[Oct 09, 2023] Free CyberArk Defender EPM-DEF Official Cert Guide PDF Download CyberArk EPM-DEF Official Cert Guide PDF NEW QUESTION # 24 When deploying EPM and in the Privilege Management phase what is the purpose of Discovery? A. To identify all non-administrative events B. To identify both administrative and non-administrative level events C. To identify all administrative level events D. To identify [...]

[Oct 09, 2023] Free CyberArk Defender EPM-DEF Official Cert Guide PDF Download [Q24-Q47]

Share

[Oct 09, 2023] Free CyberArk Defender EPM-DEF Official Cert Guide PDF Download

CyberArk EPM-DEF Official Cert Guide PDF

NEW QUESTION # 24
When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?

  • A. To identify all non-administrative events
  • B. To identify both administrative and non-administrative level events
  • C. To identify all administrative level events
  • D. To identify non-administrative threats

Answer: B


NEW QUESTION # 25
When working with credential rotation at the EPM level, what is the minimum time period that can be set between connections?

  • A. 72 hours
  • B. 1 hour
  • C. 24 hours
  • D. 5 hours

Answer: A


NEW QUESTION # 26
Before enabling Ransomware Protection, what should the EPM Administrator do first?

  • A. Enable the Privilege Management Inbox in Elevate mode.
  • B. Review the Authorized Applications (Ransomware Protection) group and update if necessary.
  • C. Enable Threat Protection and Threat Intelligence modules.
  • D. Enable the Control Applications Downloaded From The Internet feature in Restrict mode.

Answer: B


NEW QUESTION # 27
An EPM Administrator would like to enable a Threat Protection policy, however, the policy protects an application that is not installed on all endpoints.
What should the EPM Administrator do?

  • A. Enable the Threat Protection policy only in Detect mode.
  • B. Enable the Threat Protection policy and configure the Policy Targets.
  • C. Do not enable the Threat Protection policy.
  • D. Split up the endpoints in to separate Sets and enable Threat Protection for only one of the Sets.

Answer: D


NEW QUESTION # 28
Match the Application Groups policy to their correct description.

Answer:

Explanation:


NEW QUESTION # 29
When adding the EPM agent to a pre-existing security stack on workstation, what two steps are CyberArk recommendations. (Choose two.)

  • A. Create new advanced policies for each security tool.
  • B. EPM agent should never be run with any other security tools.
  • C. Add any pre-existing security application to the Files to Be Ignored Always.
  • D. Add EPM agent to the other security tools exclusions.

Answer: C,D


NEW QUESTION # 30
Where can you view CyberArk EPM Credential Lures events?

  • A. Policy Audit
  • B. Threat Protection Inbox
  • C. Events Management
  • D. Application Catalog

Answer: B


NEW QUESTION # 31
Which user or group will not be removed as part of CyberArk EPM's Remove Local Administrators feature?

  • A. Admin Users
  • B. Power Users
  • C. Domain Users
  • D. Built-in Local Administrator

Answer: D


NEW QUESTION # 32
On the Default Policies page, what are the names of policies that can be set as soon as EPM is deployed?

  • A. Privilege Management, Privilege Threat Protection, Local Privileged Accounts Management
  • B. Privilege Escalation, Privilege Management, Application Management
  • C. Privilege Management, Threat Protection, Application Escalation Control
  • D. Privilege Management, Application Control, Threat analysis

Answer: A


NEW QUESTION # 33
CyberArk EPM's Ransomware Protection comes with file types to be protected out of the box. If an EPM Administrator would like to remove a file type from Ransomware Protection, where can this be done?

  • A. Policy Scope within Protect Against Ransomware
  • B. Set Security Permissions within Advanced Policies
  • C. Authorized Applications (Ransomware Protection) within Application Groups
  • D. Protected Files within Agent Configurations

Answer: D


NEW QUESTION # 34
An EPM Administrator would like to enable CyberArk EPM's Ransomware Protection in Restrict mode. What should the EPM Administrator do?

  • A. Set Block unhandled applications to On.
  • B. Set Protect Against Ransomware to Restrict and Set Block unhandled applications to On.
  • C. Set Control unhandled applications to Detect.
  • D. Set Protect Against Ransomware to Restrict.

Answer: B


NEW QUESTION # 35
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?

  • A. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours
  • B. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
  • C. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
    120 hours and Terminate administrative processes when the policy expires option unchecked
  • D. An EPM admin can create an authorization token for each application needed by running:
    EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
    -action run

Answer: C


NEW QUESTION # 36
CyberArk's Privilege Threat Protection policies are available for which Operating Systems? (Choose two.)

  • A. MacOS
  • B. Windows Servers
  • C. Linux
  • D. Windows Workstations

Answer: B,D


NEW QUESTION # 37
What are Trusted sources for Windows endpoints used for?

  • A. Creating policies that contain trusted sources of applications.
  • B. Listing all the approved application to the end users.
  • C. Defining applications that can be used by the developers.
  • D. Managing groups added by recommendation.

Answer: B


NEW QUESTION # 38
How does EPM help streamline security compliance and reporting?

  • A. Use of automated distribution of reports to the security team
  • B. Create custom reports
  • C. Provides reports in standard formats such as PDF, Word and Excel
  • D. Print reports

Answer: C


NEW QUESTION # 39
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?

  • A. Authorized Applications (Ransomware Protection)
  • B. Files to be Ignored Always
  • C. Default Policies
  • D. Anti-tampering Protection

Answer: A


NEW QUESTION # 40
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?

  • A. Target use group
  • B. Creator of the policy
  • C. Policy creation date
  • D. The policy's Set name

Answer: A


NEW QUESTION # 41
When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)

  • A. Add trusted software to the Authorized Applications (Ransomware protection) Application Group
  • B. Add additional files, folders, and/or file extensions to be included to Ransomware Protection
  • C. Add trusted software to the Allow Application Group
  • D. Enable Detect privileged unhandled applications under Default Policies

Answer: A,B


NEW QUESTION # 42
What type of user can be created from the Threat Deception LSASS Credential Lures feature?

  • A. It does not create any users
  • B. A domain admin user
  • C. A local administrator user
  • D. A standard user

Answer: D


NEW QUESTION # 43
An EPM Administrator is looking to enable the Threat Deception feature, under what section should the EPM Administrator go to enable this feature?

  • A. Policy Audit
  • B. Threat Intelligence
  • C. Threat Protection Inbox
  • D. Policies

Answer: D


NEW QUESTION # 44
Which threat intelligence source requires the suspect file to be sent externally?

  • A. CyberArk Application Risk Analysis Service (ARA)
  • B. VirusTotal
  • C. Palo Alto Wildfire
  • D. NSRL

Answer: B


NEW QUESTION # 45
If Privilege Management is not working on an endpoint, what is the most likely cause that can be verified in the EPM Agent Log Files?

  • A. Agent version is incompatible.
  • B. UAC policy Run all administrators in Admin Approval Mode is set to "Enabled".
  • C. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to "Prompt for Consent for non-Windows binaries".
  • D. UAC policy Admin Approval for the Built-in Administrator Account is set to "Disabled".

Answer: B


NEW QUESTION # 46
If you want to diagnose agent EPM agent connectivity issues, what is the agent executable that can be used from the command line?

  • A. db_agent.exe
  • B. epm_agent.exe
  • C. vf_agent.exe
  • D. vault_agent.exe

Answer: B


NEW QUESTION # 47
......


CyberArk EPM-DEF exam is designed for professionals who have experience in managing privileged accounts and implementing privileged access security solutions. EPM-DEF exam is designed to test the knowledge and skills of individuals in privileged account security, risk management, and compliance. EPM-DEF exam is also suitable for professionals who want to demonstrate their expertise in implementing privileged access security solutions and managing privileged accounts.

 

Free EPM-DEF Exam Dumps to Improve Exam Score: https://dumpsvce.exam4free.com/EPM-DEF-valid-dumps.html