chapter 2 Flashcards

(28 cards)

1
Q

people, or applications or cyberark components, that have been granted access to the system in order to access passwords, manage policies. they are defined by their domain credentials

A

user

difference between users and accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the actual privileged account and passwords, they are stored in safes. ex: domain admins, local admins, root accounts and services accounts, etc

A

accounts

difference between users and accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are internal users and groups in cyberark?
How are they added?

A

users and groups that are created automatically in the vault (built-in), and users and groups that are added manually to the vault

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

users and groups that are automatically provisioned from an external directory.

  1. provisioned automatically in the vault when they authenticate via ldap for the first time
  2. these users and groups are marked with a white LDAP users or groups icon
  3. if you delete a transparent user within cyberark, it will be automatically re-created upon login if it still exists within AD and answers the mapping criteria
A

what are transparent users and groups in LDAP?

  1. How are the provisioned?
  2. What color is their icon?

What happens if you delete a transparent user?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

predefined users and groups

the most powerful user, with full safe and vault authorizations that cannot be removed
1. accessed only through the private ark client
3. has 3 factor authentication
a. password, defined during installation
b. access to the recovery private key, recprvkey
c. access only from the vault console and one additional ip address (emergency station IP)

A

master account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you change the master password?

A

login with the master user and click on user > set password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

managing users and groups using private ark client

  • users are stored in the vault database
  • it is recommended that you manage your users with an external ldap directory, such as active directory
  • users can also be manually created via the private ark client

How do you manually add?

A

private ark client interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

manage users using pvwa

what can you do in the user management module in the web portal administration view (pvwa)

A

create and edit cyberark users
create groups and assign users to them
disable a user or activate a suspended user
reset a user’s password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

transparent user management

the (blank) communicates with LDAP compliant directory servers to obtain user identification and security information.

This enables automatic provisioning and creation of unique users based upon the external group membership and attributes

A

vault

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

LDAP integration

The first steps to LDAP integration?

  1. use the wizard to guide you: define the domain using the wizard - enter the domain name
  2. select domain controllers - connect the vault with a ldap server, usually AD
  3. create directory mapping using the credentials of a bind account to authenticate to ldap
    a directory map links an ldap group with one of the built-in cyberark groups and determines how user accounts are created in the vault and the roles they will have

(blank)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

users are provisioned (how) in the vault the first time they authenticate via LDAP, receiving roles and attributes based on the directory mapping that applies to them.

LDAP users and groups that have been created in the vault are marked with a (color) LDAP user or groups icon

A

automatically

white

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

if you delete a user within cyberark, it will be automatically (re-what) upon login if it still exists in AD

to block an LDAP user or group from cyberark, (do this) them from all LDAP groups with an associated directory mapping, or disable/delete them in the external directory

a (frequency) process checks which users map to the various queries

A

re-created

remove

daily

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

the parameter AutoSyncExternalObjects in the (something.ini) file determines if, how often and when the vault’s external users and groups will be synchronized with the external directory

What does the parameter look like?

AutoSyncExternal objects = yes, 24, 1,5

Which means

yes - determines whether or not to sync with the external directory

24 - the number of hours in one period cycle

1,5 - the hours during which the sync will take place

A

dbparm.ini

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are the 2 categories of authorizations in the system?

A

vault - can be assigned only to users (not groups), cannot be inherited via group membership, can be defined via the private ark client or PVWA

safe - assigned to users and or groups, can be inherited via group membership, can be defined in the private ark client or PVWA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

predefined users are assigned different (system) authorizations based on their role and functions

the built in (blank) user has full vault authorizations by default

A

vault

administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what authorizations does the built in auditor user have by default?

17
Q

what authorizations does the built in backup user have by default?

A

backup all safes

18
Q

safe authorizations

most predefined users and groups are added to all newly created (s*****) based on their role and function

users in the auditors’ group are automatically added to all (s*****) with permission to
-list accounts
-view safe members
-view audit log

19
Q

you can modify the list of groups that are added automatically to newly created safes is controlled by a parameter in the (*.ini)

A

dbparm.ini file

20
Q

the tabs and buttons available in the <blank> depend on the logged in user's membership in a cyberark built in group</blank>

members of the vault admins have access to the (blank) tab

A

PVWA

administration

21
Q

PVWA permissions

what tab do members of auditors have?

A

privleged sessions- monitoring and monitor (classic UI)

22
Q

PVWA Permissions

what tab to members of security admins and security operators have access to?

A

security pane - security events and security configuration

23
Q

a directory map determines whether a user account or group will be created in a vault and the roles they will have, what are the 2 kinds of directory maps?

A

user mapping - allows for authentication and defines user attributes, such as vault authorizations and location

group mapping - makes LDAP groups searchable from within cyberark, allowing mapped groups to be granted safe authorizations and to be nested within built in cyberark groups

24
Q

what groups need to be created in LDAP for cyberark to work?

A

cyberark auditors
cyberark safe managers
cyber ark users
cyberark vault admins

25
the LDAP integration wizard is used to map what four AD groups to the four predefined cyber ark roles?
vault admins safe managers auditors users
26
the (group) mapping is applied to any user who is a member of the LDAP group cyberark vault admins LDAP users are provisioned in the vault with the appropriate authorizations the first time the users log in
vault admins
27
in addition to the predefined mappings, you can create (type) directory mappings via a simplified wizard on the (system)
custom PVWA
28
PVWA permissions the tabs and buttons available the in the pvwa depend on the logged in user's membership in a cyberark built in groups members of the (group) have access to the administration tab
vault admins