SureTorrent EPM-DEF Exam Questions Real EPM-DEF Practice Dumps [Q25-Q45]

Share

SureTorrent EPM-DEF Exam Questions | Real EPM-DEF Practice Dumps

Verified EPM-DEF Exam Dumps Q&As - Provide EPM-DEF with Correct Answers

NEW QUESTION # 25
If Privilege Management is not working on an endpoint, what is the most likely cause that can be verified in the EPM Agent Log Files?

  • A. Agent version is incompatible.
  • B. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to "Prompt for Consent for non-Windows binaries".
  • C. UAC policy Admin Approval for the Built-in Administrator Account is set to "Disabled".
  • D. UAC policy Run all administrators in Admin Approval Mode is set to "Enabled".

Answer: D


NEW QUESTION # 26
CyberArk's Privilege Threat Protection policies are available for which Operating Systems? (Choose two.)

  • A. Linux
  • B. MacOS
  • C. Windows Workstations
  • D. Windows Servers

Answer: C,D


NEW QUESTION # 27
Where can you view CyberArk EPM Credential Lures events?

  • A. Policy Audit
  • B. Threat Protection Inbox
  • C. Application Catalog
  • D. Events Management

Answer: B


NEW QUESTION # 28
An EPM Administrator would like to enable CyberArk EPM's Ransomware Protection in Restrict mode. What should the EPM Administrator do?

  • A. Set Control unhandled applications to Detect.
  • B. Set Protect Against Ransomware to Restrict and Set Block unhandled applications to On.
  • C. Set Block unhandled applications to On.
  • D. Set Protect Against Ransomware to Restrict.

Answer: B


NEW QUESTION # 29
An EPM Administrator would like to exclude an application from all Threat Protection modules. Where should the EPM Administrator make this change?

  • A. Protect Against Ransomware under Default Policies.
  • B. Authorized Applications under Application Groups.
  • C. Privilege Threat Protection under Policies.
  • D. Threat Protection under Agent Configurations.

Answer: B


NEW QUESTION # 30
Which threat intelligence source requires the suspect file to be sent externally?

  • A. CyberArk Application Risk Analysis Service (ARA)
  • B. Palo Alto Wildfire
  • C. NSRL
  • D. VirusTotal

Answer: D


NEW QUESTION # 31
For Advanced Policies, what can the target operating system users be set to?

  • A. AD Groups, Azure AD Groups
  • B. Local or AD users and groups, Azure AD User, Azure AD Group
  • C. Local or AD users and groups
  • D. Local or AD users, Azure AD Users

Answer: C


NEW QUESTION # 32
What feature is designed to exclude applications from CyberArk EPM's Ransomware Protection, without whitelisting the application launch?

  • A. Authorized Applications (Ransomware Protection)
  • B. Trusted Sources
  • C. Policy Recommendations
  • D. Threat Intelligence

Answer: A


NEW QUESTION # 33
How does a Trusted Source policy affect an application?

  • A. Applications will be allowed to run and will inherit the process token from the EPM agent.
  • B. Application from the defined trusted sources must be configured on a per application basis, in order to define run and elevation parameters.
  • C. Applications will be allowed to run and will only elevate if required.
  • D. Applications will be allowed to run always in elevated mode.

Answer: B


NEW QUESTION # 34
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?

  • A. Default Policies
  • B. Authorized Applications (Ransomware Protection)
  • C. Anti-tampering Protection
  • D. Files to be Ignored Always

Answer: B


NEW QUESTION # 35
How does CyberArk EPM's Ransomware Protection feature monitor for Ransomware Attacks?

  • A. It monitors for any unauthorized access to specified files.
  • B. It sandboxes the suspected ransomware and applies heuristics.
  • C. It performs a lookup of file signatures against VirusTotal's database.
  • D. It compares known ransomware signatures retrieved from virus databases.

Answer: B


NEW QUESTION # 36
An application has been identified by the LSASS Credentials Harvesting Module.
What is the recommended approach to excluding the application?

  • A. In Agent Configurations, add the application to the Threat Protection Exclusions
  • B. Add the application to the Files to be Ignored Always in Agent Configurations.
  • C. Add the application to an Advanced Policy or Application Group with an Elevate policy action.
  • D. Exclude the application within the LSASS Credentials Harvesting module.

Answer: A


NEW QUESTION # 37
When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?

  • A. To identify all administrative level events
  • B. To identify non-administrative threats
  • C. To identify both administrative and non-administrative level events
  • D. To identify all non-administrative events

Answer: C


NEW QUESTION # 38
Which policy can be used to improve endpoint performance for applications commonly used for software development?

  • A. Trusted Application
  • B. Software Updater
  • C. Trusted Source
  • D. Developer Applications

Answer: A


NEW QUESTION # 39
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?

  • A. Heartbeat Timeout
  • B. Policy Update Rate
  • C. Condition Timeout
  • D. Event Queue Flush Period

Answer: D


NEW QUESTION # 40
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?

  • A. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
  • B. An EPM admin can create an authorization token for each application needed by running:
    EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
    -action run
  • C. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours and Terminate administrative processes when the policy expires option unchecked
  • D. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours

Answer: C


NEW QUESTION # 41
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?

  • A. The policy's Set name
  • B. Target use group
  • C. Policy creation date
  • D. Creator of the policy

Answer: B


NEW QUESTION # 42
Which of the following is CyberArk's Recommended FIRST roll out strategy?

  • A. Implement Threat Detection
  • B. Implement Application Control
  • C. Implement Ransomware Protection
  • D. Implement Privilege Management

Answer: D


NEW QUESTION # 43
Select the default threat intelligence source that requires additional licensing.

  • A. Palo Alto WildFire
  • B. CyberArk Application Risk Analysis Service
  • C. NSRL
  • D. VirusTotal

Answer: A


NEW QUESTION # 44
What can you manage by using User Policies?

  • A. Just-In-Time endpoint access and elevation, access to removable drives, and Services access.
  • B. Just-In-Time endpoint access and elevation, access to removable drives, filesystem and registry access, Services access, and User account control monitoring.
  • C. Filesystem and registry access, access to removable drives, and Services access.
  • D. Access to Windows Services only.

Answer: B


NEW QUESTION # 45
......

Get Top-Rated CyberArk EPM-DEF Exam Dumps Now: https://www.suretorrent.com/EPM-DEF-exam-guide-torrent.html

Pass Your EPM-DEF Dumps Free Latest CyberArk Practice Tests: https://drive.google.com/open?id=1133lpXVBP9iIzBaAo__yyYIdYn6iONv6