CyberArk Sentry – Secrets Manager Free Sample Questions

20 free sample questions225 in the full practice test

Try simulator

SECRET-SEN Sample Questions

  1. Question 1

    A financial services company is designing a multi-site Conjur DAP architecture for disaster recovery. They have a primary data center (DC1) and a secondary data center (DC2). The requirement is that if DC1 fails completely, DC2 must be able to continue serving secrets without manual intervention. The cluster spans both data centers. What is the minimum number of nodes required, and how should they be distributed to ensure automatic failover and maintain quorum if DC1 is lost?

    Answer and explanation

    Correct answer: C

    To maintain quorum and enable automatic failover after losing an entire data center, the surviving data center must contain a majority of the voting nodes (Master and Standbys). In a 5-node cluster (1 Master, 4 Standbys), the quorum size is 3. By placing 3 Standbys in DC2, if DC1 (containing the Master and 1 Standby) is lost, the 3 remaining Standbys in DC2 can form a new quorum, elect a new Master, and continue operations. Followers do not participate in quorum elections.

  2. Question 2

    An administrator deployed the Conjur Kubernetes Authenticator. Pods in the prod-apps namespace are failing to authenticate, and the authenticator logs show 401 Unauthorized errors. The policy correctly defines the host identity host/prod-apps/deployment/my-app. The pod's ServiceAccount is also correctly defined and assigned. Which of the following is the most likely cause for this authentication failure?

    Answer and explanation

    Correct answer: C

    The Conjur Kubernetes Authenticator works by validating a pod's ServiceAccount token with the Kubernetes API server. To do this, it must have the permission to create tokenreviews.authentication.k8s.io resources. If the authenticator's ClusterRole is missing this permission, the K8s API server will reject its validation requests, leading to a 401 Unauthorized error when the pod tries to authenticate to Conjur.

  3. Question 3

    Multiple answers

    A DevOps team is structuring their Conjur policies for a microservices application. They want to grant a specific service, billing-api, read and execute permissions on a database password. They also want to allow members of the db-admins group to update the password. Which of the following policy statements are required to achieve this configuration? (Select TWO)

    Answer and explanation

    Correct answers: C, D

    This statement correctly uses !permit to grant the billing-api host the necessary read and execute privileges on the db/password variable.

    This statement correctly uses !permit to grant the db-admins group the specific update privilege on the db/password variable, adhering to the principle of least privilege.

  4. Question 4

    A rapidly growing e-commerce company is migrating its entire platform to Google Kubernetes Engine (GKE). Their security team has mandated the use of CyberArk Conjur for all secrets management. The platform consists of dozens of microservices, each with its own database credentials, API keys, and certificates. The DevOps team uses a GitOps workflow with ArgoCD to manage all Kubernetes manifests.

    The current challenge is integrating Conjur into this GitOps model. The secrets must be available to the application containers as files mounted to a specific path (e.g., /etc/secrets), and the process must be fully automated without storing any Conjur-related credentials in Git. The security team also requires that secret rotation in Conjur is reflected in the running pods within 5 minutes without requiring a pod restart.

    The DevOps team is evaluating two primary methods for secret injection: the 'Summon-in-Init' pattern and the 'Secrets Provider for K8s' sidecar pattern.

    Which solution best meets all the company's requirements?

    Answer and explanation

    Correct answer: B

    The 'Secrets Provider for K8s' sidecar pattern is the optimal solution. It meets all requirements: it runs continuously to handle secret rotation without pod restarts; it makes secrets available as files via a shared volume; and it uses the pod's intrinsic ServiceAccount identity for authentication, which integrates perfectly with a GitOps workflow without storing static credentials. The init container pattern fails the rotation requirement as it only runs once at startup.

  5. Question 5

    When writing a Conjur policy, you need to define a group of administrators who can manage other users. What policy record type should be used to create this group?

    - !______ db-admins

    Answer and explanation

    Correct answer: A

    In Conjur's policy YAML syntax, the !group record type is used to declare a new group role. This group can then be granted permissions or have members, such as users, added to it.

  6. Question 6

    True or False: When using the Vault Conjur Synchronizer, secrets are synchronized from the Vault to Conjur in near real-time, but updates made directly in Conjur are NOT synchronized back to the Vault.

    Answer and explanation

    Correct answer: A

    The statement is true. The Vault Conjur Synchronizer is designed for unidirectional synchronization. It treats the CyberArk Vault as the single source of truth for secrets. Any changes made to synchronized secrets directly within Conjur will be overwritten during the next synchronization cycle from the Vault.

  7. Question 7

    During the installation of a Conjur Follower, the process fails. Review of the logs shows 'Failed to authenticate to master: SSL certificate validation failed'. The administrator has already imported the Master's certificate into the Follower's trust store using evoke ca import. What is the most likely remaining cause of this issue?

    Answer and explanation

    Correct answer: A

    Even if the CA that signed the certificate is trusted, SSL validation will still fail if the hostname used to connect to the Master does not match one of the names listed in the certificate's Subject Alternative Name (SAN) field. This is a common oversight during setup, where an IP address or a different DNS alias is used to configure the Follower.

  8. Question 8

    A security architect is designing a Conjur policy and needs to prevent a powerful role from being granted to any new members accidentally. The architect wants to ensure that the membership of the global-admins group can never be changed after it is initially defined. Which policy record should be used to achieve this?

    Answer and explanation

    Correct answer: B

    The !revoke statement is used to permanently remove the admin privilege from a role's admin_option. By revoking the admin_option from the global-admins group itself, no one (not even users with admin rights on the group) can subsequently grant new members to that group. This effectively makes the group's membership immutable.

  9. Question 9

    A developer is using Summon to provide a secret to a shell script. The secrets.yml file contains the following entry:

    DB_PASSWORD: !var staging/mysql/password

    The script is executed with the command summon ./start-app.sh. Inside start-app.sh, how would the developer access the value of the secret?

    Answer and explanation

    Correct answer: B

    Summon retrieves the secrets defined in secrets.yml and exposes them as environment variables to the subprocess it executes. The key in the YAML file (DB_PASSWORD) becomes the name of the environment variable, so the script can access the secret's value using $DB_PASSWORD.

  10. Question 10

    A security audit reveals that a Conjur policy loaded in 'append' mode has inadvertently granted excessive permissions over time. The administrator needs to reset the permissions for the production/database policy branch to a known, clean state defined in a file named prod-db-reset.yml. Which command should be used to achieve this?

    Answer and explanation

    Correct answer: C

    The --replace method is designed for this exact scenario. It completely deletes all existing policy objects within the specified branch (production/database) before loading the new policy from the file. This ensures that any old or excessive permissions are removed and only the permissions from prod-db-reset.yml exist.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 225 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon