PAM-CDE-RECERT Sample Questions

PAM-CDE-RECERT Sample Questions & Answers

Free CyberArk CDE Recertification practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full PAM-CDE-RECERT simulator →

Free PAM-CDE-RECERT Sample Questions with Answers

Real questions from the CyberArk CDE Recertification practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1

    True or False: When configuring a custom connection component for a web application using the PSM Web Connector framework, the WebFormFields property must be manually encrypted before being placed in the connection component configuration.

    Show answer & explanation

    Correct answer: B

    This is correct. The PVWA handles the encryption of sensitive parameters like WebFormFields automatically upon saving the connection component configuration. The administrator enters the values in plain text during setup.

  2. Question 2

    A CPM is failing to reconcile a password for a local account on a Windows Server. The reconcile account is a domain admin, and network connectivity is confirmed. The logs show the error message: CACPM344E Verifying Password Safe: , Folder: Root, Object: failed (try #1). Code: 2114, Error: The service has not been started. What is the most likely cause of this failure?

    Show answer & explanation

    Correct answer: B

    The error code 2114 and message The service has not been started directly correspond to the 'Server' service (service name LanmanServer) on the target machine being stopped. The CPM relies on this service for remote administration tasks, including password reconciliation for local accounts. This is the most direct cause.

  3. Question 3

    A client has implemented PTA and is concerned about the volume of data being sent from their Domain Controllers to the PTA server. They want to ensure that only relevant security events are forwarded to minimize network bandwidth usage. What is the recommended method to achieve this?

    Show answer & explanation

    Correct answer: C

    This is the CyberArk recommended best practice. Windows Event Forwarding (WEF) allows administrators to create subscriptions with XPath queries to select only the specific event IDs that PTA needs for its analysis. This filtering happens on the source (Domain Controller), ensuring that only relevant data is sent over the network, thus minimizing bandwidth.

  4. Question 4

    During a failover test of a DR Vault, the CAVaultManager command to promote the DR Vault fails with an error indicating that replication is still active. The administrator has already stopped the PrivateArk Server service on the primary Vault. What is the most likely reason for this failure?

    Show answer & explanation

    Correct answer: A

    The CyberArk Event Notification Engine (ENE) service is responsible for triggering replication. Even if the main Vault service is stopped, a running ENE can still attempt to initiate replication tasks, which can interfere with the DR promotion process. The documented DR procedure requires stopping both the PrivateArk Server and the ENE services on the primary Vault before promoting the DR Vault.

  5. Question 5

    Case Study: A healthcare organization is implementing CyberArk to manage credentials for its Electronic Health Record (EHR) system. The EHR system uses a combination of Windows servers, Oracle databases, and a proprietary Java thick-client application for administration.

    Current Situation: The organization has deployed a standard CyberArk architecture with a single Vault, PVWA, CPM, and PSM. The Windows and Oracle accounts are being managed successfully. However, they are struggling to manage sessions for the Java thick-client application, which requires specific command-line parameters on launch, including the target server and username.

    Requirements:

    1. All administrative sessions to the EHR thick-client must be isolated and recorded via PSM.
    2. The connection process must be seamless for the administrator, without them needing to know the privileged password.
    3. The solution must be able to pass dynamic parameters (server address, username) to the application at runtime.

    Constraint: The organization does not have the budget for a full-time developer to create a complex, custom-coded solution.

    Which approach should the CDE recommend to meet all requirements?

    Show answer & explanation

    Correct answer: D

    This is the optimal solution. The PSM Universal Connector is designed for this exact scenario. It allows an administrator to use AutoIt, a simple scripting language, to automate the launching of an application. The script can dynamically pull the address, username, and password from the Vault and pass them as command-line parameters or inject them into GUI fields. This meets all technical requirements, provides a seamless user experience, ensures recording, and avoids the need for complex .NET development, thus respecting the budget constraint.

