CertSafari

    Free CyberArk Sentry Certification – Modern PAM Sample Questions

    35 free sample questions from our bank of 309+, covering every exam domain, with answers and detailed explanations. Updated August 2026.

    Domain 1: Architecture and Implementation Concepts

    Subdomain 1.1: Architecture and Implementation Concepts

    1.During a new Privilege Cloud implementation, the project team is currently identifying critical business assets, defining success criteria, and establishing the project timeline. Which phase of the implementation methodology is the team executing?

    1. A.Discovery and Initiation
    2. B.Definition and Planning
    3. C.Launch and Execution
    4. D.Optimization and Expansion
    Show answer & explanation

    Correct answer: BDefinition and Planning

    • A. Discovery and Initiation typically involves initial high-level stakeholder alignment and broad scoping. While identifying assets can begin here, the specific tasks of formalizing success criteria and building a detailed project timeline occur in the next phase.
    • B. Definition and Planning is the phase where the team defines the scope and project roadmap in detail. Key activities include identifying specific critical business assets, defining measurable success criteria, and establishing the project timeline to guide the execution.
    • C. Launch and Execution focuses on the actual technical deployment, configuration of the Privilege Cloud environment, and the onboarding of accounts as defined during the planning phase.
    • D. Optimization and Expansion occurs after the initial implementation is complete. It focuses on refining processes, increasing user adoption, and extending the solution to additional use cases or business units.

    Subdomain 1.1: Architecture and Implementation Concepts

    2.An administrator needs to discover local administrator accounts on thousands of remote Windows laptops that frequently disconnect from the corporate network. Which CyberArk discovery method is most effective for this scenario?

    1. A.Central Policy Manager (CPM) Auto-Discovery
    2. B.CyberArk Discovery and Audit (DNA) tool
    3. C.CyberArk Endpoint Privilege Manager (EPM) integration
    4. D.Privilege Cloud Secure Tunnel network scans
    Show answer & explanation

    Correct answer: BCyberArk Discovery and Audit (DNA) tool

    • A. Central Policy Manager (CPM) Auto-Discovery is designed to find and onboard accounts from systems that are consistently connected to the network. It requires the target system to be online and reachable during the scanning window, making it less effective for remote laptops with intermittent connectivity.
    • B. The CyberArk Discovery and Audit (DNA) tool is a specialized, non-intrusive utility designed to identify privileged accounts and security risks across an organization. It is highly effective for endpoints because it can be deployed via automated management tools (like SCCM) to run locally and generate reports, making it the standard choice for discovering local administrator accounts on disconnected or loosely connected devices.
    • C. While Endpoint Privilege Manager (EPM) manages local administrator rights and provides visibility into endpoint accounts, its primary focus is on enforcing least privilege and application control rather than serving as the dedicated discovery tool for a PAM implementation. In the context of PAM discovery methods, DNA is the intended tool for auditing.
    • D. The Privilege Cloud Secure Tunnel facilitates communication between a CyberArk SaaS environment and on-premises components like the CPM or PSM. It is an infrastructure connectivity component, not a discovery mechanism, and cannot scan systems that are not currently connected to the corporate network.

    Subdomain 1.1: Architecture and Implementation Concepts

    3.A customer plans to deploy the CPM and PSM on the same Windows Server to reduce infrastructure costs. For an enterprise environment expecting 500 concurrent PSM sessions, this combined deployment is a supported and recommended architecture.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. The statement is false because while co-locating components is technically possible in lab or very small environments, it is not a recommended or supported architecture for enterprise-grade deployments, particularly when handling high volumes such as 500 concurrent sessions.
    • B. The statement is false because an environment requiring 500 concurrent PSM sessions would require a load-balanced farm of multiple dedicated PSM servers. CyberArk best practices dictate that the PSM and CPM should reside on separate servers in production to ensure scalability, security, and resource availability, as a single server cannot handle 500 concurrent sessions.

    Subdomain 1.1: Architecture and Implementation Concepts

    4.A global enterprise has data centers in the US and Europe. They want to manage passwords in both regions while minimizing cross-region latency and avoiding complex firewall rules for password management traffic. What is the recommended Central Policy Manager (CPM) architecture?

    1. A.Deploy a single CPM in the US and use the Privilege Cloud Secure Tunnel to route traffic to Europe.
    2. B.Deploy separate CPMs in each region and assign Safes to the CPMs based on geographic location.
    3. C.Use the Privileged Session Manager for SSH (PSMP) to proxy CPM traffic across regions.
    4. D.Enable CPM active-active clustering across the two regions to load balance the password changes.
    Show answer & explanation

    Correct answer: BDeploy separate CPMs in each region and assign Safes to the CPMs based on geographic location.

    • A. Deploying a single CPM in one region would force password management traffic for assets in the other region to traverse the WAN, increasing latency and creating an unnecessary dependency on cross-region connectivity. The Privilege Cloud Secure Tunnel is not the standard architectural mechanism for routing cross-region CPM management traffic in this context.
    • B. Deploying separate CPMs in each region keeps password management traffic local to the data center where the target systems reside. This minimizes latency and avoids the need for complex, broad cross-region firewall openings. Assigning Safes to specific regional CPMs is the CyberArk recommended practice for distributed global environments to ensure performance and reliability.
    • C. The Privileged Session Manager for SSH (PSMP) is designed for proxying and recording privileged SSH sessions. It is not used for handling CPM password rotation tasks or proxying CPM management traffic across regions.
    • D. CPM active-active clustering across high-latency regions is not a supported or recommended architecture. CPMs are typically deployed in a standalone or active-passive configuration. Cross-region clustering would introduce synchronization complexities and fail to address the goal of localizing management traffic.

    Subdomain 1.1: Architecture and Implementation Concepts

    5.An organization is deploying the PSM HTML5 Gateway to allow clientless access for external vendors. To ensure successful session establishment, which network traffic flow must be permitted through the internal firewalls?

