CyberArk EPM-DEF Practice Test Questions and Exam Dumps Part20 Q381-400

View Full CyberArk EPM-DEF Exam Dumps and Practice Test Dumps

 

Question 381.

An EPM administrator wants to verify whether an application-control policy is still required after the associated software was removed from most endpoints. What should the administrator do FIRST?

  1. Review policy usage events and confirm the business need with the policy owner
  2. Expand the policy to all endpoints
  3. Disable event collection
  4. Keep the policy permanently without review

Correct Answer: 1. Review policy usage events and confirm the business need with the policy owner

Explanation:

Historical EPM events can show whether the policy is still being triggered and which endpoints or users continue to rely on it. The administrator should combine that evidence with confirmation from the responsible business owner before removing the rule. Some applications may remain on a small number of systems or support infrequent but important workflows. If the policy is no longer needed, retiring it reduces attack surface and simplifies administration. Expanding or retaining obsolete rules indefinitely creates unnecessary privilege and policy complexity. Regular policy recertification helps maintain a cleaner and more defensible least-privilege environment.

Question 382.

A trusted application is installed under a folder that ordinary users can modify. What is the BEST security improvement?

  1. Change the application’s icon
  2. Restrict write access to the installation directory
  3. Add more desktop shortcuts
  4. Increase endpoint storage

Correct Answer: 2. Restrict write access to the installation directory

Explanation:

A trusted application should be stored in a location that standard users cannot modify. If users can replace the executable or supporting components, they may be able to inherit the application’s trusted or elevated EPM treatment. Restrictive file and directory permissions help preserve the integrity of the privileged workflow. Administrators should combine this protection with strong application identification such as publisher information, digital signatures, hashes, or product-specific criteria. Visual changes and storage capacity do not protect the executable from substitution. Application trust is safest when both the software identity and the location containing it are protected.

Question 383.

An application is signed by a trusted publisher but should receive elevation only for one specific product line. Which rule design is BEST?

  1. Trust every signed application from the publisher
  2. Use filename only
  3. Combine publisher information with product-specific attributes
  4. Elevate every executable under Program Files

Correct Answer: 3. Combine publisher information with product-specific attributes

Explanation:

Publisher information can provide durable trust across software updates, but it may be too broad when one vendor signs many products. Product-specific criteria such as executable name, product name, version, path, or other supported attributes help ensure only the intended application receives elevation. This reduces policy maintenance compared with exact hashes while still limiting privilege appropriately. Filename-only matching is weak because names can be copied, and global publisher trust can unintentionally elevate unrelated administrative utilities. Strong EPM application definitions usually combine multiple reliable attributes instead of depending on one broad indicator.

Question 384.

An elevated program can execute user-supplied scripts without restriction. What is the PRIMARY concern?

  1. The endpoint may run out of disk space
  2. The application may generate more logs
  3. The user may change printer settings
  4. User-controlled scripts may execute with administrative privileges**

Correct Answer: 4. User-controlled scripts may execute with administrative privileges

Explanation:

If an elevated application accepts arbitrary user-controlled scripts, the user may be able to perform administrative actions far beyond the original business purpose. This can turn an approved application into a general-purpose privilege-escalation pathway. Administrators should examine how scripts are selected, where they are stored, whether standard users can modify them, and whether child processes inherit elevation. Where possible, EPM policy should restrict privilege to specific validated scripts or tightly controlled workflows rather than elevating a general-purpose interpreter or scripting environment.

Question 385.

Which application-identification method is MOST suitable when an EPM administrator wants to block one exact malicious file?

  1. Cryptographic hash
  2. Filename only
  3. File extension
  4. Shortcut label

Correct Answer: 1. Cryptographic hash

Explanation:

A cryptographic hash identifies a particular binary based on its contents. Renaming or moving the file typically does not change the hash, making it effective for blocking a known malicious executable even if a user changes the filename. The limitation is that modified variants produce different hashes and may require additional rules or other identifying criteria. Filename and extension matching are much easier to bypass because those properties can be changed without altering the actual program. Hash matching is therefore highly effective for controlling one exact known file.

Question 386.

A business application receives monthly updates that change its hash. Which policy approach is MOST maintainable?

  1. Keep the original hash forever
  2. Use trusted publisher information combined with application-specific criteria
  3. Trust all applications on the endpoint
  4. Give users permanent local administrator rights

Correct Answer: 2. Use trusted publisher information combined with application-specific criteria

Explanation:

Exact hashes typically change whenever software is updated, creating maintenance overhead for frequently released applications. Publisher-based identification can remain stable across legitimate versions, but it should be narrowed using product name, executable name, path, version, or other supported attributes. This avoids granting privilege to unrelated applications signed by the same vendor. Trusting every application or granting permanent administrator rights would create a much larger security exposure. The goal is to create an application definition that remains usable across approved updates without becoming excessively broad.

Question 387.

A user requests elevation for an application that has not been reviewed by the organization. What should the administrator do FIRST?

  1. Elevate it immediately
  2. Give the user administrator rights
  3. Validate the application’s source, business purpose, identity, and security risk
  4. Disable EPM temporarily

Correct Answer: 3. Validate the application’s source, business purpose, identity, and security risk

Explanation:

An elevation request represents a business request, not proof that the software is trustworthy. Administrators should confirm why the application is needed, where it came from, whether its publisher or signature is valid, and whether security procedures approve its use. Depending on the environment, this may also involve reputation checks, vulnerability review, or malware analysis. Only after validation should a temporary exception or permanent policy be created. Broad administrator rights or disabling EPM would introduce unnecessary risk and bypass the controlled approval process.

Question 388.

A user requires elevated access for one hour to complete an approved maintenance task. Which EPM approach BEST preserves least privilege?

  1. Permanent administrator membership
  2. Global elevation policy
  3. Disable EPM for the entire day
  4. A narrowly scoped temporary elevation with an expiration**

Correct Answer: 4. A narrowly scoped temporary elevation with an expiration

Explanation:

A short-term task should receive short-term privilege. A temporary exception can be limited to the required user, endpoint, application, and approved one-hour window. An automatic expiration ensures that the capability does not remain active after the task ends. The request should also include business justification and ownership for accountability. Permanent administrator rights or global elevation would exceed the stated requirement, while disabling EPM would affect unrelated activity. Time-bounded privilege is one of the strongest ways to support exceptional work while maintaining least privilege.

Question 389.

A newly created EPM block policy is not being enforced on some remote laptops. What should the administrator verify FIRST?

  1. Agent connectivity, synchronization, and local policy version
  2. Desktop wallpaper
  3. Printer availability
  4. Monitor resolution

Correct Answer: 1. Agent connectivity, synchronization, and local policy version

Explanation:

Remote endpoints may continue using older cached policies if they have not recently communicated with the EPM management service. Administrators should check the agent’s health, recent check-in, synchronization status, certificates, and policy version. A targeting issue may also prevent the rule from reaching the endpoint. Once communication is restored, administrators should confirm that the updated policy is applied and that related events are uploaded. Peripheral and personalization settings do not affect policy delivery.

Question 390.

An elevation rule intended for one department is unexpectedly used by another department. Which area should be reviewed FIRST?

  1. Application icon
  2. Policy targeting, group membership, and inherited scope
  3. Printer mapping
  4. Screen-lock settings

Correct Answer: 2. Policy targeting, group membership, and inherited scope

Explanation:

Unexpected privilege outside the intended department usually indicates that the policy scope is broader than expected. Administrators should review user groups, endpoint groups, inherited memberships, and overlapping assignments. Event data can identify exactly which users and systems are triggering the policy. After correcting the target scope, the administrator should verify that affected endpoints receive the updated configuration. Precise policy targeting is essential because even a trusted application should not receive elevation for users who do not have a legitimate business requirement.

