CPC-SEN Sample Questions

CPC-SEN Sample Questions & Answers

Deploying the connector and infrastructure as code during install and configuration carries the top weight, alongside account onboarding, user and safe management, privileged session monitoring, SAML and API integration, and core PAM concepts.

Launch the full CPC-SEN simulator →

Free CPC-SEN Sample Questions with Answers

Real questions from the Cyberark Sentry - Privilege Cloud practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1

    A healthcare organization is deploying Privilege Cloud and has a strict requirement that all privileged sessions to their Electronic Health Record (EHR) database servers must be monitored in real-time by a security analyst. The connection must also be terminated immediately if suspicious activity is detected. Which Privilege Cloud feature directly supports this requirement?

    Show answer & explanation

    Correct answer: C

    The PSM's Live Session Monitoring feature is designed for this exact use case. It allows authorized users (like security analysts) to view active privileged sessions in real-time. This interface includes controls to take over or terminate the session immediately, providing the necessary oversight and intervention capabilities required by the organization.

  2. Question 2

    An administrator uses the out-of-the-box "Amazon Web Services - AWS - Access Keys" platform to manage the access key of an AWS IAM user. The key has become unsynchronized, and the administrator plans to add a reconcile account to the platform so that the CPM can reconcile it. What should the administrator know about this plugin?

    Show answer & explanation

    Correct answer: A

    The AWS access keys plugin connects to AWS through the REST API, which is its only connection method. Its supported actions are Verify (connect to AWS) and Change (the IAM user must be allowed to change its own access key, globally or by group). Reconcile and Delete are not supported, so a reconcile account cannot recover an unsynchronized key. The required account parameters are Username (the IAM user), AWS Account ID, and AWS Access Key ID, and the access key secret is stored as the password.

  3. Question 3

    A university is configuring SAML authentication for Privilege Cloud with its central Shibboleth Identity Provider (IdP). After the integration is configured, users receive an 'Invalid Assertion' SAML error when they are redirected back to the Privilege Cloud portal. The IdP logs show successful authentication, the IdP's clock is synchronized with a reliable NTP source, and the Audience value configured in the IdP matches the value provided for the Privilege Cloud SAML configuration. What is the most likely misconfiguration?

    Show answer & explanation

    Correct answer: A

    When the IdP confirms a successful authentication but the assertion is rejected, and clock skew and the Audience value have been ruled out, the most likely cause is a trust problem. Privilege Cloud verifies the signature of the SAML response with the IdP's signing certificate (IdentityProviderCertificate, or the certificate in the IdP metadata provided for the configuration: "used to verify the authenticity of the responses"). If that certificate is missing, expired or different from the one the IdP signs with, the assertion is rejected even though the user authenticated at the IdP. In Privilege Cloud Standard this information is provided to Technical Support; in Shared Services it is part of the external IdP's inbound metadata in Identity Administration.

  4. Question 4Select 2

    In a Privilege Cloud Standard deployment, which two functions does the optional Secure Tunnel client provide? (Choose two.)

    Show answer & explanation

    Correct answers: C, D

    In the Privilege Cloud Standard architecture, the Secure Tunnel client is an optional on-premises component that 'enables you to securely connect Privilege Cloud with your LDAP and SIEM servers' (and set up legacy offline/remote access). The Privilege Cloud backend uses it to reach the on-premises directory for LDAPS integration and to deliver Vault audit records to the customer's SIEM over syslog. CPM and PSM do not use the tunnel: they connect directly to the Vault backend on TCP 1858 (and 443 for REST), and session isolation and recording are PSM functions. In Shared Services, AD/LDAP integration is handled by the Identity Connector and SIEM by the Audit service, and Secure Tunnel is no longer supported for new deployments as of June 30, 2026.

    In the Privilege Cloud Standard architecture, the Secure Tunnel client is an optional on-premises component that 'enables you to securely connect Privilege Cloud with your LDAP and SIEM servers' (and set up legacy offline/remote access). The Privilege Cloud backend uses it to reach the on-premises directory for LDAPS integration and to deliver Vault audit records to the customer's SIEM over syslog. CPM and PSM do not use the tunnel: they connect directly to the Vault backend on TCP 1858 (and 443 for REST), and session isolation and recording are PSM functions. In Shared Services, AD/LDAP integration is handled by the Identity Connector and SIEM by the Audit service, and Secure Tunnel is no longer supported for new deployments as of June 30, 2026.

  5. Question 5

    Case Study

    A rapidly growing e-commerce company is deploying CyberArk Privilege Cloud to manage access to its production AWS environment and on-premises legacy systems. The company has a large, distributed DevOps team that requires just-in-time (JIT) access to EC2 instances for troubleshooting. The security team has mandated that all access must be temporary, request-based, and fully audited. The legacy systems are managed by a separate IT operations team that requires persistent, standing access.

    Current Situation:
    The company uses Okta as its corporate Identity Provider (IdP) and has integrated it with Privilege Cloud for user authentication. The DevOps team members are part of an 'AWS-Admins' group in Okta. The IT operations team is in an 'IT-Ops' group. A single Safe named 'Production-Servers' has been created to store all privileged accounts.

    Requirements:

    1. DevOps users must request access to specific EC2 instances for a limited time (e.g., 4 hours).
    2. Access for DevOps users must require approval from a team lead.
    3. IT-Ops users should have immediate, non-expiring access to the legacy system accounts.
    4. All session activity for both teams must be recorded.

    Which combination of configurations will meet all these requirements?

    Show answer & explanation

    Correct answer: B

    Safes are the access boundary and the Master Policy is applied per platform. Placing the AWS accounts in an 'AWS-JIT' Safe on a dedicated platform lets a Master Policy exception activate 'Require dual control password access approval' for them only: each request states the access timeframe, team leads who are Safe members with 'Authorize account requests' confirm it, and EnforceDualControlTimeframeOnPSMConnections ends PSM sessions when the approved timeframe expires. IT-Ops receive standing 'Use accounts' access in 'Legacy-Persistent', whose accounts use platforms without dual control. 'Record and save session activity' is active by default, so both teams' PSM sessions are recorded. Giving IT-Ops 'Retrieve accounts' would allow unrecorded direct use, and exceptions cannot be created for an Okta group.

  6. Question 6

    An organization uses classic onboarding rules to automatically onboard accounts that the CPM Scanner discovers on Windows and Unix machines. Which properties can the administrator use to define the scope of a new onboarding rule?

    Show answer & explanation

    Correct answer: A

    A classic onboarding rule's scope is defined by System type (Windows/Unix), Machine type (Any/Workstation/Server), Account type (Local) and Account category (Any/Privileged/Non-privileged), and can be refined by keyword (for example user name or machine name; the API offers UserNameFilter/AddressFilter with Equals/Begins/Ends). The Platform and Safe are the rule's destination, not its scope. There are no last-logon, password-age, OU or group-membership filters in onboarding rules. Accounts that match no rule go to the Pending Accounts list. Classic Discovery is being deprecated in favor of Discovery remediation rules.

  7. Question 7

    A Privilege Cloud Connector will run as a VMware virtual machine. Which setting does CyberArk recommend in the Connector's virtual machine installation settings to ensure optimal performance?

    Show answer & explanation

    Correct answer: B

    The Connector requirements list virtual machine installation settings recommended 'to ensure optimal performance': in VMware environments install VMware Tools on every Connector VM (it also exposes the PerfMon counter VM Processor > Effective VM Speed in MHz), allocate enough memory, use the latest VM version, make sure hyper-threading is enabled (VMware 5.5 and later), and set a fixed processing-power (MHz) reservation. These are performance recommendations - VMware Tools is not a registration prerequisite, and no static MAC address is required.

  8. Question 8Select 2

    Which of the following are valid user types that can be created and managed directly within the CyberArk Privilege Cloud Identity Administration portal? (Select TWO).

    Show answer & explanation

    Correct answers: A, E

    In Identity Administration an administrator can create CyberArk (Idira) Cloud Directory users one at a time or in bulk (Users > Add User), and service users - non-human users for API and automation work, created with Add user > Service user or with 'Is Service User'/'Is OAuth confidential client' selected. Federated users are not created manually: they are created automatically in the Cloud Directory when a user first signs in through an external IdP, and their lifecycle stays with that IdP. 'Vault User' and 'Guest User' are not Identity user types.

    In Identity Administration an administrator can create CyberArk (Idira) Cloud Directory users one at a time or in bulk (Users > Add User), and service users - non-human users for API and automation work, created with Add user > Service user or with 'Is Service User'/'Is OAuth confidential client' selected. Federated users are not created manually: they are created automatically in the Cloud Directory when a user first signs in through an external IdP, and their lifecycle stays with that IdP. 'Vault User' and 'Guest User' are not Identity user types.

  9. Question 9

    A user clicks Connect in the Privilege Cloud portal to open a PSM RDP session to a target Windows server, but the session fails to launch and the user's RDP client displays: 'The remote computer requires Network Level Authentication (NLA), which your computer does not support.' The error started after a new hardening GPO was linked to the OU that contains the Privilege Cloud Connector servers. What is the recommended solution?

    Show answer & explanation

    Correct answer: D

    Privilege Cloud requires Network Level Authentication to be disabled on the Connector (PSM) server. Sessions launched from the portal use an RDP file generated by Privilege Cloud (which includes the EnableCredSspSupport setting), and CyberArk notes that when NLA is enabled on the PSM server this portal connection method is not supported, so the user's RDP client reports that the remote computer requires NLA. Disabling NLA on the PSM server (for example, excluding the Connectors from a GPO that enforces it) restores the documented configuration; NLA can remain enabled on the target servers, because it is not the PSM-to-target connection that fails. There is no EnableNLA connection-component parameter, and target-side group changes do not affect the client-to-PSM connection.

  10. Question 10

    True or False: The Privilege Cloud Connector must be joined to the customer's Active Directory domain to manage Windows domain accounts.

    Show answer & explanation

    Correct answer: B

    False. Privilege Cloud supports both in-domain and out-of-domain Connector deployments: the prerequisites script has an -OutOfDomain switch, and out-of-domain Connectors are hardened with an INF-based procedure instead of the domain GPO. The CPM manages domain accounts over the network using the account's own credentials or linked logon/reconcile accounts (CyberArk recommends the Windows Domain Accounts via LDAP plugin), so the Connector does not have to be a domain member. Domain membership is required only in specific scenarios - for example, customers who enforce NLA for native RDP connections through PSM must install PSM on an in-domain machine.

Ready for the real thing?

The full CPC-SEN simulator has every exam-style question, timed mode, and instant scoring.