Free ACCESS-DEF sample questions
Real questions from the CyberArk Defender Access practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A healthcare organization has enrolled all domain-joined corporate laptops with CyberArk Identity Windows Device Trust, and sensitive applications require a trusted device. A clinician working from home, not connected to the corporate VPN, cannot access one of these applications. The administrator confirms the user is in the correct role, can sign in to the User Portal, and the laptop was enrolled successfully. What is the most likely cause?
A company's security policy mandates that all administrative access to cloud infrastructure management consoles (like AWS, Azure) requires Multi-Factor Authentication. Which TWO of the following mechanisms in CyberArk Identity can be used to enforce this policy specifically for users in the 'Cloud Admins' role? (Select TWO)
True or False: When using the 'MFA Unlock' command for a user in the CyberArk Identity Admin Portal, the suspension of MFA challenges is permanent until the administrator manually re-enables it.
A manufacturing company is setting up a SAML-based SSO integration for a new cloud-based inventory management system. During testing, users receive a SAML error indicating an 'Invalid NameID Format'. The application vendor has specified that they require the user's UPN (User Principal Name) in the NameID field. Where in the CyberArk Identity application configuration would an administrator modify the SAML response to send the UPN as the NameID?
An administrator is creating a new Authentication Profile for high-risk applications. Users must first enter their password and then complete one additional factor of their choice: a Mobile Authenticator push notification, a security question, or an OATH OTP code. How should the profile be configured?
A new CyberArk Identity administrator is reviewing the corporate directory structure. They need to synchronize users from a specific Organizational Unit (OU) in Active Directory called 'Salesforce_Users' to a CyberArk role with the same name. What is the first component that must be deployed and configured in the on-premises environment to enable this synchronization?
During a security audit, an organization is required to produce a report of all users who have successfully authenticated to any application via CyberArk Identity over the last 90 days, including the source IP address for each login. Where in the Admin Portal can this report be generated?
A company is using the CyberArk App Gateway to provide secure remote access to an internal legacy web application that does not support SAML. The security team wants to ensure that access to this application is logged and audited. Which component is primarily responsible for generating the audit logs for access events through the App Gateway?
An administrator needs to configure automated user provisioning for Salesforce. The goal is to assign different Salesforce license types (e.g., 'Salesforce Platform', 'Chatter Free') to users based on their department attribute in Active Directory. Which CyberArk Identity feature allows for this conditional license assignment during provisioning?
10 more free samples are waiting
Create a free account to unlock the whole ACCESS-DEF sample bank, or get full access to all 226 practice questions in the simulator.