A financial services company is deploying a new PSM farm behind a network load balancer. The security policy mandates that the original client IP address must be logged for all connections to the Vault for audit purposes. The PVWA is also behind a load balancer. Which parameter must be configured on the PVWA to ensure the correct client IP is forwarded and logged?
Answer and explanation
Correct answer: B
When a PVWA is placed behind a load balancer that uses X-Forwarded-For headers to pass the original client IP, the LoadBalancerClientAddressHeader parameter must be configured in the web.config file on the PVWA server. This tells the PVWA to look for the specified header (e.g., 'X-Forwarded-For') to identify the true client IP address for logging and auditing, rather than logging the IP of the load balancer itself.
Question 2
During a disaster recovery test, a manual failover to the DR Vault was initiated. After the failover, CPM services are unable to manage passwords for any accounts. Log analysis on the CPM server shows 'ITACM024S User is not defined' errors. What is the most likely cause of this issue?
Answer and explanation
Correct answer: B
The error 'ITACM024S User is not defined' indicates the user attempting to authenticate does not exist in the Vault's user database. In a DR scenario, this most commonly occurs when the component user (like the CPM user) was created or had its credentials updated on the Primary Vault, but a full replication cycle did not complete before the failover. As a result, the DR Vault does not have the user's definition, causing authentication to fail.
Question 3
Multiple answers
A security team wants to implement a policy where any privileged session that executes the useradd command on a Linux server is automatically terminated. Which combination of CyberArk components is required to achieve this automated response? (Select TWO)
Answer and explanation
Correct answers: A, C
The PSM is required to establish, record, and control the privileged session. It is the component that can physically terminate the active session upon receiving a command.
PTA analyzes the session data from PSM in real-time. It contains the security engine and policy configuration to detect specific commands like useradd and trigger an automated response, such as instructing the PSM to terminate the session.
Question 4
True or False: When configuring PSM for SSH, the sshd_config file on the PSM server must be manually edited to enable TCP forwarding to allow session recording and control.
Answer and explanation
Correct answer: B
False. The PSM for SSH installation script (psmp_install.sh) automatically configures the sshd_config file with the required parameters, including AllowTcpForwarding yes. Manual editing for this specific purpose is not required and could lead to misconfiguration if done incorrectly.
Question 5
A global enterprise with data residency requirements is designing a CyberArk PAM architecture. They have major data centers in North America (NA), Europe (EU), and Asia-Pacific (APAC). The primary Vault must reside in NA. To minimize latency for interactive sessions, PSM servers must be deployed locally in each region. However, all session recordings must be stored centrally in the NA Vault for compliance and security review.
Current Situation:
A hardened Primary Vault is deployed in the NA data center.
A DR Vault is deployed in a separate NA location.
PVWA and CPM components are deployed in NA.
Requirements:
Deploy PSM servers in NA, EU, and APAC regions.
Users in each region must connect through their local PSM for optimal performance.
ALL session recordings from ALL regions must be securely transferred and stored in the Primary Vault in NA.
The solution must be resilient to network interruptions between regions.
Which architectural design best meets these requirements?
graph TD
subgraph NA_Datacenter [North America]
Vault[Primary Vault]
PVWA[PVWA]
PSM_NA[PSM Server NA]
end
subgraph EU_Datacenter [Europe]
PSM_EU[PSM Server EU]
end
subgraph APAC_Datacenter [Asia-Pacific]
PSM_APAC[PSM Server APAC]
end
Users_NA((Users NA)) --> PSM_NA
Users_EU((Users EU)) --> PSM_EU
Users_APAC((Users APAC)) --> PSM_APAC
PSM_NA --> Vault
PSM_EU -->|Recordings| Vault
PSM_APAC -->|Recordings| Vault
Answer and explanation
Correct answer: D
This is the correct, built-in CyberArk solution for distributed PSM deployments. The PSM is designed to cache recordings locally in a secure, encrypted format if it cannot immediately connect to the Vault. Once connectivity is restored, it automatically uploads the recordings, ensuring no data is lost and providing resilience against network interruptions. This architecture meets all stated requirements for performance, central storage, and resilience.
Question 6
An administrator needs to configure a new platform for managing Cisco router passwords. The platform must verify the new password immediately after a change and revert to the old password if the verification fails. In the platform settings, under 'Automatic Password Management', which parameter should be set to 'Yes' to enable this functionality?
Answer and explanation
Correct answer: B
The VFPerformAfterChange (Verify-Fail-Perform After Change) parameter in a platform's password management settings controls whether the CPM performs a password verification immediately after a password change. Setting this to 'Yes' ensures the new password is valid and functional before the change is considered successful.
Question 7
A new DevOps initiative requires that Jenkins jobs can retrieve database credentials from the Vault without storing any secrets on the Jenkins server itself. The security policy prohibits installing a full Credential Provider on the Jenkins server. Which CyberArk solution should be implemented to meet these requirements securely?
Answer and explanation
Correct answer: B
The Central Credential Provider (CCP) is a web service component of AAM designed for this exact use case. It allows applications like Jenkins to retrieve credentials via a secure REST API call without requiring a local agent (Credential Provider) installation. The Jenkins server authenticates to the CCP using methods like client certificates or IP address validation, eliminating the need to store secrets locally.
Question 8
An organization has implemented Just-in-Time (JIT) access using ephemeral accounts for their cloud administrators. A user reports that they can successfully request and connect to a server, but their session disconnects exactly after the time specified in the JIT access policy. What is the expected state of the ephemeral account on the target server after the session disconnects?
Answer and explanation
Correct answer: C
The core principle of JIT access with ephemeral accounts is that the account is provisioned only for the duration of the approved access window. Once the session ends or the time expires, the de-provisioning process is automatically triggered by the CPM, which removes the user account entirely from the target system, leaving no standing privileges.
Question 9
Multiple answers
A security administrator is hardening a new Vault server according to CyberArk best practices. The administrator runs the CAVaultHarden.ps1 PowerShell script. Which of the following actions is performed by this script? (Select TWO)
Answer and explanation
Correct answers: A, C
The Vault hardening script creates specific inbound and outbound Windows Firewall rules to ensure that only necessary communication for Vault operations (e.g., on port 1858) is allowed, blocking all other non-essential traffic.
A key part of the hardening process is reducing the server's attack surface. The script disables a list of predefined Windows services (e.g., Print Spooler, Windows Audio) that are not needed for the Vault to function, thereby improving its security posture.
Question 10
You are tasked with creating a custom connection component for a legacy client-server application using AutoIt. The component must launch the client, wait for a login window with the title "SecureApp Login" to appear, enter the username and password into specific controls, and then click a button labeled "Connect". Which AutoIt function should be used to pause the script until the login window is active?
Answer and explanation
Correct answer: B
The WinWaitActive function is the correct and most reliable method in AutoIt for this purpose. It pauses the script's execution until a window with the specified title becomes the active window, ensuring that subsequent ControlSend and ControlClick commands are sent to the correct target. This is a fundamental function for creating robust connection components.