Questions for the PAM CDE RECERT were updated on : Dec 01 ,2025
Page 1 out of 15. Viewing questions 1-15 out of 221
Question 1
A customer is moving from an on-premises to a public cloud deployment. What is the best and most cost-effective option to secure the server key?
A. Install the Vault in the cloud the same way that you would in an on-premises environment Place the server key in a password protected folder on the operating system
B. Install the Vault in the cloud the same way that you would in an on-premises environment Purchase a Hardware Security Module to secure the server key
C. Install the Vault using the Amazon Machine Images and secure the server key using native cloud Key Management Systems
D. Install the Vault using the Amazon Machine Images and secure the server key with a Hardware Security Module
Answer:
C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 2
You need to move a platform from using PMTerminal to using Terminal Plugin Controller (TPC) What must you do?
A. Within PVWA Click Administration > Platform Management Select the platform and then click Edit. In the left pane, click Automatic Password Management > CPM Plug-in Set the ExeName parameter value to CyberArk TPC exe
B. Using PnvateArk. select the PasswordManager_Shared safe, and then select open Locate the mi file relating to the platform you wish to change and double click At the bottom of the file, insert a line "UseTPC = True" Remove any lines that reference "PMTerminal" and save Return the mi file to the safe Restart CPM for this change to take effect
C. Open the process file of the platform you wish to configure to use TPC Add the following parameter under the States section; "use TPC=yes"
D. It is not possible to change a platform from using PMTerminal to using TPC You must locate a new version of the platform that supports TPC and import the new platform over-writing the existing platform
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 3
When creating Distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed''
A. 5 - number of primary and satellite Vaults can be specified during installation
B. 3- all primary
C. 6-1 primary and 5 satellite
D. 10-2 primary and 8 satellite
Answer:
C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 4
DRAG DROP Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence
Answer:
None
User Votes:
Explanation:
Discussions
0/ 1000
Question 5
What is the default username for the PSM for SSH maintenance user?
A. proxymng
B. psmpjnamtenance
C. psmpma/ntenanceuser
D. psmpmnguser
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 6
You have been asked to limit a platform called "Wmdows_Servers" to safes called "WindowsDCT and "WindowsDC2" The platform must not be assigned to any other safe What is the correct way to accomplish this?
A. Edit the "Wmdows_Servers" platform, expand "Automatic Password Management", then select General and modify "AllowedSafes" to be (WindowsDC1)|(WindowsDC2).
B. Edit the "Windows_Servers" platform, expand "Automatic Password Management", then select Options and modify "AllowedSafes" to be (Win")
C. Edit the "WindowsDCI" and "WindowsDC2" safes through Safe Management. Add "Wmdows_Servers" to the "AliowedPlatforms".
D. Log in to PnvateArk using an Administrative user, Select File Server File Categories. Locate the category "WindowsServersAllowedSafes" and specify "WindowsDC! WindowsDC2"
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 7
Which configuration file and Vault utility are used to migrate the server key to an HSM?
A. DBparm.ini and CAVaultManager exe
B. VaultKeys.ini and CAVaultManager exe
C. DBparm.ini and ChangeServerKeys exe
D. VaultKeys.ini and ChangeServerKeys exe
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 8
Before the hardening process your customer identified a PSM Universal Connector executable that will be required to run on the PSM Which file should you update to allow this to run?
A. PSMConfigureAppLockerxml
B. PSMHardening xml
C. PSMAppConfig xml
D. PSMConfigureHardening xml
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 9
What is a prerequisite step betore CyberArk can be configured to support RADIUS authentication?
A. Log on to the PrivateArk Client display the User properties to the user to configure, run the Authentication method dropdown list and select Radius authentication.
B. In the RADIUS server define the CyberArk Vault as a RADIUS client/agent
C. In the Vault installation folder, run CAVaultManager as administrator with the SecureSecretFiles command
D. Navigate to /Server/Conf and open DBParm mi and set the RadiusServerslnfo parameter
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 10
Which parameter must be provided when registering a primary Vault in Azure, but not in Amazon Web Services''
A. /RecPub
B. /AdminPass
C. /MasterPass
D. /RDPGateway
Answer:
D
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 11
Which browser is supported for PSM Web Connectors developed using the CyberArk Plugin Generator Utility (PGUP
A. Internet Explorer
B. Google Chrome
C. Microsoft Edge
D. Firefox
Answer:
B
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 12
Which step is required to register a Vault manually in Amazon Web Services using CAVaultManager?
A. Specify Amazon as the cloud vendor using the CloudVendor Flag
B. After running the postinstall utility, restart the "PrivateArk Server" service
C. Specify the Cloud region using the /CloudRegion flag
D. Specify whether the Vault is distributed or stand alone
Answer:
C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 13
After installing the first PSM server and before installing additional PSM servers you must ensure the user performing the installation is not a direct owner of which safe?
A. PSMUnmanagedSessionAccounts Safe
B. PSMRecordmgsSessionAccounts Safe
C. PSMUnmanagedApphcationAccounts Safe
D. PSMSessionBackupAccounts Safe
Answer:
A
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 14
You are installing PSM for SSH with AD-Bridge in CyberArkSSHD mode for your customer. ACME Corp What do you need to install to meet your customer's needs? (Choose 2)
A. libssh
B. CARKpsmp-mfra
C. CARKpsmp
D. CARKpsmp-AD Bridge
Answer:
A, C
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 15
You are responsible for installing a CPM. Which Vault authorizations will your CyberArk user need to install the CPM?
A. Add Safes. Add/Update Users Manage Directory Mapping
B. Add Safes. Add/Update Users. Reset Users' Passwords, Activate Users, Manage Server File Categories
C. Manage Directory Mapping Backup All Safes. Restore Ail Safes
D. Audit Users Activate Users Add Network Areas Manage Directory Mapping