PAM-SEN Exam Questions
132 real PAM-SEN exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51
Which statements are correct about the PSM HTML5 gateway? (Choose two.)
- Question #52
You want to change the name of the PVWAappuser of the second PVWA server. Which steps are part of the process? (Choose two.)
- Question #53
What are the basic network requirements to deploy a CPM server?
- Question #54
What is the purpose of the CPM_Preinstallation.ps1 script included with the CPM installation package?
- Question #55
When configuring RADIUS authentication, which utility is used to create a file containing an encrypted version of the RADIUS secret?
- Question #56
What is required before the first CPM can be installed?
- Question #57
You are installing the HTML5 gateway on a Linux host using the RPM provided. After installing the Tomcat webapp, what is the next step in the installation process?
- Question #58
As a member of a PAM Level-2 support team, you are troubleshooting an issue related to load balancing four PVWA servers at two data centers. You received a note from your Level-1 s...
- Question #59
Which statement is correct about a post-install hardening?
- Question #60
Which command should be executed to harden a Vault after registering it to Azure?
- Question #61
After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.2.2.2. What should you do?
- Question #62
In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA_Hardening.ps1 perform when run? (Choose two.)
- Question #63
In large-scale environments, it is important to enable the CPM to focus its search operations on specific Safes instead of scanning all Safes it sees in the Vault. How is this acco...
- Question #64
What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?
- Question #65
Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?
- Question #66
Which configuration file and Vault utility are used to migrate the server key to an HSM?
- Question #67
The account used to install a PVWA must have ownership of which safes? (Choose two.)
- Question #68
All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The...
- Question #69
Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?
- Question #70
Which component should be installed on the Vault if Distributed Vaults are used with PSM?
- Question #71
You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer. Which additional packages do you need to install to meet the customer's nee...
- Question #72
Which components can connect to a satellite Vault in a distributed Vault architecture?
- Question #73
In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?
- Question #74
Which service must be set to Automatic (delayed start) after the Vault is installed and configured?
- Question #75
A customer is moving from an on-premises to a public cloud deployment. What is the best and most cost-effective option to secure the server key?
- Question #76
Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After...
- Question #77
In which file must the attribute `SignAuthnRequest="true"' be added to the PartnerIdentityProvider element to support signed SAML requests?
- Question #78
When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
- Question #79
HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)
- Question #80
Which statement about REST API is correct? (Choose two.)
- Question #81
A first PSM server has been installed. What should you confirm before installing any additional PSM servers?
- Question #82
In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?
- Question #83
How should you configure PSM for SSH to support load balancing?
- Question #84
You are installing multiple PVWAs behind a load balancer. Which statement is correct?
- Question #85
A customer has two data centers and requires a single PVWA url. Which deployment provides the fastest time to reach the PVWA and the most redundancy?
- Question #86
A customer has three data centers distributed globally and wants highly-available PSM connections in each segmented zone. In addition, the customer needs a highly-available PSM con...
- Question #87
A customer asked you to help scope the company's PSM deployment. What should be included in the scoping conversation?
- Question #88
A customer has five main data centers with one PVWA in each center under different URLs. How can you make this setup fault tolerant?
- Question #89
This value needs to be added to the PVWA configuration file: Assuming all CyberArk PVWA servers were installed using default paths/folders, which configuration file should you loca...
- Question #90
What must you do to synchronize a new Vault server with an organization's NTP server?
- Question #95
What would be a good use case for the Replicate module?
- Question #96
What is the PRIMARY reason for installing more than 1 active CPM?
- Question #97
What is the purpose of the password Reconcile process?
- Question #98
Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?
- Question #99
When a DR vault server becomes an active vault, it will automatically fail back to the original state once the primary vault comes back online.
- Question #100
In order to avoid conflicts with the hardening process, third party applications like Antivirus and Backup Agents should be installed on the Vault server before installing the Vaul...
- Question #101
If a transparent user matches two different directory mappings, how does the system determine which user template to use?
- Question #102
The primary purpose of the CPM is Password Management.
- Question #103
The vault server uses a modified version of the Microsoft Windows firewall.
- Question #104
In a SIEM integration it is possible to use the fully-qualified domain name (FQDN) when specifying the SIEM server address(es)