Free CyberArk EPM-DEF practice questions

10 free CyberArk EPM-DEF practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 154 questions. Work through them, then open each answer to check your reasoning.

Question 1

A Helpdesk technician needs to provide remote assistance to a user whose laptop cannot connect to the Internet to pull EPM policies.

What CyberArk EPM feature should the Helpdesk technician use to allow the user elevation capabilities?

  1. Offline Policy Authorization Generator
  2. Elevate Trusted Application If Necessary
  3. Just In Time Access and Elevation
  4. Loosely Connected Devices Credential Management
Show answer and explanation

Correct answer: A. Offline Policy Authorization Generator

The Offline Policy Authorization Generator is the CyberArk EPM feature designed to enable elevation capabilities for users whose devices cannot connect to the internet to pull EPM policies. This feature generates authorization tokens that allow elevation to proceed in offline scenarios, making it the correct choice for a disconnected helpdesk support situation.

Why the other options are wrong

  • B. Elevate Trusted Application If Necessary is a policy condition, not a feature for offline elevation authorization.
  • C. Just In Time Access and Elevation requires internet connectivity to the EPM Server for real-time authorization.
  • D. Loosely Connected Devices Credential Management addresses credential management for poorly connected devices, not elevation authorization.

Question 2

Which user or group will not be removed as part of CyberArk EPM's Remove Local Administrators feature?

  1. Built-in Local Administrator
  2. Domain Users
  3. Admin Users
  4. Power Users
Show answer and explanation

Correct answer: A. Built-in Local Administrator

The Built-in Local Administrator account is protected and will not be removed by CyberArk EPM's Remove Local Administrators feature. This is a system-level protection to ensure that administrative access is not completely lost during policy enforcement.

Why the other options are wrong

  • B. Domain Users can be removed from local administrator groups as part of policy enforcement.
  • C. Admin Users are typically the target of removal policies and will be removed if not specifically protected.
  • D. Power Users can be removed from local administrator groups as part of the administrative removal policy.

Question 3

An end user is reporting that an application that needs administrative rights is crashing when selecting a certain option menu item. The Application is part of an advanced elevate policy and is working correctly except when using that menu item.

What could be the EPM cause of the error?

  1. The Users defined in the advanced policy do not include the end user running the application.
  2. The Advanced: Time options are not set correctly to include the time that the user is running the application at.
  3. The Elevate Child Processes option is not enabled.
  4. The Specify permissions to be set for selected Services on End-user Computers is set to Allow Start/Stop
Show answer and explanation

Correct answer: C. The Elevate Child Processes option is not enabled.

When an application crashes on a specific menu item that requires administrative rights, the issue is typically that child processes spawned by the application are not being elevated. Enabling the 'Elevate Child Processes' option ensures that any subprocesses initiated by the main application receive the necessary administrative privileges, resolving crashes caused by permission-dependent menu operations.

Why the other options are wrong

  • A. If the user was not included in the policy, the entire application would fail, not just a specific menu item.
  • B. Time-based restrictions would prevent elevation at all times, not cause selective failures on specific menu items.
  • D. Service permission settings control which services can be started or stopped, not application menu functionality.

Question 4

Which setting in the agent configuration controls how often the agent sends events to the EPM Server?

  1. Event Queue Flush Period
  2. Heartbeat Timeout
  3. Condition Timeout
  4. Policy Update Rate
Show answer and explanation

Correct answer: A. Event Queue Flush Period

The Event Queue Flush Period setting in agent configuration controls the interval at which the EPM Agent sends accumulated events to the EPM Server. This setting determines how frequently event data is transmitted, allowing administrators to balance real-time monitoring with network efficiency.

Why the other options are wrong

  • B. Heartbeat Timeout controls how long the server waits before considering an agent unresponsive, not event transmission frequency.
  • C. Condition Timeout relates to policy condition evaluation timing, not event queue flushing.
  • D. Policy Update Rate controls how often the agent checks for policy updates from the server, not event transmission frequency.

Question 5

Which of the following application options can be used when defining trusted sources?

  1. Publisher, Product, Size, URL
  2. Publisher, Name, Size, URI
  3. Product, URL, Machine, Package
  4. Product, Publisher, User/Group, Installation Package
Show answer and explanation

Correct answer: D. Product, Publisher, User/Group, Installation Package

When defining trusted sources in CyberArk EPM, the available application options include Product, Publisher, User/Group, and Installation Package. These criteria allow administrators to identify and trust applications based on their origin, ownership, user context, and installation source.

Why the other options are wrong

  • A. Size and URL are not valid criteria for defining trusted application sources in EPM.
  • B. URI is not a standard option for trusted source application matching in EPM policies.
  • C. Machine as a trusted source criterion is not part of the application definition options in EPM.

Question 6

What EPM component is responsible for communicating password changes in credential rotation?

  1. EPM Agent
  2. EPM Server
  3. EPM API
  4. EPM Discovery
Show answer and explanation

Correct answer: A. EPM Agent

The EPM Agent is responsible for communicating password changes during credential rotation. When a credential rotation occurs, the agent on the endpoint receives the new credentials and applies them, then communicates the rotation status back to the EPM Server.

Why the other options are wrong

  • B. The EPM Server initiates and orchestrates rotation but does not directly communicate changes to endpoints.
  • C. The EPM API facilitates integration but is not the component responsible for credential change communication.
  • D. EPM Discovery identifies credentials and systems but does not handle credential rotation communication.

Question 7

An EPM Administrator would like to notify end users whenever the Elevate policy is granting users elevation for their applications.

Where should the EPM Administrator go to enable the end-user dialog?

  1. End-user UI in the left panel of the console
  2. Advanced, Agent Configurations
  3. Default Policies
  4. End-User UI within the policy
Show answer and explanation

Correct answer: D. End-User UI within the policy

The End-User UI settings within the specific policy allow EPM Administrators to configure and enable notifications that inform end users when elevation has been granted. This policy-level setting controls the user-facing dialog that appears during elevation events.

Why the other options are wrong

  • A. The End-user UI left panel in the console configures global UI settings, not elevatio-pecific notifications.
  • B. Advanced Agent Configurations control agent behavior and reporting, not end-user elevation dialogs.
  • C. Default Policies provide baseline policy templates but do not contain end-user notification settings for elevation.

Question 8

Which of the following is CyberArk's Recommended FIRST roll out strategy?

  1. Implement Application Control
  2. Implement Privilege Management
  3. Implement Threat Detection
  4. Implement Ransomware Protection
Show answer and explanation

Correct answer: B. Implement Privilege Management

CyberArk recommends implementing Privilege Management as the first rollout strategy for EPM. This foundational approach establishes control over administrative privileges and elevation rights before implementing broader security features, allowing organizations to stabilize privilege management before adding additional security layers.

Why the other options are wrong

  • A. Application Control is typically implemented after privilege management is established.
  • C. Threat Detection is an advanced monitoring capability implemented after foundational controls are in place.
  • D. Ransomware Protection is a specialized use case typically deployed after core privilege management is operational.

Question 9

An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection.

What setting should the EPM Administrator configure to add the extension?

  1. Authorized Applications (Ransomware Protection)
  2. Files to be Ignored Always
  3. Anti-tampering Protection
  4. Default Policies
Show answer and explanation

Correct answer: A. Authorized Applications (Ransomware Protection)

Authorized Applications under Ransomware Protection is the setting where an EPM Administrator configures file extensions to be monitored and protected. This setting allows administrators to specify which file types should be subject to ransomware protection policies.

Why the other options are wrong

  • B. Files to be Ignored Always is used to exclude files from monitoring, not to add extensions for protection.
  • C. Anti-tampering Protection prevents unauthorized modification of security software itself, not file extension monitoring.
  • D. Default Policies provides baseline protection rules but is not where specific file extensions are configured for monitoring.

Question 10

When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?

  1. To identify all non-administrative events
  2. To identify all administrative level events
  3. To identify both administrative and non-administrative level events
  4. To identify non-administrative threats
Show answer and explanation

Correct answer: C. To identify both administrative and non-administrative level events

Discovery in the Privilege Management phase identifies both administrative and no-dministrative level events to provide a comprehensive understanding of all user activities and privilege usage patterns across the environment. This comprehensive analysis enables informed policy creation.

Why the other options are wrong

  • A. Discovery identifies more than just non-administrative events; it captures the full scope of activity.
  • B. Discovery is not limited to administrative events only; it captures both levels of activity.
  • D. Discovery identifies events, not threats, and covers both administrative and no-dministrative activities.

That was 10 of 154.

The full CyberArk EPM-DEF pack has all 154 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack