Labour Day Special - 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: c4sdisc65

PAM-SEN PDF

$38.5

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

PAM-SEN PDF + Testing Engine

$61.6

$175.99

3 Months Free Update

  • Exam Name: CyberArk Sentry PAM
  • Last Update: May 5, 2024
  • Questions and Answers: 136
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

PAM-SEN Engine

$46.2

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included

PAM-SEN Practice Exam Questions with Answers CyberArk Sentry PAM Certification

Question # 6

Which configuration file and Vault utility are used to migrate the server key to an HSM?

A.

DBparm.ini and CAVaultManager.exe

B.

VaultKeys.ini and CAVaultManager.exe

C.

DBparm.ini and ChangeServerKeys.exe

D.

VaultKeys.ini and ChangeServerKeys.exe

Full Access
Question # 7

Which user is enabled when replicating data between active and stand-by Vaults?

A.

DR

B.

Backup

C.

Operator

D.

Auditor

Full Access
Question # 8

In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?

A.

retention period

B.

number of PSMs

C.

number of users

D.

number of targets

Full Access
Question # 9

In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?

A.

PARAgent.ini

B.

DBParm.ini

C.

TSParm.ini

D.

CyberArkv2 MIB file

Full Access
Question # 10

A customer has two data centers and requires a single PVWA url.

Which deployment provides the fastest time to reach the PVWA and the most redundancy?

A.

Deploy two PVWAs behind a global traffic manager.

B.

Deploy one PVWA only.

C.

Deploy two PVWAs in an active/standby mode.

D.

Deploy two PVWAs using DNS round robin.

Full Access
Question # 11

You are installing multiple PVWAs behind a load balancer.

Which statement is correct?

A.

Port 1858 must be opened between the load balancer and the PVWAs.

B.

The load balancer must be configured in DNS round robin.

C.

The load balancer must support "sticky sessions".

D.

The LoadBalancerClientAddressHeader parameter in the PVWA.ini file must be set.

Full Access
Question # 12

Which CyberArk component changes passwords on Target Devices?

A.

Vault

B.

CPM

C.

PVWA

D.

PSM

E.

PrivateArk

F.

OPM

G.

AIM

Full Access
Question # 13

All 80 employees from your satellite Tokyo office are complaining that browsing the PVWA site is very slow; however, your New York headquarters users are not experiencing this. The current PAM solution is:

2 distributed Vaults, the primary one in New York and a satellite in Tokyo

2 PVWA servers, both in New York with load balancing configured

2 PSM servers, both in New York without load balancing configured

1 CPM server in New York

All PVWA, PSM, and CPM servers are connected to the primary Vault

Which proposal optimally resolves the performance issue while minimizing the impact to production?

A.

Install two new PVWA servers in Tokyo data center, configure load balancing, connect to the local satellite Vault and provide the URL of new PVWA servers to the local employees.

B.

Install two new PVWA servers in New York data center, configure load balancing and have them connect to the satellite Vault in Tokyo.

C.

Install two new PSM servers in the Tokyo data center, configure load balancing, connect to the local satellite vault, and inform the local employees to browse using the same PVWA URL.

D.

Change the current distributed Vaults architecture, migrate back to a Primary-DR architecture, install two new PVWA servers in the Tokyo data center and configure load balancing. Connect to the local DR Vault and provide the URL of new PVWA servers to the local employees.

Full Access
Question # 14

What is a step to enable NTP synchronization on a stand-alone Vault?

A.

Run Powershell and add the NTP module.

B.

Restart the organization's NTP servers.

C.

Edit dbparm.ini and add a Firewall rule for the NTP address.

D.

Restart the Vault Event Notification Engine service.

Full Access
Question # 15

What is a prerequisite step before CyberArk can be configured to support RADIUS authentication?

A.

Log on to the PrivateArk Client, display the User properties of the user to configure, run the Authentication method drop-down list, and select RADIUS authentication.

B.

In the RADIUS server, define the CyberArk Vault as a RADIUS client/agent. Most Voted

C.

In the Vault installation folder, run CAVaultManager as administrator with the SecureSecretFiles command.

D.

Navigate to /Server/Conf and open DBParm.ini and set the RadiusServersInfo parameter.

Full Access
Question # 16

What is determined by the "MaxConcurrentConnections" setting within a platform?

