SECRET-SEN Sample Questions

SECRET-SEN Sample Questions & Answers

Deploying Conjur and the Vault Conjur Synchronizer carries the top weight, alongside Kubernetes secrets management guided by the Conjur policy framework, overall Secrets Manager architecture, and application integration through Summon or the API.

Launch the full SECRET-SEN simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    CyberArk Secrets Manager Architecture · Vault Conjur Synchronizer Functionality

    True or False: When using the Vault Conjur Synchronizer, secrets are synchronized from the Vault to Conjur in near real-time, but updates made directly in Conjur are NOT synchronized back to the Vault.

    Show answer & explanation

    Correct answer: A

    The statement is true. The Vault Conjur Synchronizer is designed for unidirectional synchronization. It treats the CyberArk Vault as the single source of truth for secrets. Any changes made to synchronized secrets directly within Conjur will be overwritten during the next synchronization cycle from the Vault.

  2. Question 2Intermediate

    Installation and Configuration · Troubleshooting Follower Installation

    During the installation of a Conjur Follower, the process fails. Review of the logs shows 'Failed to authenticate to master: SSL certificate validation failed'. The administrator has already imported the Master's certificate into the Follower's trust store using evoke ca import. What is the most likely remaining cause of this issue?

    Show answer & explanation

    Correct answer: A

    Even if the CA that signed the certificate is trusted, SSL validation will still fail if the hostname used to connect to the Master does not match one of the names listed in the certificate's Subject Alternative Name (SAN) field. This is a common oversight during setup, where an IP address or a different DNS alias is used to configure the Follower.

  3. Question 3Advanced

    Policy Management and Security · Advanced Policy Controls

    A security architect is designing a Conjur policy and needs to prevent a powerful role from being granted to any new members accidentally. The architect wants to ensure that the membership of the global-admins group can never be changed after it is initially defined. Which policy record should be used to achieve this?

    Show answer & explanation

    Correct answer: B

    The !revoke statement is used to permanently remove the admin privilege from a role's admin_option. By revoking the admin_option from the global-admins group itself, no one (not even users with admin rights on the group) can subsequently grant new members to that group. This effectively makes the group's membership immutable.

  4. Question 4Beginner

    Application Integration · Using Summon

    A developer is using Summon to provide a secret to a shell script. The secrets.yml file contains the following entry:

    DB_PASSWORD: !var staging/mysql/password

    The script is executed with the command summon ./start-app.sh. Inside start-app.sh, how would the developer access the value of the secret?

    Show answer & explanation

    Correct answer: B

    Summon retrieves the secrets defined in secrets.yml and exposes them as environment variables to the subprocess it executes. The key in the YAML file (DB_PASSWORD) becomes the name of the environment variable, so the script can access the secret's value using $DB_PASSWORD.

  5. Question 5Intermediate

    Policy Management and Security · Policy Loading Methods

    A security audit reveals that a Conjur policy loaded in 'append' mode has inadvertently granted excessive permissions over time. The administrator needs to reset the permissions for the production/database policy branch to a known, clean state defined in a file named prod-db-reset.yml. Which command should be used to achieve this?

    Show answer & explanation

    Correct answer: C

    The --replace method is designed for this exact scenario. It completely deletes all existing policy objects within the specified branch (production/database) before loading the new policy from the file. This ensures that any old or excessive permissions are removed and only the permissions from prod-db-reset.yml exist.

  6. Question 6Intermediate

    CyberArk Secrets Manager Architecture · Quorum and Failover Scenarios

    A company has a Conjur cluster with one Master and four Standby nodes. During a network event, the Master becomes isolated from all four Standby nodes, but the Standby nodes can still communicate with each other. Applications, which connect to the Standby nodes via a load balancer, report that they can no longer retrieve secrets. What is the state of the cluster?

    graph TD subgraph "Initial State" M1(Master) --- S1(Standby) M1 --- S2(Standby) M1 --- S3(Standby) M1 --- S4(Standby) end subgraph "Partitioned State" subgraph "Partition A" M1_iso(Isolated Master) end subgraph "Partition B" S1_p(Standby) S2_p(Standby) S3_p(Standby) S4_p(Standby) S1_p --- S2_p S2_p --- S3_p S3_p --- S4_p end end style M1_iso fill:#f9f

    Show answer & explanation

    Correct answer: C

    A Conjur cluster with 5 voting members (1 Master + 4 Standbys) requires a quorum of (5/2) + 1 = 3 members to operate. When the Master is isolated, the remaining four Standby nodes still constitute a majority (4 > 3). They will hold an election, promote one Standby to be the new Master, and the cluster will remain fully functional for both reads and writes. The application failures are likely due to a separate issue, such as the load balancer still attempting to route traffic to the isolated old Master.

  7. Question 7Beginner

    Installation and Configuration · Initial Setup and Security

    When deploying a Conjur cluster using Docker, which command is used to generate the master key that encrypts sensitive data within the Conjur backend?

    Show answer & explanation

    Correct answer: D

    In a standard Docker Compose deployment of Conjur, the docker-compose run --no-deps conjur data-key generate command is used to create the data encryption key. This key is crucial for the security of the Conjur instance and must be backed up securely. The output of this command is then stored and used to start the Conjur container.

  8. Question 8Intermediate

    Application Integration · CI/CD Integration Patterns

    An organization wants to authenticate Jenkins jobs to Conjur. Each Jenkins job runs on a dynamically provisioned agent. What is the most secure and scalable method to authenticate these Jenkins jobs so they can retrieve secrets?

    Show answer & explanation

    Correct answer: B

    The JWT Authenticator is designed for this use case. It allows external identity providers like Jenkins to issue short-lived, signed JSON Web Tokens (JWTs). Conjur can be configured to trust Jenkins as an issuer and validate these tokens. This method provides a unique, auditable identity for each job without managing long-lived static API keys, making it highly secure and scalable for dynamic environments.

  9. Question 9Intermediate

    Kubernetes Integration · Troubleshooting Secrets Provider

    A Kubernetes pod, configured to use the Secrets Provider for K8s, is failing to start. The secrets-provider container log shows the error: Failed to retrieve secrets: 404 Not Found for variable 'production/webapp/api-key'. The Conjur policy granting the pod's identity permission to the variable exists. What is a possible cause for this error?

    Show answer & explanation

    Correct answer: B

    A 404 Not Found error specifically for a variable, when authentication and authorization are otherwise working, strongly indicates that the variable itself has been defined in policy but has no secret value assigned to it. The Secrets Provider attempts to fetch the value, but since none exists, the API returns a 404. A permissions issue would typically result in a 403 Forbidden error.

  10. Question 10BeginnerSelect 2

    CyberArk Secrets Manager Architecture · Component Roles

    What are the primary functions of a Conjur Follower in a DAP cluster? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Followers act as read-only replicas of the Master, allowing an organization to scale out secret retrieval capacity by handling read requests from applications and authenticators.

    Followers can authenticate local hosts and applications. They maintain a replica of the policy and data, allowing them to handle the entire authentication and secret retrieval workflow without needing to contact the Master for every request.

Ready for the real thing?

The full SECRET-SEN simulator has every exam-style question, timed mode, and instant scoring.