Cyberark Sentry - Privilege Cloud Free Sample Questions

20 free sample questions253 in the full practice test

Try simulator

CPC-SEN Sample Questions

  1. Question 1

    A financial services firm uses Privilege Cloud with on-premises Connectors running CPM and PSM, and must plan disaster recovery for password management at a secondary site. According to CyberArk, how is disaster recovery provided for the CPM component?

    Answer and explanation

    Correct answer: A

    CyberArk documents an active-passive Disaster Recovery CPM: you install and configure a second CPM instance (selecting CPM mode Passive during installation through Connector Management or the Privilege Cloud installer) and, if the primary CPM is down, you manually switch over to the DR CPM. Only one CPM instance can be active at a time, so active-active CPMs managing the same accounts, or two running copies of the same CPM, are not supported, and the on-premises CPM is not failed over by CyberArk. For sessions, high availability comes from deploying multiple PSMs, typically behind a load balancer.

  2. Question 2

    A security administrator is configuring Privilege Cloud to manage the password of a Cisco IOS user account with the "Cisco router via SSH" platform. The Cisco user does not have the privileges needed to change passwords, so the CPM must switch to Enable mode on the router to change the password. What must be configured for the CPM to do this?

    Answer and explanation

    Correct answer: A

    The Cisco router plugin documents that a Cisco user password 'without password management privileges' requires a link to an additional password object that enables the CPM to switch to Enable mode and change the password on the remote machine. The CiscoEnable password object provides this and is linked in the account's Details tab > Linked Accounts, where an enable password is an 'other' linked account defined at account level. There is no fixed 'EnablePrompt' platform parameter, because TPC prompt conditions are user-defined names in the Prompts file. The CiscoTerminal type also needs a linked object to switch to Enable mode. With TACACS, only reconciliation of local accounts is enabled, and Verify and Change are disabled by default.

  3. Question 3

    Multiple answers

    During a security audit of a Privilege Cloud deployment, an auditor notices that the PSM servers on the Connectors write session recordings to a local folder and asks whether recordings are retained on the PSM hosts. Which TWO statements accurately describe how PSM handles session recordings in Privilege Cloud? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    CyberArk documents that PSM recordings are saved temporarily in a local folder until the PSM session ends, when they are uploaded to the Vault. They are stored in Recording Safes that PSM creates automatically when the first recording is uploaded, named according to the platform's SessionRecorderSafe parameter (default PSMRecordings, or dynamic names such as PSM-{AccountSafeName}); retention is defined per recording Safe (SessionRecorderSafeRetention). No SFTP server, network share or Support-side configuration is needed to keep recordings off the PSM hosts.

  4. Question 4

    A consultant uses the Privilege Cloud REST API to onboard several hundred Active Directory service accounts. The accounts are added successfully, but the CPM's password changes fail because the domain password policy prevents these users from changing their own passwords (for example, a minimum password age). A reconcile account that is allowed to reset passwords is linked to the platform. What should the consultant configure so that the CPM can rotate these passwords?

    Answer and explanation

    Correct answer: A

    ChangePasswordInResetMode is a platform-level parameter in the Additional Policy Settings (default No). When it is set to Yes, the CPM performs password changes as reset operations using the associated reconciliation account instead of changing the password with the current one. CyberArk notes this is useful when a one-time password is used with a directory minimum password-age restriction or when the password policy prevents users from changing their own passwords (password plugins only). It is not a parameter of the Add Account API, whose body contains properties such as platformId, safeName, secret and secretManagement. Disabling automatic management would stop rotation altogether, and ImmediateInterval only sets the delay before a user-initiated management operation runs.

  5. Question 5

    True or False: When integrating CyberArk Privilege Cloud with an external SIEM system, the Secure Tunnel on the Privilege Cloud Connector must be used to forward audit logs.

    Answer and explanation

    Correct answer: B

    False. Privilege Cloud can integrate with a SIEM in two ways: the recommended Audit service SIEM integration (Setup space > Integrations > Export to SIEM), which does not use the Secure Tunnel, or syslog forwarding, for which the Secure Tunnel is deployed on premises so that the Privilege Cloud backend can send syslog messages to the SIEM servers (up to five). The Secure Tunnel is used for SIEM, LDAP (Standard) and legacy remote-access connections — CPM and PSM communicate with the Vault directly over TCP 1858. Since June 30, 2026 the Secure Tunnel is no longer supported for new deployments; organizations that require syslog must ask Technical Support to enable it.

  6. Question 6

    A healthcare organization is deploying Privilege Cloud and has a strict requirement that all privileged sessions to their Electronic Health Record (EHR) database servers must be monitored in real-time by a security analyst. The connection must also be terminated immediately if suspicious activity is detected. Which Privilege Cloud feature directly supports this requirement?

