CyberArk Defender PAM & Sentry PAM Free Sample Questions

20 free sample questions175 in the full practice test

Try simulator

PAM-DEF-SEN Sample Questions

  1. Question 1

    A financial services company is deploying a distributed CyberArk PAS environment with a Primary Vault in New York and a Satellite Vault in London. During a network outage, the London PSM servers lose connectivity to the Primary Vault but can still communicate with the London Satellite Vault. What is the expected behavior for privileged sessions initiated from London during this outage?

    Answer and explanation

    Correct answer: C

    In a Distributed Vaults architecture, PSM servers are configured to cache Safe data locally. During a network failure where the PSM can reach the Satellite Vault but not the Primary Vault, it can continue to initiate and record sessions. The session recordings are stored locally in the PSM's recording folder and are automatically uploaded to the Primary Vault once the connection is re-established. This ensures business continuity for privileged access in remote sites.

  2. Question 2

    A security architect is designing the firewall rules for a new CyberArk deployment. To ensure proper communication for session recording uploads and other critical functions, which component requires persistent, stateful connectivity to the Vault server on port 1858?

    Answer and explanation

    Correct answer: B

    The Central Policy Manager (CPM) is the component responsible for automated password management. It communicates with the Vault on TCP port 1858 to retrieve account details, execute password changes on target systems, and update the Vault with the new credentials. This connection is fundamental for the core function of the CPM. While PVWA and PSM also connect to the Vault, the CPM's role in policy enforcement makes its connection particularly critical and persistent.

  3. Question 3

    Multiple answers

    During a security audit, it was discovered that a Master Policy exception was created to allow a group of developers to view passwords directly without requiring a reason. To comply with a new Zero Trust policy, all password retrievals must be justified and approved. Which TWO actions are required to enforce this policy for the developer group? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  4. Question 4

    True or False: The 'CreateCredFile' utility can be used to create credential files for all CyberArk components, including the Vault service user (master user).

    Answer and explanation

    Correct answer: B

    False. The 'CreateCredFile' utility is used to create encrypted credential files for application users that authenticate to the Vault (e.g., component users like GatewayUser, PSMAppUser, etc.). It cannot be used to create or manage the credential files for the core Vault service users, such as the Master or Administrator users. The Vault service user's credentials are created and managed during the Vault installation and hardening process using different, dedicated utilities.

  5. Question 5

    A large retail company needs to onboard thousands of local administrator accounts from their point-of-sale (POS) systems into CyberArk. The accounts follow a standard naming convention but exist across multiple network segments. A full network scan is not feasible due to performance concerns. Which onboarding method provides the most efficient and targeted approach?

    Answer and explanation

    Correct answer: C

    The Password Upload Utility is designed for large-scale, targeted onboarding. By creating a CSV file with the specific IP addresses of the POS systems and the details of the accounts to be onboarded, the company can avoid a broad, performance-intensive network scan. This method is highly efficient for onboarding a large number of known accounts, making it the ideal choice for this scenario.

  6. Question 6

    An administrator is attempting to troubleshoot a failing PSM-RDP connection. The user receives a generic PSM error message: "PSMSR126E Failure occurred while handling session." Analysis of the PSM console log reveals the error "PSMSR035E Privileged Session Manager has been terminated." What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    The PSMSR035E error indicates that the PSM service itself terminated unexpectedly. A primary cause for this is misconfiguration of the local security policy on the PSM server. The PSMConnect and PSMAdminConnect users require the 'Allow log on locally' user right to establish the initial session context. If this right is missing, the session manager process will fail to initialize and terminate, leading to the generic error presented to the end-user. This is a common issue after server hardening or GPO application.

  7. Question 7

    A deployment engineer needs to harden a new Vault server according to CyberArk's security best practices. Which utility is specifically designed to automate the majority of the required post-installation security configurations on the Vault server?

    Answer and explanation

    Correct answer: C

    CAVaultManager.exe is the Vault management utility that includes the 'Secure' command (e.g., CAVaultManager Secure). This command is executed after the initial Vault installation to apply a comprehensive set of security configurations, including setting up the Vault's internal firewall, configuring permissions, and disabling unnecessary services. It is a critical step in the Vault hardening process.

  8. Question 8

    A custom CPM plugin for a proprietary database is failing during the password verification step. The change process completes successfully, but the verify step fails with a generic error. The plugin uses a PMPasswordVerification.exe process. What is the most effective first step to diagnose the cause of the verification failure?

    Answer and explanation

    Correct answer: B

    The most effective way to troubleshoot CPM plugin issues is to enable detailed logging. By increasing the debug level in the CPM's configuration file (main_apppass.ini), the CPM will generate verbose logs (pm.log and pm_error.log) that capture the step-by-step execution of the plugin process, including the exact commands sent and responses received during the verification step. This detailed output is essential for identifying whether the issue is with the logic, syntax, or prompts in the verification process file.

  9. Question 9

    A security team wants to implement a policy where all privileged commands executed during a PSM for SSH session on Linux servers are captured as distinct events, in addition to the full session video recording. Which CyberArk feature must be configured to achieve this?

    Answer and explanation

    Correct answer: C

    The feature specifically designed to capture and index typed commands within an SSH session is 'Audit privileged commands' (also known as SSH keystroke logging). When enabled in the Master Policy and/or on a specific platform, the PSM for SSH will parse the session data, identify commands, and store them as searchable audit events. This provides a text-based audit trail that complements the video recording, allowing auditors to quickly search for specific commands without watching the entire session.

  10. Question 10

    A compliance report requires a list of all Safes that have not had their object-level access control settings modified in the last 180 days. Which tool or interface would be most suitable for generating this specific report?

    Answer and explanation

    Correct answer: C

    The Export Vault Data (EVD) utility is a powerful command-line tool for extracting detailed information from the Vault for custom reporting and analysis. For a specific requirement like finding Safes based on the last modification date of their access control settings, EVD provides the necessary flexibility to query Vault metadata that is not available through the standard PVWA reports or the PrivateArk Client's reporting features. A custom query could be crafted to filter Safes based on the 'SafeLastModified' timestamp and other relevant properties.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 175 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon