Skip to content

PAM-CDE-RECERT CyberArk CDE Recertification Practice Questions

Prepare for PAM-CDE-RECERT with more than an answer.

230 questions in the full set20 sample questionsUpdated Aug 20, 2026
Exam fee
$300 USD
Time limit
90 minutes
Passing score
70%
Level
Professional
Valid for
24 months
Domains covered on the exam 5
  1. Privileged Access Security Solution Architecture and Design25%
  2. Privileged Session Management (PSM)20%
  3. Central Policy Manager (CPM) and Account Management20%
  4. Privileged Threat Analytics (PTA)15%
  5. Maintenance, Troubleshooting, and Operations20%
  1. 1

    Case Study: An energy company has a mature CyberArk PAM implementation. They need to provide secure administrative access to a new cloud-based Kubernetes environment hosted in AWS EKS.

    Current Situation: The DevOps team uses kubectl command-line tools from their workstations to manage the EKS cluster. Authentication is currently managed via IAM roles and static access keys stored insecurely on developer laptops. The CISO has mandated that all access must be managed and audited through CyberArk.

    Requirements:

    1. Eliminate static access keys from developer workstations.
    2. Provide just-in-time, temporary credentials for kubectl access.
    3. All kubectl commands executed by administrators must be captured for audit.
    4. The solution must integrate with the existing on-premises CyberArk PAM infrastructure.

    Which combination of CyberArk components and configurations should be used to meet these requirements?

    Show answer details

    Correct answer: C

    This is the most comprehensive and secure solution. PSM for SSH provides the secure, isolated, and audited session for all administrator activity. On the bastion host, the AAM Credential Provider can be used to dynamically fetch short-lived AWS credentials from the Vault. The kubectl commands are then run within this audited session using the temporary credentials, meeting all stated requirements.

  2. 2

    A custom AutoIt-based PSM connector for a legacy Windows application occasionally freezes, causing the PSM session to hang indefinitely. This ties up a PSM license and prevents the user from logging off cleanly. Which parameter in the connection component configuration should be adjusted to automatically terminate these hung sessions?

    Show answer details

    Correct answer: C

    The ExecutionTimeout parameter is specifically designed for this purpose. It defines the maximum time (in seconds) that the dispatcher (e.g., AutoIt script) is allowed to run. If the script hangs and exceeds this timeout, the PSM will automatically terminate the process, freeing up the session and license.

  3. 3

    A company's security policy requires that all domain administrator accounts stored in CyberArk must be disabled in Active Directory when not in use. The account should only be enabled for a short period when a user explicitly requests access. Which CyberArk feature should be configured on the platform to enforce this policy?

    Show answer details

    Correct answer: D

    The out-of-the-box Windows Domain Account platform includes a process file specifically for this use case, often referred to as the ENE (Enable/Disable) process. By associating this process with the platform, the CPM will keep the account disabled in AD. When a user checks out the password, the CPM automatically enables the account. When the user checks it back in, the CPM disables it again, perfectly matching the just-in-time access requirement.

  4. 4

    A CDE has configured PTA to forward alerts to the corporate SIEM via Syslog. The SOC team reports that they are receiving alerts, but the alert messages are truncated and difficult to parse. Which setting should the CDE investigate to resolve this issue?

    Show answer details

    Correct answer: B

    PTA can send Syslog messages in various formats (like CEF for ArcSight, LEEF for QRadar, or a generic format). If the SIEM is expecting a specific format (e.g., CEF) but is receiving another, its parser may fail, leading to truncated or unreadable messages. Ensuring the format configured in systemparm.properties on the PTA server matches the SIEM's expected input format is the correct troubleshooting step.

  5. 5

    You are using the PACLI utility to automate the creation of a large number of safes. However, the script fails with an authentication error. You have confirmed the username and password are correct. The PACLI is being run from a server that is not the Vault server. What is the most common cause for this authentication failure?

    Show answer details

    Correct answer: B

    PACLI relies on a vault.ini file to know which Vault to connect to. If this file is not present in the PACLI directory or does not contain the correct IP address and port for the target Vault, PACLI will fail to connect, resulting in an authentication error. This is the most frequent issue when running PACLI from a remote machine.

  6. 6

    A financial services client is deploying a CyberArk PAM solution across two geographically separate data centers for disaster recovery. The primary data center hosts the active Vault, and the secondary data center hosts a passive DR Vault. The client's RPO is near-zero, and the RTO is 4 hours. The network link between the data centers is stable but has variable latency. Which Vault replication method should be implemented to meet these requirements?

    Show answer details

    Correct answer: A

    Asynchronous replication using PAReplicate is the standard and recommended method for CyberArk DR Vaults. It provides a near-zero RPO by replicating Vault data at frequent intervals (typically every few minutes). It is resilient to network latency, making it suitable for geographically separate data centers. The failover process is well-documented and can be accomplished within the 4-hour RTO.

  7. 7

    During a PSM for SSH deployment, a security administrator reports that they can initiate a session to a target Linux server, but the session recording is not being created. The PSM server logs indicate a successful connection, but the session does not appear in the PVWA Monitoring tab. Which of the following configuration parameters is the most likely cause of this issue?

    Show answer details

    Correct answer: C

    The Master Policy is the primary control for enabling or disabling session recording. If the 'Audit privileged session activity' rule is disabled for the platform governing the target account, PSM will establish the connection but will not record it, matching the described symptoms perfectly.

  8. 8

    A consultant is developing a custom CPM plugin for a legacy mainframe application that uses a proprietary command-line interface for password changes. The password change process requires three distinct steps: logon, change password, and logoff. The consultant has created three separate scripts for these actions. How should the Process.ini file be configured to execute these scripts in the correct order?

    Show answer details

    Correct answer: B

    This is the correct approach. The Process.ini file uses specific commands to define the sequence. pmprerun is executed first for logon actions. pmpass is executed for the actual password change. pmpostrun is executed last for logoff or cleanup actions. This structure allows the CPM to manage each phase of the process correctly.

  9. 9

    A security operations center (SOC) analyst receives a high-severity alert from Privileged Threat Analytics (PTA) indicating a suspected Pass-the-Hash attack originating from a domain controller. The source is a legitimate administrator's workstation, but the activity is occurring outside of business hours. Which of the following data sources are MOST critical for PTA to accurately generate this specific type of alert? (Select TWO)

    Show answer details

    Correct answer: A, B

    PTA requires Windows Security Event Logs, specifically those related to authentication (like Event ID 4624), to detect credential theft attacks such as Pass-the-Hash. It analyzes the authentication type and logon patterns to identify anomalies.

    PTA can perform deep packet inspection on network traffic to detect the characteristic signatures of Pass-the-Hash and other attacks. This network-level visibility is a key data source for detecting attacks in real-time.

  10. 10

    You are performing a quarterly health check of a customer's CyberArk environment. You notice that the italog.log file on the Vault server is growing excessively and contains repeated warnings about ITADB323W and ITADB324W. What is the MOST appropriate first step to diagnose and resolve this issue?

    Show answer details

    Correct answer: D

    The ITADB323W and ITADB324W warnings indicate that the Vault database is fragmented, which can impact performance. The standard and recommended procedure to resolve this is to perform an offline defragmentation of the database using the CAVaultManager DefragmentDB command during a maintenance window. This is the correct first step to address the root cause.

Create an account to continue.