Question 391.

A user claims EPM blocked a legitimate application incorrectly. What is the BEST starting point for troubleshooting?

  1. Review the associated EPM application event and effective policy action
  2. Check office access records
  3. Review printer logs
  4. Change the user’s desktop theme

Correct Answer: 1. Review the associated EPM application event and effective policy action

Explanation:

The EPM event provides direct evidence of how the application was handled. It can show which executable was launched, which user and endpoint were involved, and which policy action occurred. Administrators can then determine whether the application changed, another rule took precedence, or the endpoint was assigned to a different scope. Event-based troubleshooting avoids guessing and reduces the risk of making unnecessary or overly broad policy changes. Unrelated physical or endpoint-personalization information provides little value in diagnosing application-control decisions.

Question 392.

A trusted elevated application launches a helper executable from a user-writable directory. What is the BEST security response?

  1. Ignore the helper because the parent is trusted
  2. Review and protect the helper location and determine whether the child inherits elevation
  3. Give users administrator rights
  4. Disable event monitoring

Correct Answer: 2. Review and protect the helper location and determine whether the child inherits elevation

Explanation:

A user-writable helper location creates a potential privilege-escalation path. An attacker may be able to replace the legitimate helper with malicious code, and if the child process inherits elevation, that replacement may run with administrative rights. Administrators should protect the directory with restrictive permissions, verify the helper application’s identity, and test parent-child privilege behavior. A trusted parent executable does not automatically make all child processes safe. EPM policy should cover the complete privileged workflow and its dependencies.

Question 393.

Which practice BEST helps identify EPM policies that can be retired?

  1. Review historical policy usage and confirm continued need with the business owner
  2. Keep every policy permanently
  3. Expand rarely used policies to more users
  4. Disable event retention

Correct Answer: 1. Review historical policy usage and confirm continued need with the business owner

Explanation:

Historical events show whether a policy is still used, which users depend on it, and how frequently it is triggered. This evidence can help identify rules that may have become obsolete. However, administrators should also consult the business owner because some privileged workflows are infrequent but important. Policies that no longer have a valid business purpose should be removed to reduce attack surface and policy complexity. Retaining every rule indefinitely or disabling event history weakens governance and makes least-privilege maintenance more difficult.

Question 394.

A department repeatedly requests temporary elevation for the same approved installer. What is the BEST long-term response?

  1. Give users permanent administrator rights
  2. Validate the recurring need and create a narrowly scoped standard elevation policy
  3. Disable EPM for the department
  4. Share one privileged password

Correct Answer: 2. Validate the recurring need and create a narrowly scoped standard elevation policy

Explanation:

Repeated temporary requests are often evidence of a predictable business workflow that should be supported through a standard policy. The administrator should verify the installer, determine its exact privilege requirements, and target the rule only to the appropriate users or endpoints. This can reduce support effort while maintaining least privilege. Permanent administrator rights or shared passwords would grant far broader capability than required. Standard application-specific elevation is appropriate when the business need is recurring, well understood, and safe to define precisely.

Question 395.

Which operating-system control BEST complements EPM by protecting trusted elevated executables from modification?

  1. Restrictive file and directory permissions
  2. Larger storage volumes
  3. Additional printer restrictions
  4. Screen-lock settings

Correct Answer: 1. Restrictive file and directory permissions

Explanation:

Trusted executables should be stored in directories that standard users cannot modify. Restrictive file-system permissions reduce the chance that users or malware can replace, alter, or add components that inherit EPM trust. This protection should be combined with strong application-identification criteria such as publisher data, hashes, signatures, or product metadata. EPM and operating-system permissions reinforce each other: EPM controls privilege decisions while file permissions help preserve the integrity of the files receiving that privilege. Storage capacity and display settings do not provide this protection.

Question 396.

A security manager needs to determine who changed an EPM policy that unexpectedly granted elevation. Which record is MOST useful?

