SECRET-SEN CyberArk Sentry – Secrets Manager Practice Questions
Prepare for SECRET-SEN with more than an answer.
- Exam fee
- $200 USD
- Level
- Sentry
- Valid for
- 2 years
Domains covered on the exam 5
- CyberArk Secrets Manager Architecture20%
- Installation and Configuration25%
- Policy Management and Security20%
- Kubernetes Integration20%
- Application Integration15%
- 1
True or False: When deploying the Vault Conjur Synchronizer, the
Synchronizeruser in the Vault must be a member of theVault Adminsgroup.Show answer details
Correct answer: B
The statement is false. The
Synchronizeruser does not need to be a Vault Admin. According to the principle of least privilege, it only needs specific, limited permissions:List Accounts,View Safe Members, andRetrieve Accountson the Safes containing the secrets to be synchronized, as well as membership in thePVWAMonitorsgroup. - 2
A policy defines a layer and grants a host within that layer permissions to a secret. Later, a developer needs to move the host to a different layer. What is the most efficient way to update the host's layer membership without disrupting its identity?
Show answer details
Correct answer: B
The correct way to manage role membership is with
!grantand!revoke. To move the host, you load a policy that revokes its membership from the old layer and grants it membership in the new layer. This modifies the existing host's relationships without needing to delete and recreate the host identity itself, which would invalidate its API key. - 3
A financial technology company, FinCorp, is deploying a critical payment processing application in a Kubernetes cluster. Due to regulatory compliance, all access to secrets must be strictly controlled and audited. The application pods need credentials to access a transactional database and an external payment gateway API. The Security Operations team manages all credentials centrally in a CyberArk Vault.
The current architecture uses the Vault Conjur Synchronizer to replicate secrets to a Conjur DAP cluster. The Kubernetes Authenticator is configured to grant pod identities access to these secrets. The security team has defined a policy that maps the application's Kubernetes ServiceAccount to a Conjur host. During a security review, an auditor raises a concern about the process of authenticating the application to Conjur.
The auditor's question is: 'How does Conjur verify that a JWT it receives actually originates from a legitimate pod in the cluster and not from a rogue process that has stolen a token?'
Which component and action form the basis of this verification process?
Show answer details
Correct answer: B
This is the core of the Kubernetes authentication mechanism. Conjur does not trust the JWT outright. Instead, the authenticator service, which has its own trusted identity with the Kubernetes API, takes the JWT from the connecting pod and sends it to the
TokenReviewAPI endpoint. The Kubernetes API Server, the ultimate authority on token validity, checks if the token is valid, active, and not expired. Only upon receiving a successfulTokenReviewresponse does Conjur consider the pod authenticated. This prevents replay attacks or the use of stolen, expired tokens.sequenceDiagram participant Pod participant Conjur as Conjur Authenticator participant K8s as Kubernetes API Server Pod->>Conjur: Authenticate with ServiceAccount JWT Conjur->>K8s: Create TokenReview(JWT) K8s-->>Conjur: TokenReviewResponse (Valid/Invalid) alt Token is Valid Conjur-->>Pod: Conjur Access Token else Token is Invalid Conjur-->>Pod: 401 Unauthorized end - 4
A Python application running on a virtual machine needs to fetch secrets from Conjur. The security policy prohibits storing long-lived API keys on the VM. The VM has an IAM role assigned to it in AWS. Which authentication method should be used to provide the application with a Conjur identity?
Show answer details
Correct answer: C
The Authn-AWS authenticator is specifically designed for this purpose. It leverages the trusted identity provided by AWS IAM. The application makes a signed AWS API request, which Conjur can validate. This proves the application's identity (its IAM role) without needing any pre-configured secrets on the VM itself, fulfilling the security requirement.
