10 free CyberArk EPM-DEF practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 154 questions. Work through them, then open each answer to check your reasoning.
Get all 154 questions (US$39) · Download these 10 as a PDF
Question 1
A Helpdesk technician needs to provide remote assistance to a user whose laptop cannot connect to the Internet to pull EPM policies.
What CyberArk EPM feature should the Helpdesk technician use to allow the user elevation capabilities?
Show answer and explanation
Correct answer: A. Offline Policy Authorization Generator
The Offline Policy Authorization Generator is the CyberArk EPM feature designed to enable elevation capabilities for users whose devices cannot connect to the internet to pull EPM policies. This feature generates authorization tokens that allow elevation to proceed in offline scenarios, making it the correct choice for a disconnected helpdesk support situation.
Why the other options are wrong
- B. Elevate Trusted Application If Necessary is a policy condition, not a feature for offline elevation authorization.
- C. Just In Time Access and Elevation requires internet connectivity to the EPM Server for real-time authorization.
- D. Loosely Connected Devices Credential Management addresses credential management for poorly connected devices, not elevation authorization.
Question 2
Which user or group will not be removed as part of CyberArk EPM's Remove Local Administrators feature?
Show answer and explanation
Correct answer: A. Built-in Local Administrator
The Built-in Local Administrator account is protected and will not be removed by CyberArk EPM's Remove Local Administrators feature. This is a system-level protection to ensure that administrative access is not completely lost during policy enforcement.
Why the other options are wrong
- B. Domain Users can be removed from local administrator groups as part of policy enforcement.
- C. Admin Users are typically the target of removal policies and will be removed if not specifically protected.
- D. Power Users can be removed from local administrator groups as part of the administrative removal policy.
Question 3
An end user is reporting that an application that needs administrative rights is crashing when selecting a certain option menu item. The Application is part of an advanced elevate policy and is working correctly except when using that menu item.
What could be the EPM cause of the error?
Show answer and explanation
Correct answer: C. The Elevate Child Processes option is not enabled.
When an application crashes on a specific menu item that requires administrative rights, the issue is typically that child processes spawned by the application are not being elevated. Enabling the 'Elevate Child Processes' option ensures that any subprocesses initiated by the main application receive the necessary administrative privileges, resolving crashes caused by permission-dependent menu operations.
Why the other options are wrong
- A. If the user was not included in the policy, the entire application would fail, not just a specific menu item.
- B. Time-based restrictions would prevent elevation at all times, not cause selective failures on specific menu items.
- D. Service permission settings control which services can be started or stopped, not application menu functionality.
Question 4
Which setting in the agent configuration controls how often the agent sends events to the EPM Server?
Show answer and explanation
Correct answer: A. Event Queue Flush Period
The Event Queue Flush Period setting in agent configuration controls the interval at which the EPM Agent sends accumulated events to the EPM Server. This setting determines how frequently event data is transmitted, allowing administrators to balance real-time monitoring with network efficiency.
Why the other options are wrong
- B. Heartbeat Timeout controls how long the server waits before considering an agent unresponsive, not event transmission frequency.
- C. Condition Timeout relates to policy condition evaluation timing, not event queue flushing.
- D. Policy Update Rate controls how often the agent checks for policy updates from the server, not event transmission frequency.
Question 5
Which of the following application options can be used when defining trusted sources?
Show answer and explanation
Correct answer: D. Product, Publisher, User/Group, Installation Package
When defining trusted sources in CyberArk EPM, the available application options include Product, Publisher, User/Group, and Installation Package. These criteria allow administrators to identify and trust applications based on their origin, ownership, user context, and installation source.
Why the other options are wrong
- A. Size and URL are not valid criteria for defining trusted application sources in EPM.
- B. URI is not a standard option for trusted source application matching in EPM policies.
- C. Machine as a trusted source criterion is not part of the application definition options in EPM.
Question 6
What EPM component is responsible for communicating password changes in credential rotation?
Show answer and explanation
Correct answer: A. EPM Agent
The EPM Agent is responsible for communicating password changes during credential rotation. When a credential rotation occurs, the agent on the endpoint receives the new credentials and applies them, then communicates the rotation status back to the EPM Server.
Why the other options are wrong
- B. The EPM Server initiates and orchestrates rotation but does not directly communicate changes to endpoints.
- C. The EPM API facilitates integration but is not the component responsible for credential change communication.
- D. EPM Discovery identifies credentials and systems but does not handle credential rotation communication.
Question 7
An EPM Administrator would like to notify end users whenever the Elevate policy is granting users elevation for their applications.
Where should the EPM Administrator go to enable the end-user dialog?
Show answer and explanation
Correct answer: D. End-User UI within the policy
The End-User UI settings within the specific policy allow EPM Administrators to configure and enable notifications that inform end users when elevation has been granted. This policy-level setting controls the user-facing dialog that appears during elevation events.
Why the other options are wrong
- A. The End-user UI left panel in the console configures global UI settings, not elevatio-pecific notifications.
- B. Advanced Agent Configurations control agent behavior and reporting, not end-user elevation dialogs.
- C. Default Policies provide baseline policy templates but do not contain end-user notification settings for elevation.
Question 8
Which of the following is CyberArk's Recommended FIRST roll out strategy?
Show answer and explanation
Correct answer: B. Implement Privilege Management
CyberArk recommends implementing Privilege Management as the first rollout strategy for EPM. This foundational approach establishes control over administrative privileges and elevation rights before implementing broader security features, allowing organizations to stabilize privilege management before adding additional security layers.
Why the other options are wrong
- A. Application Control is typically implemented after privilege management is established.
- C. Threat Detection is an advanced monitoring capability implemented after foundational controls are in place.
- D. Ransomware Protection is a specialized use case typically deployed after core privilege management is operational.
Question 9
An EPM Administrator would like to include a particular file extension to be monitored and protected under Ransomware Protection.
What setting should the EPM Administrator configure to add the extension?
Show answer and explanation
Correct answer: A. Authorized Applications (Ransomware Protection)
Authorized Applications under Ransomware Protection is the setting where an EPM Administrator configures file extensions to be monitored and protected. This setting allows administrators to specify which file types should be subject to ransomware protection policies.
Why the other options are wrong
- B. Files to be Ignored Always is used to exclude files from monitoring, not to add extensions for protection.
- C. Anti-tampering Protection prevents unauthorized modification of security software itself, not file extension monitoring.
- D. Default Policies provides baseline protection rules but is not where specific file extensions are configured for monitoring.
Question 10
When deploying EPM and in the Privilege Management phase what is the purpose of Discovery?
Show answer and explanation
Correct answer: C. To identify both administrative and non-administrative level events
Discovery in the Privilege Management phase identifies both administrative and no-dministrative level events to provide a comprehensive understanding of all user activities and privilege usage patterns across the environment. This comprehensive analysis enables informed policy creation.
Why the other options are wrong
- A. Discovery identifies more than just non-administrative events; it captures the full scope of activity.
- B. Discovery is not limited to administrative events only; it captures both levels of activity.
- D. Discovery identifies events, not threats, and covers both administrative and no-dministrative activities.
That was 10 of 154.
The full CyberArk EPM-DEF pack has all 154 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
