, Azure AD Group
Answer: B
NEW QUESTION # 29
Which EPM reporting tool provides a comprehensive view of threat detection activity?
- A. Detected Threats
- B. McAfee ePO Reports
- C. Threat Detection Events
- D. Threat Detection Dashboard
Answer: D
NEW QUESTION # 30
An EPM Administrator would like to enable CyberArk EPM's Ransomware Protection in Restrict mode. What should the EPM Administrator do?
- A. Set Control unhandled applications to Detect.
- B. Set Protect Against Ransomware to Restrict.
- C. Set Block unhandled applications to On.
- D. Set Protect Against Ransomware to Restrict and Set Block unhandled applications to On.
Answer: D
NEW QUESTION # 31
An EPM Administrator would like to notify end users whenever the Elevate policy is granting users elevation for their applications. Where should the EPM Administrator go to enable the end-user dialog?
- A. Advanced, Agent Configurations
- B. Default Policies
- C. End-user UI in the left panel of the console
- D. End-User UI within the policy
Answer: D
NEW QUESTION # 32
When working with credential rotation/loosely connected devices, what additional CyberArk components are required?
- A. PTA
- B. PVWA
- C. DAP
- D.
Answer: B
NEW QUESTION # 33
How does CyberArk EPM's Ransomware Protection feature monitor for Ransomware Attacks?
- A. It compares known ransomware signatures retrieved from virus databases.
- B. It performs a lookup of file signatures against VirusTotal's database.
- C. It sandboxes the suspected ransomware and applies heuristics.
- D. It monitors for any unauthorized access to specified files.
Answer: C
NEW QUESTION # 34
CyberArk EPM's Ransomware Protection comes with file types to be protected out of the box. If an EPM Administrator would like to remove a file type from Ransomware Protection, where can this be done?
- A. Policy Scope within Protect Against Ransomware
- B. Protected Files within Agent Configurations
- C. Authorized Applications (Ransomware Protection) within Application Groups
- D. Set Security Permissions within Advanced Policies
Answer: B
NEW QUESTION # 35
An EPM Administrator would like to exclude an application from all Threat Protection modules. Where should the EPM Administrator make this change?
- A. Protect Against Ransomware under Default Policies.
- B. Authorized Applications under Application Groups.
- C. Threat Protection under Agent Configurations.
- D. Privilege Threat Protection under Policies.
Answer: B
NEW QUESTION # 36
For the CyberArk EPM Threat Deception Credential Lure feature, what is the recommendation regarding the username creation?
- A. The username should have a strong password associated.
- B. The username should not match to an existing account.
- C. The username should match the built-in local Administrator.
- D. The username should match to an existing account.
Answer: B
NEW QUESTION # 37
What are valid policy options for JIT and elevation policies?
- A. Grant administrative access, Policy name, Log off to apply policy, Collect policy violation information
- B. Terminate administrative services, Grant policy access for, Policy name, Collect audit reports
- C. Grant temporary access for, Policy name, Terminate administrative processes when the policy expires, Collect audit information
- D. Grant temporary access for all users, Policy name, Restart administrative processes in admin approval mode, Collect audit information
Answer: A
NEW QUESTION # 38
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?
- A. Creator of the policy
- B. The policy's Set name
- C. Policy creation date
- D. Target use group
Answer: D
NEW QUESTION # 39
Match the Trusted Source to its correct definition:
Answer:
Explanation:

NEW QUESTION # 40
Which programming interface enables you to perform activities on EPM objects via a REST Web Service?
- A. Application Password SDK
- B. EPM Web Services SDK
- C. Java password SDK
- D. Mac Credential Provider SDK
Answer: B
NEW QUESTION # 41
When enabling Threat Protection policies, what should an EPM Administrator consider? (Choose two.)
- A. Some Threat Protection policies are applicable only for Windows Servers as opposed to Workstations.
- B. Certain Threat Protection policies apply for specific applications not found on all machines
- C. Threat Protection policies requires an additional agent to be installed.
- D. Threat Protection features are not available in all regions.
Answer: A,B
NEW QUESTION # 42
When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)
- A. Add additional files, folders, and/or file extensions to be included to Ransomware Protection
- B. Add trusted software to the Authorized Applications (Ransomware protection) Application Group
- C. Add trusted software to the Allow Application Group
- D. Enable Detect privileged unhandled applications under Default Policies
Answer: A,B
NEW QUESTION # 43
What unauthorized change can CyberArk EPM Ransomware Protection prevent?
- A. Windows Registry Keys
- B. Website Data
- C. Certificates in the Certificate Store
- D. Local Administrator Passwords
Answer: C
NEW QUESTION # 44
A Helpdesk technician needs to provide remote assistance to a user whose laptop cannot connect to the Internet to pull EPM policies. What CyberArk EPM feature should the Helpdesk technician use to allow the user elevation capabilities?
- A. Elevate Trusted Application If Necessary
- B. Offline Policy Authorization Generator
- C. Just In Time Access and Elevation
- D. Loosely Connected Devices Credential Management
Answer: C
NEW QUESTION # 45
What are the policy targeting options available for a policy upon creation?
- A. OS Computers, EPM Sets, AD Users
- B. AD Users and Groups, Computers in AD Security Groups, Servers
- C. Computers in this set, Computers in AD Security Groups, Users and Groups
- D. EPM Sets, Computers in AD Security Groups, AD Users and AD Security Groups
Answer: D
NEW QUESTION # 46
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?
- A. Policy Update Rate
- B. Condition Timeout
- C. Heartbeat Timeout
- D. Event Queue Flush Period
Answer: D
NEW QUESTION # 47
If you want to diagnose agent EPM agent connectivity issues, what is the agent executable that can be used from the command line?
- A. epm_agent.exe
- B. vf_agent.exe
- C. db_agent.exe
- D. vault_agent.exe
Answer: A
NEW QUESTION # 48
......
Online Exam Practice Tests with detailed explanations!: https://latestdumps.actual4exams.com/EPM-DEF-real-braindumps.html