PAM-DEF CyberArk Defender – PAM Practice Questions
Prepare for PAM-DEF with more than an answer.
- Exam fee
- $200 USD
- Level
- Defender
- Valid for
- 2 years
Domains covered on the exam 7
- Introduction to Privileged Access Management and Defense in Depth10%
- CyberArk PAM Architecture20%
- Safe Management15%
- Account Management20%
- Password Management20%
- User and Group Management10%
- Monitoring and Troubleshooting5%
- 1
True or False: The PrivateArk Administrative Client can only be installed on the Vault server itself for security reasons.
Show answer details
Correct answer: B
The PrivateArk Administrative Client is a thick client that can be installed on any hardened administrative workstation that has network connectivity to the Vault server on port 1858. It is not restricted to being installed only on the Vault server. In fact, installing it on a separate, secure machine is a common practice.
- 2
An organization wants to simplify user access by allowing their employees to log into the PVWA using their existing corporate Active Directory credentials. They also want to automatically assign users to CyberArk groups based on their AD group memberships. Which features are required to implement this? (Select TWO)
Show answer details
Correct answer: B, D
LDAP (or LDAPS) integration is the primary method used to configure the PVWA to authenticate users against an Active Directory domain.
Directory Mapping is the feature that allows an administrator to link an external group from LDAP/AD to an internal Vault group. This enables transparent user provisioning and automatic permission granting based on a user's existing AD group membership.
- 3
A new platform for managing Cisco IOS devices has been created. A network engineer is now attempting to verify the password for an account using this new platform, but the action fails. The CPM log shows a timeout error when trying to connect to the device. The CPM server can successfully ping the Cisco device. Which of the following platform parameters is most likely misconfigured?
Show answer details
Correct answer: C
For network devices managed via protocols like Telnet or SSH, the 'Port' parameter in the platform's target account properties is crucial. While ping (ICMP) might work, the actual management port (e.g., 22 for SSH, 23 for Telnet) could be blocked by a firewall or the device might be listening on a non-standard port. A timeout error strongly suggests the CPM cannot establish a connection on the specified management port, making this the most likely misconfiguration.
- 4
A multinational bank uses CyberArk to manage its privileged accounts. During a recent audit, a finding was raised concerning the Vault's backup process. The current process involves a full backup of the Vault's data and configuration files to a network share. However, the auditor noted that the operator performing the backup has read access to the network share, potentially exposing the encrypted safe contents.
The security team has been tasked with redesigning the backup process to ensure that the backup operator can perform the backup and restore operations but cannot access the encrypted data within the backup files. The solution must use standard CyberArk utilities.
Which approach meets these requirements?
flowchart TD subgraph Current Process A[Vault Operator] -- Runs --> B(PAReplicate Utility) B -- Writes --> C{Network Share} A -- Has Read Access --> C end subgraph Proposed Solution D[Backup Operator] -- Runs --> E(CAVaultManager Utility) E -- Creates --> F((Split Backup Files)) D -- Manages --> F endShow answer details
Correct answer: C
The
CAVaultManager SecureBackupcommand is specifically designed for this scenario. It creates a backup that is further encrypted with a new, unique key. The process separates the roles: a 'Backup' user can create the backup files but cannot read them, while a separate 'Restore' user, who holds the corresponding decryption key, is required to restore the data. This enforces segregation of duties and ensures the backup operator cannot access the sensitive data within the backups, directly addressing the audit finding using built-in CyberArk functionality. - 5
Which safe member authorization is required for a user to initiate a PSM connection to an account, without being able to see the account's password?
Show answer details
Correct answer: C
The 'Use password' authorization grants a user the ability to connect to a target system through PSM, where the credentials are used seamlessly in the background. This allows the user to access the target system without ever viewing or retrieving the actual password, adhering to the principle of least privilege.
- 6
What is the primary function of the PSM for SSH (PSMP) component?
Show answer details
Correct answer: B
The PSM for SSH (PSMP) acts as an SSH proxy server. It allows users to connect to target Unix/Linux systems using their preferred native SSH clients, while ensuring the sessions are isolated, controlled, and recorded according to the organization's security policy. This provides a seamless user experience without sacrificing security and audit capabilities.
- 7
An administrator is onboarding a new Windows service account. To enable automatic password management, a 'Logon' account and a 'Reconcile' account must be associated with the service account. What is the purpose of the 'Reconcile' account in this context?
Show answer details
Correct answer: C
A Reconcile account is a separate, highly privileged account (like a domain administrator) that the CPM can use to reset the password of a target account directly on the endpoint. This is used in situations where the Vault's stored password is out of sync ('password is in a locked state'), allowing the CPM to regain control and resynchronize the credential.
- 8
During a routine audit, it was discovered that a new team of database administrators requires temporary, emergency access to a production SQL server account. The current platform configuration for this account enforces a dual-control workflow for password retrieval. The security policy mandates that for emergency access, the request must bypass the standard dual-control approval process but still require a documented justification and be automatically revoked after two hours. Which is the most efficient and secure method to configure this exception in CyberArk?
Show answer details
Correct answer: C
The Master Policy is the correct place to manage exceptions to platform-level settings. Creating an exception that overrides the 'Require multi-level approval' rule for a specific time window allows for controlled, temporary emergency access without altering the base platform security for all other accounts. This method is auditable, time-bound, and aligns with the principle of least privilege. Temporarily disabling the platform setting or creating a new safe are less efficient, more disruptive, and harder to audit for a temporary access scenario.
- 9
A financial services company is deploying a distributed CyberArk architecture with a primary Vault and a Disaster Recovery (DR) Vault. A junior administrator is attempting to troubleshoot a replication failure. They have confirmed network connectivity and that the
padr.inifile is correctly configured. What are the next TWO most likely causes of the replication failure? (Select TWO)Show answer details
Correct answer: C, D
The dedicated DR user must be a member of the built-in 'DR Users' group to have the necessary permissions to initiate and maintain replication. An incorrect password for this user is also a very common cause of failure.
The password for the DR user is stored in the
padr.inifile on the DR Vault server. If this password does not match the one set in the Vault for the DR user, authentication will fail, and replication cannot start. This is a primary troubleshooting step after confirming network connectivity. - 10
A PSM server is configured to use a custom recording safe named 'PSM_Recordings_Finance' for all sessions initiated from platforms tagged with the 'Finance' category. However, a security analyst reports that recordings for the 'Finance-DB-Admins' platform are still being stored in the default 'PSMRecordings' safe. What is the most likely reason for this misconfiguration?
Show answer details
Correct answer: D
CyberArk uses a hierarchy for configuration. A parameter set directly on a specific platform will always override the more general setting configured on the PSM server itself (in the
basic_psm.inior via PVWA Options). In this case, the specific platform setting is taking precedence, causing recordings to be sent to the default safe instead of the intended custom safe.
