PAM-SEN Exam Questions
136 real PAM-SEN exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Managing and Monitoring Privileged Sessions (Advanced)
Which statements are correct about the PSM HTML5 gateway? (Choose two.)
PSM HTML5 gatewayNLAprinter redirectionsession limitations - Question #52Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
You want to change the name of the PVWAappuser of the second PVWA server. Which steps are part of the process? (Choose two.)
PVWA appusercredential filePrivateArkuser rename process - Question #53Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
What are the basic network requirements to deploy a CPM server?
CPMnetwork requirementsPort 1858PVWA connectivity - Question #54Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
What is the purpose of the CPM_Preinstallation.ps1 script included with the CPM installation package?
CPM installationpre-installation scriptTLS configuration.NET version - Question #55Integrations with External Systems
When configuring RADIUS authentication, which utility is used to create a file containing an encrypted version of the RADIUS secret?
RADIUSCreateAuthFileencrypted secretauthentication utility - Question #56Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
What is required before the first CPM can be installed?
CPM installationVault prerequisitePVWA prerequisiteinstallation order - Question #57Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
You are installing the HTML5 gateway on a Linux host using the RPM provided. After installing the Tomcat webapp, what is the next step in the installation process?
HTML5 gatewayTomcatguacdinstallation sequence - Question #58Advanced Auditing, Reporting and Troubleshooting
As a member of a PAM Level-2 support team, you are troubleshooting an issue related to load balancing four PVWA servers at two data centers. You received a note from your Level-1 s...
load balancingPVWALoadBalancerClientAddressHeadersource IP troubleshooting - Question #59Security Best Practices and Hardening
Which statement is correct about a post-install hardening?
Vault hardeningCAVaultHarden.exepost-installationhardening options - Question #60Security Best Practices and Hardening
Which command should be executed to harden a Vault after registering it to Azure?
Vault hardeningAzureHardenVaultFW.ps1firewall hardening - Question #61Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.2.2.2. What should you do?
NTP configurationWindows FirewallVault installationDBParm.ini - Question #62Security Best Practices and Hardening
In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA_Hardening.ps1 perform when run? (Choose two.)
PVWA hardeningIIS hardeningWindows FirewallPVWA_Hardening.ps1 - Question #63Managing and Protecting Privileged Accounts and Credentials (Advanced)
In large-scale environments, it is important to enable the CPM to focus its search operations on specific Safes instead of scanning all Safes it sees in the Vault. How is this acco...
CPM configurationAllowedSafe parameterplatform policySafe scanning - Question #64Integrations with External Systems
What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?
RADIUS authenticationRADIUS client configurationVault integrationMFA - Question #65Security Best Practices and Hardening
Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?
PSM for SSHauto-hardeningpsmpparmsconfiguration file - Question #66Security Best Practices and Hardening
Which configuration file and Vault utility are used to migrate the server key to an HSM?
HSM integrationserver key migrationVaultKeys.iniChangeServerKeys.exe - Question #67Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
The account used to install a PVWA must have ownership of which safes? (Choose two.)
PVWA installationsafe ownershipVaultInternalNotification Engine - Question #68Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The...
distributed Vault architecturePVWA deploymentload balancingperformance optimization - Question #69Integrations with External Systems
Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?
SAML configurationIdP AudienceServiceProviderNamesaml.config - Question #70Disaster Recovery and High Availability
Which component should be installed on the Vault if Distributed Vaults are used with PSM?
distributed VaultRabbitMQPSM integrationsatellite Vault - Question #71Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer. Which additional packages do you need to install to meet the customer's nee...
PSM for SSHAD-BridgeCyberArkSSHD integrated modepackage dependencies - Question #72Disaster Recovery and High Availability
Which components can connect to a satellite Vault in a distributed Vault architecture?
distributed Vault architecturesatellite Vaultcomponent connectivityPVWA PSM - Question #73Managing and Monitoring Privileged Sessions (Advanced)
In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?
PSM recordingsstorage planningretention periodcapacity sizing - Question #74Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
Which service must be set to Automatic (delayed start) after the Vault is installed and configured?
Vault installationWindows Time serviceNTPservice startup type - Question #75Security Best Practices and Hardening
A customer is moving from an on-premises to a public cloud deployment. What is the best and most cost-effective option to secure the server key?
cloud deploymentserver key protectionnative cloud KMSHSM - Question #76Managing and Monitoring Privileged Sessions (Advanced)
Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After...
MFA cachingPSM for SSHdefault configurationCyberArkSSHD mode - Question #77Integrations with External Systems
In which file must the attribute `SignAuthnRequest="true"' be added to the PartnerIdentityProvider element to support signed SAML requests?
SAML signed requestsPVWAConfig.xmlSignAuthnRequestIdP integration - Question #78Disaster Recovery and High Availability
When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
distributed Vault architecturesatellite Vaultscalability limitsVault topology - Question #79Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)
HTML5 GatewayOS compatibilityRHELCentOS - Question #80Integrations with External Systems
Which statement about REST API is correct? (Choose two.)
REST APIauthentication tokensession managementAPI security - Question #81Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
A first PSM server has been installed. What should you confirm before installing any additional PSM servers?
PSM installationPSMUnmanagedSessionAccountscomponent prerequisitesmulti-PSM deployment - Question #82Advanced Auditing, Reporting and Troubleshooting
In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?
SNMPPARAgent.iniVault configurationlog filtering - Question #83Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
How should you configure PSM for SSH to support load balancing?
PSM for SSHload balancingVIP configurationPVWA options - Question #84Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
You are installing multiple PVWAs behind a load balancer. Which statement is correct?
PVWAload balancersticky sessionsmulti-PVWA deployment - Question #85Disaster Recovery and High Availability
A customer has two data centers and requires a single PVWA url. Which deployment provides the fastest time to reach the PVWA and the most redundancy?
PVWA deploymentglobal traffic managermulti-datacenterredundancy - Question #86Disaster Recovery and High Availability
A customer has three data centers distributed globally and wants highly-available PSM connections in each segmented zone. In addition, the customer needs a highly-available PSM con...
PSM deploymentmulti-datacenterload balancingzone segmentation - Question #87Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
A customer asked you to help scope the company's PSM deployment. What should be included in the scoping conversation?
PSM scopingsession recordingsretention periodcapacity planning - Question #88Disaster Recovery and High Availability
A customer has five main data centers with one PVWA in each center under different URLs. How can you make this setup fault tolerant?
PVWAfault toleranceload balancingmulti-datacenter - Question #89Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
This value needs to be added to the PVWA configuration file: Assuming all CyberArk PVWA servers were installed using default paths/folders, which configuration file should you loca...
PVWAweb.configconfiguration file pathinstallation defaults - Question #90Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
What must you do to synchronize a new Vault server with an organization's NTP server?
Vault configurationNTP synchronizationfirewall rulesAllowNonStandardFWAddresses - Question #91Security Best Practices and Hardening
Drag and Drop Question Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence. Answer:
CPM hardeningout-of-domain deploymenthardening scriptPowerShell - Question #92Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
Drag and Drop Question The installCyberArkSSHD parameter on the PSM for SSH can be set to multiple values. Match each value to the correct condition. Answer:
PSM for SSHinstallCyberArkSSHDSSHD configurationPAM module - Question #93Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
Drag and Drop Question Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence. Answer:
PVWA installationinstallation sequencecomponent registrationhardening scripts - Question #94Disaster Recovery and High Availability
Drag and Drop Question Arrange the steps to failover to the DR CPM in the correct sequence. Answer:
CPM failoverDR proceduresVault.inicredential file recreation - Question #95Disaster Recovery and High Availability
What would be a good use case for the Replicate module?
Replicate moduleoff-site replicationdisaster recoverybackup strategy - Question #96Secure Privileged Access Management (PAM) Solution Deployment (Advanced)
What is the PRIMARY reason for installing more than 1 active CPM?
CPM deploymentscalabilitydevice management capacitymultiple CPMs - Question #97Managing and Protecting Privileged Accounts and Credentials (Advanced)
What is the purpose of the password Reconcile process?
password reconciliationCPMaccount managementpassword rotation - Question #98Advanced Auditing, Reporting and Troubleshooting
Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?
SNMP trapsparagent.iniVault monitoringalerting configuration - Question #99Disaster Recovery and High Availability
When a DR vault server becomes an active vault, it will automatically fail back to the original state once the primary vault comes back online.
DR vaultfailbackPADR.iniAllowFailback - Question #100Security Best Practices and Hardening
In order to avoid conflicts with the hardening process, third party applications like Antivirus and Backup Agents should be installed on the Vault server before installing the Vaul...
Vault hardeningthird-party applicationsinstallation ordersecurity baseline