Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CyberArk PAM-DEF Exam - Topic 6 Question 75 Discussion

A Vault administrator have associated a logon account to one of their Unix root accounts in the vault. When attempting to verify the root account's password the Central Policy Manager (CPM) will:
C) log in first with the logon account, then run the SU command to log in as root using the password in the Vault
A) ignore the logon account and attempt to log in as root
B) prompt the end user with a dialog box asking for the login account to use
D) none of these

CyberArk PAM-DEF Exam - Topic 6 Question 75 Discussion

Actual exam question for CyberArk's PAM-DEF exam
Question #: 75
Topic #: 6
[All PAM-DEF Questions]

A Vault administrator have associated a logon account to one of their Unix root accounts in the vault. When attempting to verify the root account's password the Central Policy Manager (CPM) will:

Show Suggested Answer Hide Answer
Suggested Answer: C

According to the web search results, when a Vault administrator has associated a logon account to one of their Unix root accounts in the vault, the CPM will log in first with the logon account, then run the SU command to log in as root using the password in the Vault1.This is a common use case for using a logon account, as the best practice for Unix systems is to disallow the root user from logging in using SSH, which is what the CPM uses to sign in to a system to manage the password2.The logon account can be defined on the target account level or on the platform level, making it available to all accounts associated with the platform2.The CPM can also use the logon account to initiate PSM sessions to the target machine3.


Contribute your Thoughts:

0/2000 characters
Laura
2 days ago
I'm not so sure. What if it’s A? Just going straight to root?
upvoted 0 times
...
Evette
7 days ago
I agree, C seems logical. It’s a secure way to access root.
upvoted 0 times
...
Hyman
12 days ago
I think it's C. Makes sense to use the logon account first.
upvoted 0 times
...
Levi
18 days ago
D seems possible, but I can't see why they wouldn't use the logon account.
upvoted 0 times
...
Jani
23 days ago
I agree with C too, it’s the safest way to handle it.
upvoted 0 times
...
Haydee
28 days ago
Wait, does the CPM really do that? Sounds complicated.
upvoted 0 times
...
Lashonda
1 month ago
Definitely not A, that would be risky!
upvoted 0 times
...
Fabiola
1 month ago
I think it's C, that makes the most sense.
upvoted 0 times
...
Marvel
1 month ago
I'm leaning towards option D, but I can't remember if there was a specific scenario where none of these would apply.
upvoted 0 times
...
Alline
2 months ago
I feel like option C makes sense because using the SU command is a common way to switch users in Unix, but I can't recall if that's how CPM operates.
upvoted 0 times
...
Wilda
2 months ago
I remember a practice question where it asked about using a logon account, and I think it involved prompting the user. Could it be option B?
upvoted 0 times
...
Gayla
2 months ago
I think the CPM might just try to log in as root directly, but I'm not entirely sure if that's the right approach.
upvoted 0 times
...

Save Cancel