CyberArk Defender - EPM Sample Questions:
1. An EPM Administrator would like to exclude an application from all Threat Protection modules. Where should the EPM Administrator make this change?
A) Privilege Threat Protection under Policies.
B) Authorized Applications under Application Groups.
C) Protect Against Ransomware under Default Policies.
D) Threat Protection under Agent Configurations.
2. When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)
A) Add trusted software to the Authorized Applications (Ransomware protection) Application Group
B) Enable Detect privileged unhandled applications under Default Policies
C) Add trusted software to the Allow Application Group
D) Add additional files, folders, and/or file extensions to be included to Ransomware Protection
3. An EPM Administrator is looking to enable the Threat Deception feature, under what section should the EPM Administrator go to enable this feature?
A) Threat Protection Inbox
B) Policies
C) Policy Audit
D) Threat Intelligence
4. A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?
A) An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
B) An EPM admin can create an authorization token for each application needed by running:
EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
-action run
C) An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours
D) An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours and Terminate administrative processes when the policy expires option unchecked
5. What is the CyberArk recommended practice when deploying the EPM agent to non-persistent VDIs?
A) a separate license
B) a VDI advanced policy
C) A separate set
D) A separate computer group
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: A,D | Question # 3 Answer: B | Question # 4 Answer: D | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Matt

