ACCESS-DEF Sample Questions & Answers
User provisioning and deprovisioning ties with single sign-on paired with multi-factor authentication for the top weight, alongside core identity and access management concepts, password policies, and audit or compliance reporting.
Launch the full ACCESS-DEF simulator →Free ACCESS-DEF Sample Questions with Answers
Real questions from the CyberArk Defender Access practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Advanced
Multi-Factor Authentication - MFA · Authentication Profile Configuration
An administrator is creating a new Authentication Profile for high-risk applications. Users must first enter their password and then complete one additional factor of their choice: a Mobile Authenticator push notification, a security question, or an OATH OTP code. How should the profile be configured?
Show answer & explanation
Correct answer: A
An authentication profile (Settings > Authentication > Add Profile) defines Multiple Authentication Mechanisms as Challenge 1 and Challenge 2. The user must pass both challenges and may choose any one of the mechanisms selected in each challenge column. Password in Challenge 1 plus Mobile Authenticator, Security Question(s) and OATH OTP Client in Challenge 2 gives a password followed by the user's choice of second factor. Mechanisms under Single Authentication Mechanism are each enough on their own and would bypass the two challenges. The same mechanism cannot be selected in both challenge menus, and a rule selects only one profile.
- Question 2Beginner
CyberArk Identity Architecture & Components · Directory Integration
A new CyberArk Identity administrator is reviewing the corporate directory structure. They need to synchronize users from a specific Organizational Unit (OU) in Active Directory called 'Salesforce_Users' to a CyberArk role with the same name. What is the first component that must be deployed and configured in the on-premises environment to enable this synchronization?
Show answer & explanation
Correct answer: B
The CyberArk Identity Connector is a required component that is installed on a Windows server within the corporate network. It acts as a secure proxy between the CyberArk Identity cloud tenant and the on-premises Active Directory. It is responsible for handling authentication requests and synchronizing users, groups, and OUs.
- Question 3Intermediate
Security and Compliance · Reporting and Auditing
During a security audit, an organization is required to produce a report of all users who have successfully authenticated to any application via CyberArk Identity over the last 90 days, including the source IP address for each login. Where in the Admin Portal can this report be generated?
Show answer & explanation
Correct answer: B
The Admin Portal contains a dedicated 'Reports' section with numerous built-in reports for security and compliance. A report such as 'User Logins' or a similar audit event report can be filtered by date range (e.g., last 90 days) and will contain the necessary details, including username, application, timestamp, and source IP address.
- Question 4Intermediate
Single Sign-On (SSO) and Application Management · App Gateway Functionality
A company is using the CyberArk App Gateway to provide secure remote access to an internal legacy web application that does not support SAML. The security team wants to ensure that access to this application is logged and audited. Which component is primarily responsible for generating the audit logs for access events through the App Gateway?
Show answer & explanation
Correct answer: C
When a user accesses an application through the App Gateway, the initial authentication and authorization are handled by the CyberArk Identity platform. Therefore, the platform itself generates the primary audit trail for the access event, which can be viewed in the built-in reports. The App Gateway acts as a reverse proxy, but the central logging occurs within the Identity tenant.
- Question 5Advanced
Single Sign-On (SSO) and Application Management · Automated Provisioning and Role Mapping
An administrator needs to configure automated user provisioning for Salesforce. The goal is to assign different Salesforce license types (e.g., 'Salesforce Platform', 'Chatter Free') to users based on their department attribute in Active Directory. Which CyberArk Identity feature allows for this conditional license assignment during provisioning?
Show answer & explanation
Correct answer: C
The 'Provisioning' feature for applications like Salesforce allows for detailed role mapping. An administrator can create mappings that link CyberArk Identity roles (which can be populated dynamically from AD groups or attributes) to specific destination roles and license types within Salesforce. This allows for fine-grained, automated assignment of the correct licenses upon user creation.
- Question 6IntermediateSelect 3
Security and Compliance · Self-Service Password Reset (SSPR)
A university is setting up self-service password reset (SSPR) for its student population. To minimize help desk calls, they want to provide multiple options for identity verification. Which of the following are valid authentication factors that can be configured for use with the CyberArk Identity SSPR workflow? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
SSPR in CyberArk Identity requires the challenges in the authentication profile selected under User Security Policies > Self Service > Password Reset (for example, the Default Password Reset Profile). Profiles can use authentication mechanisms such as Security Question(s), Text message (SMS) confirmation code, and Email confirmation code (sent to the email address on the user's account). IP geolocation and a manager's access-request approval are not authentication mechanisms.