    1. A.TCP 443 from the end-user workstation to the HTML5 Gateway, and TCP 3389 from the HTML5 Gateway to the PSM server.
    2. B.TCP 3389 from the end-user workstation directly to the PSM server.
    3. C.TCP 443 from the HTML5 Gateway directly to the target systems.
    4. D.TCP 1858 from the HTML5 Gateway to the Privilege Cloud Vault.
    Show answer & explanation

    Correct answer: ATCP 443 from the end-user workstation to the HTML5 Gateway, and TCP 3389 from the HTML5 Gateway to the PSM server.

    • A. In the PSM HTML5 Gateway architecture, end-users establish a secure session using a web browser via HTTPS (TCP 443). The gateway (based on Apache Guacamole) then translates this traffic into RDP and connects to the PSM server over TCP 3389. This allows for clientless access where the user does not need an RDP client on their local machine.
    • B. This traffic flow represents a standard PSM connection using a native RDP client. It bypasses the HTML5 Gateway entirely and is not the correct flow for clientless browser-based access.
    • C. The HTML5 Gateway does not initiate connections directly to the target systems. Its role is to bridge the web traffic to the PSM server, which then manages the connection to the final target.
    • D. TCP 1858 is the proprietary CyberArk Vault protocol port. While the PSM and other components must communicate with the Vault, the HTML5 Gateway communicates with the PSM and does not require a direct connection to the Vault.

    Subdomain 1.1: Architecture and Implementation Concepts

    6.When utilizing Privilege Cloud Account Discovery, what is the function of an 'Onboarding Rule'?

    1. A.To automatically provision discovered accounts into specific Safes and assign them to Platforms based on predefined criteria.
    2. B.To block unauthorized users from accessing the Discovery scan reports.
    3. C.To determine which network subnets the CPM scanner is allowed to probe.
    4. D.To automatically delete legacy accounts from target servers if they have not been used in 90 days.
    Show answer & explanation

    Correct answer: ATo automatically provision discovered accounts into specific Safes and assign them to Platforms based on predefined criteria.

    • A. Correct. Onboarding Rules define the criteria (such as account name, source, or type) used to automatically move discovered accounts from the Pending Accounts list into the Vault. This includes automatically assigning them to a specific Safe and a target Platform, which streamlines and automates the process of securing privileged accounts.
    • B. Incorrect. Access to discovery reports and scan results is managed through Privilege Cloud role-based access control (RBAC) and permissions, not through Onboarding Rules, which focus on the lifecycle of the accounts themselves.
    • C. Incorrect. The definition of network subnets, Active Directory organizational units, or specific IP ranges to be scanned is configured within the Discovery Scan or Source settings, not within the Onboarding Rules.
    • D. Incorrect. Onboarding Rules are used to bring accounts into the system for management. Deleting legacy or inactive accounts from target servers is a lifecycle cleanup task handled by administrative policies or manual intervention, not by discovery onboarding logic.

    Domain 2: Deployment

    Subdomain 2.1: Deployment

    7.Which tool is used to install the Connector Management Agent on a designated Windows server?

    1. A.The CyberArk Installer wizard (setup.exe) provided in the SFE.
    2. B.A PowerShell script generated and downloaded from the Connector Management portal.
    3. C.The Privilege Cloud Secure Tunnel installer executable.
    4. D.The CyberArk Identity Connector installation wizard.
    Show answer & explanation

    Correct answer: BA PowerShell script generated and downloaded from the Connector Management portal.

    • A. Incorrect. The CyberArk Installer wizard (setup.exe) provided in the SFE is typically used for on-premises installations of components like the Vault, CPM, and PSM, and is not the deployment method for the Connector Management Agent.
    • B. Correct. The Connector Management Agent is installed on a Windows server by running a PowerShell script that is uniquely generated and downloaded from the Connector Management portal. This script automates the download of necessary files, registers the agent with the tenant, and handles the installation.
    • C. Incorrect. The Privilege Cloud Secure Tunnel installer is a standalone executable specifically for creating a secure connection between the customer's on-premises network and the Privilege Cloud environment; it is distinct from the Connector Management Agent.
    • D. Incorrect. The CyberArk Identity Connector is a separate component used primarily for identity management and AD/LDAP integration. While it also uses a Windows installer, it is not the same as the Connector Management Agent used for PAM component management.

    Subdomain 2.1: Deployment

    8.How is a CPM component upgraded to a newer version in a Privilege Cloud environment utilizing the Connector Management service?

    1. A.By downloading the installer from the SFE and running setup.exe manually on the CPM server.
    2. B.By selecting the CPM component in the Connector Management portal and initiating the automated upgrade process.
    3. C.By running the Prerequisites.ps1 script with the -Upgrade flag.
    4. D.By submitting a support ticket to CyberArk to perform the upgrade on the backend.
    Show answer & explanation

    Correct answer: BBy selecting the CPM component in the Connector Management portal and initiating the automated upgrade process.

    • A. This describes a manual upgrade process typically used in on-premises (Self-Hosted) environments. In a Privilege Cloud environment utilizing Connector Management, lifecycle actions are handled through a centralized service rather than manual server-side installers.
    • B. In a Privilege Cloud environment that uses Connector Management, the CPM is upgraded through the Connector Management portal. The administrator selects the specific component and initiates an automated upgrade process, which is managed by the Connector Management agent installed on the server.
    • C. The Prerequisites.ps1 script is used for environmental validation and preparation, such as installing necessary Windows roles or features. It is not the tool used to execute the component upgrade in the Connector Management workflow.
    • D. While CyberArk manages the backend infrastructure, the upgrade of customer-side components (like the CPM on a Connector server) is a customer responsibility performed via the service interface, not through a support ticket.

    Subdomain 2.1: Deployment

    9.What is a primary prerequisite for deploying the Secure Infrastructure Access (SIA) connector on a designated host machine?

    1. A.The host must be a Windows Server 2022 machine joined to an Active Directory domain.
    2. B.The host must be a Linux machine with Docker installed and running.
    3. C.The host must have the Remote Desktop Session Host role installed.
    4. D.The host must have a direct, unauthenticated connection to the internet.
    Show answer & explanation

    Correct answer: BThe host must be a Linux machine with Docker installed and running.

    • A. Incorrect. The SIA connector deployment is not restricted to Windows Server 2022, nor does it require the host to be joined to an Active Directory domain. It is designed to run on specific supported Linux distributions.
    • B. Correct. The CyberArk Secure Infrastructure Access (SIA) connector is deployed as a containerized application. Therefore, a primary prerequisite is a supported Linux host with a container engine like Docker or Podman installed and running to provide the necessary runtime environment.
    • C. Incorrect. The Remote Desktop Session Host (RDSH) role is a Windows Server feature used for Remote Desktop Services (RDS). It is not a requirement for the Linux-based SIA connector.
    • D. Incorrect. While the connector requires outbound connectivity to the CyberArk Identity Security Platform, a direct and unauthenticated internet connection is not required and would violate security best practices. The connector can operate through proxies and firewalls using authenticated, encrypted outbound traffic.

    Subdomain 2.1: Deployment

    10.Where does an administrator navigate within the Privilege Cloud portal to set or reset the password for the installeruser account?

    1. A.Administration -> Configuration Options -> Options
    2. B.Policies -> Access Control -> Safes
    3. C.User Provisioning -> Users -> Search for 'installeruser' -> Update Password
    4. D.Identity Admin Portal -> Core Services -> Users
    Show answer & explanation

    Correct answer: CUser Provisioning -> Users -> Search for 'installeruser' -> Update Password

    • A. This path is used for configuring system-wide parameters, UI settings, and general platform options. It does not contain functionality for managing or resetting user account passwords.
    • B. This area is dedicated to managing Safe structures, defining access control lists, and setting permissions on vaulted objects. It is not the location for managing the credentials of the installeruser account.
    • C. In Privilege Cloud, the installeruser is a local vault account used for component registration. Its password is managed directly within the Privilege Cloud portal by navigating to User Provisioning -> Users, searching for the account, and selecting the option to update or reset the password.
    • D. The Identity Admin Portal is used for managing CyberArk Identity cloud directory users and core services. While Privilege Cloud is integrated with Identity, the specific installeruser local account is managed through the Privilege Cloud's internal user provisioning interface rather than the Identity portal.

    Subdomain 2.1: Deployment

    11.During the preparation of a Windows Server for the Privilege Cloud Connector, which PowerShell execution policy is typically required to successfully run the CyberArk prerequisite and installation scripts?

    1. A.Restricted
    2. B.AllSigned
    3. C.RemoteSigned or Unrestricted
    4. D.Default
    Show answer & explanation

    Correct answer: CRemoteSigned or Unrestricted

    • A. The 'Restricted' execution policy is the default on many Windows systems and prevents any PowerShell scripts from running, which would block the CyberArk prerequisite and installation scripts from executing.
    • B. The 'AllSigned' policy requires all scripts, including those created locally, to be signed by a trusted publisher. While more secure, it is often too restrictive for the deployment process and may block environment-specific or utility scripts used during the CyberArk installation.
    • C. The 'RemoteSigned' or 'Unrestricted' execution policies are typically required. 'RemoteSigned' allows locally created scripts to run without a signature and requires a digital signature for scripts downloaded from the internet, while 'Unrestricted' allows all scripts to run. These settings ensure that CyberArk's deployment and configuration scripts can execute successfully.
    • D. The 'Default' policy for Windows Server versions is usually 'Restricted,' which does not allow the execution of PowerShell scripts, thereby preventing the installation process.

    Subdomain 2.1: Deployment

    12.A customer is deploying the CyberArk Identity Connector to facilitate Active Directory authentication. To ensure high availability and fault tolerance for user logins, what is the CyberArk recommended approach?

    1. A.Install a single Identity Connector on a server with dual power supplies.
    2. B.Install at least two Identity Connectors on separate servers within the network.
    3. C.Configure the Identity Connector to replicate its database to the Privilege Cloud Vault.
    4. D.Deploy the Identity Connector in an Active/Passive Windows Server Failover Cluster.
    Show answer & explanation

    Correct answer: BInstall at least two Identity Connectors on separate servers within the network.

    • A. Incorrect. A single Identity Connector, even with hardware redundancy like dual power supplies, represents a single point of failure. Hardware redundancy does not provide the application-level availability or software fault tolerance needed for uninterrupted user authentication.
    • B. Correct. CyberArk's best practice for high availability and fault tolerance is to install at least two Identity Connectors on separate servers. This ensures that if one server or connector becomes unavailable, the remaining connector(s) can continue to handle Active Directory authentication requests.
    • C. Incorrect. The Identity Connector functions as a bridge between your network and the CyberArk cloud; it does not replicate a local database to the Privilege Cloud Vault for availability purposes.
    • D. Incorrect. Windows Server Failover Clustering (Active/Passive) is not the recommended deployment model for Identity Connectors. CyberArk recommends using multiple, independent connectors, which is simpler to manage and provides better resilience than a traditional cluster.

    Domain 3: Administrator Tasks

    Subdomain 3.1: Administrator Tasks

    13.Which component is responsible for sending email notifications to approvers when a user submits a Dual Control access request?

