AllowNonStandardFWAddresses Firewall Exception Syntax - answer-
AllowNonStandardFWAddresses=[HSM-IP],Yes,1024:inbound/tcp,1024:outbo
und/tcp
Syntax Command CAVaultManager uses to store a secret - answer-
CAVaultManager.exe /SecretType HSM /Secret password
Syntax command to install a server key to an HSM device using
CAVaultManager - answer-CaVaultManager.exe LoadServerKeyToHSM
Syntax command to re-generate a key on the HSM where the new value is
unknown to the operator - answer-CAVaultManager.exe
GenerateKeyOnHSM /ServerKey.
Then, ChangeServerKeys.exe
Any changes made to the DBParms.ini configuration file require a _________ -
answer-reboot
What should you do to complete a post-install hardening of the Vault? -
answer-1.) Identify appropriate services are started.
2.) Check that firewall exceptions have been made in the DBParms.ini file.
3.) Ensure the server key is running successfully on the HSM.
4.) Ensure the Operator disk is correctly secured with NTFS permissions.
Steps to complete a Vault installation - answer-1.) Check that the server
rebooted properly
2.) Ensure that the ITALog displays the following message: ITAFW001I
Firewall is open for client communication"
3.) Ensure the three safes: System, VaultInternal, Notification Engine were
created.
4.) Ensure the 6 services were installed and started. (Later flash card)
5.) Test master login
6.) Network Areas should be configured to only allow connections from the
planned IP addresses for CyberArk Components
What 6 services are installed and started after installing the Vault? - answer-
1.) Cyber-Ark Event Notification Engine
2.) Cyber-Ark Hardened Windows Firewall
3.) CyberArk Logic Container
4.) PrivateArk Database
5.) PrivateArk Remote Control Agent
6.) PrivateArk Server
, How do you prepare a Windows server for Vault installation? - answer-1.)
Ensure it meets the minimum requirements for CyberArk.
2.) Ensure the server is of type Workstation and has never been connected
to a domain.
3.) Load installation files into the server.
4.) Disable all network components aside from IPv4 and optionally IPv6.
4.) Disable DNS lookup and LMHosts lookup for WINS. Disable NetBios as
well.
Four Stages of PVWA Installation - answer-1.) Pre-Installation Tasks
2.) Installation
3.) Post-Install Tasks
4.) Hardening
PVWA Pre-Installation Tasks - answer-1.) Review Requirements
2.) Close Applications and Log On
3.) Run Prerequisites Script
PVWA Installation Tasks - answer-1.) Run the PVWA Installation Script
2.) Registration (Connecting to the Vault)
PVWA Post-Installation Tasks - answer-1.) Check Installation Log Files
2.) Check User Permissions on Web Server
3.) Add Restrictions to Credential Files
4.) Set API Throttling
PVWA Hardening Tasks - answer-1.) Run Hardening Script
2.) Apply Post Hardening Configurations
3.) *Harden server in a Domain environment
*Only perform this task if your PVWA server is part of a domain
What VAULT permissions are needed to perform integration for the PVWA? -
answer-- Add Safes
- Add/Update Users
- Activate Users
- Manage Server File Categories
- Audit Users
The user performing the installation must have the following Safe
Permissions with ownership of the VaultInternal and Notification Engine
safes. - answer-- List Files
- Retrieve Files
- Manage Safe
- Manage Safe Owners