Broadcom Privileged Access Management Technical Specialist (250-572) Certification Sample Questions
Getting knowledge of the Broadcom 250-572 exam structure and question format is vital in preparing for the Symantec Privileged Access Management Technical Specialist certification exam. Our Broadcom Privileged Access Management Technical Specialist sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Broadcom 250-572 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Symantec Privileged Access Management Technical Specialist Sample Practice Test. Therefore, solve the Broadcom Privileged Access Management Technical Specialist sample questions to stay one step forward in grabbing the Broadcom Privileged Access Management Technical Specialist credential.
These Broadcom 250-572 sample questions are simple and basic questions similar to the actual Broadcom Privileged Access Management Technical Specialist questions. If you want to evaluate your preparation level, we suggest taking our Symantec Privileged Access Management Technical Specialist Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Broadcom 250-572 Sample Questions:
01. An auditor asks the organization to show that a contractor could not have reached the payment systems at any point during the engagement, rather than to show that they did not reach them.
Which evidence answers the question as asked?
a) The recordings of every session the contractor opened, which show in full what was done on each of the systems they connected to.
b) The vault checkout history, which shows the credentials the contractor took out and when each one was returned to it.
c) The command filter logs, which list the commands the contractor was prevented from running.
d) The permissions in force for the contractor over that period, which state the destinations they were permitted to reach.
02. An organization wants to limit what an administrator can do while working on a Windows server through the brokered graphical path. A colleague proposes reusing the approach applied on the terminal path, where the session's input is inspected against a rule set.
What actually bounds the graphical session?
a) The rule set applied to session input, once written to name the graphical equivalents of what it would otherwise match
b) The entitlement that admitted the administrator to the target, which is re-evaluated for every action taken during the session and refuses the ones falling outside it
c) The rights of the account the session opens under, with a desktop exposing whatever that account is able to run on the host
d) The socket constraints placed on the session, which decide which programs the administrator may open on the desktop
03. A brokered session to a web application ends and the vaulted login is returned to the vault. The engineer never saw the password.
Which exposure still has to be addressed?
a) The engineer could present the same password on another system, since privileged passwords are frequently reused.
b) The application may still treat the browser as signed in, leaving access that outlives the check-in.
c) The next check-out will be refused until the password has been rotated, the vault treating a used value as spent.
d) The recording can no longer be tied to the engineer.
04. One administrative tool is to be published over RDP to two groups. One group must be able to make changes with it; the other must be able only to view.
How should that be arranged?
a) Publish it twice, each publication running under an account holding the rights that group's work needs.
b) Publish it once and rely on the entitlement, because a grant made for viewing confers only the ability to view.
c) Publish it once and give the viewing group a shorter session, since limiting how long the tool is held limits what can be done with it.
d) Publish it once and apply a command filter to the viewing group.
05. An integration withdraws the privileged entitlements of leavers each night. One night it stops partway through, having withdrawn some and left others in place, and the failure is noticed the following morning.
What does this tell the team about how the integration should be built?
a) It should file a request for an administrator to complete the remaining withdrawals by hand the next morning.
b) It should be given a broader identity, since the run stopped where its permissions ran out rather than where the list did.
c) It should run less often and against smaller lists, so that a single failure leaves less of the estate in an unknown state.
d) It should be safe to run again, and leave the estate in the intended state either way.
06. Several administrators reach a Windows server through brokered graphical sessions, all of them signing on with the same managed account. During one session an administrator uses a management tool that offers to remember the password for a separate remote system, and accepts.
What should the administrator responsible for that server do?
a) Nothing, since the value was saved inside a session that was recorded and attributed to the administrator who saved it.
b) Rotate the managed account's password, because the saved value is a copy of that account's credential and rotation invalidates it.
c) Remove the saved value, because the next person to hold the account inherits it.
d) Add a command filter to that server so the tool cannot write into the account's profile again.
07. A filter denies a named list of destructive commands. A user reaches the same effect by invoking one of them by another name and along another path, and the filter allows it.
What is the durable fix?
a) Add the name and path that were used to the list of denials, and repeat that each time another variant is found.
b) Deny everything and permit only the commands the role needs, so an unanticipated invocation is refused by default.
c) Apply the filter to the role rather than to the individual user, so that every member is covered by the same rules.
d) Enable logging on the filter so that the variant is recorded the next time somebody uses it.
08. An organization builds and retires servers continuously, and every one of them arrives with privileged accounts that must be vaulted, given an owner, and made reachable by the right administrators.
Why does Privileged Access Manager publish an External API alongside its administrative console?
a) So administrative work can be driven programmatically at the rate the estate actually changes
b) So the passwords of target accounts can be changed on a schedule without anyone approving each change
c) So privileged sessions can be established directly between an administrator's workstation and the target device without a broker in the path
d) So an administrator's session to a target host can be recorded without the traffic passing through a proxy
09. A team wants an operator to be able to invoke a maintenance action already defined for a group of targets, while the definition of that action stays under the control of the engineers who wrote it.
What does the platform's permission model have to allow for this to work?
a) Every permission in PAM covers both use and maintenance of an object.
b) Predefined actions answer to each target's own local privileges rather than to permissions held in PAM.
c) A user who may run a predefined action is also trusted with revising the definition behind it.
d) Running a predefined action and editing its definition are granted as separate permissions.
10. During an outage an engineer signed on to a Linux server at the console and changed the root password by hand. The platform still holds the value it set at the last scheduled change, and automated sign-ons to that host now fail.
What should the administrator do first?
a) Remove the account from management and add it again, so that discovery locates the account a second time.
b) Raise the rotation frequency for the account so that the next scheduled change corrects the difference sooner.
c) Reconcile the account so that the platform's stored value and the host's current password agree again.
d) Open a brokered session to the host and read the engineer's new password out of the session record.
Answers:
|
Question: 01 Answer: d |
Question: 02 Answer: c |
Question: 03 Answer: b |
Question: 04 Answer: a |
Question: 05 Answer: d |
|
Question: 06 Answer: c |
Question: 07 Answer: b |
Question: 08 Answer: a |
Question: 09 Answer: d |
Question: 10 Answer: c |
Note: For any error in Symantec Privileged Access Management Technical Specialist (250-572) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
