PAM-DEF Sample Questions

PAM-DEF Sample Questions & Answers

Core architecture, account onboarding and password rotation each tie for the top weight, alongside safe configuration and administration, user administration, PAM fundamentals and defense in depth, and system monitoring.

Launch the full PAM-DEF simulator →

Free PAM-DEF Sample Questions with Answers

Real questions from the CyberArk Defender – PAM practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Safe Management · Policy Management and Exceptions

    A hospital is using CyberArk to manage credentials for critical medical devices. A new regulation requires that any password for a device involved in patient care must be at least 20 characters long and changed every 30 days. However, a specific set of older infusion pumps can only support passwords with a maximum length of 15 characters. How should a Defender administrator implement this policy while maintaining compliance for the older devices?

    Show answer & explanation

    Correct answer: C

    Platform settings are the most appropriate place to define technical constraints like password length for a specific type of target system. The best practice is to set the general policy on a base platform and then duplicate and modify that platform for exception cases. This allows for granular control over the devices that cannot meet the standard, while the Master Policy can still enforce the 30-day rotation across both platforms. Using Master Policy exceptions for technical password constraints is less scalable than using platforms.

  2. Question 2Beginner

    Monitoring and Troubleshooting · Session Auditing

    A security team wants to ensure that all commands executed during PSM sessions on critical Linux servers are logged and auditable, even if the session itself is not being actively recorded as a video. Which component or feature must be configured to meet this requirement?

    Show answer & explanation

    Correct answer: C

    PSM provides two types of session recording: video and text (keystroke logging). To capture the specific commands typed during a session for auditing purposes, text recording must be enabled in the platform settings. This creates a searchable text log of all activity within the session, which is distinct from the video recording of the session.

  3. Question 3Beginner

    User and Group Management · LDAP Directory Mapping

    When defining an LDAP Directory Mapping in the PVWA, what is the primary purpose of the 'LDAP Branch' field?

    Show answer & explanation

    Correct answer: B

    The 'LDAP Branch' field specifies the starting point within the LDAP directory tree (e.g., an Organizational Unit) from which CyberArk will search for the users or groups being mapped. This allows administrators to limit the scope of the directory mapping to relevant parts of their Active Directory or LDAP structure.

  4. Question 4Advanced

    Monitoring and Troubleshooting · CPM Password Management Failure

    A CPM is failing to change the password for a local Windows account on a target server. The log file shows the error message: CACPM243W Failed to receive response from remote machine. Error: 5. Access is denied. The reconcile account has been verified to have the correct permissions on the target server. Which of the following is the MOST likely cause of this error?

    Show answer & explanation

    Correct answer: C

    The 'Access is denied' error (code 5) for remote operations on Windows servers, especially when credentials and network connectivity are correct, is a classic symptom of User Account Control (UAC) remote restrictions. For non-domain accounts (or even domain accounts under certain conditions), UAC can strip administrative tokens from remote connections. To resolve this, a specific registry key (LocalAccountTokenFilterPolicy) must be created and set to '1' on the target server to allow remote administrative tasks.

  5. Question 5Advanced

    Safe Management · Automated Safe Provisioning and Permissions

    A global retail corporation is implementing CyberArk Privileged Access Security. They have a central IT team in North America and regional IT teams in Europe and Asia. The security policy requires that the regional IT teams can only manage safes and accounts pertaining to their specific region.

    The current safe naming convention is Region-Application-Environment, for example, EU-SAP-Prod or APAC-Oracle-Dev. The regional teams are mapped to Active Directory groups, such as CyberArk-Admins-EU and CyberArk-Admins-APAC. The goal is to grant safe management permissions automatically based on the safe's name without requiring manual intervention from the global IT team for every new safe created.

    Which CyberArk feature should be used to achieve this automated, attribute-based safe permission model?

    Show answer & explanation

    Correct answer: D

    CyberArk's 'Safe Provisioning and Governance' feature is designed specifically for this use case. It allows administrators to create rules that automatically assign permissions to users and groups based on safe properties, including the safe name. By creating a rule that looks for safes starting with 'EU-' and automatically adds the 'CyberArk-Admins-EU' group, the company can achieve a fully automated, scalable, and policy-driven approach to safe delegation without manual scripting or cumbersome Master Policy exceptions.

  6. Question 6Intermediate

    CyberArk PAM Architecture · Vault Configuration

    What is the function of the AllowNonStandardFWAddresses parameter in the dbparm.ini file?

    Show answer & explanation

    Correct answer: B

    This parameter is critical in environments where components like PVWA, CPM, or PSM communicate with the Vault through a firewall performing NAT. When set to 'Yes', it instructs the Vault to ignore the source IP address in the packet's header (which would be the NAT device's IP) and instead use the IP address embedded within the CyberArk protocol data, ensuring the component is correctly identified and authorized.

  7. Question 7Intermediate

    Monitoring and Troubleshooting · PVWA User Interface Issues

    A user reports they can see an account in the PVWA, but the 'Connect' button is missing. They have 'Use' and 'List' permissions on the safe. What is the most likely reason for the missing 'Connect' button?

    Show answer & explanation

    Correct answer: B

    The 'Connect' button in the PVWA only appears if there is a Privileged Session Manager (PSM) server associated with the account's platform. This is configured by setting the PSMServerID in the platform settings. If this parameter is not defined, the PVWA does not know where to proxy the session, and therefore the 'Connect' button is not displayed, even if the user has appropriate permissions.

  8. Question 8Beginner

    CyberArk PAM Architecture · Vault Key Management

    To securely store the Server Key for a software-based Vault installation, the recommended best practice is to store it _____

    Show answer & explanation

    Correct answer: C

    For the highest level of security, CyberArk strongly recommends storing the Server Key, which encrypts all other keys in the Vault, within a FIPS 140-2 compliant Hardware Security Module (HSM). This ensures the key never resides on the server's disk and is protected by dedicated hardware, preventing its theft even if the Vault server itself is compromised.

  9. Question 9Beginner

    CyberArk PAM Architecture · Administrative Tools

    True or False: The PrivateArk Administrative Client can only be installed on the Vault server itself for security reasons.

    Show answer & explanation

    Correct answer: B

    The PrivateArk Administrative Client is a thick client that can be installed on any hardened administrative workstation that has network connectivity to the Vault server on port 1858. It is not restricted to being installed only on the Vault server. In fact, installing it on a separate, secure machine is a common practice.

  10. Question 10IntermediateSelect 2

    User and Group Management · Active Directory Integration

    An organization wants to simplify user access by allowing their employees to log into the PVWA using their existing corporate Active Directory credentials. They also want to automatically assign users to CyberArk groups based on their AD group memberships. Which features are required to implement this? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    LDAP (or LDAPS) integration is the primary method used to configure the PVWA to authenticate users against an Active Directory domain.

    Directory Mapping is the feature that allows an administrator to link an external group from LDAP/AD to an internal Vault group. This enables transparent user provisioning and automatic permission granting based on a user's existing AD group membership.

Ready for the real thing?

The full PAM-DEF simulator has every exam-style question, timed mode, and instant scoring.