PAM-SEN Sample Questions

PAM-SEN Sample Questions & Answers

Installation and safe design tie with everyday password rotation, session recording and account discovery for the top weight, alongside Application Access Control and EPM, core privileged-account risk concepts, and disaster-recovery best practices.

Launch the full PAM-SEN simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    CyberArk PAM Administration and Operations · Platform Configuration

    An administrator needs to configure a new platform for managing Cisco router passwords. The platform must verify the new password immediately after a change and revert to the old password if the verification fails. In the platform settings, under 'Automatic Password Management', which parameter should be set to 'Yes' to enable this functionality?

    Show answer & explanation

    Correct answer: B

    The VFPerformAfterChange (Verify-Fail-Perform After Change) parameter in a platform's password management settings controls whether the CPM performs a password verification immediately after a password change. Setting this to 'Yes' ensures the new password is valid and functional before the change is considered successful.

  2. Question 2Intermediate

    Advanced CyberArk PAM Features · Application Access Manager (AAM)

    A new DevOps initiative requires that Jenkins jobs can retrieve database credentials from the Vault without storing any secrets on the Jenkins server itself. The security policy prohibits installing a full Credential Provider on the Jenkins server. Which CyberArk solution should be implemented to meet these requirements securely?

    Show answer & explanation

    Correct answer: B

    The Central Credential Provider (CCP) is a web service component of AAM designed for this exact use case. It allows applications like Jenkins to retrieve credentials via a secure REST API call without requiring a local agent (Credential Provider) installation. The Jenkins server authenticates to the CCP using methods like client certificates or IP address validation, eliminating the need to store secrets locally.

  3. Question 3Intermediate

    CyberArk PAM Administration and Operations · Just-in-Time Access

    An organization has implemented Just-in-Time (JIT) access using ephemeral accounts for their cloud administrators. A user reports that they can successfully request and connect to a server, but their session disconnects exactly after the time specified in the JIT access policy. What is the expected state of the ephemeral account on the target server after the session disconnects?

    Show answer & explanation

    Correct answer: C

    The core principle of JIT access with ephemeral accounts is that the account is provisioned only for the duration of the approved access window. Once the session ends or the time expires, the de-provisioning process is automatically triggered by the CPM, which removes the user account entirely from the target system, leaving no standing privileges.

  4. Question 4IntermediateSelect 2

    CyberArk PAM Deployment and Configuration · Vault Hardening

    A security administrator is hardening a new Vault server according to CyberArk best practices. The administrator runs the CAVaultHarden.ps1 PowerShell script. Which of the following actions is performed by this script? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    The Vault hardening script creates specific inbound and outbound Windows Firewall rules to ensure that only necessary communication for Vault operations (e.g., on port 1858) is allowed, blocking all other non-essential traffic.

    A key part of the hardening process is reducing the server's attack surface. The script disables a list of predefined Windows services (e.g., Print Spooler, Windows Audio) that are not needed for the Vault to function, thereby improving its security posture.

  5. Question 5Advanced

    Advanced CyberArk PAM Features · Custom Connection Components

    You are tasked with creating a custom connection component for a legacy client-server application using AutoIt. The component must launch the client, wait for a login window with the title "SecureApp Login" to appear, enter the username and password into specific controls, and then click a button labeled "Connect". Which AutoIt function should be used to pause the script until the login window is active?

    Show answer & explanation

    Correct answer: B

    The WinWaitActive function is the correct and most reliable method in AutoIt for this purpose. It pauses the script's execution until a window with the specified title becomes the active window, ensuring that subsequent ControlSend and ControlClick commands are sent to the correct target. This is a fundamental function for creating robust connection components.

  6. Question 6Intermediate

    CyberArk PAM Administration and Operations · Platform Management and CPM Restriction

    True or False: The AllowedSafes parameter can be configured at the platform level to restrict a specific CPM plugin to managing accounts only within a defined list of Safes.

    Show answer & explanation

    Correct answer: A

    True. The AllowedSafes parameter is a powerful performance and security feature. By configuring it on a platform (e.g., a Windows Domain Account platform), you instruct the CPM to only scan and manage accounts associated with that platform if they reside in the specified Safes. This prevents the CPM from needlessly scanning all Safes, which can significantly improve performance in large environments.

  7. Question 7Advanced

    Advanced CyberArk PAM Features · DevOps and Secrets Management

    Company Background:
    Global Logistics Inc. (GLI) is a multinational shipping company with a central IT team in New York and regional IT teams in London and Singapore. They have an established CyberArk PAM Core PAS environment, with the Primary Vault and core components located in their New York data center. The company is experiencing rapid growth in its cloud-native application development, which heavily relies on AWS services.

    Current Situation:
    GLI's application teams in all three regions are developing applications that run on Amazon EC2 instances. These applications need to retrieve secrets, such as database connection strings and API keys, from the CyberArk Vault. The central IT team has observed that direct requests from EC2 instances in London and Singapore to the Application Access Manager (AAM) Credential Providers in New York are experiencing high latency, impacting application performance. A recent security audit also raised concerns about the lack of a standardized and secure method for authenticating these EC2 instances to AAM.

    Requirements:

    1. Eliminate high latency for secret retrieval by applications running in AWS.
    2. Implement a secure, scalable, and AWS-native authentication method for EC2 instances requesting secrets.
    3. The solution must not require manual creation or management of application IDs in CyberArk for each new EC2 instance.
    4. Maintain the single, central Vault in New York as the authoritative source for all secrets.

    Which solution should the CyberArk Sentry recommend to meet all of GLI's requirements?

    sequenceDiagram participant EC2 as EC2 Instance (London) participant Conjur as Conjur Follower (AWS London) participant Vault as CyberArk Vault (New York) EC2->>Conjur: Request Secret (with IAM Role) Conjur->>Vault: Authenticate & Sync Secret Vault-->>Conjur: Secret Value Conjur-->>EC2: Provide Secret Value

    Show answer & explanation

    Correct answer: C

    This is the ideal solution. Deploying Conjur Followers in each region provides a local, low-latency cache for secrets. The Conjur IAM Authenticator leverages an AWS-native, secure, and scalable authentication method (IAM Roles), eliminating the need for manual App ID management. The Conjur-Vault synchronizer ensures that the New York Vault remains the single source of truth, meeting all stated requirements.

  8. Question 8Intermediate

    CyberArk PAM Deployment and Configuration · LDAP Integration

    When integrating LDAP over SSL (LDAPS) for user authentication, the PVWA server must trust the certificate presented by the domain controller. Where in the PVWA configuration is the path to the trusted CA certificate specified?

    Show answer & explanation

    Correct answer: C

    For LDAPS integration, the ldap.conf file, typically located in C:\CyberArk\PVWA\etc\, must be configured. The TLS_CACERT directive within this file is used to specify the full path to the file containing the trusted root CA certificate. This allows the PVWA's underlying LDAP client to validate the domain controller's SSL certificate.

  9. Question 9Intermediate

    Best Practices and Security Considerations · Vault Security Configuration

    To ensure that the PrivateArk Client can only be run from a specific, secured network segment, which parameter should be configured in the Vault's dbparm.ini file?

    Show answer & explanation

    Correct answer: C

    The SecureAdminConnections parameter in dbparm.ini is used to restrict administrative clients, including the PrivateArk Client, to specific network areas. By setting this parameter to Yes,IP= , you enforce that only connections originating from the defined IP range can use the PrivateArk Client, effectively creating a secure administrative zone.

  10. Question 10Beginner

    CyberArk PAM Administration and Operations · Auditing and Reporting

    A compliance requirement states that a report must be generated quarterly showing all privileged accounts that have not had their passwords rotated in over 90 days. Which tool or feature within the CyberArk suite is best suited for generating this specific report?

    Show answer & explanation

    Correct answer: C

    The PVWA includes a built-in reporting engine. The 'Privileged Accounts Inventory' report can be customized with filters, such as 'Last Password Change' date, to easily identify and list all accounts that have not been rotated within a specified timeframe (e.g., 90 days). This is the standard method for generating compliance and operational reports.

Ready for the real thing?

The full PAM-SEN simulator has every exam-style question, timed mode, and instant scoring.