Exam Details

  • Exam Code
    :CAU302
  • Exam Name
    :CyberArk Defender - Sentry
  • Certification
    :CyberArk Certifications
  • Vendor
    :CyberArk
  • Total Questions
    :237 Q&As
  • Last Updated
    :May 26, 2025

CyberArk CyberArk Certifications CAU302 Questions & Answers

  • Question 201:

    Which utility can be used to copy a server key to an HSM?

    A. PrivateArk Client

    B. A proprietary utility provided by the HSM Vendor

    C. ChangeServerKeys.exe

    D. CAVaultManager.exe

  • Question 202:

    Which parameter controls how often the CPM looks for accounts that need to be changed from recently completed Dual control requests?

    A. HeadStartInterval

    B. Interval

    C. ImmediateInterval

    D. The CPM does not change the password under this circumstance

  • Question 203:

    Which of the following PTA detections are included in the Core PAS offering? (Choose all that apply.)

    A. Suspected Credential Theft

    B. Over-Pass-The-Hash

    C. Golden Ticket

    D. Unmanaged Privileged Access

  • Question 204:

    When working with the CyberArk Disaster Recovery (DR) solution, which services should be running on the DR Vault?

    A. CyberArk Vault Disaster Recovery (DR), PrivateArk Database

    B. CyberArk Vault Disaster Recovery

    C. CyberArk Vault Disaster Recovery, PrivateArk Database, PrivateArk Server

    D. CyberArk Vault Disaster Recovery, PrivateArk Database, CyberArk Event Notification Engine

  • Question 205:

    Which one of the following reports is NOT generated by using the PVWA?

    A. Accounts Inventory

    B. Application Inventory

    C. Active/Non-Active Users

    D. Compliance Status

  • Question 206:

    tsparm.ini is the main configuration file for the vault.

    A. TRUE

    B. FALSE

  • Question 207:

    What is the proper way to allow the Vault to resolve host names?

    A. Define a DNS server.

    B. Define a WINS server.

    C. Define the local hosts file.

    D. The Vault cannot resolve host names due to security standards.

  • Question 208:

    All of your Unix root passwords are stored in the safe UnixRoot. Dual control is enabled for some of the accounts in that safe. The members of the AD group UnixAdmins need to be able to use the show, copy, and connect buttons on those passwords at any time without confirmation. The members of the AD group OperationsStaff need to be able to use the show, copy and connect buttons on those passwords on an emergency basis, but only with the approval of a member of OperationsManagers. The members of OperationsManagers never need to be able to use the show, copy or connect buttons themselves.

    Which safe permissions do you need to grant to OperationsManagers? (Choose all that apply.)

    A. Use Accounts

    B. Retrieve Accounts

    C. List Accounts

    D. Authorize Password Requests

    E. Access Safe without Authorization

  • Question 209:

    The ACME Company has been a CyberArk customer for many years. ACME Management has asked you to perform a "Health Check" review of the CyberArk deployment. During your analysis you discover that the PSM Component server is fully functional. The RDP SSL certificate is self-signed and the CyberArk Privileged Session Management Service is running under the Local Service. SSL 3.0 is enabled in the Registry.

    A. The PSM Component Server is configured as defined in PAS Installation Guide.

    B. The PSM Component Server has been installed correctly but PSM Hardening procedures have not been followed and must be rebuilt.

    C. The PSM Component Server has been installed correctly but PSM Hardening procedures have not been followed. Hardening procedures must be applied manually to the existing configuration.

    D. The PSM Component Server has been installed correctly but PVWA Hardening procedures have not been followed. Hardening procedures can be applied via the Installation Automation script or manually to the existing configuration.

  • Question 210:

    When managing SSH keys, the CPM stores the Public Key ________________.

    A. In the Vault

    B. On the target server

    C. A and B

    D. Nowhere because the public key can always be generated from the private key

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CyberArk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAU302 exam preparations and CyberArk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.