Skip to content

EPM-DEF Cyberark Endpoint Privilege Manager Practice Questions

Prepare for EPM-DEF with more than an answer.

218 questions in the full set20 sample questionsUpdated Jan 29, 2026
Exam fee
$200 USD
Level
Defender
Valid for
2 years
Domains covered on the exam 5
  1. EPM Concepts and Architecture20%
  2. Deployment and Configuration25%
  3. Policy Management30%
  4. User Management and Access Control15%
  5. Troubleshooting and Maintenance10%
  1. 1

    A software development team uses a specific version of a Java Development Kit (JDK) that requires administrative rights to register some components during its first run. The team needs to be able to run this JDK without permanent admin rights. The CISO is concerned about elevating the entire java.exe process, as it could be used to run malicious code. What is the most secure EPM policy configuration to meet this need?

    Show answer details

    Correct answer: C

    This is the most secure and precise approach. By creating an Elevate policy for java.exe and adding a condition based on the command-line parameters, you ensure that elevation is only granted when Java is being used for the intended, legitimate purpose (running their specific application). Any other attempt to run java.exe for different purposes will not be elevated, mitigating the security risk.

  2. 2

    What is the function of the 'Privilege Cloud Connector' in an EPM deployment?

    Show answer details

    Correct answer: C

    In a CyberArk EPM SaaS (cloud-hosted) environment, the Privilege Cloud Connector is a component installed within the customer's on-premises network. Its primary role is to bridge the gap between the cloud service and internal resources, most commonly to enable LDAP integration for synchronizing users and groups from the on-premises Active Directory.

  3. 3

    A user on a macOS endpoint needs to install a new application using a .pkg installer which requires administrator credentials. The user does not have these credentials. An EPM policy is in place to elevate applications. How does the user initiate the elevation process for this installer?

    Show answer details

    Correct answer: C

    On macOS, the EPM agent integrates directly with the standard OS authentication prompt. When an action requires elevation, the native prompt appears. The EPM agent adds an icon next to the password field. The user clicks this icon to trigger the EPM elevation workflow (which may be silent, require justification, etc.) instead of entering a password.

  4. 4

    An organization wants to delegate the responsibility of managing policies for the 'Marketing' computer set to the Marketing IT team. However, they should not be able to view or edit policies for any other sets, such as 'Finance' or 'R&D'. How can this be achieved in EPM?

    Show answer details

    Correct answer: B

    EPM supports granular delegation through scoped roles. By creating a role with 'Policy Administrator' permissions and then scoping that role to a specific Set ('Marketing'), you grant the assigned users full policy management rights, but only for the computers and policies associated with that Set. They will be unable to see or affect other Sets.

  5. 5

    After deploying an Application Control policy in 'Block' mode, a help desk technician reports that Microsoft Office updates are failing. The policy was intended to block all non-approved applications. What is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    Microsoft Office updates are complex and often involve multiple executables, temporary files, and scripts that are launched as child processes of the main update service. A restrictive 'Block' mode policy that only allows the main Office applications will inadvertently block these necessary child processes, causing the update to fail. The solution is to identify and create rules to allow these specific update-related processes.

  6. 6

    A financial services firm is deploying CyberArk EPM to achieve PCI DSS compliance. A key requirement is to control and audit the use of command-line tools like regedit.exe and cmd.exe on servers handling cardholder data. The security team wants to allow specific administrators to use these tools but require a documented business justification for each use. Which EPM policy configuration is the most effective and compliant approach?

    Show answer details

    Correct answer: C

    An Elevate policy lets only the targeted administrators run regedit.exe and cmd.exe with admin rights, and its End user UI setting shows a prompt that asks the user for a justification each time the policy is enforced. With Audit policy enforcement turned on, each of these events is collected, so every use is both justified and recorded, which is the evidence PCI DSS asks for. A notification that only reminds users to document their actions captures no justification, a Block policy with per-use exceptions stops legitimate admin work and moves justification into a manual process, and a Detect policy only monitors and leaves justification outside EPM.

  7. 7

    A pharmaceutical company is using EPM to manage local administrator rights. The security policy dictates that the built-in local Administrator account (SID S-1-5-....-500) must be disabled and its password vaulted, but a specific domain group, 'PharmaLab Admins', must be retained in the local Administrators group on lab workstations. When configuring the 'Remove Local Administrators' policy, which action should be taken?

    Show answer details

    Correct answer: B

    The Remove local administrators policy removes users and groups from the local Administrators group, except built-in admin users and the users and groups that the EPM administrator excludes by adding them to the policy scope. Adding 'PharmaLab Admins' there keeps that group in the local Administrators group. The built-in Administrator account is already left alone by the policy, so excluding its SID changes nothing (disabling and vaulting it is done outside this policy). Turning the policy off and using GPO gives up EPM's control, and a second lower-priority policy is not how EPM keeps a group: exclusions in the policy scope are.

  8. 8

    During an EPM agent deployment to a set of isolated, air-gapped industrial control systems (ICS), a consultant discovers the endpoints have no network connectivity to the EPM server. A technician on-site needs to run a specific diagnostics tool that requires elevation, but no pre-existing policies on the agent allow this. Which EPM feature is designed for this specific scenario?

    Show answer details

    Correct answer: C

    The Offline Policy Authorization Generator (OPAG) is the EPM tool for endpoint users who have no connection to the EPM server and cannot receive policy updates. An EPM administrator runs the tool (EPM_OPAG_tool.exe) to create an authorization code, and the on-site user runs the application with that code through 'Run with authorization code' (or first sends a Request for Authorization), provided OPAG is enabled in the agent configuration. The EPM secure token is different: it lets an admin upgrade, stop or uninstall an agent protected by Agent self-defense, not elevate an application. A just-in-time access request needs the EPM server to approve it, and policy push by removable media or a self-defense bypass code is not the EPM mechanism for this.

  9. 9

    True or False: When an EPM advanced policy elevates an application with the Elevate action, the application's child processes are also elevated by default.

    Show answer details

    Correct answer: B

    An EPM policy covers child processes only when the Include child processes option is selected for the application definition (childProcess = true in the policy API); otherwise the rule applies to the matching process and not to its children. CyberArk says to use this option with caution and only for applications that need it, such as software installers, because once it is selected every descendant runs with the same elevated token and no other policy, even one with higher priority, applies to those descendants.

  10. 10

    A university is using EPM to manage student lab computers. They want to prevent students from installing unauthorized software. The IT team has created a 'Trusted Sources' policy to allow installations only from the university's software portal and network shares. A student attempts to install a legitimate, digitally signed application downloaded from the vendor's official website, but the installation is blocked. What is the most likely reason for this block?

    Show answer details

    Correct answer: C

    Trusted Sources policies restrict installations to specific origins, such as URLs, network paths, or publishers. Even if an application is legitimate and signed, if its download source (the vendor's website) is not explicitly listed in the 'Trusted Sources' definition, EPM will block the installation as it originates from an untrusted location.

Create an account to continue.