PAM-CDE-RECERT Sample Questions

PAM-CDE-RECERT Sample Questions & Answers

Core architecture components and authentication integration carry the top weight, alongside onboarding accounts through Central Policy Manager hardening, configuring the Privileged Session Manager, system-health maintenance, and threat analytics.

Launch the full PAM-CDE-RECERT simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Privileged Access Security Solution Architecture and Design · Distributed Architecture

    A global retailer is designing a new PAM architecture. They have a primary data center in North America and a secondary data center in Europe. The security policy states that privileged sessions initiated in Europe must be proxied through a local PSM server in the European data center to minimize latency and comply with data sovereignty regulations. How should this be configured?

    flowchart LR subgraph Europe User_EU[EU User] PVWA_EU[PVWA] PSM_EU[PSM Server] end subgraph North_America Vault[Active Vault] PSM_NA[PSM Server] end User_EU --> PVWA_EU PVWA_EU --> Vault PVWA_EU --> PSM_EU PSM_EU --> Target[Target System]
    Show answer & explanation

    Correct answer: C

    This is the correct design. In the PVWA Administration > Configuration Options, you can define multiple PSM servers and assign them unique IDs. You can then edit a platform's settings (UI & Workflows > Privileged Session Management) to use a specific ID for the PSM Server. By associating European platforms with the European PSM server ID, all sessions for those platforms will be routed to the local PSM.

  2. Question 2Intermediate

    Privileged Session Management (PSM) · PSM Web Connector Configuration

    True or False: When configuring a custom connection component for a web application using the PSM Web Connector framework, the WebFormFields property must be manually encrypted before being placed in the connection component configuration.

    Show answer & explanation

    Correct answer: B

    This is correct. The PVWA handles the encryption of sensitive parameters like WebFormFields automatically upon saving the connection component configuration. The administrator enters the values in plain text during setup.

  3. Question 3Intermediate

    Central Policy Manager (CPM) and Account Management · CPM Troubleshooting

    A CPM is failing to reconcile a password for a local account on a Windows Server. The reconcile account is a domain admin, and network connectivity is confirmed. The logs show the error message: CACPM344E Verifying Password Safe: , Folder: Root, Object: failed (try #1). Code: 2114, Error: The service has not been started. What is the most likely cause of this failure?

    Show answer & explanation

    Correct answer: B

    The error code 2114 and message The service has not been started directly correspond to the 'Server' service (service name LanmanServer) on the target machine being stopped. The CPM relies on this service for remote administration tasks, including password reconciliation for local accounts. This is the most direct cause.

  4. Question 4Intermediate

    Privileged Threat Analytics (PTA) · PTA Configuration

    A client has implemented PTA and is concerned about the volume of data being sent from their Domain Controllers to the PTA server. They want to ensure that only relevant security events are forwarded to minimize network bandwidth usage. What is the recommended method to achieve this?

    Show answer & explanation

    Correct answer: C

    This is the CyberArk recommended best practice. Windows Event Forwarding (WEF) allows administrators to create subscriptions with XPath queries to select only the specific event IDs that PTA needs for its analysis. This filtering happens on the source (Domain Controller), ensuring that only relevant data is sent over the network, thus minimizing bandwidth.

  5. Question 5Advanced

    Maintenance, Troubleshooting, and Operations · Disaster Recovery Testing

    During a failover test of a DR Vault, the CAVaultManager command to promote the DR Vault fails with an error indicating that replication is still active. The administrator has already stopped the PrivateArk Server service on the primary Vault. What is the most likely reason for this failure?

    Show answer & explanation

    Correct answer: A

    The CyberArk Event Notification Engine (ENE) service is responsible for triggering replication. Even if the main Vault service is stopped, a running ENE can still attempt to initiate replication tasks, which can interfere with the DR promotion process. The documented DR procedure requires stopping both the PrivateArk Server and the ENE services on the primary Vault before promoting the DR Vault.

  6. Question 6Advanced

    Privileged Session Management (PSM) · Custom Connection Component Design

    Case Study: A healthcare organization is implementing CyberArk to manage credentials for its Electronic Health Record (EHR) system. The EHR system uses a combination of Windows servers, Oracle databases, and a proprietary Java thick-client application for administration.

