CyberArk PAM CDE RECERT Exam Questions

Questions for the PAM CDE RECERT were updated on : Dec 01 ,2025

Page 1 out of 15. Viewing questions 1-15 out of 221

Question 1

A customer is moving from an on-premises to a public cloud deployment. What is the best and most
cost-effective option to secure the server key?

  • A. Install the Vault in the cloud the same way that you would in an on-premises environment Place the server key in a password protected folder on the operating system
  • B. Install the Vault in the cloud the same way that you would in an on-premises environment Purchase a Hardware Security Module to secure the server key
  • C. Install the Vault using the Amazon Machine Images and secure the server key using native cloud Key Management Systems
  • D. Install the Vault using the Amazon Machine Images and secure the server key with a Hardware Security Module
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

You need to move a platform from using PMTerminal to using Terminal Plugin Controller (TPC) What
must you do?

  • A. Within PVWA Click Administration > Platform Management Select the platform and then click Edit. In the left pane, click Automatic Password Management > CPM Plug-in Set the ExeName parameter value to CyberArk TPC exe
  • B. Using PnvateArk. select the PasswordManager_Shared safe, and then select open Locate the mi file relating to the platform you wish to change and double click At the bottom of the file, insert a line "UseTPC = True" Remove any lines that reference "PMTerminal" and save Return the mi file to the safe Restart CPM for this change to take effect
  • C. Open the process file of the platform you wish to configure to use TPC Add the following parameter under the States section; "use TPC=yes"
  • D. It is not possible to change a platform from using PMTerminal to using TPC You must locate a new version of the platform that supports TPC and import the new platform over-writing the existing platform
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

When creating Distributed Vault environment architecture, what is the maximum number of Vault
servers that can be deployed''

  • A. 5 - number of primary and satellite Vaults can be specified during installation
  • B. 3- all primary
  • C. 6-1 primary and 5 satellite
  • D. 10-2 primary and 8 satellite
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

DRAG DROP
Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence

Answer:

None

User Votes:

Explanation:

Discussions
vote your answer:
0 / 1000

Question 5

What is the default username for the PSM for SSH maintenance user?

  • A. proxymng
  • B. psmpjnamtenance
  • C. psmpma/ntenanceuser
  • D. psmpmnguser
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

You have been asked to limit a platform called "Wmdows_Servers" to safes called "WindowsDCT and
"WindowsDC2" The platform must not be assigned to any other safe What is the correct way to
accomplish this?

  • A. Edit the "Wmdows_Servers" platform, expand "Automatic Password Management", then select General and modify "AllowedSafes" to be (WindowsDC1)|(WindowsDC2).
  • B. Edit the "Windows_Servers" platform, expand "Automatic Password Management", then select Options and modify "AllowedSafes" to be (Win")
  • C. Edit the "WindowsDCI" and "WindowsDC2" safes through Safe Management. Add "Wmdows_Servers" to the "AliowedPlatforms".
  • D. Log in to PnvateArk using an Administrative user, Select File Server File Categories. Locate the category "WindowsServersAllowedSafes" and specify "WindowsDC! WindowsDC2"
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Which configuration file and Vault utility are used to migrate the server key to an HSM?

  • A. DBparm.ini and CAVaultManager exe
  • B. VaultKeys.ini and CAVaultManager exe
  • C. DBparm.ini and ChangeServerKeys exe
  • D. VaultKeys.ini and ChangeServerKeys exe
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

Before the hardening process your customer identified a PSM Universal Connector executable that
will be required to run on the PSM Which file should you update to allow this to run?

  • A. PSMConfigureAppLockerxml
  • B. PSMHardening xml
  • C. PSMAppConfig xml
  • D. PSMConfigureHardening xml
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

What is a prerequisite step betore CyberArk can be configured to support RADIUS authentication?

  • A. Log on to the PrivateArk Client display the User properties to the user to configure, run the Authentication method dropdown list and select Radius authentication.
  • B. In the RADIUS server define the CyberArk Vault as a RADIUS client/agent
  • C. In the Vault installation folder, run CAVaultManager as administrator with the SecureSecretFiles command
  • D. Navigate to /Server/Conf and open DBParm mi and set the RadiusServerslnfo parameter
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which parameter must be provided when registering a primary Vault in Azure, but not in Amazon
Web Services''

  • A. /RecPub
  • B. /AdminPass
  • C. /MasterPass
  • D. /RDPGateway
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Which browser is supported for PSM Web Connectors developed using the CyberArk Plugin
Generator Utility (PGUP

  • A. Internet Explorer
  • B. Google Chrome
  • C. Microsoft Edge
  • D. Firefox
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

Which step is required to register a Vault manually in Amazon Web Services using CAVaultManager?

  • A. Specify Amazon as the cloud vendor using the CloudVendor Flag
  • B. After running the postinstall utility, restart the "PrivateArk Server" service
  • C. Specify the Cloud region using the /CloudRegion flag
  • D. Specify whether the Vault is distributed or stand alone
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

After installing the first PSM server and before installing additional PSM servers you must ensure the
user performing the installation is not a direct owner of which safe?

  • A. PSMUnmanagedSessionAccounts Safe
  • B. PSMRecordmgsSessionAccounts Safe
  • C. PSMUnmanagedApphcationAccounts Safe
  • D. PSMSessionBackupAccounts Safe
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

You are installing PSM for SSH with AD-Bridge in CyberArkSSHD mode for your customer. ACME Corp
What do you need to install to meet your customer's needs? (Choose 2)

  • A. libssh
  • B. CARKpsmp-mfra
  • C. CARKpsmp
  • D. CARKpsmp-AD Bridge
Answer:

A, C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

You are responsible for installing a CPM.
Which Vault authorizations will your CyberArk user need to install the CPM?

  • A. Add Safes. Add/Update Users Manage Directory Mapping
  • B. Add Safes. Add/Update Users. Reset Users' Passwords, Activate Users, Manage Server File Categories
  • C. Manage Directory Mapping Backup All Safes. Restore Ail Safes
  • D. Audit Users Activate Users Add Network Areas Manage Directory Mapping
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2