Skip to content

ACCESS-DEF Practice Questions

Prepare for ACCESS-DEF with more than an answer.

226 questions in the full set20 sample questionsUpdated Aug 20, 2026
Exam fee
$200 USD
Level
Defender (Level 2)
Valid for
2 years
Domains covered on the exam 5
  1. Identity Management Fundamentals20%
  2. User Lifecycle Management25%
  3. Authentication and Authorization25%
  4. Password and Credential Management15%
  5. Monitoring, Reporting, and Compliance15%
  1. 1

    Case Study:

    A fast-growing e-commerce company, 'GlobalCart', is modernizing its Identity and Access Management using CyberArk Identity. Their environment consists of an on-premises Active Directory for corporate employees, a separate Azure AD tenant for contractors, and a suite of critical SaaS applications including Salesforce, Zendesk, and a custom-built order processing portal. The CISO has mandated a Zero Trust security model.

    Key requirements are: 1) Provide seamless SSO for all users to all applications. 2) Automate the provisioning and deprovisioning of accounts in Salesforce and Zendesk based on AD group membership. 3) Enforce MFA for any access to the custom order processing portal, which is hosted on-premises and does not support modern authentication protocols. 4) Prevent access to all applications from devices that are not corporate-managed and enrolled in Device Trust.

    Which combination of CyberArk Identity components and configurations provides the most complete solution to meet all of GlobalCart's requirements?

    Show answer details

    Correct answer: D

    Active Directory users are covered by a Connector for AD sync and authentication. Microsoft Entra ID (Azure AD) is added directly as a directory service in the tenant (Settings > Users > Directory Services) and does not need a connector. SAML SSO plus role-mapped outbound provisioning automates accounts in Salesforce and Zendesk. The App Gateway (a Connector service) publishes the on-premises portal, which can then get an app-level MFA policy. Device Trust plus an authentication policy requiring a trusted device enforces the managed-device requirement.

  2. 2

    What is the primary function of the 'Account Mapping' script in a CyberArk Identity SAML application configuration?

    Show answer details

    Correct answer: A

    The Account Mapping script provides a powerful way to manipulate user data before it's used in the SAML assertion. Common uses include stripping the domain from a UPN to get a sAMAccountName, concatenating first and last names, or implementing complex logic to determine the correct username for the target application when the default attributes are not sufficient.

  3. 3

    A user is attempting to enroll their Android device with the CyberArk Identity mobile app but the process fails repeatedly. They are on the corporate guest Wi-Fi network which has strict firewall rules. Which outbound port is essential for the mobile app to communicate with the CyberArk Identity cloud services for enrollment and authentication?

    Show answer details

    Correct answer: D

    All communication between the CyberArk Identity mobile app (and other clients like the Connector and browser) and the CyberArk Identity cloud services occurs over TCP port 443 (HTTPS). If this port is blocked by a firewall, core functionalities like enrollment, push notifications, and portal access will fail.

  4. 4

    To meet compliance requirements, a company must enforce a password policy that prevents users from reusing any of their last 12 passwords. Where is this 'password history' setting configured in the CyberArk Identity Admin Portal?

    Show answer details

    Correct answer: B

    Password rules, including complexity, length, age and 'Password history' (the number of recent passwords that cannot be reused), are configured per policy set at Core Services > Policies > (policy set) > User Security Policies > Password Settings. Policy sets can be assigned to specific roles, so different user populations can have different requirements. Authentication profiles and rules only control MFA challenges.

  5. 5

    An administrator creates a new CyberArk Identity policy set and leaves every option under User Security Policies > Password Settings at its default. Which password requirements apply to CyberArk Cloud Directory users?

    Show answer details

    Correct answer: A

    If Password Settings are left at their defaults, CyberArk Cloud Directory passwords need a minimum length of 8 (maximum 64), at least one digit, and at least one uppercase and one lowercase letter. A symbol is not required (default No). 'Check against weak password' defaults to No, and maximum password age defaults to 365 days (not 90).

  6. 6

    A financial services firm is implementing a stringent access policy for its traders. The policy requires that any login attempt to the trading platform from outside the corporate network (defined by a specific IP range) must be challenged with a FIDO2 hardware key. However, logins from within the corporate network should only require a password. Which CyberArk Identity feature should be used to configure this conditional logic?

