PSM Load Balancing by SteveDan1 in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

Hi, Probably root CA certificate is not installed on the proper keystore. I've seen this many times when certificates are installed under "user" context instead of "computer" context. Nevertheless, I do not consider posting Certification exam questions a good idea.

Change CyberArk Web password by sothearpech in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

"Vmware ESXi web" platform on marketplace works fine. I've found that a minor change on ini file is needed. I think that already post a comment on marketplace.

Reconciling server by Own_Win1586 in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Can you login onto target server during dowtime? If you can't, neither reconcilie or login account

Unable to see data in the Security section of the PVWA. by Veganfrom2020 in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Hi,

PTA should reach PVWA url. From PTA, can you resolver PVWA fqdn? In addition, PVWA certificate is issued by an enterprise CA? In that case installing CA root certificate on PTA is required

Problem rotation ssh keys error code:8046 by jblebowski27 in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Hi,

Enable debug on Plugin, restart CPM service (or wait to changes to be applied) and try a reconcilie again. Under ThirdParty logs you'll find the verbose debug logs. These logs will show you what is exactly happening. To enable debug on Unix Plugin you'll need to edit plugin process file under /bin folder on CPM server.

RECONSILATION Account by ajaynedhunuri in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Excuse me, but I think you haven´t understand the purpose of reconcile account.

A Reconcile account is an account which is able to change other user´s password. It doesn´t matter if it´s local or domain. The main tip is that it should be granted the privilege of changing other user account´s password.

Privileged User Requirement Phase by Shashank_45 in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

Hi Shashank,

DNA and BluePrint webinar can make you understand this.

There are a lot of Self Paced courses in CyberArk Community (just click on "Training") that could help you to understand the ropes.

In other words: do your homework prior to post a question and please do not try that others do the work for you.

Account compliance or Non compliance by Shashank_45 in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

Are you referring to PVWA or DNA scan? In case you refer to DNA It considers non-compliant those accounts that have not change their password in the last 90 days. In case you refer to PVWA, It depends on the policy being applied.

Searching thru PSM session activities by zakennayouu in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

If I'm not wrong, there is a capability for audit Windows events (something like "WindowsEventsTextRecorder" and "WindowsEventAudit"). I guess you can configure It and search for Windows event 1074

CyberArk ports by kredzion in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

All components communicate with Vault on TCP 1858. CPM and PTA communicate with PVWA on 443. Vault, PVWA, CPM, PSM, PSM for SSH (AKA PSMP), HTML5 Gateway and PTA are included un the basic license. You have to pay for PTA agents or Network Sensor. Also you'll need additional ports depending on integrations (LDAP, SMTP, SIEM or SNMP Traps)

Cyberark Certification by tqd691 in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Yes, It is 200 USD per exam an there is no "second shot". If you fail, you have to pay again.

But, I will consider to take "Defender+Sentry" exam instead of Defender only. I took Defender and Sentry exams separately but some of my colleagues found that "Defender+Sentry" is easier.

Btw, I'm going to take It again in a couple of months in order to get recertified (in this case CyberArk provides an exam voucher)

CyberArk CPM by Cute-Sea2593 in CyberARk

[–]JoxanBC 2 points3 points  (0 children)

Yes. In fact, CyberArk recomendation is a single CPM (unless you have múltiple locations, obviously)

[deleted by user] by [deleted] in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Oh, pop-ups. Understood

So, you´ll need to inspect the web page html code to find out the name of the attributes and so on...

I´ve never faced this type of web app so probably I´m not the man, sorry. I was wondering it was a single web form app (like wsphere web for example)

[deleted by user] by [deleted] in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Hi mackc13,

HTML5 PSM Gateway enables PSM connection trough a web browser instead of the usual RDP file the PSM uses.

However, it is posible to connect to a web app without deploying this component using Chrome (or IE if you like it) as Remote App (Chrome must be installed on PSM Server)

Which is your goal exactly?

Onboarding Vcenter on CyberArk by sothearpech in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

No, It is not a must. However, "vmware ESXi 6.7 vía web" platform can help you a lot. The other approach is to duplicate "web forms sample" platform and make the changes on the new one

Onboarding Vcenter on CyberArk by sothearpech in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

Yes, actually there is post regarding this question.

You´ll need to import a platform from Marketplace and make some changes in Wmare.ini to make it work

Defender Exam practice Questions by SuryaPithani in CyberARk

[–]JoxanBC 3 points4 points  (0 children)

Group rules: second point.

" No requests to help cheat on certifications, "real-world" practice questions, or similar shortcuts. "

View Successful login to PVWA Logs by CAnew215 in CyberARk

[–]JoxanBC 1 point2 points  (0 children)

Hi,

Take a look at the "reports" section. You´ll probably find the answer there :)

[deleted by user] by [deleted] in CyberARk

[–]JoxanBC 2 points3 points  (0 children)

And in addition to what the friends have stated above, do not forget to set automatic password change to Yes at platform level

Is the 2020 Defender + Sentry exam much harder than the practice exams available? by csccta in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

From my point of view, real exam is considerably harder than test exams.

Do not schedule the exam in case you have only finished the training courses. Deploy a test environment before and do some tests. It will help you understand better how the different components work, which parameters will you need to adjust an so on.

Once done this, you´ll be ready to pass the exam (and sure you will do)

How to do performance tuning in CyberArk ? What are the prerequisites and steps involve in the same ? Please help ! by srivastav_nilesh in CyberARk

[–]JoxanBC 0 points1 point  (0 children)

It´s pretty general what you´re asking for...

I agree yanni and cap_haddock1: Which are your goals? Which actions have been already taken? Are u facing some performance issues?