CyberArk Defender – PAM Free Sample Questions

20 free sample questions214 in the full practice test

Try simulator

PAM-DEF Sample Questions

  1. Question 1

    During a routine audit, it was discovered that a new team of database administrators requires temporary, emergency access to a production SQL server account. The current platform configuration for this account enforces a dual-control workflow for password retrieval. The security policy mandates that for emergency access, the request must bypass the standard dual-control approval process but still require a documented justification and be automatically revoked after two hours. Which is the most efficient and secure method to configure this exception in CyberArk?

    Answer and explanation

    Correct answer: C

    The Master Policy is the correct place to manage exceptions to platform-level settings. Creating an exception that overrides the 'Require multi-level approval' rule for a specific time window allows for controlled, temporary emergency access without altering the base platform security for all other accounts. This method is auditable, time-bound, and aligns with the principle of least privilege. Temporarily disabling the platform setting or creating a new safe are less efficient, more disruptive, and harder to audit for a temporary access scenario.

  2. Question 2

    Multiple answers

    A financial services company is deploying a distributed CyberArk architecture with a primary Vault and a Disaster Recovery (DR) Vault. A junior administrator is attempting to troubleshoot a replication failure. They have confirmed network connectivity and that the padr.ini file is correctly configured. What are the next TWO most likely causes of the replication failure? (Select TWO)

    Answer and explanation

    Correct answers: C, D

    The dedicated DR user must be a member of the built-in 'DR Users' group to have the necessary permissions to initiate and maintain replication. An incorrect password for this user is also a very common cause of failure.

    The password for the DR user is stored in the padr.ini file on the DR Vault server. If this password does not match the one set in the Vault for the DR user, authentication will fail, and replication cannot start. This is a primary troubleshooting step after confirming network connectivity.

  3. Question 3

    A PSM server is configured to use a custom recording safe named 'PSM_Recordings_Finance' for all sessions initiated from platforms tagged with the 'Finance' category. However, a security analyst reports that recordings for the 'Finance-DB-Admins' platform are still being stored in the default 'PSMRecordings' safe. What is the most likely reason for this misconfiguration?

    Answer and explanation

    Correct answer: D

    CyberArk uses a hierarchy for configuration. A parameter set directly on a specific platform will always override the more general setting configured on the PSM server itself (in the basic_psm.ini or via PVWA Options). In this case, the specific platform setting is taking precedence, causing recordings to be sent to the default safe instead of the intended custom safe.

  4. Question 4

    True or False: When integrating an external LDAP directory for user authentication, you must create a corresponding CyberArk Local User for every LDAP user that needs to log in.

    Answer and explanation

    Correct answer: B

    When using LDAP integration, CyberArk can be configured for transparent user management. An external user object is created automatically in the Vault the first time an LDAP user successfully authenticates. This eliminates the need to manually pre-create local users for each LDAP user.

  5. Question 5

    An administrator needs to configure a platform so that when a user connects to a target system via PSM, the session automatically executes a specific post-connection command, such as sudo -i. Where in the platform settings should this be configured?

    Answer and explanation

    Correct answer: B

    Connection Components define how PSM establishes and manages a session. The 'Target Settings' section within a specific connection component (e.g., PSM-SSH) allows for customization of the session behavior, including specifying commands to be run automatically upon connection. This is where parameters like ClientApp or custom AutoIt scripts are defined to automate interactions.

  6. Question 6

    A hospital is using CyberArk to manage credentials for critical medical devices. A new regulation requires that any password for a device involved in patient care must be at least 20 characters long and changed every 30 days. However, a specific set of older infusion pumps can only support passwords with a maximum length of 15 characters. How should a Defender administrator implement this policy while maintaining compliance for the older devices?

    Answer and explanation

    Correct answer: C

    Platform settings are the most appropriate place to define technical constraints like password length for a specific type of target system. The best practice is to set the general policy on a base platform and then duplicate and modify that platform for exception cases. This allows for granular control over the devices that cannot meet the standard, while the Master Policy can still enforce the 30-day rotation across both platforms. Using Master Policy exceptions for technical password constraints is less scalable than using platforms.

  7. Question 7

    A security team wants to ensure that all commands executed during PSM sessions on critical Linux servers are logged and auditable, even if the session itself is not being actively recorded as a video. Which component or feature must be configured to meet this requirement?

    Answer and explanation

    Correct answer: C

    PSM provides two types of session recording: video and text (keystroke logging). To capture the specific commands typed during a session for auditing purposes, text recording must be enabled in the platform settings. This creates a searchable text log of all activity within the session, which is distinct from the video recording of the session.

  8. Question 8

    When defining an LDAP Directory Mapping in the PVWA, what is the primary purpose of the 'LDAP Branch' field?

    Answer and explanation

    Correct answer: B

    The 'LDAP Branch' field specifies the starting point within the LDAP directory tree (e.g., an Organizational Unit) from which CyberArk will search for the users or groups being mapped. This allows administrators to limit the scope of the directory mapping to relevant parts of their Active Directory or LDAP structure.

  9. Question 9

    A CPM is failing to change the password for a local Windows account on a target server. The log file shows the error message: CACPM243W Failed to receive response from remote machine. Error: 5. Access is denied. The reconcile account has been verified to have the correct permissions on the target server. Which of the following is the MOST likely cause of this error?

    Answer and explanation

    Correct answer: C

    The 'Access is denied' error (code 5) for remote operations on Windows servers, especially when credentials and network connectivity are correct, is a classic symptom of User Account Control (UAC) remote restrictions. For non-domain accounts (or even domain accounts under certain conditions), UAC can strip administrative tokens from remote connections. To resolve this, a specific registry key (LocalAccountTokenFilterPolicy) must be created and set to '1' on the target server to allow remote administrative tasks.

  10. Question 10

    A global retail corporation is implementing CyberArk Privileged Access Security. They have a central IT team in North America and regional IT teams in Europe and Asia. The security policy requires that the regional IT teams can only manage safes and accounts pertaining to their specific region.

    The current safe naming convention is Region-Application-Environment, for example, EU-SAP-Prod or APAC-Oracle-Dev. The regional teams are mapped to Active Directory groups, such as CyberArk-Admins-EU and CyberArk-Admins-APAC. The goal is to grant safe management permissions automatically based on the safe's name without requiring manual intervention from the global IT team for every new safe created.

    Which CyberArk feature should be used to achieve this automated, attribute-based safe permission model?

    Answer and explanation

    Correct answer: D

    CyberArk's 'Safe Provisioning and Governance' feature is designed specifically for this use case. It allows administrators to create rules that automatically assign permissions to users and groups based on safe properties, including the safe name. By creating a rule that looks for safes starting with 'EU-' and automatically adds the 'CyberArk-Admins-EU' group, the company can achieve a fully automated, scalable, and policy-driven approach to safe delegation without manual scripting or cumbersome Master Policy exceptions.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 214 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon