[Oct 09, 2023] Free CyberArk Defender EPM-DEF Official Cert Guide PDF Download
CyberArk EPM-DEF Official Cert Guide PDF
NEW QUESTION # 24
When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?
- A. To identify all non-administrative events
- B. To identify both administrative and non-administrative level events
- C. To identify all administrative level events
- D. To identify non-administrative threats
Answer: B
NEW QUESTION # 25
When working with credential rotation at the EPM level, what is the minimum time period that can be set between connections?
- A. 72 hours
- B. 1 hour
- C. 24 hours
- D. 5 hours
Answer: A
NEW QUESTION # 26
Before enabling Ransomware Protection, what should the EPM Administrator do first?
- A. Enable the Privilege Management Inbox in Elevate mode.
- B. Review the Authorized Applications (Ransomware Protection) group and update if necessary.
- C. Enable Threat Protection and Threat Intelligence modules.
- D. Enable the Control Applications Downloaded From The Internet feature in Restrict mode.
Answer: B
NEW QUESTION # 27
An EPM Administrator would like to enable a Threat Protection policy, however, the policy protects an application that is not installed on all endpoints.
What should the EPM Administrator do?
- A. Enable the Threat Protection policy only in Detect mode.
- B. Enable the Threat Protection policy and configure the Policy Targets.
- C. Do not enable the Threat Protection policy.
- D. Split up the endpoints in to separate Sets and enable Threat Protection for only one of the Sets.
Answer: D
NEW QUESTION # 28
Match the Application Groups policy to their correct description.
Answer:
Explanation:

NEW QUESTION # 29
When adding the EPM agent to a pre-existing security stack on workstation, what two steps are CyberArk recommendations. (Choose two.)
- A. Create new advanced policies for each security tool.
- B. EPM agent should never be run with any other security tools.
- C. Add any pre-existing security application to the Files to Be Ignored Always.
- D. Add EPM agent to the other security tools exclusions.
Answer: C,D
NEW QUESTION # 30
Where can you view CyberArk EPM Credential Lures events?
- A. Policy Audit
- B. Threat Protection Inbox
- C. Events Management
- D. Application Catalog
Answer: B
NEW QUESTION # 31
Which user or group will not be removed as part of CyberArk EPM's Remove Local Administrators feature?
- A. Admin Users
- B. Power Users
- C. Domain Users
- D. Built-in Local Administrator
Answer: D
NEW QUESTION # 32
On the Default Policies page, what are the names of policies that can be set as soon as EPM is deployed?
- A. Privilege Management, Privilege Threat Protection, Local Privileged Accounts Management
- B. Privilege Escalation, Privilege Management, Application Management
- C. Privilege Management, Threat Protection, Application Escalation Control
- D. Privilege Management, Application Control, Threat analysis
Answer: A
NEW QUESTION # 33
CyberArk EPM's Ransomware Protection comes with file types to be protected out of the box. If an EPM Administrator would like to remove a file type from Ransomware Protection, where can this be done?
- A. Policy Scope within Protect Against Ransomware
- B. Set Security Permissions within Advanced Policies
- C. Authorized Applications (Ransomware Protection) within Application Groups
- D. Protected Files within Agent Configurations
Answer: D
NEW QUESTION # 34
An EPM Administrator would like to enable CyberArk EPM's Ransomware Protection in Restrict mode. What should the EPM Administrator do?
- A. Set Block unhandled applications to On.
- B. Set Protect Against Ransomware to Restrict and Set Block unhandled applications to On.
- C. Set Control unhandled applications to Detect.
- D. Set Protect Against Ransomware to Restrict.
Answer: B
NEW QUESTION # 35
A particular user in company ABC requires the ability to run any application with administrative privileges every day that they log in to their systems for a total duration of 5 working days.
What is the correct solution that an EPM admin can implement?
- A. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours - B. An EPM admin can create a secure token for the end user's computer and instruct the end user to open an administrative command prompt and run the command vfagent.exe -UseToken <securetoken_value>
- C. An EPM admin can generate a JIT access and elevation policy with temporary access timeframe set to
120 hours and Terminate administrative processes when the policy expires option unchecked - D. An EPM admin can create an authorization token for each application needed by running:
EPMOPAGtool.exe -command gentoken -targetUser <username> -filehash <file hash> -timeLimit 120
-action run
Answer: C
NEW QUESTION # 36
CyberArk's Privilege Threat Protection policies are available for which Operating Systems? (Choose two.)
- A. MacOS
- B. Windows Servers
- C. Linux
- D. Windows Workstations
Answer: B,D
NEW QUESTION # 37
What are Trusted sources for Windows endpoints used for?
- A. Creating policies that contain trusted sources of applications.
- B. Listing all the approved application to the end users.
- C. Defining applications that can be used by the developers.
- D. Managing groups added by recommendation.
Answer: B
NEW QUESTION # 38
How does EPM help streamline security compliance and reporting?
- A. Use of automated distribution of reports to the security team
- B. Create custom reports
- C. Provides reports in standard formats such as PDF, Word and Excel
- D. Print reports
Answer: C
NEW QUESTION # 39
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection. What setting should the EPM Administrator configure to add the extension?
- A. Authorized Applications (Ransomware Protection)
- B. Files to be Ignored Always
- C. Default Policies
- D. Anti-tampering Protection
Answer: A
NEW QUESTION # 40
A policy needs to be created to block particular applications for a specific user group. Based on CyberArk's policy naming best practices, what should be included in the policy's name?
- A. Target use group
- B. Creator of the policy
- C. Policy creation date
- D. The policy's Set name
Answer: A
NEW QUESTION # 41
When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)
- A. Add trusted software to the Authorized Applications (Ransomware protection) Application Group
- B. Add additional files, folders, and/or file extensions to be included to Ransomware Protection
- C. Add trusted software to the Allow Application Group
- D. Enable Detect privileged unhandled applications under Default Policies
Answer: A,B
NEW QUESTION # 42
What type of user can be created from the Threat Deception LSASS Credential Lures feature?
- A. It does not create any users
- B. A domain admin user
- C. A local administrator user
- D. A standard user
Answer: D
NEW QUESTION # 43
An EPM Administrator is looking to enable the Threat Deception feature, under what section should the EPM Administrator go to enable this feature?
- A. Policy Audit
- B. Threat Intelligence
- C. Threat Protection Inbox
- D. Policies
Answer: D
NEW QUESTION # 44
Which threat intelligence source requires the suspect file to be sent externally?
- A. CyberArk Application Risk Analysis Service (ARA)
- B. VirusTotal
- C. Palo Alto Wildfire
- D. NSRL
Answer: B
NEW QUESTION # 45
If Privilege Management is not working on an endpoint, what is the most likely cause that can be verified in the EPM Agent Log Files?
- A. Agent version is incompatible.
- B. UAC policy Run all administrators in Admin Approval Mode is set to "Enabled".
- C. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to "Prompt for Consent for non-Windows binaries".
- D. UAC policy Admin Approval for the Built-in Administrator Account is set to "Disabled".
Answer: B
NEW QUESTION # 46
If you want to diagnose agent EPM agent connectivity issues, what is the agent executable that can be used from the command line?
- A. db_agent.exe
- B. epm_agent.exe
- C. vf_agent.exe
- D. vault_agent.exe
Answer: B
NEW QUESTION # 47
......
CyberArk EPM-DEF exam is designed for professionals who have experience in managing privileged accounts and implementing privileged access security solutions. EPM-DEF exam is designed to test the knowledge and skills of individuals in privileged account security, risk management, and compliance. EPM-DEF exam is also suitable for professionals who want to demonstrate their expertise in implementing privileged access security solutions and managing privileged accounts.
Free EPM-DEF Exam Dumps to Improve Exam Score: https://dumpsvce.exam4free.com/EPM-DEF-valid-dumps.html