A.

maximum number of concurrent connections that can be opened between the CPM and the remote machines for the platform

B.

maximum number of concurrent connections that can be between the PSM and the remote machines for the platform

C.

maximum number of concurrent connections allowed for a specific account on the platform through the PSM

D.

maximum number of concurrent connections to the Vault allowed for sending audit activities relating to the platform

Full Access
Question # 17

Which components support load balancing? (Choose two.)

A.

CPM

B.

PVWA

C.

PSM

D.

PTA

E.

EPV

Full Access
Question # 18

At what point is a transparent user provisioned in the vault?

A.

When a directory mapping matching that user id is created.

B.

When a vault admin runs LDAP configuration wizard.

C.

The first time the user logs in.

D.

During the vault's nightly LD|^P refresh

Full Access
Question # 19

Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?

A.

dbparm ini

B.

paragent.ini

C.

ENEConf.ini I

D.

padr ini

Full Access
Question # 20

You are successfully managing passwords in the alpha cyberark com domain; however, when you attempt to manage a password in the beta cyberark com domain, you receive the 'network path not found' error. What should you check first?

A.

That the username and password are correct

B.

That the CPM can successfully resolve addresses in the beta cyberark com domain

C.

That the end user has the correct permissions on the safe.

D.

That an appropriate trust relationship exists between alpha.cyberark com and beta cyberark.com

Full Access
Question # 21

This value needs to be added to the PVWA configuration file:

Assuming all CyberArk PVWA servers were installed using default paths/folders, which configuration file should you locate and edit to accomplish this?

A.

c:\inetpub\wwwroot\passwordvault\web.config

B.

c:\inetpub\wwwroot\passwordvault\services\web.config

C.

c:\cyberark\password vault web access\env\web.config

D.

c:\program files\cyberark\password vault web access\web.config

Full Access
Question # 22

You need to add a new PSM server to an existing CyberArk environment.

What is the best way to determine the sizing of this server?

A.

Review the “Recommended Server Specifications” for PSMs in the CyberArk Documents website. Most Voted

B.

Use the specifications of any existing PSM and request a server of the same size.

C.

Use the CyberArk Support Knowledgebase, search for “PSM Sizing” and locate the Knowledgebase article related to sizing.

D.

Refer to the Microsoft Windows website, determine the minimum specifications required for the Operating System you are installing, and then add 4 Gb of RAM and 20 GB of disk.

Full Access
Question # 23

When integrating a Vault with HSM, which file is uploaded to the HSM device?

A.

server.key

B.

recpub.key

C.

recprv.key

D.

mdbase.dat

Full Access
Question # 24

To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?

A.

Add the FQDN & IP details for each LDAP host into the local hosts file of the Vault server. Most Voted

B.

Configure an AllowNonStandardFWAddresses rule in DBParm.ini on the Vault to allow outbound TCP 53 to the organization’s DNS servers.

C.

Ensure LDAP hosts added to the directory mapping configuration are defined using only IP addresses.

D.

Set the ReferralsDNSLookup parameter value to “No” in the directory configuration.

Full Access
Question # 25

When a DR vault server becomes an active vault, it will automatically fail back to the original state once the primary vault comes back online.

A.

True, this is the default behavior

B.

False, this is not possible

C.

True, if the 'AllowFailback' setting is set to yes in the PADR.ini file.

D.

True if the 'AllowFailback' setting is set to yes in the dbparm mi file

Full Access
Question # 26

What is the best practice for storing the Master CD?

A.

Copy the files to the Vault server and discard the CD.

B.

Copy the contents of the CD to a Hardware Security Module and discard the CD.

C.

Store the CD in a secure location, such as a physical safe.

D.

Store the CD in a secure location, such as a physical safe, and copy the contents of the CD to a folder (secured with NTFS permissions} on the vault.

Full Access
Question # 27

In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?

A.

saml.config

B.

samlconfig.ini

C.

PVWAConfig.xml

D.

PVConfiguration.xml

Full Access
Question # 28

If a transparent user matches two different directory mappings, how does the system determine which user template to use?

A.

The system will use the template for the mapping listed first.

B.

The system will use the template for the mapping listed last.

C.

The system will grant all of the vault authorizations from the two templates.

D.

The system will grant only the vault authorizations that are listed in both templates

Full Access
Question # 29

Which statement is correct about CPM behavior in a distributed Vault environment?