- 5
What is the function of the
evokecommand in a Conjur appliance?Show answer details
Correct answer: B
The
evokecommand is the primary tool for administering the Conjur appliance itself. It is used for tasks outside of the data plane, such as configuring the Master, setting up Standbys and Followers, managing certificates, and performing backups and restores. Policy management is typically done with theconjurCLI. - 6
A financial services company is designing a multi-site Conjur DAP architecture for disaster recovery. They have a primary data center (DC1) and a secondary data center (DC2). The requirement is that if DC1 fails completely, DC2 must be able to continue serving secrets without manual intervention. The cluster spans both data centers. What is the minimum number of nodes required, and how should they be distributed to ensure automatic failover and maintain quorum if DC1 is lost?
Show answer details
Correct answer: C
To maintain quorum and enable automatic failover after losing an entire data center, the surviving data center must contain a majority of the voting nodes (Master and Standbys). In a 5-node cluster (1 Master, 4 Standbys), the quorum size is 3. By placing 3 Standbys in DC2, if DC1 (containing the Master and 1 Standby) is lost, the 3 remaining Standbys in DC2 can form a new quorum, elect a new Master, and continue operations. Followers do not participate in quorum elections.
- 7
An administrator deployed the Conjur Kubernetes Authenticator. Pods in the
prod-appsnamespace are failing to authenticate, and the authenticator logs show401 Unauthorizederrors. The policy correctly defines the host identityhost/prod-apps/deployment/my-app. The pod's ServiceAccount is also correctly defined and assigned. Which of the following is the most likely cause for this authentication failure?Show answer details
Correct answer: C
The Conjur Kubernetes Authenticator works by validating a pod's ServiceAccount token with the Kubernetes API server. To do this, it must have the permission to create
tokenreviews.authentication.k8s.ioresources. If the authenticator's ClusterRole is missing this permission, the K8s API server will reject its validation requests, leading to a401 Unauthorizederror when the pod tries to authenticate to Conjur. - 8
A DevOps team is structuring their Conjur policies for a microservices application. They want to grant a specific service,
billing-api, read and execute permissions on a database password. They also want to allow members of thedb-adminsgroup to update the password. Which of the following policy statements are required to achieve this configuration? (Select TWO)Show answer details
Correct answer: C, D
This statement correctly uses
!permitto grant thebilling-apihost the necessaryreadandexecuteprivileges on thedb/passwordvariable.This statement correctly uses
!permitto grant thedb-adminsgroup the specificupdateprivilege on thedb/passwordvariable, adhering to the principle of least privilege. - 9
A rapidly growing e-commerce company is migrating its entire platform to Google Kubernetes Engine (GKE). Their security team has mandated the use of CyberArk Conjur for all secrets management. The platform consists of dozens of microservices, each with its own database credentials, API keys, and certificates. The DevOps team uses a GitOps workflow with ArgoCD to manage all Kubernetes manifests.
The current challenge is integrating Conjur into this GitOps model. The secrets must be available to the application containers as files mounted to a specific path (e.g.,
/etc/secrets), and the process must be fully automated without storing any Conjur-related credentials in Git. The security team also requires that secret rotation in Conjur is reflected in the running pods within 5 minutes without requiring a pod restart.The DevOps team is evaluating two primary methods for secret injection: the 'Summon-in-Init' pattern and the 'Secrets Provider for K8s' sidecar pattern.
Which solution best meets all the company's requirements?
Show answer details
Correct answer: B
The 'Secrets Provider for K8s' sidecar pattern is the optimal solution. It meets all requirements: it runs continuously to handle secret rotation without pod restarts; it makes secrets available as files via a shared volume; and it uses the pod's intrinsic ServiceAccount identity for authentication, which integrates perfectly with a GitOps workflow without storing static credentials. The init container pattern fails the rotation requirement as it only runs once at startup.
- 10
When writing a Conjur policy, you need to define a group of administrators who can manage other users. What policy record type should be used to create this group?
- !______ db-adminsShow answer details
Correct answer: A
In Conjur's policy YAML syntax, the
!grouprecord type is used to declare a new group role. This group can then be granted permissions or have members, such as users, added to it.
