100% Free EPM-DEF Files For passing the exam Quickly UPDATED Nov 14, 2023 EPM-DEF Dumps Questions Study Exam Guide NEW QUESTION # 35 What are Trusted sources for Windows endpoints used for? A. Creating policies that contain trusted sources of applications. B. Listing all the approved application to the end users. C. Defining applications that can be used by the developers. D. Managing groups added [...]

100% Free EPM-DEF Files For passing the exam Quickly UPDATED Nov 14, 2023 [Q35-Q58]

Share

100% Free EPM-DEF Files For passing the exam Quickly UPDATED Nov 14, 2023

EPM-DEF Dumps Questions Study Exam Guide 

NEW QUESTION # 35
What are Trusted sources for Windows endpoints used for?

  • A. Creating policies that contain trusted sources of applications.
  • B. Listing all the approved application to the end users.
  • C. Defining applications that can be used by the developers.
  • D. Managing groups added by recommendation.

Answer: B


NEW QUESTION # 36
How does a Trusted Source policy affect an application?

  • A. Applications will be allowed to run always in elevated mode.
  • B. Application from the defined trusted sources must be configured on a per application basis, in order to define run and elevation parameters.
  • C. Applications will be allowed to run and will only elevate if required.
  • D. Applications will be allowed to run and will inherit the process token from the EPM agent.

Answer: B


NEW QUESTION # 37
Where would an EPM admin configure an application policy that depends on a script returning true for an end user's machine being connected to an open (no password protection) Wi-Fi?

  • A. Advanced Policy - Options: Conditional enforcement - Apply Policy according to Script execution result
  • B. Advanced Policy - Application Control - Check Wi-Fi security
  • C. Default policies - Check if network access is secure
  • D. Advanced Policy - Access - Specify permissions to be set for Wi-Fi network security

Answer: A


NEW QUESTION # 38
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?

  • A. Policy Update Rate
  • B. Condition Timeout
  • C. Event Queue Flush Period
  • D. Heartbeat Timeout

Answer: C


NEW QUESTION # 39
A company is looking to manage their Windows Servers and Desktops with CyberArk EPM. Management would like to define different default policies between the Windows Servers and Windows Desktops.
What should the EPM Administrator do?

  • A. In the Default Policies, exclude either the Windows Servers or the Windows Desktops.
  • B. CyberArk does not recommend installing EPM Agents on Windows Servers.
  • C. Create Advanced Policies to apply different policies between Windows Servers and Windows Desktops.
  • D. Create a separate Set for Windows Servers and Windows Desktops.

Answer: C


NEW QUESTION # 40
If you want to diagnose agent EPM agent connectivity issues, what is the agent executable that can be used from the command line?

  • A. vault_agent.exe
  • B. epm_agent.exe
  • C. vf_agent.exe
  • D. db_agent.exe

Answer: B


NEW QUESTION # 41
Where can you view CyberArk EPM Credential Lures events?

  • A. Events Management
  • B. Threat Protection Inbox
  • C. Application Catalog
  • D. Policy Audit

Answer: B


NEW QUESTION # 42
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?

  • A. Files to be Ignored Always
  • B. Authorized Applications (Ransomware Protection)
  • C. Anti-tampering Protection
  • D. Default Policies

Answer: B


NEW QUESTION # 43
Can the EPM Set Administrator configure Audit Dialog Pop-ups for the Record Audit Video option?

  • A. Yes, when Audit Video recording started, when Audit Video recording is uploaded to the EPM server, and when audit recording cannot be initialized.
  • B. Yes, when Audit Video recording started, when Audit Video recording stopped, and when Audit Recording video reached size limit.
  • C. Yes, when Audit Video recording started, when not enough disk space to start the video recording, and when video recording is initializing.
  • D. No, Audit Video is only available without the possibility of having End-User dialog pop-ups.

Answer: D


NEW QUESTION # 44
An EPM Administrator is looking to enable the Threat Deception feature, under what section should the EPM Administrator go to enable this feature?

  • A. Policies
  • B. Threat Intelligence
  • C. Threat Protection Inbox
  • D. Policy Audit

Answer: A


NEW QUESTION # 45
For Advanced Policies, what can the target operating system users be set to?

