Question 1
During a routine audit, it was discovered that a new team of database administrators requires temporary, emergency access to a production SQL server account. The current platform configuration for this account enforces a dual-control workflow for password retrieval. The security policy mandates that for emergency access, the request must bypass the standard dual-control approval process but still require a documented justification and be automatically revoked after two hours. Which is the most efficient and secure method to configure this exception in CyberArk?
Answer and explanation
Correct answer: C
The Master Policy is the correct place to manage exceptions to platform-level settings. Creating an exception that overrides the 'Require multi-level approval' rule for a specific time window allows for controlled, temporary emergency access without altering the base platform security for all other accounts. This method is auditable, time-bound, and aligns with the principle of least privilege. Temporarily disabling the platform setting or creating a new safe are less efficient, more disruptive, and harder to audit for a temporary access scenario.