  1. Printer activity
  2. Desktop usage history
  3. Application inventory only
  4. Administrative audit or policy change history**

Correct Answer: 4. Administrative audit or policy change history

Explanation:

Administrative audit history records who changed EPM configuration and when. This provides accountability and allows security teams to correlate policy changes with unexpected endpoint behavior. Individual administrator identities make the audit trail more meaningful than shared accounts. Such records support troubleshooting, incident response, compliance, and change governance. Because EPM policies can grant powerful rights across many endpoints, changes should be treated as sensitive privileged actions and retained in an auditable history.

Question 397.

A user changes departments but remains assigned to an EPM elevation group from the previous role. What should happen?

  1. Remove the obsolete group membership and reassess current privilege needs
  2. Keep all previous privileges
  3. Add the user to additional elevation groups
  4. Disable group targeting

Correct Answer: 1. Remove the obsolete group membership and reassess current privilege needs

Explanation:

Privileges should follow current job responsibilities. When a user moves to another department, EPM group membership should be reviewed so elevation from the previous role does not remain unnecessarily. Keeping old privilege creates access accumulation and increases risk if the account is compromised or misused. The user should receive only those policies required for the new role. Integrating EPM targeting with identity lifecycle processes such as joiners, movers, and leavers helps keep endpoint privilege aligned with organizational changes.

Question 398.

A known malicious executable is identified during an active security incident. How should EPM be used MOST effectively?

  1. Wait for users to report the file
  2. Create a block policy using reliable identity criteria and verify endpoint synchronization
  3. Give users administrator rights so they can remove it
  4. Disable EPM event reporting

Correct Answer: 2. Create a block policy using reliable identity criteria and verify endpoint synchronization

Explanation:

EPM can help contain a known threat by blocking its execution across managed endpoints. The policy should use reliable application identity such as a cryptographic hash or other strong attributes and should be distributed rapidly to the appropriate endpoint population. Administrators must verify that agents receive the new policy and review execution events for attempted use. EPM blocking should complement broader incident-response actions because preventing future execution does not necessarily remediate an endpoint that is already compromised.

Question 399.

A high-impact elevation policy is used only once or twice each year. What should the administrator evaluate during periodic recertification?

  1. Whether the business need still exists and whether temporary request-based elevation would be safer
  2. Whether the policy can be expanded globally
  3. Whether event logging can be disabled
  4. Whether more users can be added

Correct Answer: 1. Whether the business need still exists and whether temporary request-based elevation would be safer

Explanation:

Rarely used powerful privilege creates standing exposure even when the rule is seldom triggered. Administrators should confirm the current business need, review ownership and historical usage, and determine whether temporary or approval-based elevation could meet the same requirement with less risk. A standing policy may still be justified for critical emergency operations, but low usage is a strong reason to reassess it. Expanding the rule or reducing monitoring would increase exposure without providing clear business benefit.

Question 400.

Which statement BEST describes a mature CyberArk EPM-DEF operating model?

  1. Trust all software from known publishers
  2. Grant broad elevation to reduce support requests
  3. Focus only on removing local administrator rights
  4. Continuously manage least privilege, application identity, execution context, policy scope, exceptions, events, agent health, and policy recertification**

Correct Answer: 4. Continuously manage least privilege, application identity, execution context, policy scope, exceptions, events, agent health, and policy recertification

Explanation:

A mature EPM program is an ongoing security process rather than a one-time deployment. Least privilege reduces standing administrator rights, while strong application identity ensures only intended software receives elevation or allow treatment. Secure execution context protects trusted files and supporting components, and precise targeting limits privilege to authorized users and endpoints. Temporary exceptions should be controlled and time bounded, while event analysis provides visibility into actual behavior. Agent health and synchronization ensure endpoints enforce current policy. Regular recertification removes obsolete rules as applications, users, and business requirements change, creating a sustainable and defensible endpoint privilege-management model.