  • A. Local or AD users and groups, Azure AD User, Azure AD Group
  • B. AD Groups, Azure AD Groups
  • C. Local or AD users and groups
  • D. Local or AD users, Azure AD Users

Answer: C


NEW QUESTION # 46
What unauthorized change can CyberArk EPM Ransomware Protection prevent?

  • A. Local Administrator Passwords
  • B. Windows Registry Keys
  • C. Certificates in the Certificate Store
  • D. Website Data

Answer: C


NEW QUESTION # 47
When enabling Threat Protection policies, what should an EPM Administrator consider? (Choose two.)

  • A. Threat Protection policies requires an additional agent to be installed.
  • B. Some Threat Protection policies are applicable only for Windows Servers as opposed to Workstations.
  • C. Certain Threat Protection policies apply for specific applications not found on all machines
  • D. Threat Protection features are not available in all regions.

Answer: B,C


NEW QUESTION # 48
Which programming interface enables you to perform activities on EPM objects via a REST Web Service?

  • A. Application Password SDK
  • B. Java password SDK
  • C. EPM Web Services SDK
  • D. Mac Credential Provider SDK

Answer: C


NEW QUESTION # 49
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?

  • A. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours
  • B. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
  • C. An EPM admin can create an authorization token for each application needed by running:
    EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
    -action run
  • D. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours and Terminate administrative processes when the policy expires option unchecked

Answer: D


NEW QUESTION # 50
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?

  • A. Policy creation date
  • B. Target use group
  • C. The policy's Set name
  • D. Creator of the policy

Answer: B


NEW QUESTION # 51
Which of the following is CyberArk's Recommended FIRST roll out strategy?

  • A. Implement Threat Detection
  • B. Implement Application Control
  • C. Implement Ransomware Protection
  • D. Implement Privilege Management

Answer: D


NEW QUESTION # 52
On the Default Policies page, what are the names of policies that can be set as soon as EPM is deployed?

  • A. Privilege Management, Privilege Threat Protection, Local Privileged Accounts Management
  • B. Privilege Management, Application Control, Threat analysis
  • C. Privilege Escalation, Privilege Management, Application Management
  • D. Privilege Management, Threat Protection, Application Escalation Control

Answer: A


NEW QUESTION # 53
What feature is designed to exclude applications from CyberArk EPM's Ransomware Protection, without whitelisting the application launch?

  • A. Policy Recommendations
  • B. Authorized Applications (Ransomware Protection)
  • C. Threat Intelligence
  • D. Trusted Sources

Answer: B


NEW QUESTION # 54
After a clean installation of the EPM agent, the local administrator password is not being changed on macOS and the old password can still be used to log in.
What is a possible cause?

  • A. Endpoint password policy is too restrictive.
  • B. After installation, Full Disk Access for the macOS agent to support EPM policies was not approved.
  • C. Secure Token on macOS endpoint is not enabled.
  • D. EPM agent is not able to connect to the EPM server.

Answer: C


NEW QUESTION # 55
Match the Application Groups policy to their correct description.

Answer:

Explanation:


NEW QUESTION # 56
Which of the following application options can be used when defining trusted sources?

  • A. Product, URL, Machine, Package
  • B. Product, Publisher, User/Group, Installation Package
  • C. Publisher, Name, Size, URI
  • D. Publisher, Product, Size, URL

Answer: B


NEW QUESTION # 57
What is a valid step to investigate an EPM agent that is unable to connect to the EPM server?

  • A. Ping the endpoint from the EPM server.
  • B. On the end point, open a browser session to the URL of the EPM server.
  • C. Ping the server from the endpoint.
  • D. Restart the end point

Answer: C


NEW QUESTION # 58
......


CyberArk Defender - EPM certification exam is an excellent choice for IT professionals who want to demonstrate their expertise in endpoint security management. EPM-DEF exam covers a wide range of topics related to secure endpoint management and is recognized globally by employers. By obtaining this certification, IT professionals can enhance their skills and knowledge in this critical area of IT security and advance their careers.

 

EPM-DEF Premium Exam Engine - Download Free PDF Questions: https://dumpsvce.exam4free.com/EPM-DEF-valid-dumps.html