CyberArk Sentry - PAM Free Sample Questions

20 free sample questions248 in the full practice test

Try simulator

PAM-SEN Sample Questions

  1. Question 1

    A financial services company is deploying a new PSM farm behind a network load balancer. The security policy mandates that the original client IP address must be logged for all connections to the Vault for audit purposes. The PVWA is also behind a load balancer. Which parameter must be configured on the PVWA to ensure the correct client IP is forwarded and logged?

    Answer and explanation

    Correct answer: B

    When a PVWA is placed behind a load balancer that uses X-Forwarded-For headers to pass the original client IP, the LoadBalancerClientAddressHeader parameter must be configured in the web.config file on the PVWA server. This tells the PVWA to look for the specified header (e.g., 'X-Forwarded-For') to identify the true client IP address for logging and auditing, rather than logging the IP of the load balancer itself.

  2. Question 2

    During a disaster recovery test, a manual failover to the DR Vault was initiated. After the failover, CPM services are unable to manage passwords for any accounts. Log analysis on the CPM server shows 'ITACM024S User is not defined' errors. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    The error 'ITACM024S User is not defined' indicates the user attempting to authenticate does not exist in the Vault's user database. In a DR scenario, this most commonly occurs when the component user (like the CPM user) was created or had its credentials updated on the Primary Vault, but a full replication cycle did not complete before the failover. As a result, the DR Vault does not have the user's definition, causing authentication to fail.

  3. Question 3

    Multiple answers

    A security team wants to implement a policy where any privileged session that executes the useradd command on a Linux server is automatically terminated. Which combination of CyberArk components is required to achieve this automated response? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The PSM is required to establish, record, and control the privileged session. It is the component that can physically terminate the active session upon receiving a command.

    PTA analyzes the session data from PSM in real-time. It contains the security engine and policy configuration to detect specific commands like useradd and trigger an automated response, such as instructing the PSM to terminate the session.

  4. Question 4

    True or False: When configuring PSM for SSH, the sshd_config file on the PSM server must be manually edited to enable TCP forwarding to allow session recording and control.

    Answer and explanation

    Correct answer: B

    False. The PSM for SSH installation script (psmp_install.sh) automatically configures the sshd_config file with the required parameters, including AllowTcpForwarding yes. Manual editing for this specific purpose is not required and could lead to misconfiguration if done incorrectly.

  5. Question 5

    A global enterprise with data residency requirements is designing a CyberArk PAM architecture. They have major data centers in North America (NA), Europe (EU), and Asia-Pacific (APAC). The primary Vault must reside in NA. To minimize latency for interactive sessions, PSM servers must be deployed locally in each region. However, all session recordings must be stored centrally in the NA Vault for compliance and security review.

    Current Situation:

    • A hardened Primary Vault is deployed in the NA data center.
    • A DR Vault is deployed in a separate NA location.
    • PVWA and CPM components are deployed in NA.

    Requirements:

    1. Deploy PSM servers in NA, EU, and APAC regions.
    2. Users in each region must connect through their local PSM for optimal performance.
    3. ALL session recordings from ALL regions must be securely transferred and stored in the Primary Vault in NA.
    4. The solution must be resilient to network interruptions between regions.

    Which architectural design best meets these requirements?

    graph TD subgraph NA_Datacenter [North America] Vault[Primary Vault] PVWA[PVWA] PSM_NA[PSM Server NA] end subgraph EU_Datacenter [Europe] PSM_EU[PSM Server EU] end subgraph APAC_Datacenter [Asia-Pacific] PSM_APAC[PSM Server APAC] end Users_NA((Users NA)) --> PSM_NA Users_EU((Users EU)) --> PSM_EU Users_APAC((Users APAC)) --> PSM_APAC PSM_NA --> Vault PSM_EU -->|Recordings| Vault PSM_APAC -->|Recordings| Vault

    Answer and explanation

    Correct answer: D

    This is the correct, built-in CyberArk solution for distributed PSM deployments. The PSM is designed to cache recordings locally in a secure, encrypted format if it cannot immediately connect to the Vault. Once connectivity is restored, it automatically uploads the recordings, ensuring no data is lost and providing resilience against network interruptions. This architecture meets all stated requirements for performance, central storage, and resilience.

  6. Question 6

    An administrator needs to configure a new platform for managing Cisco router passwords. The platform must verify the new password immediately after a change and revert to the old password if the verification fails. In the platform settings, under 'Automatic Password Management', which parameter should be set to 'Yes' to enable this functionality?

    Answer and explanation

    Correct answer: B

    The VFPerformAfterChange (Verify-Fail-Perform After Change) parameter in a platform's password management settings controls whether the CPM performs a password verification immediately after a password change. Setting this to 'Yes' ensures the new password is valid and functional before the change is considered successful.

  7. Question 7

    A new DevOps initiative requires that Jenkins jobs can retrieve database credentials from the Vault without storing any secrets on the Jenkins server itself. The security policy prohibits installing a full Credential Provider on the Jenkins server. Which CyberArk solution should be implemented to meet these requirements securely?

    Answer and explanation

    Correct answer: B

    The Central Credential Provider (CCP) is a web service component of AAM designed for this exact use case. It allows applications like Jenkins to retrieve credentials via a secure REST API call without requiring a local agent (Credential Provider) installation. The Jenkins server authenticates to the CCP using methods like client certificates or IP address validation, eliminating the need to store secrets locally.

  8. Question 8

    An organization has implemented Just-in-Time (JIT) access using ephemeral accounts for their cloud administrators. A user reports that they can successfully request and connect to a server, but their session disconnects exactly after the time specified in the JIT access policy. What is the expected state of the ephemeral account on the target server after the session disconnects?

    Answer and explanation

    Correct answer: C

    The core principle of JIT access with ephemeral accounts is that the account is provisioned only for the duration of the approved access window. Once the session ends or the time expires, the de-provisioning process is automatically triggered by the CPM, which removes the user account entirely from the target system, leaving no standing privileges.

  9. Question 9

    Multiple answers

    A security administrator is hardening a new Vault server according to CyberArk best practices. The administrator runs the CAVaultHarden.ps1 PowerShell script. Which of the following actions is performed by this script? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The Vault hardening script creates specific inbound and outbound Windows Firewall rules to ensure that only necessary communication for Vault operations (e.g., on port 1858) is allowed, blocking all other non-essential traffic.

    A key part of the hardening process is reducing the server's attack surface. The script disables a list of predefined Windows services (e.g., Print Spooler, Windows Audio) that are not needed for the Vault to function, thereby improving its security posture.

  10. Question 10

    You are tasked with creating a custom connection component for a legacy client-server application using AutoIt. The component must launch the client, wait for a login window with the title "SecureApp Login" to appear, enter the username and password into specific controls, and then click a button labeled "Connect". Which AutoIt function should be used to pause the script until the login window is active?

    Answer and explanation

    Correct answer: B

    The WinWaitActive function is the correct and most reliable method in AutoIt for this purpose. It pauses the script's execution until a window with the specified title becomes the active window, ensuring that subsequent ControlSend and ControlClick commands are sent to the correct target. This is a fundamental function for creating robust connection components.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 248 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon