PAM-SEN CyberArk Sentry - PAM Practice Questions
Prepare for PAM-SEN with more than an answer.
- Exam fee
- $200 USD
- Level
- Sentry
- Valid for
- 2 years
Domains covered on the exam 5
- CyberArk Privileged Account Management (PAM) Core Concepts20%
- CyberArk PAM Deployment and Configuration25%
- CyberArk PAM Administration and Operations25%
- Advanced CyberArk PAM Features20%
- Best Practices and Security Considerations10%
- 1
A new PSM server has been deployed, but users are reporting that while they can connect to target systems, their sessions are not being recorded. The PSM logs show no errors. What is a common configuration oversight that would cause this behavior?
Show answer details
Correct answer: C
Session recording behavior is controlled at the platform level. Even if the PSM is fully functional, if the specific platform associated with the target account has 'Record and Safe Session' set to 'No', the PSM will establish the connection but will not record it. This is a common reason for sessions to connect successfully but not appear in the recordings list.
- 2
A Sentry is configuring a high-availability architecture for the Password Vault Web Access (PVWA) component using a network load balancer. Which session persistence method is recommended by CyberArk to ensure a seamless user experience?
Show answer details
Correct answer: C
CyberArk recommends using cookie-based persistence, often referred to as 'sticky sessions,' on the load balancer for PVWA high availability. This method ensures that once a user establishes a session with a particular PVWA server, all subsequent requests from that user during the same session are directed to the same server. This maintains session state and prevents the user from being unexpectedly logged out or losing their work.
- 3
What is the primary function of a Reconciliation Account configured on a platform?
Show answer details
Correct answer: B
A Reconciliation Account is a highly privileged account used by the CPM as a last resort. If the CPM fails to change a password because the password stored in the Vault is out of sync with the target system (e.g., it was changed manually), the CPM will use the reconciliation account—which has permissions to reset other users' passwords—to log in and forcefully reset the managed account's password, bringing it back into a known, managed state.
- 4
A security policy requires that certain high-risk operations performed in the PrivateArk Client, such as deleting a Safe or modifying the Master Policy, require approval from a second, authorized user. Which CyberArk feature should be configured to enforce this policy?
Show answer details
Correct answer: C
Dual Control, also known as a 'four-eyes principle' or quorum, is the specific feature designed for this purpose. It is configured in the Master Policy to require that certain sensitive actions must be confirmed by one or more other authorized users before they can be executed. This prevents any single administrator from performing critical, irreversible actions alone.
- 5
When using the
CreateCredFileutility to create a credential file for a component user (e.g., PSMAppUser), which piece of information is NOT required as an input parameter for the utility?Show answer details
Correct answer: C
The
CreateCredFileutility is solely used to encrypt the user's password into a credential file (.inior.cre). It requires the username and prompts for the password, but it does not require any information about the Vault server, such as its IP address. The Vault address is specified separately in the component's own configuration file (e.g.,vault.ini). - 6
A financial services company is deploying a new PSM farm behind a network load balancer. The security policy mandates that the original client IP address must be logged for all connections to the Vault for audit purposes. The PVWA is also behind a load balancer. Which parameter must be configured on the PVWA to ensure the correct client IP is forwarded and logged?
Show answer details
Correct answer: B
When a PVWA is placed behind a load balancer that uses X-Forwarded-For headers to pass the original client IP, the
LoadBalancerClientAddressHeaderparameter must be configured in theweb.configfile on the PVWA server. This tells the PVWA to look for the specified header (e.g., 'X-Forwarded-For') to identify the true client IP address for logging and auditing, rather than logging the IP of the load balancer itself. - 7
During a disaster recovery test, a manual failover to the DR Vault was initiated. After the failover, CPM services are unable to manage passwords for any accounts. Log analysis on the CPM server shows 'ITACM024S User is not defined' errors. What is the most likely cause of this issue?
Show answer details
Correct answer: B
The error 'ITACM024S User is not defined' indicates the user attempting to authenticate does not exist in the Vault's user database. In a DR scenario, this most commonly occurs when the component user (like the CPM user) was created or had its credentials updated on the Primary Vault, but a full replication cycle did not complete before the failover. As a result, the DR Vault does not have the user's definition, causing authentication to fail.
- 8
A security team wants to implement a policy where any privileged session that executes the
useraddcommand on a Linux server is automatically terminated. Which combination of CyberArk components is required to achieve this automated response? (Select TWO)Show answer details
Correct answer: A, C
The PSM is required to establish, record, and control the privileged session. It is the component that can physically terminate the active session upon receiving a command.
PTA analyzes the session data from PSM in real-time. It contains the security engine and policy configuration to detect specific commands like
useraddand trigger an automated response, such as instructing the PSM to terminate the session. - 9
True or False: When configuring PSM for SSH, the
sshd_configfile on the PSM server must be manually edited to enable TCP forwarding to allow session recording and control.Show answer details
Correct answer: B
False. The PSM for SSH installation script (
psmp_install.sh) automatically configures thesshd_configfile with the required parameters, includingAllowTcpForwarding yes. Manual editing for this specific purpose is not required and could lead to misconfiguration if done incorrectly. - 10
A global enterprise with data residency requirements is designing a CyberArk PAM architecture. They have major data centers in North America (NA), Europe (EU), and Asia-Pacific (APAC). The primary Vault must reside in NA. To minimize latency for interactive sessions, PSM servers must be deployed locally in each region. However, all session recordings must be stored centrally in the NA Vault for compliance and security review.
Current Situation:
- A hardened Primary Vault is deployed in the NA data center.
- A DR Vault is deployed in a separate NA location.
- PVWA and CPM components are deployed in NA.
Requirements:
- Deploy PSM servers in NA, EU, and APAC regions.
- Users in each region must connect through their local PSM for optimal performance.
- ALL session recordings from ALL regions must be securely transferred and stored in the Primary Vault in NA.
- The solution must be resilient to network interruptions between regions.
Which architectural design best meets these requirements?
graph TD subgraph NA_Datacenter [North America] Vault[Primary Vault] PVWA[PVWA] PSM_NA[PSM Server NA] end subgraph EU_Datacenter [Europe] PSM_EU[PSM Server EU] end subgraph APAC_Datacenter [Asia-Pacific] PSM_APAC[PSM Server APAC] end Users_NA((Users NA)) --> PSM_NA Users_EU((Users EU)) --> PSM_EU Users_APAC((Users APAC)) --> PSM_APAC PSM_NA --> Vault PSM_EU -->|Recordings| Vault PSM_APAC -->|Recordings| VaultShow answer details
Correct answer: D
This is the correct, built-in CyberArk solution for distributed PSM deployments. The PSM is designed to cache recordings locally in a secure, encrypted format if it cannot immediately connect to the Vault. Once connectivity is restored, it automatically uploads the recordings, ensuring no data is lost and providing resilience against network interruptions. This architecture meets all stated requirements for performance, central storage, and resilience.
