Real Exam Questions EPM-DEF Dumps Exam Questions in here [Aug-2023]
Get Latest Aug-2023 Conduct effective penetration tests using EPM-DEF
NEW QUESTION # 32
After a clean installation of the EPM agent, the local administrator password is not being changed on macOS and the old password can still be used to log in.
What is a possible cause?
- A. After installation, Full Disk Access for the macOS agent to support EPM policies was not approved.
- B. Endpoint password policy is too restrictive.
- C. EPM agent is not able to connect to the EPM server.
- D. Secure Token on macOS endpoint is not enabled.
Answer: D
NEW QUESTION # 33
Which EPM reporting tool provides a comprehensive view of threat detection activity?
- A. McAfee ePO Reports
- B. Threat Detection Events
- C. Detected Threats
- D. Threat Detection Dashboard
Answer: D
NEW QUESTION # 34
Where can you view CyberArk EPM Credential Lures events?
- A. Events Management
- B. Application Catalog
- C. Threat Protection Inbox
- D. Policy Audit
Answer: C
NEW QUESTION # 35
Match the Application Groups policy to their correct description.
Answer:
Explanation:

NEW QUESTION # 36
An application has been identified by the LSASS Credentials Harvesting Module.
What is the recommended approach to excluding the application?
- A. In Agent Configurations, add the application to the Threat Protection Exclusions
- B. Add the application to an Advanced Policy or Application Group with an Elevate policy action.
- C. Exclude the application within the LSASS Credentials Harvesting module.
- D. Add the application to the Files to be Ignored Always in Agent Configurations.
Answer: A
NEW QUESTION # 37
In EPM, creation of which user type is required to use SAML?
- A. SQL User
- B. AD User
- C. Local CyberArk EPM User
- D. Azure AD User
Answer: D
NEW QUESTION # 38
Which programming interface enables you to perform activities on EPM objects via a REST Web Service?
- A. Java password SDK
- B. Application Password SDK
- C. Mac Credential Provider SDK
- D. EPM Web Services SDK
Answer: D
NEW QUESTION # 39
What is the CyberArk recommended practice when deploying the EPM agent to non-persistent VDIs?
- A. A separate computer group
- B. A separate set
- C. a separate license
- D. a VDI advanced policy
Answer: A
NEW QUESTION # 40
Before enabling Ransomware Protection, what should the EPM Administrator do first?
- A. Enable the Privilege Management Inbox in Elevate mode.
- B. Enable the Control Applications Downloaded From The Internet feature in Restrict mode.
- C. Review the Authorized Applications (Ransomware Protection) group and update if necessary.
- D. Enable Threat Protection and Threat Intelligence modules.
Answer: C
NEW QUESTION # 41
If Privilege Management is not working on an endpoint, what is the most likely cause that can be verified in the EPM Agent Log Files?
- A. Agent version is incompatible.
- B. UAC policy Admin Approval for the Built-in Administrator Account is set to "Disabled".
- C. UAC policy Run all administrators in Admin Approval Mode is set to "Enabled".
- D. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to "Prompt for Consent for non-Windows binaries".
Answer: C
NEW QUESTION # 42
For Advanced Policies, what can the target operating system users be set to?
- A. Local or AD users, Azure AD Users
- B. Local or AD users and groups
- C. AD Groups, Azure AD Groups
- D. Local or AD users and groups, Azure AD User, Azure AD Group
Answer: B
NEW QUESTION # 43
CyberArk EPM's Ransomware Protection comes with file types to be protected out of the box. If an EPM Administrator would like to remove a file type from Ransomware Protection, where can this be done?
- A. Set Security Permissions within Advanced Policies
- B. Authorized Applications (Ransomware Protection) within Application Groups
- C. Protected Files within Agent Configurations
- D. Policy Scope within Protect Against Ransomware
Answer: C
NEW QUESTION # 44
When working with credential rotation/loosely connected devices, what additional CyberArk components are required?
- A.
- B. DAP
- C. PVWA
- D. PTA
Answer: C
NEW QUESTION # 45
What is required to configure SAML authentication on EPM?
- A. OAuth token
- B. Encrypted Assertion
- C. Signed Authentication Request
- D. Signed SAML Response
Answer: D
NEW QUESTION # 46
Select the default threat intelligence source that requires additional licensing.
- A. CyberArk Application Risk Analysis Service
- B. VirusTotal
- C. NSRL
- D. Palo Alto WildFire
Answer: D
NEW QUESTION # 47
Which of the following is CyberArk's Recommended FIRST roll out strategy?
- A. Implement Threat Detection
- B. Implement Ransomware Protection
- C. Implement Privilege Management
- D. Implement Application Control
Answer: C
NEW QUESTION # 48
When deploying Ransomware Protection, what tasks should be considered before enabling this functionality?
(Choose two.)
- A. Add trusted software to the Authorized Applications (Ransomware protection) Application Group
- B. Add trusted software to the Allow Application Group
- C. Enable Detect privileged unhandled applications under Default Policies
- D. Add additional files, folders, and/or file extensions to be included to Ransomware Protection
Answer: A,D
NEW QUESTION # 49
What can you manage by using User Policies?
- A. Filesystem and registry access, access to removable drives, and Services access.
- B. Access to Windows Services only.
- C. Just-In-Time endpoint access and elevation, access to removable drives, and Services access.
- D. Just-In-Time endpoint access and elevation, access to removable drives, filesystem and registry access, Services access, and User account control monitoring.
Answer: D
NEW QUESTION # 50
When working with credential rotation at the EPM level, what is the minimum time period that can be set between connections?
- A. 1 hour
- B. 24 hours
- C. 5 hours
- D. 72 hours
Answer: D
NEW QUESTION # 51
......
Authentic Best resources for EPM-DEF Online Practice Exam: https://www.real4dumps.com/EPM-DEF_examcollection.html
Get the superior quality EPM-DEF Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1tohIPLashZkCRZgrjOQdcApJTKOt_RSI