A.

CPMs should only access the primary Vault. When it is unavailable, CPM cannot access any Vault until another Vault is promoted as the new primary Vault.

B.

CPMs should access only the satellite Vaults.

C.

CPMs should only access the primary Vault. When it is unavailable, CPM cannot access any Vault until the original primary Vault is operational again.

D.

CPM should access all Vaults - primary and the satellite.

Full Access
Question # 30

You want to change the name of the PVWAappuser of the second PVWA server.

Which steps are part of the process? (Choose two.)

A.

Update PVWA.ini with new user name

B.

Update Vault.ini with new user name

C.

Create new user in PrivateArk

D.

Rename user in PrivateArk

E.

Create new cred file for user

Full Access
Question # 31

In order to retrieve data from the vault a user MUST use an interface provided by CyberArk.

A.

TRUE

B.

FALSE

Full Access
Question # 32

Which statement about REST API is correct? (Choose two.)

A.

When a user successfully authenticates to the Vault, an authentication token is returned. Most Voted

B.

REST API Windows authentication method allows skipping the logon API by using the Windows default credentials with a Kerberos ticket.

C.

To allow High Availability, REST API can be configured to support Session Load Balancing by editing the PVConfiguration.xml and setting the AllowPVWASessionRedandancy=Yes.

D.

Each REST API call requires that a valid authentication token be provided. Most Voted

E.

REST calls are directly sent to the currently active Vault using Port 1858.

Full Access
Question # 33

What are the operating system prerequisites for installing CPM? Select all that apply.

A.

NET 3.51 Framework Feature

B.

Web Services Role

C.

Remote Desktop Services Role

D.

Windows 2008 R2 or higher.

Full Access
Question # 34

What would be a good use case for the Replicate module?

A.

Recovery Time Objectives or Recovery Point Objectives are at or near zero

B.

Integration with an Enterprise Backup Solution is required.

C.

Off site replication is required.

D.

PSM is used

Full Access
Question # 35

Which statements are correct about the PSM HTML5 gateway? (Choose two.)

A.

Smart card redirection is supported

B.

It does not support connections to target system where NLA is enabled on the PSM server

C.

SSH sessions cannot be established

D.

Printer redirection cannot be enabled

E.

It does not support session recording capabilities for applications that run outside a web browser

Full Access
Question # 36

Which component should be installed on the Vault if Distributed Vaults are used with PSM?

A.

RabbitMQ

B.

Disaster Recovery

C.

Remote Control Client

D.

Distributed Vault Server

Full Access
Question # 37

You are designing the number of PVWAs a customer must deploy. The customer has three data centers with a distributed Vault in each, requires high availability, and wants to use all Vaults at all times.

How many PVWAs does the customer need?

A.

six or more

B.

four

C.

two or less

D.

three

Full Access
Question # 38

A new domain controller has been added to your domain. You need to ensure the CyberArk infrastructure can use the new domain controller for authentication.

Which locations must you update?

A.

on the Vault server in C:\Windows\System32\drivers\etc\hosts and in the PVWAApplication under Administration > LDAP Integration > Directories > Hosts

B.

on both the Vault and the PVWA servers in C:\Windows\System32\drivers\etc\hosts

C.

in the Private Ark client under Tools > Administrative Tools > Directory Mapping

D.

on the Vault server in the certificate store and on the PVWA server in the certificate store

Full Access
Question # 39

A customer has five PVWA servers. Three are located at the primary data center and the remaining two are at a satellite data center.

What is important to consider about the load balancer? (Choose two.)

A.

It must not alter page content, or should include a mechanism to prevent pages from being altered. Most Voted

B.

It must support “sticky sessions”. Most Voted

C.

It must be able to digitally sign and issue certificates for PVWA servers.

D.

It must be able to connect to all Vault and PVWA servers through Port TCP 443.

E.

It must be configured with high-availability (HA) enabled.

Full Access
Question # 40

What is the purpose of the CPM_Preinstallation.ps1 script included with the CPM installation package?

A.

It prompts for input parameters that will be used to pre-populate form fields in the installation wizard.

B.

It automatically installs the CPM, requiring no additional user input.

C.

It allows you to install the CPM using a command line approach rather than using the installation wizard.

D.

It verifies the NET version installed on the server and sets the IIS SSL TLS server configuration.

Full Access