    1. A.The Vault Server (via ENE - Event Notification Engine)
    2. B.The Central Policy Manager (CPM)
    3. C.The Privileged Session Manager (PSM)
    4. D.The Password Vault Web Access (PVWA)
    Show answer & explanation

    Correct answer: AThe Vault Server (via ENE - Event Notification Engine)

    • A. Correct. The Event Notification Engine (ENE) is a Vault-side service responsible for sending email notifications regarding events that occur in the Vault, including Dual Control requests, password management activities, and audit alerts.
    • B. Incorrect. The Central Policy Manager (CPM) is responsible for password rotation and verification based on policy requirements, but it does not handle the email notification workflow for user access requests.
    • C. Incorrect. The Privileged Session Manager (PSM) facilitates secure remote access and records sessions; it is not involved in the administrative approval or notification workflow.
    • D. Incorrect. While the PVWA is the web interface where a user initiates a Dual Control request, the actual processing and delivery of the email notification to the approvers are handled by the Vault's Event Notification Engine (ENE).

    Subdomain 3.1: Administrator Tasks

    14.Which Master Policy rule dictates whether a privileged session initiated through PSM will be recorded?

    1. A.Require privileged session monitoring and isolation
    2. B.Record and save session activity
    3. C.Enforce check-in/check-out exclusive access
    4. D.Require dual control password access approval
    Show answer & explanation

    Correct answer: BRecord and save session activity

    • A. This rule enforces the use of PSM for session isolation and monitoring (ensuring the session goes through the PSM proxy), but it does not specifically dictate the recording component itself.
    • B. This is the specific Master Policy rule that directly controls whether session activity (such as video recordings and keystrokes) is captured and stored for auditing purposes. It is typically found as a sub-rule under 'Session Management'.
    • C. This rule manages credential lifecycle and concurrency by ensuring only one user can use an account at a time, which is unrelated to session recording functionality.
    • D. This rule mandates an approval workflow (Safe Members/Requestors/Approvers) before a credential can be accessed or a session initiated, but it does not govern recording.

    Subdomain 3.1: Administrator Tasks

    15.What is the maximum allowed length for a Safe name in the CyberArk Vault?

    1. A.28 characters
    2. B.50 characters
    3. C.64 characters
    4. D.128 characters
    Show answer & explanation

    Correct answer: A28 characters

    • A. Correct. According to CyberArk's naming conventions and technical specifications, a Safe name can contain up to 28 characters. This limit ensures compatibility across the Vault, the PrivateArk Client, and other integrated components.
    • B. Incorrect. While some metadata fields or newer API-driven platforms may use different limits, the standard Safe name limit in the CyberArk Vault is 28 characters, not 50.
    • C. Incorrect. 64 characters is not the limit for a Safe name in the CyberArk Vault; this value is often confused with password length limits or other configuration settings.
    • D. Incorrect. 128 characters is the maximum length allowed for the Name of an Account Object (the individual file representing an account inside a Safe), but the Safe name itself is restricted to 28 characters.

    Subdomain 3.1: Administrator Tasks

    16.A PAM administrator needs to migrate a custom platform from a development CyberArk environment to a production environment. What is the correct procedure to export the platform?

    1. A.Copy the platform's .ini file directly from the Vault's installation directory.
    2. B.Use the 'Export Platform' button in the PVWA Platform Management page to generate a .zip package.
    3. C.Export the PasswordManagerShared Safe using the PrivateArk Client.
    4. D.Run the PlatformExport.exe utility on the CPM server.
    Show answer & explanation

    Correct answer: BUse the 'Export Platform' button in the PVWA Platform Management page to generate a .zip package.

    • A. Copying the platform's .ini file manually from the Vault server's filesystem is not a supported or recommended method. Platforms are stored within the Vault's safes; manual file manipulation from the directory does not capture the full platform configuration or metadata required for a successful migration.
    • B. Using the 'Export Platform' button in the PVWA Platform Management page is the standard, supported procedure. This generates a .zip package containing all required configuration files and dependencies, ensuring a seamless and reliable migration to another environment.
    • C. While platform configurations are stored in the PasswordManagerShared safe, exporting the entire safe using the PrivateArk Client is not the intended mechanism for migrating individual platforms. The PVWA export tool is specifically designed for packaging individual platform definitions.
    • D. Running a 'PlatformExport.exe' utility is not a valid procedure as no such utility exists in the standard CyberArk toolset for the CPM server. Platform management is handled via the PVWA.

    Subdomain 3.1: Administrator Tasks

    17.An administrator wants to automatically onboard discovered local administrator accounts from Windows servers into specific Safes based on the operating system version. How should this be implemented?

    1. A.Create an Account Discovery Onboarding Rule with conditions matching the OS version and the target Safe.
    2. B.Modify the dbparm.ini file to map OS versions to Safes.
    3. C.Write a custom CPM plugin to move accounts after they are onboarded.
    4. D.Configure the Master Policy to route accounts based on the Discovery scan results.
    Show answer & explanation

    Correct answer: ACreate an Account Discovery Onboarding Rule with conditions matching the OS version and the target Safe.

    • A. Correct. Account Discovery Onboarding Rules are the built-in mechanism designed to automate the onboarding process. These rules allow administrators to define specific conditions—such as the operating system version, machine naming conventions, or account names—to automatically assign discovered accounts to designated target Safes.
    • B. Incorrect. The dbparm.ini file is used for configuration parameters of the CyberArk Vault itself (e.g., network settings, database locations, and logging). It has no role in the logic of account discovery or mapping OS versions to Safes.
    • C. Incorrect. CPM (Central Policy Manager) plugins are used for managing passwords (change, verify, reconcile) on target systems. They are not used for the onboarding process or for moving accounts between Safes based on discovery metadata.
    • D. Incorrect. The Master Policy defines global security and compliance settings, such as password complexity requirements and rotation schedules. It does not provide functionality for routing or onboarding discovered accounts.

    Subdomain 3.1: Administrator Tasks

    18.In CyberArk Privilege Cloud, an administrator wants to group multiple Windows Server platforms under a single access policy so that a specific team can access all of them. What is the recommended approach?

    1. A.Create a single Safe, store all the Windows accounts in it, and assign the team's Role to that Safe.
    2. B.Merge all the Windows platforms into a single master platform.
    3. C.Assign the team's Role directly to the Master Policy.
    4. D.Configure a custom Onboarding Rule to bypass Safe permissions.
    Show answer & explanation

    Correct answer: ACreate a single Safe, store all the Windows accounts in it, and assign the team's Role to that Safe.

    • A. Correct. In the CyberArk security model, Safes are the fundamental unit of authorization. By placing accounts—regardless of their associated platforms—into a specific Safe and assigning a team's Role or Group to that Safe, you centralize access control and apply a consistent access policy for that team.
    • B. Incorrect. Platforms are templates that define management behavior (such as CPM rotation cycles and PSM connection settings), not access control boundaries. Merging platforms is not a standard practice for managing user permissions.
    • C. Incorrect. The Master Policy defines global organization-wide security settings (e.g., password complexity, dual control requirements). It is not used to grant specific teams access to individual accounts or platforms.
    • D. Incorrect. Onboarding rules are used to automate the discovery and placement of accounts into Safes. They do not bypass the Safe permission model, which remains the mandatory enforcement point for access.

    Domain 4: End User Tasks

    Subdomain 4.1: End User Tasks

    19.Which of the following methods can an end-user utilize to provide a required reason or ticket ID when connecting natively through PSM for SSH?(Select 2)

    1. A.Appending the reason/ticket to the SSH connection string.
    2. B.Entering the reason/ticket interactively when prompted by the PSMP server.
    3. C.Modifying the local SSH config file to include a Reason parameter.
    4. D.Sending the reason via a REST API call prior to connection.
    5. E.Emailing the reason to the PSMP service account.
    Show answer & explanation

    Correct answers: A, BAppending the reason/ticket to the SSH connection string.; Entering the reason/ticket interactively when prompted by the PSMP server.

    • A. Appending the reason or ticket to the SSH connection string is a valid method for native PSM for SSH (PSMP) connections. Depending on the configured syntax (often using symbols like '#' or '%'), users can include the necessary justification directly within the connection command.
    • B. PSM for SSH can be configured to interactively prompt the user for a reason or ticket ID if it is not provided in the connection string. This interactive prompt occurs after authentication but before the session is established to ensure compliance with Master Policy requirements.
    • C. The local SSH configuration file (~/.ssh/config) is a client-side tool used for connection shortcuts and parameters. It does not support a 'Reason' parameter that is natively recognized or processed by the CyberArk PSM for SSH gateway.
    • D. While CyberArk provides REST APIs for various administrative and integration tasks, the native PSM for SSH (PSMP) workflow does not utilize external API calls from the end-user to provide session justification prior to connection.
    • E. Emailing a service account is not an integrated or supported method for satisfying session justification requirements in CyberArk. Justification must be provided within the connection workflow itself.

    Subdomain 4.1: End User Tasks

    20.An end-user submits a request to access a highly privileged account, which requires Dual Control. The manager approves the request. However, when the user attempts to retrieve the password, the 'Show' and 'Copy' buttons are still disabled. What is the most likely cause?

    1. A.The user is attempting to access the account outside of the requested timeframe.
    2. B.The manager did not provide a comment during the approval process.
    3. C.The user's session timed out and they need to re-authenticate.
    4. D.The account is currently checked out by the manager who approved it.
    Show answer & explanation

    Correct answer: AThe user is attempting to access the account outside of the requested timeframe.

    • A. Correct. In a Dual Control workflow, users must specify a timeframe for their access request. Even if the request is approved by a manager, the 'Show', 'Copy', and 'Connect' buttons will only be enabled during the specific time window that was requested and approved.
    • B. Incorrect. While a manager may be required to provide a reason for approval for auditing purposes, the lack of a comment would prevent the approval from being finalized in the system rather than disabling the retrieval buttons after approval.
    • C. Incorrect. A session timeout would force the user to log back into the PVWA (PrivateArk Web Access). It would not specifically result in the retrieval buttons being disabled for an approved request.
    • D. Incorrect. While an account being checked out (Exclusive Access) would prevent another user from using it, the system would typically display a 'Locked by' status. In the context of Dual Control, the most common reason for buttons remaining disabled after approval is that the current time is outside the requested access window.

    Subdomain 4.1: End User Tasks

    21.When an end-user attempts to retrieve a password for an account that requires ticketing system integration, what happens if the user enters a ticket number that does not exist or is closed in the ITSM tool (assuming strict validation is enabled)?

    1. A.The PVWA denies the retrieval request and displays an error message.
    2. B.The PVWA allows the retrieval but flags the session as high risk in PTA.
    3. C.The PVWA prompts the user to create a new ticket interactively.
    4. D.The PVWA bypasses the ticket check and relies on Dual Control instead.
    Show answer & explanation

    Correct answer: AThe PVWA denies the retrieval request and displays an error message.

    • A. Correct. When strict ticket validation is enabled, the PVWA communicates with the integrated ITSM system (such as ServiceNow or BMC Remedy) to verify the status of the provided ticket. If the ticket number is invalid, non-existent, or closed, the PVWA denies the retrieval request and displays an error message, ensuring that access is only granted for authorized and active changes.
    • B. Incorrect. Ticket validation serves as a mandatory gatekeeper. If the validation fails under strict settings, the request is blocked entirely; the PVWA does not allow the retrieval and then rely on PTA (Privileged Threat Analytics) for risk flagging.
    • C. Incorrect. The PVWA does not provide an interactive interface to create tickets within the ITSM system. The user must provide a valid, pre-existing ticket number that satisfies the validation criteria.
    • D. Incorrect. Ticketing system integration and Dual Control are independent security features. Strict ticketing validation is a mandatory requirement if configured and is not bypassed or replaced by Dual Control approvals.

    Subdomain 4.1: End User Tasks

    22.What is a prerequisite for an end-user to successfully use the CyberArk Mobile app for offline password retrieval during a Privilege Cloud outage?

    1. A.The user must have previously authenticated to the app and synced the accounts while online.
    2. B.The user must have a physical smart card inserted into their mobile device.
    3. C.The user must be connected to the corporate VPN.
    4. D.The user must have local administrator rights on the target server.
    Show answer & explanation

    Correct answer: AThe user must have previously authenticated to the app and synced the accounts while online.

    • A. To use the CyberArk Mobile app for offline access (typically for Business Continuity during a Privilege Cloud outage), the app must have cached the necessary account data. This requires the user to have successfully authenticated and performed a synchronization of their accounts while a network connection was active prior to the outage.
    • B. A physical smart card is not a requirement for the CyberArk Mobile app's offline functionality. The app typically utilizes mobile-native security features, such as biometrics or PINs, to secure the locally cached data.
    • C. Connectivity, including a corporate VPN, is exactly what is unavailable or bypassed during an outage or when using offline mode. The purpose of offline retrieval is to provide access when a connection to the Privilege Cloud service cannot be established.
    • D. Offline password retrieval is a function of the CyberArk vaulting system and the mobile app's cache; it does not depend on the user's permissions on the target server itself, but rather their permissions within the CyberArk Vault to access that specific account.

    Subdomain 4.1: End User Tasks

    23.True or False: If Privilege Cloud is completely unavailable, end-users can bypass the Vault and use their personal Active Directory credentials to log directly into target servers managed by exclusive, vaulted accounts.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. The statement is false because CyberArk is designed to centralize and control access to privileged accounts. If Privilege Cloud is unavailable, users do not have an inherent 'bypass' to use personal Active Directory credentials to access targets managed by exclusive accounts; such access would circumvent the security, rotation, and auditing policies mandated by the Vault.
    • B. The statement is false because exclusive, vaulted accounts are intended to be used through CyberArk controls to ensure security and accountability. In the event of an outage, standard users cannot bypass the Vault workflow using personal credentials. Organizations typically rely on emergency 'break-glass' procedures rather than a bypass to personal AD identities to maintain access to target servers.

    Domain 5: Developer Tasks

    Subdomain 5.1: Developer Tasks

    24.When using the Plugin Generator Utility (PGU) to create a connector for a Windows-based thick client, what are the primary output files generated?

    1. A.A Python script (.py) and a JSON configuration file.
    2. B.An AutoIt script (.au3) and a Connection Component XML file.
    3. C.A PowerShell script (.ps1) and a YAML file.
    4. D.A compiled executable (.exe) and a DLL file.
    Show answer & explanation

    Correct answer: BAn AutoIt script (.au3) and a Connection Component XML file.

    • A. Incorrect. The Plugin Generator Utility (PGU) for Windows-based thick clients does not generate Python scripts or JSON configuration files. These are not standard output formats for PGU-based thick client connectors.
    • B. Correct. For Windows-based thick clients, the PGU records user actions and generates an AutoIt script (.au3) containing the automation logic. It also produces a Connection Component XML file, which is used to define the component's properties and import them into the CyberArk environment.
    • C. Incorrect. PowerShell scripts and YAML files are not the primary outputs of the PGU for thick-client connector creation. CyberArk relies on AutoIt for UI-based automation in this context.
    • D. Incorrect. The PGU generates source scripts and configuration metadata (XML), not compiled binary executables (.exe) or library files (.dll).

    Subdomain 5.1: Developer Tasks

    25.In the Plugin Generator Utility (PGU), what is the purpose of the 'Test' functionality after recording a Web application?

    1. A.It sends a test password change request to the target application.
    2. B.It uploads the generated files to the Vault's PSMUnmanagedSessionAccounts safe.
    3. C.It executes the generated XML configuration locally using the PSM Web Dispatcher engine to verify the login flow before uploading to the PVWA.
    4. D.It compiles the AutoIt script into a standalone executable.
    Show answer & explanation

    Correct answer: CIt executes the generated XML configuration locally using the PSM Web Dispatcher engine to verify the login flow before uploading to the PVWA.

    • A. Incorrect. The Test functionality in the PGU is focused on validating the recorded session flow (connection), not on performing CPM-related tasks like initiating a password change request against the target application.
    • B. Incorrect. Uploading files to a Vault safe is a deployment or publishing step. The 'Test' feature is specifically designed to validate the recording's accuracy and functionality before any files are uploaded to the Vault or PVWA.
    • C. Correct. The 'Test' functionality allows developers to run the generated XML configuration locally using the same PSM Web Dispatcher engine that will be used in production. This ensures the recorded login, navigation, and logout steps work as intended before the plugin is distributed.
    • D. Incorrect. The PGU for Web applications generates XML configurations and uses a specialized web dispatcher engine; it does not compile AutoIt scripts into standalone executables as part of the test verification process.

    Subdomain 5.1: Developer Tasks

    26.In a CPM SSH plugin utilizing the Terminal Plugin Controller (TPC), what is the primary function of the prompts.ini file?

    1. A.To define the sequence of commands sent to the target system.
    2. B.To store the credentials used for the connection.
    3. C.To define regular expressions that match expected terminal outputs, such as login prompts or error messages.
    4. D.To configure the network timeout settings for the SSH connection.
    Show answer & explanation

    Correct answer: CTo define regular expressions that match expected terminal outputs, such as login prompts or error messages.

    • A. Incorrect. The sequence of commands sent to the target system is typically defined in the process.ini file or the specific plugin logic script, which dictates the flow of execution.
    • B. Incorrect. Credentials used for connection are stored securely within the CyberArk Vault and are passed to the plugin at runtime; they are not stored in the prompts.ini file.
    • C. Correct. In a TPC-based SSH plugin, the prompts.ini file is used to define the regular expressions that identify expected terminal responses (e.g., 'Password:', 'Username:', or 'Access Denied'). This allows the CPM to recognize the current state of the terminal session and respond with the appropriate data.
    • D. Incorrect. Network timeout settings and other connection-level parameters are generally configured within the platform settings or parameters in the process.ini file, rather than the prompts.ini file.

    Subdomain 5.1: Developer Tasks

    27.A CPM verify operation fails because the target server displays a custom legal banner requiring the user to press 'Y' before the login prompt appears. How should the developer resolve this?

    1. A.Disable the legal banner on the target server, as CPM cannot handle interactive banners.
    2. B.Add a new state in process.ini to handle the banner, map it to a prompt in prompts.ini, and send 'Y' as the command.
    3. C.Increase the Timeout parameter in the platform settings.
    4. D.Change the Protocol parameter to Telnet.
    Show answer & explanation

    Correct answer: BAdd a new state in process.ini to handle the banner, map it to a prompt in prompts.ini, and send 'Y' as the command.

    • A. Disabling the legal banner is generally not an acceptable solution because banners are often mandated by security or compliance policies. Furthermore, CPM is fully capable of handling interactive prompts by modifying its configuration files, so disabling the banner is unnecessary.
    • B. The standard way to handle custom prompts in CyberArk CPM terminal-based plugins (like PMTerminal or TPC) is to update the configuration files. By defining the banner's text as a new prompt in prompts.ini and adding a corresponding state in process.ini to send 'Y', the CPM can automate the interaction and proceed to the login phase.
    • C. Increasing the Timeout parameter only extends the duration the CPM waits for a recognizable prompt. Because the CPM does not recognize the banner as a valid state, it will eventually time out regardless of how long the limit is set.
    • D. Changing the protocol to Telnet does not solve the logic issue of the interactive banner. Prompt handling occurs at a layer above the protocol, and switching to Telnet would also compromise security without addressing the root cause.

    Subdomain 5.1: Developer Tasks

    28.Which of the following are standard operational sections found within a CPM process.ini file?(Select 3)

    1. A.[Logon]
    2. B.[Change]
    3. C.[Reconcile]
    4. D.[Audit]
    5. E.[Report]
    Show answer & explanation

    Correct answers: A, B, C[Logon]; [Change]; [Reconcile]

    • A. Correct. The [Logon] section is a standard operational section in a CPM process.ini file used to define the sequence of commands and parameters required to authenticate to a target system before performing password management tasks.
    • B. Correct. The [Change] section is a core operational section that specifies the commands and logic needed to change a password on the target system during a regular rotation cycle.
    • C. Correct. The [Reconcile] section is a standard operational section used to configure the workflow for password reconciliation, defining how the CPM resets credentials when the current password is unknown or out of sync.
    • D. Incorrect. The [Audit] section is not a standard operational section in a CPM process.ini file. Auditing and activity logging are handled by the CPM engine and stored in the Vault's activity logs or local CPM log files.
    • E. Incorrect. The [Report] section is not a standard operational section in a CPM process.ini file. Reporting functionality is managed through the PVWA or PrivateArk Client rather than the process logic file.

    Subdomain 5.1: Developer Tasks

    29.How does the Terminal Plugin Controller (TPC) handle a situation where multiple prompts defined in a state's expected prompts list match the current terminal output?

    1. A.It throws an 'Ambiguous Prompt' error and terminates the plugin.
    2. B.It evaluates them in the order they are listed in the state definition and triggers the transition for the first match.
    3. C.It prompts the PVWA user to manually select the correct prompt.
    4. D.It randomly selects one of the matching prompts.
    Show answer & explanation

    Correct answer: BIt evaluates them in the order they are listed in the state definition and triggers the transition for the first match.

    • A. TPC does not terminate with an 'Ambiguous Prompt' error. It is designed with a deterministic matching logic to handle the output stream efficiently.
    • B. The Terminal Plugin Controller (TPC) processes expected prompts sequentially. When the terminal output matches multiple defined prompts, TPC triggers the transition for the first one listed in the state definition. This ensures predictable and deterministic behavior during plugin execution.
    • C. TPC operates as part of the CPM (Central Policy Manager) background processes. It does not provide an interactive interface for PVWA users to resolve prompt matches manually during runtime.
    • D. Random selection would result in non-deterministic and unreliable plugin behavior. TPC follows a top-down evaluation order to ensure consistency across different executions.

    Domain 6: Auditor Tasks

    Subdomain 6.1: Auditor Tasks

    30.Which permission is strictly required on a Safe for an Auditor to view the text-based audit logs of password retrievals, but NOT necessarily the video recordings?

    1. A.List accounts
    2. B.View Audit
    3. C.Use accounts
    4. D.Retrieve accounts
    Show answer & explanation

    Correct answer: BView Audit

    • A. Incorrect. The 'List accounts' permission allows a user to see the accounts that exist within a Safe, but it does not grant access to the activity logs or audit trail information.
    • B. Correct. The 'View Audit' permission is the specific Safe-level permission required to view text-based audit records and activities, such as password retrieval events. While video recordings (PSM sessions) are also part of the audit process, they often require additional permissions on the Recordings safe, making 'View Audit' the base requirement for text-based logs.
    • C. Incorrect. 'Use accounts' allows a user to connect to target systems via the PSM without seeing the password. It does not provide any visibility into the audit logs or the actions of other users.
    • D. Incorrect. 'Retrieve accounts' allows a user to view or copy the clear-text password from the Vault. While an auditor might perform retrievals, this permission is for accessing the secret itself, not for reviewing the audit trail.

    Subdomain 6.1: Auditor Tasks

    31.An auditor needs to find a specific session where a user executed the `rm -rf /var/log` command. How can the auditor locate this exact moment without watching all videos in their entirety?

    1. A.Download the video and use a third-party OCR tool to scan the frames.
    2. B.Use the Search function in the Monitoring page to query the keystroke logger data, then click the event to jump to the timestamp.
    3. C.Request the Vault Admin to extract the SQL database tables containing the video metadata.
    4. D.Play the video in the PVWA and use the fast-forward feature at 8x speed.
    Show answer & explanation

    Correct answer: BUse the Search function in the Monitoring page to query the keystroke logger data, then click the event to jump to the timestamp.

    • A. Downloading the video and using external OCR tools is not a standard or supported CyberArk workflow. PSM provides built-in searchable event logs, making third-party manual analysis unnecessary and potentially insecure.
    • B. The Monitoring page in the PVWA allows auditors to search through captured keystrokes and session events. When a specific command is found in the search results, clicking on it will automatically navigate the integrated session player to the exact timestamp of that action, enabling efficient auditing without manual video scrubbing.
    • C. Auditors access audit data through the PVWA interface. Requesting direct SQL database extracts from the Vault is an overly complex, non-standard, and unnecessary procedure that introduces security risks.
    • D. While the PVWA player includes a fast-forward feature, it is an inefficient and manual way to find specific commands. It does not utilize the searchable metadata index that CyberArk provides specifically to avoid manual video review.

    Subdomain 6.1: Auditor Tasks

    32.When an auditor shares a link to a recorded session from the PVWA, what authentication is required for the recipient to view it?

    1. A.No authentication is required; the link is publicly accessible.
    2. B.The recipient must authenticate to the PVWA and have the necessary Safe permissions for the account used in the session.
    3. C.The recipient must provide a one-time password sent via email.
    4. D.The recipient must authenticate using a special 'Auditor' local Vault account.
    Show answer & explanation

    Correct answer: BThe recipient must authenticate to the PVWA and have the necessary Safe permissions for the account used in the session.

    • A. Incorrect. Recorded session links from PVWA are not publicly accessible and contain sensitive audit data. Access is strictly controlled and requires valid CyberArk authentication.
    • B. Correct. Sharing a link to a recording does not bypass security. The recipient must authenticate to the PVWA and must have the appropriate Safe permissions (such as View Audit/View Session Recordings) on the Safe where the recording resides to view the content.
    • C. Incorrect. CyberArk does not utilize a one-time password (OTP) sent via email for the purpose of accessing shared recording links. Standard PVWA authentication methods are used.
    • D. Incorrect. While auditors are often part of a specific group, there is no requirement to use a specific local Vault account named 'Auditor'. Any authorized user with the correct permissions can view the session.

    Subdomain 6.1: Auditor Tasks

    33.A compliance mandate requires that all audit logs be kept for 7 years, but video recordings should only be kept for 90 days to save storage. How should the auditor verify this configuration?

    1. A.Check the dbparm.ini file for the AuditRetention and VideoRetention parameters.
    2. B.Check the Safe properties: 'Save account activity' should be 2555 days, and the recording Safe's 'Save object history' should be 90 days.
    3. C.Check the PVWA Options menu for the GlobalRetention settings.
    4. D.Check the PSM basic_psm.ini file for the RecordingRetention parameter.
    Show answer & explanation

    Correct answer: BCheck the Safe properties: 'Save account activity' should be 2555 days, and the recording Safe's 'Save object history' should be 90 days.

    • A. The dbparm.ini file is used for low-level Vault database configuration. It does not contain specific 'AuditRetention' or 'VideoRetention' parameters for individual compliance requirements; these are managed at the Safe level.
    • B. In CyberArk, data retention is managed via Safe properties. 'Save account activity' defines how long audit logs are preserved (7 years equals 2555 days). For video recordings, which are stored as objects in the Recording Safes, the 'Save object history' property defines their retention (90 days as per the requirement).
    • C. The PVWA Options menu contains global settings for the web interface and platform behavior, but it is not the authoritative location for verifying data retention periods for audits and session recordings.
    • D. The basic_psm.ini file contains local configuration for the PSM server component. It does not control or store the retention policy for recordings once they are stored in the Vault.

    Subdomain 6.1: Auditor Tasks

    34.When a session is terminated by an auditor via the PVWA, what happens to the recording of that session?

    1. A.The recording is immediately deleted to protect user privacy.
    2. B.The recording is finalized up to the point of termination and uploaded to the Vault.
    3. C.The recording is saved locally on the PSM server but not uploaded to the Vault.
    4. D.The recording is sent via email to the Vault Admin.
    Show answer & explanation

    Correct answer: BThe recording is finalized up to the point of termination and uploaded to the Vault.

    • A. Terminating a session does not result in the deletion of the audit trail. CyberArk is designed for compliance and forensic accountability, so session recordings are preserved rather than removed.
    • B. When an auditor terminates a live session through the PVWA, the Privileged Session Manager (PSM) finalizes the video and/or keystroke recording up to the exact moment of termination. This file is then automatically uploaded to the PSMRecordings safe in the Vault to ensure the audit trail remains complete and available for later review.
    • C. While recordings are temporarily cached on the PSM server during an active session, CyberArk's standard workflow ensures they are uploaded to the Vault upon termination for secure, centralized storage and retention.
    • D. Session recordings are binary files stored securely within the Vault and accessed via the PVWA interface. They are not sent via email due to security protocols and the potential size of the media files.

    Subdomain 6.1: Auditor Tasks

    35.Auditors with only the 'View Audit' Safe permission can automatically terminate any active session they are monitoring without requiring additional permissions.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. The statement is false because the 'View Audit' Safe permission is limited to viewing audit records and logs; it does not provide the active session control required to terminate or suspend a live connection.
    • B. The statement is false because terminating a session is a privileged action that requires specific management rights, such as 'Monitor Sessions' or 'Manage Safe', depending on the configuration, and is distinct from simple audit viewing permissions.

    Want the full experience?

    These are just samples. Practice the full CyberArk Sentry Certification – Modern PAM question bank in quiz mode — free, no signup, with domain practice and exam simulation.