EPM-DEF Sample Questions & Answers
Elevation and application-control policy management is the single biggest topic, alongside EPM installation, setup and customization, core concepts and architecture, troubleshooting and upkeep, and administering users and groups.
Launch the full EPM-DEF simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Policy Management · Managing Privilege Threat Protection Events
An EPM administrator is analyzing event data and notices that a large number of 'Privilege Threat' events are being generated by a custom in-house application that performs memory scraping as part of its normal function. This is causing a high volume of false positives. What is the recommended approach to suppress these specific events without disabling threat protection for other applications?
Show answer & explanation
Correct answer: B
The correct way to handle legitimate applications that trigger threat protection events is to create an Application Group for that specific application. This Application Group can then be added to the Exclusions list within the Privilege Threat Protection policy. This surgically excludes only the specified application, maintaining protection for all other processes.
- Question 2Intermediate
Policy Management · Using Wildcards in Application Groups
A system administrator needs to define a flexible Application Group that includes all executables within any subfolder of
C:\Program Files\VendorTools\. The folder structure underVendorToolschanges frequently as new versions are released. Which parameter type should be used to define the application path to ensure all current and future tools are included?Show answer & explanation
Correct answer: B
Using the 'Folder Path' parameter type and enabling the 'Include subfolders' option is the most robust and maintainable method. This configuration dynamically includes any executable within the specified root folder and all its subdirectories, automatically accommodating new versions and tools without requiring policy updates.
- Question 3AdvancedSelect 2
Deployment and Configuration · Agent Configuration for Performance Tuning
A global retailer is deploying EPM to thousands of Point-of-Sale (POS) terminals across different geographical regions with varying network latency. To optimize performance and reduce load on the central EPM server, the administrator needs to control how frequently agents check in for policy updates and send collected events. Which TWO settings in the Agent Configuration are most relevant for this task?
Show answer & explanation
Correct answers: A, D
This setting directly controls how often the agent contacts the server to check for new or updated policies. Increasing this interval for stable environments like POS terminals reduces network traffic and server load.
This setting determines how often the agent sends its collected event data to the server. Increasing this period means the agent batches more events together before sending, which reduces the frequency of communication and is ideal for high-latency networks.
- Question 4Advanced
Policy Management · Comprehensive Policy Strategy for Controlled Environments
Case Study
A manufacturing company, 'RoboCorp', is implementing CyberArk EPM to secure its factory floor workstations, which run critical production software. The environment is strictly controlled, and any downtime is extremely costly. The CISO has mandated a Zero Trust, least-privilege model.
Current Situation:
Factory operators currently run as local administrators to use legacy machine control software ('ControlApp.exe'), which requires elevated rights to interact with hardware drivers. The software is old, unsigned, and its publisher is unknown. The IT team has deployed EPM agents in 'Detect' mode and has collected data for one week.Requirements:
- Remove all operator accounts from the local Administrators group.
- Allow 'ControlApp.exe' to run with the necessary elevated privileges without prompting the operator.
- Prevent any other unauthorized applications from running.
- Ensure the solution is highly resilient and continues to function even if the EPM server is temporarily unreachable.
Which EPM policy configuration best meets all of RoboCorp's requirements?
Show answer & explanation
Correct answer: B
This solution meets all requirements. It removes admin rights. It uses a file hash to securely identify the specific, unsigned application. The Elevate policy runs it silently (no prompt). The default block policy prevents unauthorized software. Because policies are cached locally on the agent, this configuration will continue to function correctly even if the EPM server is unreachable, ensuring factory resilience.
- Question 5Advanced
Troubleshooting and Maintenance · Diagnosing Policy Application Failures
An administrator is troubleshooting an EPM policy that is supposed to elevate
setup.exefor a specific application. The policy uses the application's digital signature for identification. However, when a user tries to run the installer, it is not elevated. The administrator verifies the policy is active and applied to the correct computer set. The following flowchart represents the EPM agent's policy evaluation logic. Based on the diagram, what is the MOST likely cause of the failure?flowchart TD A[User launches setup.exe] --> B{Is application in policy?}; B -->|No| C[Apply Default Policy]; B -->|Yes| D{Does signature match?}; D -->|No| E[Block/Detect as per policy]; D -->|Yes| F{Is user/computer in scope?}; F -->|No| G[Ignore Policy Match]; F -->|Yes| H[Elevate Application];Show answer & explanation
Correct answer: B
According to the flowchart, after confirming the application is defined in a policy (B), the next critical check is the signature match (D). Since the administrator has already verified the policy is active and the computer is in scope (implying F is correct), the most probable point of failure is the signature check (D). This could happen if the vendor released a new version signed with a different certificate, or if the file's signature is corrupted or expired.
- Question 6Beginner
User Management and Access Control · Configuring Role-Based Access Control (RBAC)
A new EPM administrator is tasked with creating a role for the IT help desk team. This role should allow technicians to view EPM events and generate reports for troubleshooting, but they must NOT be able to create, modify, or delete any policies. Which specific permission should be assigned to this new role?
Show answer & explanation
Correct answer: B
The 'View-Only Administrator' role is specifically designed for this purpose. It grants read-only access to the EPM console, allowing users to view policies, events, and reports without having any permissions to make changes. This adheres to the principle of least privilege.
- Question 7Beginner
Deployment and Configuration · Agent Installation Command Line
The command to silently install the CyberArk EPM agent using the MSI package with a specific Set ID is:
msiexec /i " .msi" /qn SET_ID=_____Show answer & explanation
Correct answer: B
The
SET_IDparameter in the msiexec command requires the exact name of the Set that the agent should be assigned to upon installation. This name is defined in the EPM console (e.g., 'Workstations', 'Servers', 'VDI_Pool_A'). The agent will then inherit the policies and configuration assigned to that Set. - Question 8Intermediate
Policy Management · Understanding Ransomware Protection
A hospital's IT department is concerned about the potential for ransomware to encrypt critical files on clinical workstations. They want to use EPM's ransomware protection capabilities. What is the primary mechanism by which the EPM agent's anti-ransomware module protects files?
Show answer & explanation
Correct answer: B
CyberArk EPM's ransomware protection works by creating and monitoring hidden decoy files. When a process, such as ransomware, begins to encrypt files on a system, it will inevitably attempt to modify one of these decoys. The EPM agent detects this unauthorized modification, identifies the offending process, terminates it, and can automatically restore the decoy file, effectively stopping the ransomware in its tracks.
- Question 9Beginner
Deployment and Configuration · Active Directory Integration
When integrating CyberArk EPM with an organization's Active Directory, what is the primary purpose of the 'Directory Sync' component?
Show answer & explanation
Correct answer: C
The Directory Sync component connects to Active Directory via LDAP to read and import object information. This allows EPM administrators to create policies that target AD users and groups directly, rather than having to recreate them manually. It keeps the EPM's view of the directory synchronized with the actual state of Active Directory.
- Question 10Intermediate
EPM Concepts and Architecture · Agent Feature Parity
True or False: The CyberArk EPM agent for macOS provides the exact same set of features as the Windows agent, including credential theft protection and ransomware protection.
Show answer & explanation
Correct answer: B
While the EPM agent for macOS provides core functionality like privilege management and application control, it does not have complete feature parity with the Windows agent. Certain advanced security features, such as credential theft protection (which targets Windows-specific mechanisms like LSASS) and the decoy-based ransomware protection, are specific to the Windows platform and not available on macOS.
Ready for the real thing?
The full EPM-DEF simulator has every exam-style question, timed mode, and instant scoring.