    Show answer details

    Correct answer: C

    Authentication Rules are the core component for implementing adaptive MFA. An administrator can create a rule that specifies a condition, such as the source IP address not being in a predefined range, and then apply a specific Authentication Profile (e.g., one requiring FIDO2) when that condition is met. The default policy can be set to password-only, which would apply to all other conditions, including logins from the corporate IP range.

  7. 7

    A healthcare organization has enrolled all domain-joined corporate laptops with CyberArk Identity Windows Device Trust, and sensitive applications require a trusted device. A clinician working from home, not connected to the corporate VPN, cannot access one of these applications. The administrator confirms the user is in the correct role, can sign in to the User Portal, and the laptop was enrolled successfully. What is the most likely cause?

    Show answer details

    Correct answer: A

    Windows Device Trust requires a domain-joined Windows computer, a tenant with IWA configured, and a connection to the domain controller (for example, inside the corporate network or connected through a VPN). A laptop at home without VPN cannot meet the domain controller connectivity requirement, so the device-trust check fails and access to apps that require a trusted device is denied. An expired enrollment code affects only new enrollments, not an already-enrolled laptop.

  8. 8

    A company's security policy mandates that all administrative access to cloud infrastructure management consoles (like AWS, Azure) requires Multi-Factor Authentication. Which TWO of the following mechanisms in CyberArk Identity can be used to enforce this policy specifically for users in the 'Cloud Admins' role? (Select TWO)

    Show answer details

    Correct answer: A, E

    Two documented mechanisms work. (1) App-level policy: each cloud console app has a Policy tab where you add authentication rules and profiles. For web-app access, a rule can use the Role filter (Cloud Admins), so MFA is required whenever those users launch AWS or Azure. (2) A policy set assigned to the 'Cloud Admins' role (policy sets can target all users or specified roles), placed above more general sets, applies its authentication policy (an MFA profile) to those users when they sign in to CyberArk Identity. The Role filter cannot be used in portal-login rules, policies are assigned to roles rather than individual accounts, and MFA Unlock temporarily suspends MFA instead of enforcing it.

    Two documented mechanisms work. (1) App-level policy: each cloud console app has a Policy tab where you add authentication rules and profiles. For web-app access, a rule can use the Role filter (Cloud Admins), so MFA is required whenever those users launch AWS or Azure. (2) A policy set assigned to the 'Cloud Admins' role (policy sets can target all users or specified roles), placed above more general sets, applies its authentication policy (an MFA profile) to those users when they sign in to CyberArk Identity. The Role filter cannot be used in portal-login rules, policies are assigned to roles rather than individual accounts, and MFA Unlock temporarily suspends MFA instead of enforcing it.

  9. 9

    True or False: When using the 'MFA Unlock' command for a user in the CyberArk Identity Admin Portal, the suspension of MFA challenges is permanent until the administrator manually re-enables it.

    Show answer details

    Correct answer: B

    The 'MFA Unlock' command is a temporary troubleshooting tool. It suspends the multi-factor authentication requirement for the selected user for a fixed duration, typically 10 minutes, to allow them to log in and resolve their MFA device issue. After the time expires, MFA is automatically re-enforced.

  10. 10

    A manufacturing company is setting up a SAML-based SSO integration for a new cloud-based inventory management system. During testing, users receive a SAML error indicating an 'Invalid NameID Format'. The application vendor has specified that they require the user's UPN (User Principal Name) in the NameID field. Where in the CyberArk Identity application configuration would an administrator modify the SAML response to send the UPN as the NameID?

    Show answer details

    Correct answer: C

    In a CyberArk Identity SAML app, the NameID (subject) value is the login user name that the app's Account Mapping page produces (LoginUser.Username). By default the assertion script calls setSubjectName(LoginUser.Username). To send the UPN, set Account Mapping to use the directory service field userPrincipalName, or use an account mapping script. If the SP also requires a specific format, set ' Format' on the Trust page under Service Provider Configuration. The Identity Provider Configuration section holds only the IdP's entity ID, signing certificate and URLs.

Create an account to continue.