Skip to content

SECRET-SEN CyberArk Sentry – Secrets Manager Practice Questions

Prepare for SECRET-SEN with more than an answer.

225 questions in the full set20 sample questionsUpdated Jan 29, 2026
Exam fee
$200 USD
Level
Sentry
Valid for
2 years
Domains covered on the exam 5
  1. CyberArk Secrets Manager Architecture20%
  2. Installation and Configuration25%
  3. Policy Management and Security20%
  4. Kubernetes Integration20%
  5. Application Integration15%
  1. 1

    True or False: When deploying the Vault Conjur Synchronizer, the Synchronizer user in the Vault must be a member of the Vault Admins group.

    Show answer details

    Correct answer: B

    The statement is false. The Synchronizer user does not need to be a Vault Admin. According to the principle of least privilege, it only needs specific, limited permissions: List Accounts, View Safe Members, and Retrieve Accounts on the Safes containing the secrets to be synchronized, as well as membership in the PVWAMonitors group.

  2. 2

    A policy defines a layer and grants a host within that layer permissions to a secret. Later, a developer needs to move the host to a different layer. What is the most efficient way to update the host's layer membership without disrupting its identity?

    Show answer details

    Correct answer: B

    The correct way to manage role membership is with !grant and !revoke. To move the host, you load a policy that revokes its membership from the old layer and grants it membership in the new layer. This modifies the existing host's relationships without needing to delete and recreate the host identity itself, which would invalidate its API key.

  3. 3

    A financial technology company, FinCorp, is deploying a critical payment processing application in a Kubernetes cluster. Due to regulatory compliance, all access to secrets must be strictly controlled and audited. The application pods need credentials to access a transactional database and an external payment gateway API. The Security Operations team manages all credentials centrally in a CyberArk Vault.

    The current architecture uses the Vault Conjur Synchronizer to replicate secrets to a Conjur DAP cluster. The Kubernetes Authenticator is configured to grant pod identities access to these secrets. The security team has defined a policy that maps the application's Kubernetes ServiceAccount to a Conjur host. During a security review, an auditor raises a concern about the process of authenticating the application to Conjur.

    The auditor's question is: 'How does Conjur verify that a JWT it receives actually originates from a legitimate pod in the cluster and not from a rogue process that has stolen a token?'

    Which component and action form the basis of this verification process?

    Show answer details

    Correct answer: B

    This is the core of the Kubernetes authentication mechanism. Conjur does not trust the JWT outright. Instead, the authenticator service, which has its own trusted identity with the Kubernetes API, takes the JWT from the connecting pod and sends it to the TokenReview API endpoint. The Kubernetes API Server, the ultimate authority on token validity, checks if the token is valid, active, and not expired. Only upon receiving a successful TokenReview response does Conjur consider the pod authenticated. This prevents replay attacks or the use of stolen, expired tokens.

    sequenceDiagram participant Pod participant Conjur as Conjur Authenticator participant K8s as Kubernetes API Server Pod->>Conjur: Authenticate with ServiceAccount JWT Conjur->>K8s: Create TokenReview(JWT) K8s-->>Conjur: TokenReviewResponse (Valid/Invalid) alt Token is Valid Conjur-->>Pod: Conjur Access Token else Token is Invalid Conjur-->>Pod: 401 Unauthorized end

  4. 4

    A Python application running on a virtual machine needs to fetch secrets from Conjur. The security policy prohibits storing long-lived API keys on the VM. The VM has an IAM role assigned to it in AWS. Which authentication method should be used to provide the application with a Conjur identity?

    Show answer details

    Correct answer: C

    The Authn-AWS authenticator is specifically designed for this purpose. It leverages the trusted identity provided by AWS IAM. The application makes a signed AWS API request, which Conjur can validate. This proves the application's identity (its IAM role) without needing any pre-configured secrets on the VM itself, fulfilling the security requirement.

  5. 5

    What is the function of the evoke command in a Conjur appliance?

