New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

PAM-SEN CyberArk Sentry PAM Questions and Answers

Questions 4

You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer.

Which additional packages do you need to install to meet the customer’s needs? (Choose two.)

Options:

A.

CARKpsmp-infra

B.

libssh

C.

OpenSSH 7.8 or higher

D.

CARKpsmp-ADBridge

E.

CARKpsmp-SSHD

Buy Now
Questions 5

You are installing multiple PVWAs behind a load balancer.

Which statement is correct?

Options:

A.

Port 1858 must be opened between the load balancer and the PVWAs.

B.

The load balancer must be configured in DNS round robin.

C.

The load balancer must support "sticky sessions".

D.

The LoadBalancerClientAddressHeader parameter in the PVWA.ini file must be set.

Buy Now
Questions 6

Which service must be set to Automatic (delayed start) after the Vault is installed and configured?

Options:

A.

Windows Time service

B.

PrivateArk Database

C.

Windows Update service

D.

PrivateArk Server

Buy Now
Questions 7

You have been asked to limit a platform called “Windows_Servers” to safes called “WindowsDC1” and “WindowsDC2”. The platform must not be assigned to any other safe.

What is the correct way to accomplish this?

Options:

A.

Edit the “Windows_Servers” platform, expand “Automatic Password Management”, then select General and modify “AllowedSafes” to be (WindowsDC1)|(WindowsDC2).

B.

Edit the “Windows_Servers” platform, expand “Automatic Password Management”, then select Options and modify “AllowedSafes” to be (Win*).

C.

Edit the “WindowsDC1” and “WindowsDC2” safes through Safe Management, Add “Windows_Servers” to the “AllowedPlatforms”.

D.

Log in to PrivateArk using an Administrative user, Select File, Server File Categories, Locate the category “WindowsServersAllowedSafes” and specify “WindowsDC1,WindowsDC2”.

Buy Now
Questions 8

After installing the first PSM server and before installing additional PSM servers, you must ensure the user performing the installation is not a direct owner of which safe?

Options:

A.

PSMUnmanagedSessionAccounts Safe

B.

PSMRecordingsSessionAccounts Safe

C.

PSMUnmanagedApplicationAccounts Safe

D.

PSMSessionBackupAccounts Safe

Buy Now
Questions 9

Which of the following are prerequisites for installing PVWA Check all that Apply.

Options:

A.

Web Services Role

B.

NET 4.5.1 Framework Feature

C.

Remote Desktop Services Role

D.

Windows BitLocker

Buy Now
Questions 10

In which configuration file do you add LoadBalancerClientAddressHeader when you enable x-forwarding on the PVWA loadbalancer?

Options:

A.

PVconfiguration.xml

B.

web.config

C.

apigw.ini

D.

CyberArkScheduledTasks.exe.config

Buy Now
Questions 11

The security of the Vault Server is entirely dependent on the security of the network.

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 12

How should you configure PSM for SSH to support load balancing?

Options:

A.

by using a network load balancer Most Voted

B.

in PVWA > Options > PSM for SSH Proxy > Servers

C.

in PVWA > Options > PSM for SSH Proxy > Servers > VIP

D.

by editing sshd.config on the all the PSM for SSH servers

Buy Now
Questions 13

The vault server uses a modified version of the Microsoft Windows firewall.

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 14

What is the purpose of the password Reconcile process?

Options:

A.

To test that CyberArk is storing accurate credentials for accounts.

B.

To change the password of an account according to organizationally defined password rules

C.

To allow CyberArk to manage unknown or lost credentials.

D.

To generate a new complex password.

Buy Now
Questions 15

What is the name of the account used to establish the initial RDP session from the end user client machine to the PSM server?

Options:

A.

PSMConnect

B.

PSMAdminConnect

C.

PSM

D.

The credentials the end user retrieved from the vault

Buy Now
Questions 16

Which of the following are supported authentication methods for CyberArk? Check all that apply

Options:

A.

CyberArk Password (SRP)

B.

LDAP

C.

SAML

D.

PKI

E.

RADIUS

F.

OracleSSO

G.

Biometric

Buy Now
Questions 17

In order to retrieve data from the vault a user MUST use an interface provided by CyberArk.

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 18

A vault admin received an email notification that a password verification process has failed Which service sent the message?

Options:

A.

The PrivateArk Server Service on the Vault.

B.

The CyberArk Password Manager service on the Components Server.

C.

The CyberArk Event Notification Engine Service on the Vault

D.

The CyberArk Privileged Session Manager service on the Vault.

Buy Now
Questions 19

What are the basic network requirements to deploy a CPM server?

Options:

A.

Port 1858 to Vault and Port 443 to PVWA

B.

Port 1858 only

C.

all ports to the Vault

D.

Port UDP/1858 to Vault and all required ports to targets and Port 389 to the PSM

Buy Now
Questions 20

CyberArk User Neil is trying to connect to the Target Linux server 192.168.1.164 using a domain account ACME/linuxuser01 on domain acme.corp using PSM for SSH server 192.168.65.145.

What is the correct syntax?

Options:

A.

ssh neil@linuxuser01:acme.corp@192.168.1.164@192.168.65.145

B.

ssh neil@linuxuser01#acme.corp@192.168.1.164@192.168.65.145 Most Voted

C.

ssh neil@linuxuser01@192.168.1.164@192.168.65.145

D.

ssh neil@linuxuser01@acme.corp@192.168.1.164@192.168.65.145

Buy Now
Questions 21

Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence.

Options:

Buy Now
Questions 22

There is a requirement for a password to change between 01:00 and 03:00 on Saturdays and Sundays; however, this does not work consistently.

Which platform setting may be the cause?

Options:

A.

The Interval setting for the platform is incorrect and must be less than 120.

B.

The ImmediateInterval setting for the platform is incorrect and must be greater than or equal to 1.

C.

The DaysToRun setting for the platform is incorrect and must be set to Sat,Sun.

D.

The HeadStartInterval setting for the platform is incorrect and must be set to 0.

Buy Now
Questions 23

This value needs to be added to the PVWA configuration file:

Assuming all CyberArk PVWA servers were installed using default paths/folders, which configuration file should you locate and edit to accomplish this?

Options:

A.

c:\inetpub\wwwroot\passwordvault\web.config

B.

c:\inetpub\wwwroot\passwordvault\services\web.config

C.

c:\cyberark\password vault web access\env\web.config

D.

c:\program files\cyberark\password vault web access\web.config

Buy Now
Questions 24

A customer is moving from an on-premises to a public cloud deployment.

What is the best and most cost-effective option to secure the server key?

Options:

A.

Install the Vault in the cloud the same way you would in an on-premises environment. Place the server key in a password protected folder on the operating system.

B.

Install the Vault in the cloud the same way you would in an on-premises environment. Purchase a Hardware Security Module to secure the server key.

C.

Install the Vault using the native cloud images and secure the server key using native cloud Key Management Systems.

D.

Install the Vault using the native cloud images and secure the server key with a Hardware Security Module.

Buy Now
Questions 25

What is the PRIMARY reason for installing more than 1 active CPM?

Options:

A.

Installing CPMs in multiple sites prevents complex firewall rules to manage devices at remote sites.

B.

Multiple instances create fault tolerance.

C.

Multiple instances increase response time.

D.

Having additional CPMs increases the maximum number of devices CyberArk can manage

Buy Now
Questions 26

A customer has five main data centers with one PVWA in each center under different URLs.

How can you make this setup fault tolerant?

Options:

A.

This setup is already fault tolerant.

B.

Install more PVWAs in each data center.

C.

Continuously monitor PVWA status and send users the link to another PVWA if issues are encountered.

D.

Load balance all PVWAs under same URL.

Buy Now
Questions 27

Does CyberArk need service accounts on each server to change passwords?

Options:

A.

Yes. it requires a domain administrator account to change any password on any server.

B.

Yes. it requires a local administrator account on any Windows server and a root level account on any Unix server.

C.

No. passwords are changed by the Password Provider Agent.

D.

No. the CPM uses the account information stored in the vault to login and change the account's password using its own credentials

Buy Now
Questions 28

The account used to install a PVWA must have ownership of which safes? (Choose two.)

Options:

A.

VaultInternal

B.

PVWAConfig

C.

System

D.

Notification Engine

E.

PVWAReports

Buy Now
Questions 29

When performing “In Domain” hardening of a PSM server, which steps must be performed? (Choose two.)

Options:

A.

Import CyberArk policy settings from the provided file into a new GPO. Most Voted

B.

Apply advanced audit on the PSM server.

C.

Link GPO to a dedicated OU containing CyberArk PSM servers. Most Voted

D.

Import an INF file to the local machine.

E.

Configure AppLocker rules to block running unknown executables.

Buy Now
Questions 30

Which configuration file and Vault utility are used to migrate the server key to an HSM?

Options:

A.

DBparm.ini and CAVaultManager.exe

B.

VaultKeys.ini and CAVaultManager.exe

C.

DBparm.ini and ChangeServerKeys.exe

D.

VaultKeys.ini and ChangeServerKeys.exe

Buy Now
Questions 31

You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_Admin safes.

How do you set this in CyberArk?

Options:

A.

In the CYBRWINDAD platform, under Automatic Password Management/General, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN). Most Voted

B.

In the settings for Configuration/CPM assigned to the WINDEMEA and WINDEMEAADMIN safes, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEAADMIN).

C.

In the CYBRWINDAD platform, under UI&Workflows/Properties/Optional, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).

D.

Modify cpm.ini on the relevant CPM/s and add the setting AllowedSafesCYBRWINDAD and set to (WINDEMEA)|(WINDEMEAADMIN).

Buy Now
Questions 32

Which files does the Vault Installation Wizard prompt you for during the Vault install?

Options:

A.

Operator CD and License Most Voted

B.

Master CD and License

C.

Operator CD and Vault Certificate

D.

Master CD and DBparm.ini

Buy Now
Questions 33

Which CyberArk component changes passwords on Target Devices?

Options:

A.

Vault

B.

CPM

C.

PVWA

D.

PSM

E.

PrivateArk

F.

OPM

G.

AIM

Buy Now
Questions 34

HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)

Options:

A.

Red Hat Enterprise Linux 7.x

B.

CentOS 7.x

C.

Ubuntu 20.x

D.

AK 7.x

E.

Android 11.x

Buy Now
Questions 35

All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The current PAM solution is:

2 distributed Vaults, the primary one in New York and a satellite in Tokyo

2 PVWA servers, both in New York with load balancing configured

2 PSM servers, both in New York without load balancing configured

1 CPM server in New York

All PVWA, PSM, and CPM servers are connected to the primary Vault

Which proposal optimally resolves the performance issue while minimizing the impact to production?

Options:

A.

Install two new PVWA servers in Tokyo data center, configure load balancing, connect to the local satellite Vault and provide the URL of new PVWA servers to the local employees.

B.

Install two new PVWA servers in New York data center, configure load balancing and have them connect to the satellite Vault in Tokyo.

C.

Install two new PSM servers in the Tokyo data center, configure load balancing, connect to the local satellite vault, and inform the local employees to browse using the same PVWA URL.

D.

Change the current distributed Vaults architecture, migrate back to a Primary-DR architecture, install two new PVWA servers in the Tokyo data center and configure load balancing. Connect to the local DR Vault and provide the URL of new PVWA servers to the local employees.

Buy Now
Questions 36

Which statement is correct about a post-install hardening?

Options:

A.

The Vault must be hardened during the Vault installation process. Most Voted

B.

After the Vault server is installed, you must join the server to the Enterprise Domain and reboot the host.

C.

It is executed after Vault installation by running CAVaultHarden.exe and hardening options can be edited by changing the Hardening.ini file. Most Voted

D.

If it is mandated by an organization’s IT governance, you do not have to execute Vault hardening; however, server hardening cannot be reversed.

Buy Now
Questions 37

When integrating a Vault with HSM, which file is uploaded to the HSM device?

Options:

A.

server.key

B.

recpub.key

C.

recprv.key

D.

mdbase.dat

Buy Now
Questions 38

In a SIEM integration it is possible to use the fully-qualified domain name (FQDN) when specifying the SIEM server address(es)

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 39

As a member of a PAM Level-2 support team, you are troubleshooting an issue related to load balancing four PVWA servers at two data centers. You received a note from your Level-1 support team stating “When testing PVWA website from a workstation, we noticed that the “Source IP of last sign-in” was shown as the VIP (Virtual IP address) assigned to the four PVWA servers instead of the workstation IP where the PVWA site was launched from.”

Which step should you take?

Options:

A.

Verify the “LoadBalancerClientAddressHeader” parameter setting in PVWA configuration file Web.config is set to “X-Forwarded-For”.

B.

Add the VIP (Virtual IP address) assigned to the four PVWA servers to the certificates issued for all four PVWA servers, if missing.

C.

Add a firewall rule to allow the testing workstation to connect to the VIP (Virtual IP address) assigned to the four PVWA servers on Port TCP 443.

D.

Edit the dbparm.ini file on the Vault server and add the IP or subnet of the workstation to the whitelist.

Buy Now
Questions 40

You are designing the number of PVWAs a customer must deploy. The customer has three data centers with a distributed Vault in each, requires high availability, and wants to use all Vaults at all times.

How many PVWAs does the customer need?

Options:

A.

six or more

B.

four

C.

two or less

D.

three

Buy Now
Exam Code: PAM-SEN
Exam Name: CyberArk Sentry PAM
Last Update: Dec 22, 2024
Questions: 136

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99