
SureTorrent EPM-DEF Exam Questions | Real EPM-DEF Practice Dumps
Verified EPM-DEF Exam Dumps Q&As - Provide EPM-DEF with Correct Answers
NEW QUESTION # 25
If Privilege Management is not working on an endpoint, what is the most likely cause that can be verified in the EPM Agent Log Files?
- A. Agent version is incompatible.
- B. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to "Prompt for Consent for non-Windows binaries".
- C. UAC policy Admin Approval for the Built-in Administrator Account is set to "Disabled".
- D. UAC policy Run all administrators in Admin Approval Mode is set to "Enabled".
Answer: D
NEW QUESTION # 26
CyberArk's Privilege Threat Protection policies are available for which Operating Systems? (Choose two.)
- A. Linux
- B. MacOS
- C. Windows Workstations
- D. Windows Servers
Answer: C,D
NEW QUESTION # 27
Where can you view CyberArk EPM Credential Lures events?
- A. Policy Audit
- B. Threat Protection Inbox
- C. Application Catalog
- D. Events Management
Answer: B
NEW QUESTION # 28
An EPM Administrator would like to enable CyberArk EPM's Ransomware Protection in Restrict mode. What should the EPM Administrator do?
- A. Set Control unhandled applications to Detect.
- B. Set Protect Against Ransomware to Restrict and Set Block unhandled applications to On.
- C. Set Block unhandled applications to On.
- D. Set Protect Against Ransomware to Restrict.
Answer: B
NEW QUESTION # 29
An EPM Administrator would like to exclude an application from all Threat Protection modules. Where should the EPM Administrator make this change?
- A. Protect Against Ransomware under Default Policies.
- B. Authorized Applications under Application Groups.
- C. Privilege Threat Protection under Policies.
- D. Threat Protection under Agent Configurations.
Answer: B
NEW QUESTION # 30
Which threat intelligence source requires the suspect file to be sent externally?
- A. CyberArk Application Risk Analysis Service (ARA)
- B. Palo Alto Wildfire
- C. NSRL
- D. VirusTotal
Answer: D
NEW QUESTION # 31
For Advanced Policies, what can the target operating system users be set to?
- A. AD Groups, Azure AD Groups
- B. Local or AD users and groups, Azure AD User, Azure AD Group
- C. Local or AD users and groups
- D. Local or AD users, Azure AD Users
Answer: C
NEW QUESTION # 32
What feature is designed to exclude applications from CyberArk EPM's Ransomware Protection, without whitelisting the application launch?
- A. Authorized Applications (Ransomware Protection)
- B. Trusted Sources
- C. Policy Recommendations
- D. Threat Intelligence
Answer: A
NEW QUESTION # 33
How does a Trusted Source policy affect an application?
- A. Applications will be allowed to run and will inherit the process token from the EPM agent.
- B. Application from the defined trusted sources must be configured on a per application basis, in order to define run and elevation parameters.
- C. Applications will be allowed to run and will only elevate if required.
- D. Applications will be allowed to run always in elevated mode.
Answer: B
NEW QUESTION # 34
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?
- A. Default Policies
- B. Authorized Applications (Ransomware Protection)
- C. Anti-tampering Protection
- D. Files to be Ignored Always
Answer: B
NEW QUESTION # 35
How does CyberArk EPM's Ransomware Protection feature monitor for Ransomware Attacks?
- A. It monitors for any unauthorized access to specified files.
- B. It sandboxes the suspected ransomware and applies heuristics.
- C. It performs a lookup of file signatures against VirusTotal's database.
- D. It compares known ransomware signatures retrieved from virus databases.
Answer: B
NEW QUESTION # 36
An application has been identified by the LSASS Credentials Harvesting Module.
What is the recommended approach to excluding the application?
- A. In Agent Configurations, add the application to the Threat Protection Exclusions
- B. Add the application to the Files to be Ignored Always in Agent Configurations.
- C. Add the application to an Advanced Policy or Application Group with an Elevate policy action.
- D. Exclude the application within the LSASS Credentials Harvesting module.
Answer: A
NEW QUESTION # 37
When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?
- A. To identify all administrative level events
- B. To identify non-administrative threats
- C. To identify both administrative and non-administrative level events
- D. To identify all non-administrative events
Answer: C
NEW QUESTION # 38
Which policy can be used to improve endpoint performance for applications commonly used for software development?
- A. Trusted Application
- B. Software Updater
- C. Trusted Source
- D. Developer Applications
Answer: A
NEW QUESTION # 39
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?
- A. Heartbeat Timeout
- B. Policy Update Rate
- C. Condition Timeout
- D. Event Queue Flush Period
Answer: D
NEW QUESTION # 40
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?
- A. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
- B. An EPM admin can create an authorization token for each application needed by running:
EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
-action run - C. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours and Terminate administrative processes when the policy expires option unchecked - D. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours
Answer: C
NEW QUESTION # 41
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?
- A. The policy's Set name
- B. Target use group
- C. Policy creation date
- D. Creator of the policy
Answer: B
NEW QUESTION # 42
Which of the following is CyberArk's Recommended FIRST roll out strategy?
- A. Implement Threat Detection
- B. Implement Application Control
- C. Implement Ransomware Protection
- D. Implement Privilege Management
Answer: D
NEW QUESTION # 43
Select the default threat intelligence source that requires additional licensing.
- A. Palo Alto WildFire
- B. CyberArk Application Risk Analysis Service
- C. NSRL
- D. VirusTotal
Answer: A
NEW QUESTION # 44
What can you manage by using User Policies?
- A. Just-In-Time endpoint access and elevation, access to removable drives, and Services access.
- B. Just-In-Time endpoint access and elevation, access to removable drives, filesystem and registry access, Services access, and User account control monitoring.
- C. Filesystem and registry access, access to removable drives, and Services access.
- D. Access to Windows Services only.
Answer: B
NEW QUESTION # 45
......
Get Top-Rated CyberArk EPM-DEF Exam Dumps Now: https://www.suretorrent.com/EPM-DEF-exam-guide-torrent.html
Pass Your EPM-DEF Dumps Free Latest CyberArk Practice Tests: https://drive.google.com/open?id=1133lpXVBP9iIzBaAo__yyYIdYn6iONv6