SECRET-SEN Sample Questions & Answers
Deploying Conjur and the Vault Conjur Synchronizer carries the top weight, alongside Kubernetes secrets management guided by the Conjur policy framework, overall Secrets Manager architecture, and application integration through Summon or the API.
Launch the full SECRET-SEN simulator →Showing 10 of 20 free samples.
- Question 1Beginner
CyberArk Secrets Manager Architecture · Vault Conjur Synchronizer Functionality
True or False: When using the Vault Conjur Synchronizer, secrets are synchronized from the Vault to Conjur in near real-time, but updates made directly in Conjur are NOT synchronized back to the Vault.
Show answer & explanation
Correct answer: A
The statement is true. The Vault Conjur Synchronizer is designed for unidirectional synchronization. It treats the CyberArk Vault as the single source of truth for secrets. Any changes made to synchronized secrets directly within Conjur will be overwritten during the next synchronization cycle from the Vault.
- Question 2Intermediate
Installation and Configuration · Troubleshooting Follower Installation
During the installation of a Conjur Follower, the process fails. Review of the logs shows 'Failed to authenticate to master: SSL certificate validation failed'. The administrator has already imported the Master's certificate into the Follower's trust store using
evoke ca import. What is the most likely remaining cause of this issue?Show answer & explanation
Correct answer: A
Even if the CA that signed the certificate is trusted, SSL validation will still fail if the hostname used to connect to the Master does not match one of the names listed in the certificate's Subject Alternative Name (SAN) field. This is a common oversight during setup, where an IP address or a different DNS alias is used to configure the Follower.
- Question 3Advanced
Policy Management and Security · Advanced Policy Controls
A security architect is designing a Conjur policy and needs to prevent a powerful role from being granted to any new members accidentally. The architect wants to ensure that the membership of the
global-adminsgroup can never be changed after it is initially defined. Which policy record should be used to achieve this?Show answer & explanation
Correct answer: B
The
!revokestatement is used to permanently remove theadminprivilege from a role'sadmin_option. By revoking theadmin_optionfrom theglobal-adminsgroup itself, no one (not even users with admin rights on the group) can subsequently grant new members to that group. This effectively makes the group's membership immutable. - Question 4Beginner
Application Integration · Using Summon
A developer is using Summon to provide a secret to a shell script. The
secrets.ymlfile contains the following entry:DB_PASSWORD: !var staging/mysql/passwordThe script is executed with the command
summon ./start-app.sh. Insidestart-app.sh, how would the developer access the value of the secret?Show answer & explanation
Correct answer: B
Summon retrieves the secrets defined in
secrets.ymland exposes them as environment variables to the subprocess it executes. The key in the YAML file (DB_PASSWORD) becomes the name of the environment variable, so the script can access the secret's value using$DB_PASSWORD. - Question 5Intermediate
Policy Management and Security · Policy Loading Methods
A security audit reveals that a Conjur policy loaded in 'append' mode has inadvertently granted excessive permissions over time. The administrator needs to reset the permissions for the
production/databasepolicy branch to a known, clean state defined in a file namedprod-db-reset.yml. Which command should be used to achieve this?Show answer & explanation
Correct answer: C
The
--replacemethod is designed for this exact scenario. It completely deletes all existing policy objects within the specified branch (production/database) before loading the new policy from the file. This ensures that any old or excessive permissions are removed and only the permissions fromprod-db-reset.ymlexist. - Question 6Intermediate
CyberArk Secrets Manager Architecture · Quorum and Failover Scenarios
A company has a Conjur cluster with one Master and four Standby nodes. During a network event, the Master becomes isolated from all four Standby nodes, but the Standby nodes can still communicate with each other. Applications, which connect to the Standby nodes via a load balancer, report that they can no longer retrieve secrets. What is the state of the cluster?
graph TD subgraph "Initial State" M1(Master) --- S1(Standby) M1 --- S2(Standby) M1 --- S3(Standby) M1 --- S4(Standby) end subgraph "Partitioned State" subgraph "Partition A" M1_iso(Isolated Master) end subgraph "Partition B" S1_p(Standby) S2_p(Standby) S3_p(Standby) S4_p(Standby) S1_p --- S2_p S2_p --- S3_p S3_p --- S4_p end end style M1_iso fill:#f9fShow answer & explanation
Correct answer: C
A Conjur cluster with 5 voting members (1 Master + 4 Standbys) requires a quorum of
(5/2) + 1 = 3members to operate. When the Master is isolated, the remaining four Standby nodes still constitute a majority (4 > 3). They will hold an election, promote one Standby to be the new Master, and the cluster will remain fully functional for both reads and writes. The application failures are likely due to a separate issue, such as the load balancer still attempting to route traffic to the isolated old Master. - Question 7Beginner
Installation and Configuration · Initial Setup and Security
When deploying a Conjur cluster using Docker, which command is used to generate the master key that encrypts sensitive data within the Conjur backend?
Show answer & explanation
Correct answer: D
In a standard Docker Compose deployment of Conjur, the
docker-compose run --no-deps conjur data-key generatecommand is used to create the data encryption key. This key is crucial for the security of the Conjur instance and must be backed up securely. The output of this command is then stored and used to start the Conjur container. - Question 8Intermediate
Application Integration · CI/CD Integration Patterns
An organization wants to authenticate Jenkins jobs to Conjur. Each Jenkins job runs on a dynamically provisioned agent. What is the most secure and scalable method to authenticate these Jenkins jobs so they can retrieve secrets?
Show answer & explanation
Correct answer: B
The JWT Authenticator is designed for this use case. It allows external identity providers like Jenkins to issue short-lived, signed JSON Web Tokens (JWTs). Conjur can be configured to trust Jenkins as an issuer and validate these tokens. This method provides a unique, auditable identity for each job without managing long-lived static API keys, making it highly secure and scalable for dynamic environments.
- Question 9Intermediate
Kubernetes Integration · Troubleshooting Secrets Provider
A Kubernetes pod, configured to use the Secrets Provider for K8s, is failing to start. The
secrets-providercontainer log shows the error:Failed to retrieve secrets: 404 Not Found for variable 'production/webapp/api-key'. The Conjur policy granting the pod's identity permission to the variable exists. What is a possible cause for this error?Show answer & explanation
Correct answer: B
A
404 Not Founderror specifically for a variable, when authentication and authorization are otherwise working, strongly indicates that the variable itself has been defined in policy but has no secret value assigned to it. The Secrets Provider attempts to fetch the value, but since none exists, the API returns a 404. A permissions issue would typically result in a403 Forbiddenerror. - Question 10BeginnerSelect 2
CyberArk Secrets Manager Architecture · Component Roles
What are the primary functions of a Conjur Follower in a DAP cluster? (Select TWO)
Show answer & explanation
Correct answers: B, D
Followers act as read-only replicas of the Master, allowing an organization to scale out secret retrieval capacity by handling read requests from applications and authenticators.
Followers can authenticate local hosts and applications. They maintain a replica of the policy and data, allowing them to handle the entire authentication and secret retrieval workflow without needing to contact the Master for every request.
Ready for the real thing?
The full SECRET-SEN simulator has every exam-style question, timed mode, and instant scoring.