    Show answer details

    Correct answer: B

    The evoke command is the primary tool for administering the Conjur appliance itself. It is used for tasks outside of the data plane, such as configuring the Master, setting up Standbys and Followers, managing certificates, and performing backups and restores. Policy management is typically done with the conjur CLI.

  6. 6

    A financial services company is designing a multi-site Conjur DAP architecture for disaster recovery. They have a primary data center (DC1) and a secondary data center (DC2). The requirement is that if DC1 fails completely, DC2 must be able to continue serving secrets without manual intervention. The cluster spans both data centers. What is the minimum number of nodes required, and how should they be distributed to ensure automatic failover and maintain quorum if DC1 is lost?

    Show answer details

    Correct answer: C

    To maintain quorum and enable automatic failover after losing an entire data center, the surviving data center must contain a majority of the voting nodes (Master and Standbys). In a 5-node cluster (1 Master, 4 Standbys), the quorum size is 3. By placing 3 Standbys in DC2, if DC1 (containing the Master and 1 Standby) is lost, the 3 remaining Standbys in DC2 can form a new quorum, elect a new Master, and continue operations. Followers do not participate in quorum elections.

  7. 7

    An administrator deployed the Conjur Kubernetes Authenticator. Pods in the prod-apps namespace are failing to authenticate, and the authenticator logs show 401 Unauthorized errors. The policy correctly defines the host identity host/prod-apps/deployment/my-app. The pod's ServiceAccount is also correctly defined and assigned. Which of the following is the most likely cause for this authentication failure?

    Show answer details

    Correct answer: C

    The Conjur Kubernetes Authenticator works by validating a pod's ServiceAccount token with the Kubernetes API server. To do this, it must have the permission to create tokenreviews.authentication.k8s.io resources. If the authenticator's ClusterRole is missing this permission, the K8s API server will reject its validation requests, leading to a 401 Unauthorized error when the pod tries to authenticate to Conjur.

  8. 8

    A DevOps team is structuring their Conjur policies for a microservices application. They want to grant a specific service, billing-api, read and execute permissions on a database password. They also want to allow members of the db-admins group to update the password. Which of the following policy statements are required to achieve this configuration? (Select TWO)

    Show answer details

    Correct answer: C, D

    This statement correctly uses !permit to grant the billing-api host the necessary read and execute privileges on the db/password variable.

    This statement correctly uses !permit to grant the db-admins group the specific update privilege on the db/password variable, adhering to the principle of least privilege.

  9. 9

    A rapidly growing e-commerce company is migrating its entire platform to Google Kubernetes Engine (GKE). Their security team has mandated the use of CyberArk Conjur for all secrets management. The platform consists of dozens of microservices, each with its own database credentials, API keys, and certificates. The DevOps team uses a GitOps workflow with ArgoCD to manage all Kubernetes manifests.

    The current challenge is integrating Conjur into this GitOps model. The secrets must be available to the application containers as files mounted to a specific path (e.g., /etc/secrets), and the process must be fully automated without storing any Conjur-related credentials in Git. The security team also requires that secret rotation in Conjur is reflected in the running pods within 5 minutes without requiring a pod restart.

    The DevOps team is evaluating two primary methods for secret injection: the 'Summon-in-Init' pattern and the 'Secrets Provider for K8s' sidecar pattern.

    Which solution best meets all the company's requirements?

    Show answer details

    Correct answer: B

    The 'Secrets Provider for K8s' sidecar pattern is the optimal solution. It meets all requirements: it runs continuously to handle secret rotation without pod restarts; it makes secrets available as files via a shared volume; and it uses the pod's intrinsic ServiceAccount identity for authentication, which integrates perfectly with a GitOps workflow without storing static credentials. The init container pattern fails the rotation requirement as it only runs once at startup.

  10. 10

    When writing a Conjur policy, you need to define a group of administrators who can manage other users. What policy record type should be used to create this group?

    - !______ db-admins

    Show answer details

    Correct answer: A

    In Conjur's policy YAML syntax, the !group record type is used to declare a new group role. This group can then be granted permissions or have members, such as users, added to it.

Create an account to continue.