  6. Question 6

    A CDE is configuring SAML authentication for the PVWA. The Identity Provider (IdP) is ADFS. After completing the configuration, users receive an error from the IdP stating that the SAML request is invalid. The IdP administrator confirms that the signing certificate is correct, but the Audience URL in the SAML request from the PVWA is not what they expected. Where in the PVWA configuration must the CDE correct the Audience URL value?

    Show answer & explanation

    Correct answer: A

    The Audience URL for the SAML request is a fundamental parameter that is defined in the web.config file located in the PVWA's installation directory (e.g., C:\inetpub\wwwroot\PasswordVault). This is the correct location to modify the value to match what is configured in the IdP's relying party trust.

  7. Question 7Select 3

    You are tasked with onboarding a new application that requires its password to be stored in a file on a specific Linux server. The password file must be owned by a specific service account, have 600 permissions, and be updated every 30 days. Which components are required to automate this entire process using CyberArk? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, D

    The CPM is required to automatically rotate the application's password in the Vault every 30 days, as per the policy requirement.

    The Credential Provider (CP) is the agent installed on the Linux server that securely retrieves the password from the Vault. It is essential for providing the password to the application.

    After the CPM changes the password in the Vault, a mechanism is needed to update the file on the Linux server. A custom script, triggered by the Credential Provider after a password change notification, is the standard way to write the new password to the file and set the required ownership and permissions (chown and chmod 600).

  8. Question 8

    The CreateCredFile utility is used to create the credential file for which CyberArk component user?

    Show answer & explanation

    Correct answer: C

    The CreateCredFile utility is specifically used to create the user credential file (user.ini) for the DR user. This file allows the PADR (Privileged Access Disaster Recovery) service to authenticate to the Vault to perform replication tasks.

  9. Question 9

    A customer is unable to view live and recorded PSM sessions via the HTML5 Gateway. They receive a generic connection error in the browser. The PVWA and PSM servers are confirmed to be running. The CDE needs to troubleshoot the communication flow. What is the correct sequence of connections for an HTML5-based PSM session?

    Show answer & explanation

    Correct answer: B

    This is the correct flow. The user's browser establishes a secure WebSocket connection to the HTML5 Gateway. The Gateway then communicates with the appropriate PSM server, and the PSM server connects to the target device. The Gateway acts as a tunnel, converting the RDP protocol into WebSocket traffic for the browser. Troubleshooting should focus on each of these legs: Browser-to-Gateway, Gateway-to-PSM, and PSM-to-Target.

  10. Question 10

    Case Study: An energy company has a mature CyberArk PAM implementation. They need to provide secure administrative access to a new cloud-based Kubernetes environment hosted in AWS EKS.

    Current Situation: The DevOps team uses kubectl command-line tools from their workstations to manage the EKS cluster. Authentication is currently managed via IAM roles and static access keys stored insecurely on developer laptops. The CISO has mandated that all access must be managed and audited through CyberArk.

    Requirements:

    1. Eliminate static access keys from developer workstations.
    2. Provide just-in-time, temporary credentials for kubectl access.
    3. All kubectl commands executed by administrators must be captured for audit.
    4. The solution must integrate with the existing on-premises CyberArk PAM infrastructure.

    Which combination of CyberArk components and configurations should be used to meet these requirements?

    Show answer & explanation

    Correct answer: C

    This is the most comprehensive and secure solution. PSM for SSH provides the secure, isolated, and audited session for all administrator activity. On the bastion host, the AAM Credential Provider can be used to dynamically fetch short-lived AWS credentials from the Vault. The kubectl commands are then run within this audited session using the temporary credentials, meeting all stated requirements.

10 more sample questions — free with an ExamJungle account, plus the full PAM-CDE-RECERT simulator with 230 exam-style questions.

Ready for the real thing?

The full PAM-CDE-RECERT simulator has every exam-style question, timed mode, and instant scoring.