CPC-SEN Cyberark Sentry - Privilege Cloud Practice Questions
Prepare for CPC-SEN with more than an answer.
- Exam fee
- $400 USD
- Level
- Sentry (Level 3)
- Valid for
- 2 years
Domains covered on the exam 7
- CyberArk Privilege Cloud Overview and Architecture15%
- Installation and Configuration25%
- Account Management and Onboarding20%
- User Management and Access Control15%
- Session Management and Monitoring15%
- Integration and APIs10%
- Security, Compliance, and Troubleshooting10%
- 1
An administrator needs to integrate a proprietary Windows thick-client admin tool with PSM. The tool opens a login dialog in which the username, target address and password must be entered, and users must never see the password. Which PSM feature should be used to build this integration?
Show answer details
Correct answer: C
PSM Universal Connectors automate the launch and authentication process of application clients so that PSM opens an isolated, recorded session without exposing the credentials. The automation (finding the login window and its controls and entering the credentials that PSM retrieves from the Vault) is written in AutoIt, developed from the PSMAutoItDispatcherSkeleton.au3 skeleton, packaged, and imported through Account platforms > Manage Connectors. The HTML5 gateway only displays PSM sessions in a browser, and the RDP and SSH proxies connect native RDP and SSH clients; they do not automate an application's login dialog. A client that accepts its credentials as command-line arguments can instead be launched by a connection component with ClientInvokeType=CommandLine, without an AutoIt script.
- 2
A new security policy requires that all privileged accounts stored in a particular Safe must have their passwords changed every 30 days. However, one specific service account in that Safe must be exempt from this policy, and its password should only be changed manually. How should an administrator configure this?
Show answer details
Correct answer: C
CyberArk allows for granular control by enabling overrides at the individual account level. While the platform linked to the Safe dictates the general policy (e.g., 30-day rotation), an administrator can edit the specific service account's properties, disable 'Automatic Management' for that single account, and effectively create an exception without affecting any other accounts in the Safe or modifying the platform itself.
- 3
A company has integrated their Privilege Cloud tenant with CyberArk's Privileged Threat Analytics (PTA) service. A security analyst receives a high-severity alert from PTA indicating a 'Suspected Credential Theft' event originating from a developer's workstation. What is the most likely trigger for this specific type of alert?
Show answer details
Correct answer: B
PTA's 'Suspected credentials theft' detection (event type 21) is raised when a user connects to a machine or cloud service without first retrieving the required credentials from the Vault — an indication that the password was obtained some other way. PTA correlates logon activity reported by its SIEM/Unix/cloud sensors with the Vault's retrieval audits, and it can automatically trigger a password change to contain the threat. Off-hours activity, repeated failed Vault authentications and risky commands inside a PSM session map to other detections (irregular hours/days, suspicious multiple authentication failures, suspicious activities detected in a privileged session). A password that was retrieved from the Vault and then used is the expected pattern, not credential theft.
- 4
During LDAP integration setup in Privilege Cloud Standard, an administrator needs a directory mapping to search for users only in a specific Organizational Unit (OU) in Active Directory called 'DBAdmins'. Which directory mapping property specifies this starting point for the search?
Show answer details
Correct answer: C
A Privilege Cloud (Standard) directory map has an LDAPBranch - the LDAP branch used for external directory queries - so it is set to the OU's distinguished name (for example OU=DBAdmins,DC=example,DC=com). LDAPQuery is an optional filter applied to the users in that branch, and DomainGroups lists the LDAP groups whose members receive the map's authorizations. The domain connection itself has a 'Domain base context' (for example DC=MyDomain,DC=com). UserDN and SearchFilter are not directory-map properties.
- 5
An architect is explaining what happens when an end user on the corporate network starts a PSM session to a Windows target from the Privilege Cloud portal (PVWA).
Which description of the high-level connection flow is correct?
Show answer details
Correct answer: A
When a user clicks Connect in the portal, an RDP file is downloaded, and the user's RDP client connects to the PSM that runs on the customer's Connector. The PSM communicates with the Vault backend over TCP 1858, retrieves the target credentials, opens the session directly to the target system, and isolates and records it, so the user never sees the password. The Secure Tunnel is not part of this path. It connects the backend to on-premises LDAP and SIEM servers (and legacy remote access), and it is not supported for new deployments since June 30, 2026. Users outside the network connect remotely over HTML5 instead of RDP.
- 6
A financial services firm uses Privilege Cloud with on-premises Connectors running CPM and PSM, and must plan disaster recovery for password management at a secondary site. According to CyberArk, how is disaster recovery provided for the CPM component?
Show answer details
Correct answer: A
CyberArk documents an active-passive Disaster Recovery CPM: you install and configure a second CPM instance (selecting CPM mode Passive during installation through Connector Management or the Privilege Cloud installer) and, if the primary CPM is down, you manually switch over to the DR CPM. Only one CPM instance can be active at a time, so active-active CPMs managing the same accounts, or two running copies of the same CPM, are not supported, and the on-premises CPM is not failed over by CyberArk. For sessions, high availability comes from deploying multiple PSMs, typically behind a load balancer.
- 7
A security administrator is configuring Privilege Cloud to manage the password of a Cisco IOS user account with the "Cisco router via SSH" platform. The Cisco user does not have the privileges needed to change passwords, so the CPM must switch to Enable mode on the router to change the password. What must be configured for the CPM to do this?
Show answer details
Correct answer: A
The Cisco router plugin documents that a Cisco user password 'without password management privileges' requires a link to an additional password object that enables the CPM to switch to Enable mode and change the password on the remote machine. The CiscoEnable password object provides this and is linked in the account's Details tab > Linked Accounts, where an enable password is an 'other' linked account defined at account level. There is no fixed 'EnablePrompt' platform parameter, because TPC prompt conditions are user-defined names in the Prompts file. The CiscoTerminal type also needs a linked object to switch to Enable mode. With TACACS, only reconciliation of local accounts is enabled, and Verify and Change are disabled by default.
- 8
During a security audit of a Privilege Cloud deployment, an auditor notices that the PSM servers on the Connectors write session recordings to a local folder and asks whether recordings are retained on the PSM hosts. Which TWO statements accurately describe how PSM handles session recordings in Privilege Cloud? (Select TWO)
Show answer details
Correct answer: B, D
CyberArk documents that PSM recordings are saved temporarily in a local folder until the PSM session ends, when they are uploaded to the Vault. They are stored in Recording Safes that PSM creates automatically when the first recording is uploaded, named according to the platform's SessionRecorderSafe parameter (default PSMRecordings, or dynamic names such as PSM-{AccountSafeName}); retention is defined per recording Safe (SessionRecorderSafeRetention). No SFTP server, network share or Support-side configuration is needed to keep recordings off the PSM hosts.
CyberArk documents that PSM recordings are saved temporarily in a local folder until the PSM session ends, when they are uploaded to the Vault. They are stored in Recording Safes that PSM creates automatically when the first recording is uploaded, named according to the platform's SessionRecorderSafe parameter (default PSMRecordings, or dynamic names such as PSM-{AccountSafeName}); retention is defined per recording Safe (SessionRecorderSafeRetention). No SFTP server, network share or Support-side configuration is needed to keep recordings off the PSM hosts.
- 9
A consultant uses the Privilege Cloud REST API to onboard several hundred Active Directory service accounts. The accounts are added successfully, but the CPM's password changes fail because the domain password policy prevents these users from changing their own passwords (for example, a minimum password age). A reconcile account that is allowed to reset passwords is linked to the platform. What should the consultant configure so that the CPM can rotate these passwords?
Show answer details
Correct answer: A
ChangePasswordInResetModeis a platform-level parameter in the Additional Policy Settings (default No). When it is set to Yes, the CPM performs password changes as reset operations using the associated reconciliation account instead of changing the password with the current one. CyberArk notes this is useful when a one-time password is used with a directory minimum password-age restriction or when the password policy prevents users from changing their own passwords (password plugins only). It is not a parameter of the Add Account API, whose body contains properties such as platformId, safeName, secret and secretManagement. Disabling automatic management would stop rotation altogether, and ImmediateInterval only sets the delay before a user-initiated management operation runs. - 10
True or False: When integrating CyberArk Privilege Cloud with an external SIEM system, the Secure Tunnel on the Privilege Cloud Connector must be used to forward audit logs.
Show answer details
Correct answer: B
False. Privilege Cloud can integrate with a SIEM in two ways: the recommended Audit service SIEM integration (Setup space > Integrations > Export to SIEM), which does not use the Secure Tunnel, or syslog forwarding, for which the Secure Tunnel is deployed on premises so that the Privilege Cloud backend can send syslog messages to the SIEM servers (up to five). The Secure Tunnel is used for SIEM, LDAP (Standard) and legacy remote-access connections — CPM and PSM communicate with the Vault directly over TCP 1858. Since June 30, 2026 the Secure Tunnel is no longer supported for new deployments; organizations that require syslog must ask Technical Support to enable it.