SSPR in CyberArk Identity requires the challenges in the authentication profile selected under User Security Policies > Self Service > Password Reset (for example, the Default Password Reset Profile). Profiles can use authentication mechanisms such as Security Question(s), Text message (SMS) confirmation code, and Email confirmation code (sent to the email address on the user's account). IP geolocation and a manager's access-request approval are not authentication mechanisms.
SSPR in CyberArk Identity requires the challenges in the authentication profile selected under User Security Policies > Self Service > Password Reset (for example, the Default Password Reset Profile). Profiles can use authentication mechanisms such as Security Question(s), Text message (SMS) confirmation code, and Email confirmation code (sent to the email address on the user's account). IP geolocation and a manager's access-request approval are not authentication mechanisms.
- Question 7Intermediate
Multi-Factor Authentication - MFA · Authentication Policy Settings
A system administrator is reviewing the following Authentication Policy settings. What is the effect of the 'Continue with additional challenges after failed challenge' option being set to True?
graph TD A[Start Login] --> B{Challenge 1: Password}; B -->|Success| C{Challenge 2: Email code}; B -->|Fail & Continue=True| C; B -->|Fail & Continue=False| D[Failure reported immediately]; C -->|All challenges passed| F[Access Granted]; C -->|Any challenge failed| G[Generic failure reported at the end];Show answer & explanation
Correct answer: B
'Continue with additional challenges after failed challenge' is under Core Services > Policies > Authentication Policies > CyberArk Identity. When it is True, a user who fails a challenge (for example, enters a wrong password) still steps through the remaining required challenges. Only after the last one is the user told that authentication failed, without saying which challenge failed. This makes it harder for attackers to learn which factor they got wrong. When it is False, the user is notified immediately after the failed challenge. The companion setting 'Do not send challenge request when previous challenge response failed' controls whether SMS, email or phone challenges are still sent. The setting does not lock accounts or trigger MFA Unlock.
- Question 8Beginner
CyberArk Identity Architecture & Components · App Gateway Deployment
True or False: The CyberArk Identity App Gateway must be deployed in a cloud environment, such as AWS or Azure, and cannot be installed on-premises.
Show answer & explanation
Correct answer: B
The CyberArk Identity App Gateway is a flexible component that can be deployed on-premises within a corporate DMZ or in a public/private cloud environment. Its purpose is to be co-located with the internal applications it is providing secure access to, making on-premises deployment a common and fully supported scenario.
- Question 9Intermediate
Device Trust and Endpoint Management · Device Enrollment Methods
A consultant is asked to deploy CyberArk Identity Windows Device Trust for a company whose Windows machines are all non-domain-joined. The company wants certificate-based device trust for access to the User Portal and web apps. Which statement is correct?
Show answer & explanation
Correct answer: B
Windows Device Trust supports only domain-joined Windows computers (with IWA configured and connectivity to a domain controller). AD users on devices that are not domain-joined, and CyberArk Cloud Directory users, are not supported. Group Policy, MAC address import and RADIUS are not Device Trust enrollment methods either. For non-domain-joined machines, a different CyberArk agent is required.
- Question 10Beginner
Security and Compliance · IP Address Restriction
A company has identified a range of IP addresses (198.51.100.0/24) that are known to be malicious and are being used in brute-force attacks against their CyberArk Identity user portal. What is the most direct and effective way to prevent all login attempts from this IP range?
Show answer & explanation
Correct answer: B
CyberArk Identity has a dedicated Blocked IP Ranges feature (Identity Administration portal > Settings > Network > Blocked IP Ranges > Add). You enter the custom IP range (or Outside Secure Zones) and choose the block type (Authentication only, which is the default, Sign-in page, or both). An Active entry blocks access from those addresses to CyberArk Identity. This targets the tenant directly, unlike an on-premises firewall, which cannot filter traffic to the SaaS portal. It is also simpler than building an authentication rule.
Ready for the real thing?
The full ACCESS-DEF simulator has every exam-style question, timed mode, and instant scoring.