    Answer and explanation

    Correct answer: C

    The PSM's Live Session Monitoring feature is designed for this exact use case. It allows authorized users (like security analysts) to view active privileged sessions in real-time. This interface includes controls to take over or terminate the session immediately, providing the necessary oversight and intervention capabilities required by the organization.

  7. Question 7

    An administrator uses the out-of-the-box "Amazon Web Services - AWS - Access Keys" platform to manage the access key of an AWS IAM user. The key has become unsynchronized, and the administrator plans to add a reconcile account to the platform so that the CPM can reconcile it. What should the administrator know about this plugin?

    Answer and explanation

    Correct answer: A

    The AWS access keys plugin connects to AWS through the REST API, which is its only connection method. Its supported actions are Verify (connect to AWS) and Change (the IAM user must be allowed to change its own access key, globally or by group). Reconcile and Delete are not supported, so a reconcile account cannot recover an unsynchronized key. The required account parameters are Username (the IAM user), AWS Account ID, and AWS Access Key ID, and the access key secret is stored as the password.

  8. Question 8

    A university is configuring SAML authentication for Privilege Cloud with its central Shibboleth Identity Provider (IdP). After the integration is configured, users receive an 'Invalid Assertion' SAML error when they are redirected back to the Privilege Cloud portal. The IdP logs show successful authentication, the IdP's clock is synchronized with a reliable NTP source, and the Audience value configured in the IdP matches the value provided for the Privilege Cloud SAML configuration. What is the most likely misconfiguration?

    Answer and explanation

    Correct answer: A

    When the IdP confirms a successful authentication but the assertion is rejected, and clock skew and the Audience value have been ruled out, the most likely cause is a trust problem. Privilege Cloud verifies the signature of the SAML response with the IdP's signing certificate (IdentityProviderCertificate, or the certificate in the IdP metadata provided for the configuration: "used to verify the authenticity of the responses"). If that certificate is missing, expired or different from the one the IdP signs with, the assertion is rejected even though the user authenticated at the IdP. In Privilege Cloud Standard this information is provided to Technical Support; in Shared Services it is part of the external IdP's inbound metadata in Identity Administration.

  9. Question 9

    Multiple answers

    In a Privilege Cloud Standard deployment, which two functions does the optional Secure Tunnel client provide? (Choose two.)

    Answer and explanation

    Correct answers: C, D

    In the Privilege Cloud Standard architecture, the Secure Tunnel client is an optional on-premises component that 'enables you to securely connect Privilege Cloud with your LDAP and SIEM servers' (and set up legacy offline/remote access). The Privilege Cloud backend uses it to reach the on-premises directory for LDAPS integration and to deliver Vault audit records to the customer's SIEM over syslog. CPM and PSM do not use the tunnel: they connect directly to the Vault backend on TCP 1858 (and 443 for REST), and session isolation and recording are PSM functions. In Shared Services, AD/LDAP integration is handled by the Identity Connector and SIEM by the Audit service, and Secure Tunnel is no longer supported for new deployments as of June 30, 2026.

  10. Question 10

    Case Study

    A rapidly growing e-commerce company is deploying CyberArk Privilege Cloud to manage access to its production AWS environment and on-premises legacy systems. The company has a large, distributed DevOps team that requires just-in-time (JIT) access to EC2 instances for troubleshooting. The security team has mandated that all access must be temporary, request-based, and fully audited. The legacy systems are managed by a separate IT operations team that requires persistent, standing access.

    Current Situation:
    The company uses Okta as its corporate Identity Provider (IdP) and has integrated it with Privilege Cloud for user authentication. The DevOps team members are part of an 'AWS-Admins' group in Okta. The IT operations team is in an 'IT-Ops' group. A single Safe named 'Production-Servers' has been created to store all privileged accounts.

    Requirements:

    1. DevOps users must request access to specific EC2 instances for a limited time (e.g., 4 hours).
    2. Access for DevOps users must require approval from a team lead.
    3. IT-Ops users should have immediate, non-expiring access to the legacy system accounts.
    4. All session activity for both teams must be recorded.

    Which combination of configurations will meet all these requirements?

    Answer and explanation

    Correct answer: B

    Safes are the access boundary and the Master Policy is applied per platform. Placing the AWS accounts in an 'AWS-JIT' Safe on a dedicated platform lets a Master Policy exception activate 'Require dual control password access approval' for them only: each request states the access timeframe, team leads who are Safe members with 'Authorize account requests' confirm it, and EnforceDualControlTimeframeOnPSMConnections ends PSM sessions when the approved timeframe expires. IT-Ops receive standing 'Use accounts' access in 'Legacy-Persistent', whose accounts use platforms without dual control. 'Record and save session activity' is active by default, so both teams' PSM sessions are recorded. Giving IT-Ops 'Retrieve accounts' would allow unrecorded direct use, and exceptions cannot be created for an Okta group.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 253 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon