CyberArk CDE Recertification Free Sample Questions

20 free sample questions230 in the full practice test

Try simulator

PAM-CDE-RECERT Sample Questions

  1. Question 1

    A financial services client is deploying a CyberArk PAM solution across two geographically separate data centers for disaster recovery. The primary data center hosts the active Vault, and the secondary data center hosts a passive DR Vault. The client's RPO is near-zero, and the RTO is 4 hours. The network link between the data centers is stable but has variable latency. Which Vault replication method should be implemented to meet these requirements?

    Answer and explanation

    Correct answer: A

    Asynchronous replication using PAReplicate is the standard and recommended method for CyberArk DR Vaults. It provides a near-zero RPO by replicating Vault data at frequent intervals (typically every few minutes). It is resilient to network latency, making it suitable for geographically separate data centers. The failover process is well-documented and can be accomplished within the 4-hour RTO.

  2. Question 2

    During a PSM for SSH deployment, a security administrator reports that they can initiate a session to a target Linux server, but the session recording is not being created. The PSM server logs indicate a successful connection, but the session does not appear in the PVWA Monitoring tab. Which of the following configuration parameters is the most likely cause of this issue?

    Answer and explanation

    Correct answer: C

    The Master Policy is the primary control for enabling or disabling session recording. If the 'Audit privileged session activity' rule is disabled for the platform governing the target account, PSM will establish the connection but will not record it, matching the described symptoms perfectly.

  3. Question 3

    A consultant is developing a custom CPM plugin for a legacy mainframe application that uses a proprietary command-line interface for password changes. The password change process requires three distinct steps: logon, change password, and logoff. The consultant has created three separate scripts for these actions. How should the Process.ini file be configured to execute these scripts in the correct order?

    Answer and explanation

    Correct answer: B

    This is the correct approach. The Process.ini file uses specific commands to define the sequence. pmprerun is executed first for logon actions. pmpass is executed for the actual password change. pmpostrun is executed last for logoff or cleanup actions. This structure allows the CPM to manage each phase of the process correctly.

  4. Question 4

    Multiple answers

    A security operations center (SOC) analyst receives a high-severity alert from Privileged Threat Analytics (PTA) indicating a suspected Pass-the-Hash attack originating from a domain controller. The source is a legitimate administrator's workstation, but the activity is occurring outside of business hours. Which of the following data sources are MOST critical for PTA to accurately generate this specific type of alert? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    PTA requires Windows Security Event Logs, specifically those related to authentication (like Event ID 4624), to detect credential theft attacks such as Pass-the-Hash. It analyzes the authentication type and logon patterns to identify anomalies.

    PTA can perform deep packet inspection on network traffic to detect the characteristic signatures of Pass-the-Hash and other attacks. This network-level visibility is a key data source for detecting attacks in real-time.

  5. Question 5

    You are performing a quarterly health check of a customer's CyberArk environment. You notice that the italog.log file on the Vault server is growing excessively and contains repeated warnings about ITADB323W and ITADB324W. What is the MOST appropriate first step to diagnose and resolve this issue?

    Answer and explanation

    Correct answer: D

    The ITADB323W and ITADB324W warnings indicate that the Vault database is fragmented, which can impact performance. The standard and recommended procedure to resolve this is to perform an offline defragmentation of the database using the CAVaultManager DefragmentDB command during a maintenance window. This is the correct first step to address the root cause.

  6. Question 6

    A global retailer is designing a new PAM architecture. They have a primary data center in North America and a secondary data center in Europe. The security policy states that privileged sessions initiated in Europe must be proxied through a local PSM server in the European data center to minimize latency and comply with data sovereignty regulations. How should this be configured?

    flowchart LR subgraph Europe User_EU[EU User] PVWA_EU[PVWA] PSM_EU[PSM Server] end subgraph North_America Vault[Active Vault] PSM_NA[PSM Server] end User_EU --> PVWA_EU PVWA_EU --> Vault PVWA_EU --> PSM_EU PSM_EU --> Target[Target System]
    Answer and explanation

    Correct answer: C

    This is the correct design. In the PVWA Administration > Configuration Options, you can define multiple PSM servers and assign them unique IDs. You can then edit a platform's settings (UI & Workflows > Privileged Session Management) to use a specific ID for the PSM Server. By associating European platforms with the European PSM server ID, all sessions for those platforms will be routed to the local PSM.

  7. Question 7

    True or False: When configuring a custom connection component for a web application using the PSM Web Connector framework, the WebFormFields property must be manually encrypted before being placed in the connection component configuration.

    Answer and explanation

    Correct answer: B

    This is correct. The PVWA handles the encryption of sensitive parameters like WebFormFields automatically upon saving the connection component configuration. The administrator enters the values in plain text during setup.

  8. Question 8

    A CPM is failing to reconcile a password for a local account on a Windows Server. The reconcile account is a domain admin, and network connectivity is confirmed. The logs show the error message: CACPM344E Verifying Password Safe: , Folder: Root, Object: failed (try #1). Code: 2114, Error: The service has not been started. What is the most likely cause of this failure?

    Answer and explanation

    Correct answer: B

    The error code 2114 and message The service has not been started directly correspond to the 'Server' service (service name LanmanServer) on the target machine being stopped. The CPM relies on this service for remote administration tasks, including password reconciliation for local accounts. This is the most direct cause.

  9. Question 9

    A client has implemented PTA and is concerned about the volume of data being sent from their Domain Controllers to the PTA server. They want to ensure that only relevant security events are forwarded to minimize network bandwidth usage. What is the recommended method to achieve this?

    Answer and explanation

    Correct answer: C

    This is the CyberArk recommended best practice. Windows Event Forwarding (WEF) allows administrators to create subscriptions with XPath queries to select only the specific event IDs that PTA needs for its analysis. This filtering happens on the source (Domain Controller), ensuring that only relevant data is sent over the network, thus minimizing bandwidth.

  10. Question 10

    During a failover test of a DR Vault, the CAVaultManager command to promote the DR Vault fails with an error indicating that replication is still active. The administrator has already stopped the PrivateArk Server service on the primary Vault. What is the most likely reason for this failure?

    Answer and explanation

    Correct answer: A

    The CyberArk Event Notification Engine (ENE) service is responsible for triggering replication. Even if the main Vault service is stopped, a running ENE can still attempt to initiate replication tasks, which can interfere with the DR promotion process. The documented DR procedure requires stopping both the PrivateArk Server and the ENE services on the primary Vault before promoting the DR Vault.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 230 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon