Cyberark Defender Endpoint Privilege Manager Free Sample Questions

Covers core EPM concepts and architecture, installation, setup and customization, elevation and application control policies, user and group management, and troubleshooting and maintenance.

20 free sample questions218 in the full practice test

Try simulator

EPM-DEF Sample Questions

  1. Question 1

    A financial services firm is deploying CyberArk EPM to achieve PCI DSS compliance. A key requirement is to control and audit the use of command-line tools like regedit.exe and cmd.exe on servers handling cardholder data. The security team wants to allow specific administrators to use these tools but require a documented business justification for each use. Which EPM policy configuration is the most effective and compliant approach?

    Answer and explanation

    Correct answer: C

    This is the most effective and compliant solution. It allows authorized users to run the necessary tools while enforcing a mandatory justification prompt. This action is audited, creating a clear record that directly supports PCI DSS requirements for tracking and justifying administrative actions in the cardholder data environment.

  2. Question 2

    A pharmaceutical company is using EPM to manage local administrator rights. The security policy dictates that the built-in local Administrator account (SID S-1-5-....-500) must be disabled and its password vaulted, but a specific domain group, 'PharmaLab Admins', must be retained in the local Administrators group on lab workstations. When configuring the 'Remove Local Administrators' policy, which action should be taken?

    Answer and explanation

    Correct answer: B

    The 'Remove Local Administrators' policy is designed to remove accounts from the local Administrators group. To prevent a specific user or group from being removed, it must be added to the Exclusions list within the policy configuration. The built-in Administrator account is typically not removed by this policy by default, so excluding it is unnecessary.

  3. Question 3

    Multiple answers

    During an EPM agent deployment to a set of isolated, air-gapped industrial control systems (ICS), a consultant discovers the endpoints have no network connectivity to the EPM server. A technician on-site needs to run a specific diagnostics tool that requires elevation, but no pre-existing policies on the agent allow this. Which EPM feature is designed for this specific scenario? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Secure Token generation is a mechanism specifically for authorizing actions on disconnected endpoints. An administrator generates a time-sensitive token that can be relayed to the user.

    The On-demand Policy Authorization Generator is the tool used by an administrator with EPM console access to create a one-time authorization code (Secure Token) for a specific application on a specific offline machine.

  4. Question 4

    True or False: When an EPM policy is configured to elevate an application using the 'Run with administrative privileges' action, the application's child processes will also be elevated by default.

    Answer and explanation

    Correct answer: B

    By default, EPM does not automatically elevate child processes spawned by an elevated parent application. This is a security feature to prevent privilege escalation. To elevate child processes, the 'Elevate child processes' option must be explicitly enabled within the advanced policy settings.

  5. Question 5

    A university is using EPM to manage student lab computers. They want to prevent students from installing unauthorized software. The IT team has created a 'Trusted Sources' policy to allow installations only from the university's software portal and network shares. A student attempts to install a legitimate, digitally signed application downloaded from the vendor's official website, but the installation is blocked. What is the most likely reason for this block?

    Answer and explanation

    Correct answer: C

    Trusted Sources policies restrict installations to specific origins, such as URLs, network paths, or publishers. Even if an application is legitimate and signed, if its download source (the vendor's website) is not explicitly listed in the 'Trusted Sources' definition, EPM will block the installation as it originates from an untrusted location.

  6. Question 6

    An EPM administrator is analyzing event data and notices that a large number of 'Privilege Threat' events are being generated by a custom in-house application that performs memory scraping as part of its normal function. This is causing a high volume of false positives. What is the recommended approach to suppress these specific events without disabling threat protection for other applications?

    Answer and explanation

    Correct answer: B

    The correct way to handle legitimate applications that trigger threat protection events is to create an Application Group for that specific application. This Application Group can then be added to the Exclusions list within the Privilege Threat Protection policy. This surgically excludes only the specified application, maintaining protection for all other processes.

  7. Question 7

    A system administrator needs to define a flexible Application Group that includes all executables within any subfolder of C:\Program Files\VendorTools\. The folder structure under VendorTools changes frequently as new versions are released. Which parameter type should be used to define the application path to ensure all current and future tools are included?

    Answer and explanation

    Correct answer: B

    Using the 'Folder Path' parameter type and enabling the 'Include subfolders' option is the most robust and maintainable method. This configuration dynamically includes any executable within the specified root folder and all its subdirectories, automatically accommodating new versions and tools without requiring policy updates.

  8. Question 8

    Multiple answers

    A global retailer is deploying EPM to thousands of Point-of-Sale (POS) terminals across different geographical regions with varying network latency. To optimize performance and reduce load on the central EPM server, the administrator needs to control how frequently agents check in for policy updates and send collected events. Which TWO settings in the Agent Configuration are most relevant for this task?

    Answer and explanation

    Correct answers: A, D

    This setting directly controls how often the agent contacts the server to check for new or updated policies. Increasing this interval for stable environments like POS terminals reduces network traffic and server load.

    This setting determines how often the agent sends its collected event data to the server. Increasing this period means the agent batches more events together before sending, which reduces the frequency of communication and is ideal for high-latency networks.

  9. Question 9

    Case Study

    A manufacturing company, 'RoboCorp', is implementing CyberArk EPM to secure its factory floor workstations, which run critical production software. The environment is strictly controlled, and any downtime is extremely costly. The CISO has mandated a Zero Trust, least-privilege model.

    Current Situation:
    Factory operators currently run as local administrators to use legacy machine control software ('ControlApp.exe'), which requires elevated rights to interact with hardware drivers. The software is old, unsigned, and its publisher is unknown. The IT team has deployed EPM agents in 'Detect' mode and has collected data for one week.

    Requirements:

    1. Remove all operator accounts from the local Administrators group.
    2. Allow 'ControlApp.exe' to run with the necessary elevated privileges without prompting the operator.
    3. Prevent any other unauthorized applications from running.
    4. Ensure the solution is highly resilient and continues to function even if the EPM server is temporarily unreachable.

    Which EPM policy configuration best meets all of RoboCorp's requirements?

    Answer and explanation

    Correct answer: B

    This solution meets all requirements. It removes admin rights. It uses a file hash to securely identify the specific, unsigned application. The Elevate policy runs it silently (no prompt). The default block policy prevents unauthorized software. Because policies are cached locally on the agent, this configuration will continue to function correctly even if the EPM server is unreachable, ensuring factory resilience.

  10. Question 10

    An administrator is troubleshooting an EPM policy that is supposed to elevate setup.exe for a specific application. The policy uses the application's digital signature for identification. However, when a user tries to run the installer, it is not elevated. The administrator verifies the policy is active and applied to the correct computer set. The following flowchart represents the EPM agent's policy evaluation logic. Based on the diagram, what is the MOST likely cause of the failure?

    flowchart TD A[User launches setup.exe] --> B{Is application in policy?}; B -->|No| C[Apply Default Policy]; B -->|Yes| D{Does signature match?}; D -->|No| E[Block/Detect as per policy]; D -->|Yes| F{Is user/computer in scope?}; F -->|No| G[Ignore Policy Match]; F -->|Yes| H[Elevate Application];

    Answer and explanation

    Correct answer: B

    According to the flowchart, after confirming the application is defined in a policy (B), the next critical check is the signature match (D). Since the administrator has already verified the policy is active and the computer is in scope (implying F is correct), the most probable point of failure is the signature check (D). This could happen if the vendor released a new version signed with a different certificate, or if the file's signature is corrupted or expired.