exam questions

Exam PAM-DEF All Questions

View all questions & answers for the PAM-DEF exam

Exam PAM-DEF topic 1 question 9 discussion

Actual exam question from CyberArk's PAM-DEF
Question #: 9
Topic #: 1
[All PAM-DEF Questions]

Which processes reduce the risk of credential theft? (Choose two.)

  • A. require dual control password access approval
  • B. require password change every X days
  • C. enforce check-in/check-out exclusive access
  • D. enforce one-time password access
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
uswarrior
Highly Voted 1 year, 4 months ago
Selected Answer: BD
I think the answer should be B and D. In order to prevent credential theft, one needs to rotate passwords and make use of OTPs. Dual control is to prevent insider threat and exclusive access (check in and check out) is for user accountability.
upvoted 7 times
...
penuelaandy
Highly Voted 1 year, 9 months ago
Selected Answer: CD
Sample exam by cyberark says the proccess to reduce the risk is using one-time passwords. Using Dual-Control is to enforce collusion, IMO.
upvoted 7 times
...
cf57f90
Most Recent 1 month, 2 weeks ago
Selected Answer: CD
The Answer is: CD
upvoted 2 times
...
Imdroc
2 months, 3 weeks ago
Selected Answer: CD
The Answer is: CD
upvoted 1 times
...
JasonLee
5 months, 1 week ago
Selected Answer: CD
To achieve personal accountability, enable this rule and the Enforce check-in/check-out exclusive access rule together. The timeframe that an account will be available before it will be automatically changed is determined by the MinValidityPeriod platform setting or by the timeframe defined in the dual control request. https://docs.cyberark.com/privilege-cloud-standard/Latest/en/Content/Privilege%20Cloud/privCloud-master-policy-rules.htm
upvoted 1 times
...
Jabelo
10 months, 1 week ago
Selected Answer: BD
BD is correct
upvoted 3 times
...
acello
1 year ago
Selected Answer: BD
BD because if credential theft is suspected, one would rotate credentials. Only B and D present options for rotating credentials while A and C focus on non-repudiation specifically.
upvoted 4 times
...
ThomasKong
1 year, 1 month ago
From my perspective, my answer is A & B A - Dual Control - Let say Password A has been hacked, but B still holding by another approval person. B - Change password x day - usually this is offer for those ID after usage or the ID keep on rotate min 1 day/1 hour after usage. Its will reduce the Password get stolen risk. C & D - Enforce means, check in and one time password seem like the security not still strong yet. Although, the method seem strong, but just give an example. Is the hacker, require try few times to enter your system ? check in check out and enforce to login one time, seem enough time to hacker go into your system. And this 2 method seem like same concept, is only allow a single person login into server. So, what is the prevent and control here ?
upvoted 1 times
...
miky_Cissp
1 year, 1 month ago
AC A. Require dual control password access approval: This process ensures that users must receive approval from authorized users before they can access passwords, reducing the risk of unauthorized access. C. Enforce check-in/check-out exclusive access: This process ensures that only one user can access a privileged credential at a given time, providing a clear audit trail and reducing the risk of credential theft.
upvoted 2 times
...
WHudson
1 year, 2 months ago
Selected Answer: BD
BD - according to the sample CyberArk questions: Exclusive access - Non-repudation (individual accountability) One Time Password - Reduced risk of credential theft Dual Control - To force "collusion to commit"
upvoted 5 times
...
Remy
1 year, 3 months ago
Selected Answer: BD
https://docs.cyberark.com/PrivCloud/Latest/en/Content/Privilege%20Cloud/privCloud-master-policy-rules.htm
upvoted 1 times
...
brossva
1 year, 5 months ago
Selected Answer: CD
CD is correcct
upvoted 1 times
...
umesh02
1 year, 9 months ago
A,D both impact stopping credential theft immediately
upvoted 1 times
umesh02
1 year, 9 months ago
Its CD
upvoted 3 times
...
...
Ketan_20
1 year, 9 months ago
Answers: B,C https://cyberark-customers.force.com/s/article/Securing-Human-Interactive-PAM-Administrator-PowerShell-Scripts#:~:text=Shorter%20rotation%20intervals%20and%20the%20use%20of%20one-time,PAM%20administrator%20credentials%20because%20of%20their%20high-risk%20nature.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...