CyberArk Defender Access Free Sample Questions

20 free sample questions226 in the full practice test

Try simulator

ACCESS-DEF Sample Questions

  1. Question 1

    A financial services firm is implementing a stringent access policy for its traders. The policy requires that any login attempt to the trading platform from outside the corporate network (defined by a specific IP range) must be challenged with a FIDO2 hardware key. However, logins from within the corporate network should only require a password. Which CyberArk Identity feature should be used to configure this conditional logic?

    Answer and explanation

    Correct answer: C

    Authentication Rules are the core component for implementing adaptive MFA. An administrator can create a rule that specifies a condition, such as the source IP address not being in a predefined range, and then apply a specific Authentication Profile (e.g., one requiring FIDO2) when that condition is met. The default policy can be set to password-only, which would apply to all other conditions, including logins from the corporate IP range.

  2. Question 2

    A healthcare organization has enrolled all domain-joined corporate laptops with CyberArk Identity Windows Device Trust, and sensitive applications require a trusted device. A clinician working from home, not connected to the corporate VPN, cannot access one of these applications. The administrator confirms the user is in the correct role, can sign in to the User Portal, and the laptop was enrolled successfully. What is the most likely cause?

    Answer and explanation

    Correct answer: B

    Windows Device Trust requires a domain-joined Windows computer, a tenant with IWA configured, and a connection to the domain controller (for example, inside the corporate network or connected through a VPN). A laptop at home without VPN cannot meet the domain controller connectivity requirement, so the device-trust check fails and access to apps that require a trusted device is denied. An expired enrollment code affects only new enrollments, not an already-enrolled laptop.

  3. Question 3

    Multiple answers

    A company's security policy mandates that all administrative access to cloud infrastructure management consoles (like AWS, Azure) requires Multi-Factor Authentication. Which TWO of the following mechanisms in CyberArk Identity can be used to enforce this policy specifically for users in the 'Cloud Admins' role? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    Two documented mechanisms work. (1) App-level policy: each cloud console app has a Policy tab where you add authentication rules and profiles. For web-app access, a rule can use the Role filter (Cloud Admins), so MFA is required whenever those users launch AWS or Azure. (2) A policy set assigned to the 'Cloud Admins' role (policy sets can target all users or specified roles), placed above more general sets, applies its authentication policy (an MFA profile) to those users when they sign in to CyberArk Identity. The Role filter cannot be used in portal-login rules, policies are assigned to roles rather than individual accounts, and MFA Unlock temporarily suspends MFA instead of enforcing it.

  4. Question 4

    True or False: When using the 'MFA Unlock' command for a user in the CyberArk Identity Admin Portal, the suspension of MFA challenges is permanent until the administrator manually re-enables it.

    Answer and explanation

    Correct answer: B

    The 'MFA Unlock' command is a temporary troubleshooting tool. It suspends the multi-factor authentication requirement for the selected user for a fixed duration, typically 10 minutes, to allow them to log in and resolve their MFA device issue. After the time expires, MFA is automatically re-enforced.

  5. Question 5

    A manufacturing company is setting up a SAML-based SSO integration for a new cloud-based inventory management system. During testing, users receive a SAML error indicating an 'Invalid NameID Format'. The application vendor has specified that they require the user's UPN (User Principal Name) in the NameID field. Where in the CyberArk Identity application configuration would an administrator modify the SAML response to send the UPN as the NameID?

    Answer and explanation

    Correct answer: C

    In a CyberArk Identity SAML app, the NameID (subject) value is the login user name that the app's Account Mapping page produces (LoginUser.Username). By default the assertion script calls setSubjectName(LoginUser.Username). To send the UPN, set Account Mapping to use the directory service field userPrincipalName, or use an account mapping script. If the SP also requires a specific format, set ' Format' on the Trust page under Service Provider Configuration. The Identity Provider Configuration section holds only the IdP's entity ID, signing certificate and URLs.

  6. Question 6

    An administrator is creating a new Authentication Profile for high-risk applications. Users must first enter their password and then complete one additional factor of their choice: a Mobile Authenticator push notification, a security question, or an OATH OTP code. How should the profile be configured?

    Answer and explanation

    Correct answer: A

    An authentication profile (Settings > Authentication > Add Profile) defines Multiple Authentication Mechanisms as Challenge 1 and Challenge 2. The user must pass both challenges and may choose any one of the mechanisms selected in each challenge column. Password in Challenge 1 plus Mobile Authenticator, Security Question(s) and OATH OTP Client in Challenge 2 gives a password followed by the user's choice of second factor. Mechanisms under Single Authentication Mechanism are each enough on their own and would bypass the two challenges. The same mechanism cannot be selected in both challenge menus, and a rule selects only one profile.

  7. Question 7

    A new CyberArk Identity administrator is reviewing the corporate directory structure. They need to synchronize users from a specific Organizational Unit (OU) in Active Directory called 'Salesforce_Users' to a CyberArk role with the same name. What is the first component that must be deployed and configured in the on-premises environment to enable this synchronization?

    Answer and explanation

    Correct answer: B

    The CyberArk Identity Connector is a required component that is installed on a Windows server within the corporate network. It acts as a secure proxy between the CyberArk Identity cloud tenant and the on-premises Active Directory. It is responsible for handling authentication requests and synchronizing users, groups, and OUs.

  8. Question 8

    During a security audit, an organization is required to produce a report of all users who have successfully authenticated to any application via CyberArk Identity over the last 90 days, including the source IP address for each login. Where in the Admin Portal can this report be generated?

    Answer and explanation

    Correct answer: B

    The Admin Portal contains a dedicated 'Reports' section with numerous built-in reports for security and compliance. A report such as 'User Logins' or a similar audit event report can be filtered by date range (e.g., last 90 days) and will contain the necessary details, including username, application, timestamp, and source IP address.

  9. Question 9

    A company is using the CyberArk App Gateway to provide secure remote access to an internal legacy web application that does not support SAML. The security team wants to ensure that access to this application is logged and audited. Which component is primarily responsible for generating the audit logs for access events through the App Gateway?

    Answer and explanation

    Correct answer: C

    When a user accesses an application through the App Gateway, the initial authentication and authorization are handled by the CyberArk Identity platform. Therefore, the platform itself generates the primary audit trail for the access event, which can be viewed in the built-in reports. The App Gateway acts as a reverse proxy, but the central logging occurs within the Identity tenant.

  10. Question 10

    An administrator needs to configure automated user provisioning for Salesforce. The goal is to assign different Salesforce license types (e.g., 'Salesforce Platform', 'Chatter Free') to users based on their department attribute in Active Directory. Which CyberArk Identity feature allows for this conditional license assignment during provisioning?

    Answer and explanation

    Correct answer: C

    The 'Provisioning' feature for applications like Salesforce allows for detailed role mapping. An administrator can create mappings that link CyberArk Identity roles (which can be populated dynamically from AD groups or attributes) to specific destination roles and license types within Salesforce. This allows for fine-grained, automated assignment of the correct licenses upon user creation.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 226 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon