Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

CyberArk PAM-SEN CyberArk Sentry PAM Exam Practice Test

Demo: 40 questions
Total 136 questions

CyberArk Sentry PAM Questions and Answers

Question 1

What is determined by the "MaxConcurrentConnections" setting within a platform?

Options:

A.

maximum number of concurrent connections that can be opened between the CPM and the remote machines for the platform

B.

maximum number of concurrent connections that can be between the PSM and the remote machines for the platform

C.

maximum number of concurrent connections allowed for a specific account on the platform through the PSM

D.

maximum number of concurrent connections to the Vault allowed for sending audit activities relating to the platform

Question 2

Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? Choose all that apply

Options:

A.

Store the CD in a physical safe and mount the CD every time vault maintenance is performed.

B.

Copy the contents of the CD to the System Safe on the vault

C.

Copy the contents of the CD to a folder on the vault server and secure it with NTFS permissions.

D.

Store the server key in a Hardware Security Module.

E.

Store the server key in the Provider cache

Question 3

Which components support load balancing? (Choose two.)

Options:

A.

CPM

B.

PVWA

C.

PSM

D.

PTA

E.

EPV

Question 4

Which user is enabled when replicating data between active and stand-by Vaults?

Options:

A.

DR

B.

Backup

C.

Operator

D.

Auditor

Question 5

Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After setting the Authentication to SSH key and enabling MFA Caching from the PVWA interface, the Linux Team cannot connect successfully using the new MFA caching feature.

What is the most probable cause?

Options:

A.

OpenSSH 7.8 or above is not installed.

B.

The MFACaching parameter in the psmpparms file is not set to True.

C.

A passphrase policy must be added.

D.

MFA caching is not supported when the PSM for SSH is deployed with default settings.

Question 6

If a transparent user matches two different directory mappings, how does the system determine which user template to use?

Options:

A.

The system will use the template for the mapping listed first.

B.

The system will use the template for the mapping listed last.

C.

The system will grant all of the vault authorizations from the two templates.

D.

The system will grant only the vault authorizations that are listed in both templates

Question 7

You are installing the HTML5 gateway on a Linux host using the RPM provided.

After installing the Tomcat webapp, what is the next step in the installation process?

Options:

A.

Deploy the HTML5 service (guacd). Most Voted

B.

Secure the connection between the guacd and the webapp.

C.

Secure the webapp and JWT validation endpoint.

D.

Configure ASLR.

Question 8

When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?

Options:

A.

5 - number of primary and satellite Vaults can be specified during installation

B.

3 - all primary

C.

6 - 1 primary and 5 satellite

D.

10 - 2 primary and 8 satellite

Question 9

What is the default username for the PSM for SSH maintenance user when InstallCyberarkSSHD is set to yes?

Options:

A.

proxymng

B.

psmp_maintenance

C.

psmpmaintenanceuser

D.

psmpmnguser

Question 10

For redundancy, you want to add a secondary RADIUS server.

What must you do to accomplish this?

Options:

A.

Add to the application settings of the PVWA web.config file.

B.

In the PVWA vault.ini file, list each RADIUS server host address in the "Addresses" attribute separated by commas.

C.

Open the DBParm.ini on the Vault server. Add the second RADIUS server configuration settings after the first one, separated by a comma. Most Voted

D.

In the PVWA web.config file, add the location element at the end of the config file. Set the path value to "Default Web Site/PasswordVault/api/auth/pkipn/logon".

Question 11

The RemoteApp feature of PSM allows seamless Application windows (i e the Desktop of the PSM server will not be visible)

Options:

A.

TRUE

B.

FALSE

Question 12

Name two ways of viewing the ITAlog

Options:

A.

Log into the vault locally and navigate to the Server folder under the PrivateArk install location.

B.

Log into the PVWA and go to the Reports tab.

C.

Access the System Safe from the PrivateArk client.

D.

Go to the Thirdpary log directory on the CPM

Question 13

In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?

Options:

A.

PARAgent.ini

B.

DBParm.ini

C.

TSParm.ini

D.

CyberArkv2 MIB file

Question 14

A stand alone Vault server requires DNS services to operate properly.

Options:

A.

TRUE

B.

FALSE

Question 15

Does CyberArk need service accounts on each server to change passwords?

Options:

A.

Yes. it requires a domain administrator account to change any password on any server.

B.

Yes. it requires a local administrator account on any Windows server and a root level account on any Unix server.

C.

No. passwords are changed by the Password Provider Agent.

D.

No. the CPM uses the account information stored in the vault to login and change the account's password using its own credentials

Question 16

What are the basic network requirements to deploy a CPM server?

Options:

A.

Port 1858 to Vault and Port 443 to PVWA

B.

Port 1858 only

C.

all ports to the Vault

D.

Port UDP/1858 to Vault and all required ports to targets and Port 389 to the PSM

Question 17

Which CyberArk component changes passwords on Target Devices?

Options:

A.

Vault

B.

CPM

C.

PVWA

D.

PSM

E.

PrivateArk

F.

OPM

G.

AIM

Question 18

What must you do to prepare a Windows server for PVWA installation?

Options:

A.

In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell. Most Voted

B.

Install the PrivateArk client.

C.

Verify the user performing the installation is Domain Administrator and has logon access to the Vault server.

D.

Enable IPv6.

Question 19

Which step is required to register a Vault manually in Amazon Web Services using CAVaultManager?

Options:

A.

Specify Amazon as the cloud vendor using the /CloudVendor Flag

B.

After running the postinstall utility, restart the "PrivateArk Server" service

C.

Specify the Cloud region using the /CloudRegion flag

D.

Specify whether the Vault is distributed or stand alone

Question 20

A customer asked you to help scope the company's PSM deployment.

What should be included in the scoping conversation?

Options:

A.

Recordings file path

B.

Recordings codec

C.

Recordings retention period

D.

Recordings file type

Question 21

All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The current PAM solution is:

2 distributed Vaults, the primary one in New York and a satellite in Tokyo

2 PVWA servers, both in New York with load balancing configured

2 PSM servers, both in New York without load balancing configured

1 CPM server in New York

All PVWA, PSM, and CPM servers are connected to the primary Vault

Which proposal optimally resolves the performance issue while minimizing the impact to production?

Options:

A.

Install two new PVWA servers in Tokyo data center, configure load balancing, connect to the local satellite Vault and provide the URL of new PVWA servers to the local employees.

B.

Install two new PVWA servers in New York data center, configure load balancing and have them connect to the satellite Vault in Tokyo.

C.

Install two new PSM servers in the Tokyo data center, configure load balancing, connect to the local satellite vault, and inform the local employees to browse using the same PVWA URL.

D.

Change the current distributed Vaults architecture, migrate back to a Primary-DR architecture, install two new PVWA servers in the Tokyo data center and configure load balancing. Connect to the local DR Vault and provide the URL of new PVWA servers to the local employees.

Question 22

Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation?

Options:

A.

255.255.255.255

B.

8.8.8.8

C.

192.168.1.1

D.

1.1.1.1

Question 23

Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?

Options:

A.

dbparm ini

B.

paragent.ini

C.

ENEConf.ini I

D.

padr ini

Question 24

Which tools are used during a CPM renaming process? (Choose two.)

Options:

A.

APIKeyManager Utility Most Voted

B.

CreateCredFile Utility Most Voted

C.

CPMInDomain_Hardening.ps1

D.

PMTerminal.exe

E.

Data Execution Prevention

Question 25

What is a step to enable NTP synchronization on a stand-alone Vault?

Options:

A.

Run Powershell and add the NTP module.

B.

Restart the organization's NTP servers.

C.

Edit dbparm.ini and add a Firewall rule for the NTP address.

D.

Restart the Vault Event Notification Engine service.

Question 26

Which of the following are supported authentication methods for CyberArk? Check all that apply

Options:

A.

CyberArk Password (SRP)

B.

LDAP

C.

SAML

D.

PKI

E.

RADIUS

F.

OracleSSO

G.

Biometric

Question 27

If a customer has one data center and requires fault tolerance, how many PVWAs should be deployed?

Options:

A.

two or more

B.

one PVWA cluster

C.

one

D.

two PVWA clusters

Question 28

Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?

Options:

A.

IdP “EntityID” and “PartnerIdentityProvider Name” in PVWA saml.config file

B.

IdP “User name” and “SingleSignOnServiceUrl” in PVWA saml.config file

C.

IdP “Audience” and “ServiceProviderName” in the PVWA saml.config file

D.

IdP “Secure hash algorithm” and “Certificate” in the PVWA saml.config file

Question 29

What must you do to synchronize a new Vault server with an organization’s NTP server?

Options:

A.

Configure an AllowNonStandardFWAddresses rule for the organization’s NTP server in DBParm.ini on the Vault server.

B.

Use the Windows Firewall console to configure a rule on the Vault server which allows communication with the organization’s NTP server.

C.

Ensure the organization’s NTP server is installed in the same location as the Vault server requiring synchronization.

D.

Update the AutoSyncExternalObjects configuration in DBParm.ini on the Vault server to schedule regular synchronization.

Question 30

You want to change the name of the PVWAappuser of the second PVWA server.

Which steps are part of the process? (Choose two.)

Options:

A.

Update PVWA.ini with new user name

B.

Update Vault.ini with new user name

C.

Create new user in PrivateArk

D.

Rename user in PrivateArk

E.

Create new cred file for user

Question 31

When SAML authentication is used to sign in to the PVWA, which service performs the actual authentication?

Options:

A.

Active Directory (AD)

B.

Identity Provider (IdP) Most Voted

C.

Service Provider (SP)

D.

CyberArk Password Vault Web Access (PVWA)

Question 32

When a DR vault server becomes an active vault, it will automatically fail back to the original state once the primary vault comes back online.

Options:

A.

True, this is the default behavior

B.

False, this is not possible

C.

True, if the 'AllowFailback' setting is set to yes in the PADR.ini file.

D.

True if the 'AllowFailback' setting is set to yes in the dbparm mi file

Question 33

A customer has two data centers and requires a single PVWA url.

Which deployment provides the fastest time to reach the PVWA and the most redundancy?

Options:

A.

Deploy two PVWAs behind a global traffic manager.

B.

Deploy one PVWA only.

C.

Deploy two PVWAs in an active/standby mode.

D.

Deploy two PVWAs using DNS round robin.

Question 34

Which parameter must be provided when registering a primary Vault in Azure, but not in Amazon Web Services?

Options:

A.

/RecPub

B.

/AdminPass

C.

/MasterPass

D.

/RDPGateway

Question 35

As Vault Admin, you have been asked to enable your organization's CyberArk users to authenticate using LDAP.

In addition to Audit Users, which permission do you need to complete this task?

Options:

A.

Add Network Areas

B.

Manage Directory Mapping

C.

Add/Update Users

D.

Activate Users

Question 36

In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?

Options:

A.

retention period

B.

number of PSMs

C.

number of users

D.

number of targets

Question 37

The account used to install a PVWA must have ownership of which safes? (Choose two.)

Options:

A.

VaultInternal

B.

PVWAConfig

C.

System

D.

Notification Engine

E.

PVWAReports

Question 38

To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?

Options:

A.

Add the FQDN & IP details for each LDAP host into the local hosts file of the Vault server. Most Voted

B.

Configure an AllowNonStandardFWAddresses rule in DBParm.ini on the Vault to allow outbound TCP 53 to the organization’s DNS servers.

C.

Ensure LDAP hosts added to the directory mapping configuration are defined using only IP addresses.

D.

Set the ReferralsDNSLookup parameter value to “No” in the directory configuration.

Question 39

Which pre-requisite step must be completed before installing a Vault?

Options:

A.

Join the server to a domain.

B.

Install a clean operating system.

C.

Install antivirus software.

D.

Copy the master CD to a folder on the Vault server.

Question 40

When integrating a Vault with HSM, which file is uploaded to the HSM device?

Options:

A.

server.key

B.

recpub.key

C.

recprv.key

D.

mdbase.dat

Demo: 40 questions
Total 136 questions