    Current Situation: The organization has deployed a standard CyberArk architecture with a single Vault, PVWA, CPM, and PSM. The Windows and Oracle accounts are being managed successfully. However, they are struggling to manage sessions for the Java thick-client application, which requires specific command-line parameters on launch, including the target server and username.

    Requirements:

    1. All administrative sessions to the EHR thick-client must be isolated and recorded via PSM.
    2. The connection process must be seamless for the administrator, without them needing to know the privileged password.
    3. The solution must be able to pass dynamic parameters (server address, username) to the application at runtime.

    Constraint: The organization does not have the budget for a full-time developer to create a complex, custom-coded solution.

    Which approach should the CDE recommend to meet all requirements?

    Show answer & explanation

    Correct answer: D

    This is the optimal solution. The PSM Universal Connector is designed for this exact scenario. It allows an administrator to use AutoIt, a simple scripting language, to automate the launching of an application. The script can dynamically pull the address, username, and password from the Vault and pass them as command-line parameters or inject them into GUI fields. This meets all technical requirements, provides a seamless user experience, ensures recording, and avoids the need for complex .NET development, thus respecting the budget constraint.

  7. Question 7Intermediate

    Privileged Access Security Solution Architecture and Design · SAML Authentication Configuration

    A CDE is configuring SAML authentication for the PVWA. The Identity Provider (IdP) is ADFS. After completing the configuration, users receive an error from the IdP stating that the SAML request is invalid. The IdP administrator confirms that the signing certificate is correct, but the Audience URL in the SAML request from the PVWA is not what they expected. Where in the PVWA configuration must the CDE correct the Audience URL value?

    Show answer & explanation

    Correct answer: A

    The Audience URL for the SAML request is a fundamental parameter that is defined in the web.config file located in the PVWA's installation directory (e.g., C:\inetpub\wwwroot\PasswordVault). This is the correct location to modify the value to match what is configured in the IdP's relying party trust.

  8. Question 8AdvancedSelect 3

    Central Policy Manager (CPM) and Account Management · Application Identity Management

    You are tasked with onboarding a new application that requires its password to be stored in a file on a specific Linux server. The password file must be owned by a specific service account, have 600 permissions, and be updated every 30 days. Which components are required to automate this entire process using CyberArk? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

    The CPM is required to automatically rotate the application's password in the Vault every 30 days, as per the policy requirement.

    The Credential Provider (CP) is the agent installed on the Linux server that securely retrieves the password from the Vault. It is essential for providing the password to the application.

    After the CPM changes the password in the Vault, a mechanism is needed to update the file on the Linux server. A custom script, triggered by the Credential Provider after a password change notification, is the standard way to write the new password to the file and set the required ownership and permissions (chown and chmod 600).

  9. Question 9Beginner

    Maintenance, Troubleshooting, and Operations · Component Installation and Configuration

    The CreateCredFile utility is used to create the credential file for which CyberArk component user?

    Show answer & explanation

    Correct answer: C

    The CreateCredFile utility is specifically used to create the user credential file (user.ini) for the DR user. This file allows the PADR (Privileged Access Disaster Recovery) service to authenticate to the Vault to perform replication tasks.

  10. Question 10Intermediate

    Maintenance, Troubleshooting, and Operations · PSM HTML5 Gateway Troubleshooting

    A customer is unable to view live and recorded PSM sessions via the HTML5 Gateway. They receive a generic connection error in the browser. The PVWA and PSM servers are confirmed to be running. The CDE needs to troubleshoot the communication flow. What is the correct sequence of connections for an HTML5-based PSM session?

    Show answer & explanation

    Correct answer: B

    This is the correct flow. The user's browser establishes a secure WebSocket connection to the HTML5 Gateway. The Gateway then communicates with the appropriate PSM server, and the PSM server connects to the target device. The Gateway acts as a tunnel, converting the RDP protocol into WebSocket traffic for the browser. Troubleshooting should focus on each of these legs: Browser-to-Gateway, Gateway-to-PSM, and PSM-to-Target.

Ready for the real thing?

The full PAM-CDE-RECERT simulator has every exam-style question, timed mode, and instant scoring.