View Full CyberArk CPC-SEN Exam Dumps and Practice Test Dumps.
Question 21. What is the PRIMARY purpose of CyberArk dual control for privileged account access?
- To force two users to share the same password
- To rotate the account password twice
- To require two PSM servers for every connection
- To require an authorized approver to confirm an access request before the requester can use the protected account
Correct Answer: 4. To require an authorized approver to confirm an access request before the requester can use the protected account
Explanation:
Dual control adds an approval stage to privileged access. When a protected account requires dual control, the user first submits a connection or access request. An authorized Safe owner or approver reviews the request and can confirm or deny it. Only after approval can the requesting user access the account within the permitted timeframe and conditions. This provides separation of duties and stronger governance for highly sensitive privileged accounts. CyberArk environments can require users to provide information such as a reason and requested access timeframe as part of the approval workflow.
Question 22. Which Safe permissions are required for a user simply to connect to a target device through a managed Privilege Cloud account?
- Use account and List account
- Manage Safe and Backup Safe
- Authorize account requests and Unlock accounts
- Add accounts and Delete accounts
Correct Answer: 1. Use account and List account
Explanation:
To connect to a target using a privileged account from the Privilege Cloud portal, the user must be able to see the account and use it. Current Privilege Cloud guidance identifies Use account and List account as the permissions needed for this connection workflow. Broader permissions such as Safe administration, account deletion, or authorization of other users’ requests are not required merely to initiate an authorized connection. This follows the principle of least privilege: users should receive only the Safe capabilities necessary for their assigned task rather than broad administrative control over the Safe.
Question 23. What does the “Dual control” account status indicate in the Privilege Cloud Accounts view?
- CPM has disabled password management
- The account is locked by another user
- Users must obtain approval before accessing the account
- The account password has expired
Correct Answer: 3. Users must obtain approval before accessing the account
Explanation:
The dual control status indicates that the account is governed by an approval workflow. Users cannot simply access the account immediately, even if they otherwise have sufficient Safe permissions. Instead, they must submit an access request and wait for an authorized approver to confirm it. Privilege Cloud also displays related statuses such as Pending request and Confirmed request so users can understand the state of their approval workflow. This makes dual-control requirements visible directly in the account interface and helps users distinguish an approval requirement from CPM errors or account locking.
Question 24. What does a “Pending request” status mean for a CyberArk privileged account?
- CPM is currently rotating the password
- The user’s request for authorization has not yet been confirmed
- PSM is currently recording the session
- The Safe has been deleted
Correct Answer: 2. The user’s request for authorization has not yet been confirmed
Explanation:
A pending request means the user has submitted a request to use an account protected by an approval workflow, but the request has not yet received the necessary confirmation. Until an approver authorizes it, the requester cannot proceed with the privileged access covered by that request. Once approved, Privilege Cloud can show a Confirmed request status. These status values help users and administrators understand where a request sits in the access-governance process and distinguish approval delays from credential-management or technical connectivity problems.
Question 25. What is the security purpose of CyberArk exclusive access, also called check-in/check-out exclusive access?
- To allow every authorized user to access the same account simultaneously
- To disable password rotation permanently
- To eliminate the need for Safe permissions
- To ensure that only one authorized user at a time controls access to the protected account
Correct Answer: 4. To ensure that only one authorized user at a time controls access to the protected account
Explanation:
Exclusive access is designed for shared privileged accounts where simultaneous use would reduce accountability or create operational risk. When the account is checked out or locked for one user, another user is prevented from using the same account until it is checked back in or released according to policy. This strengthens individual accountability even when the underlying privileged account is shared. Exclusive access is part of CyberArk’s privileged-access workflow controls and is often considered alongside one-time password policies and dual control when organizations need stronger controls for highly sensitive accounts.
Question 26. What is the PRIMARY effect of a CyberArk one-time password access policy?
- The password never changes after use
- The managed password is changed after use according to the configured workflow, reducing credential reuse
- Users must know the password before they can connect
- The account is permanently locked after its first session
Correct Answer: 2. The managed password is changed after use according to the configured workflow, reducing credential reuse
Explanation:
A one-time password access policy reduces the opportunity to reuse a privileged credential after it has been exposed or used. The credential is rotated according to the configured policy so the value associated with one access event does not remain usable indefinitely. This is particularly valuable for shared privileged accounts because it limits the usefulness of a password that may have been retrieved during an approved operation. One-time password behavior can be combined with controls such as exclusive access and dual control to strengthen privileged account governance further.
Question 27. What does the CyberArk CPM “Verify” operation primarily do?
- Checks whether the password stored by CyberArk is synchronized with the password on the target system
- Creates a new Safe
- Records the privileged session
- Approves a dual-control request
Correct Answer: 1. Checks whether the password stored by CyberArk is synchronized with the password on the target system
Explanation:
The CPM Verify operation confirms that the credential CyberArk has stored is still valid on the managed target. Verification helps identify situations in which a privileged password was changed outside CyberArk or the stored value otherwise no longer matches the target system. Detecting this condition is important because automatic credential management and privileged access depend on synchronization between the protected CyberArk credential and the target account. If verification determines that the password is unsynchronized, reconciliation can be used to restore control.
Question 28. What occurs during a normal CPM password Change operation?
- CyberArk changes only the Vault copy of the password
- CyberArk deletes the managed account
- CPM changes the target account password and updates the credential managed by CyberArk
- PSM takes ownership of password rotation
Correct Answer: 3. CPM changes the target account password and updates the credential managed by CyberArk
Explanation:
A normal CPM Change operation rotates a managed password while keeping CyberArk synchronized with the target. CPM uses the current credential to authenticate, generates a new password according to platform policy, changes the credential on the target system, validates the new value, and updates the managed CyberArk credential. This is different from reconciliation, which is used when the current managed password cannot be successfully verified or used to perform the normal change. Automated password change is a central part of reducing long-lived privileged credential exposure.
Question 29. When is password reconciliation most appropriate?
- Whenever a user starts a normal PSM session
- When the CyberArk-managed password is no longer synchronized with the target and a normal change cannot be completed
- Whenever a Safe member is added
- Whenever a dual-control request is approved
Correct Answer: 2. When the CyberArk-managed password is no longer synchronized with the target and a normal change cannot be completed
Explanation:
Reconciliation is a recovery process used when the password held by CyberArk no longer matches the actual target credential or when the current password cannot be used to perform a normal rotation. A reconciliation account with sufficient authority resets the target account to a new value, allowing CyberArk to restore synchronization and resume ordinary password management. CyberArk documentation explains that verification detects unsynchronized passwords and reconciliation can then reset and resynchronize them. This distinguishes reconciliation from routine password change, which assumes the existing managed password is still valid.
Question 30. Which account is used by CPM to reset another account’s password during reconciliation?
- The PSMConnect account
- The requesting end user’s account
- The Safe owner account
- A configured reconciliation account with sufficient password-reset authority
Correct Answer: 4. A configured reconciliation account with sufficient password-reset authority
Explanation:
A reconciliation account is a privileged account that has enough authority on the target system to reset the password of the managed account. It becomes necessary when CPM cannot rely on the managed account’s current password to perform the reset. CyberArk can associate reconciliation credentials at the platform level or, where needed, at the individual account level. Because reconciliation accounts can reset other privileged credentials, they themselves require strong protection and restricted access. Their purpose is recovery and credential resynchronization, not ordinary end-user access.
Question 31. What happens when CPM automatic management is disabled for an account?
- Automated CPM operations such as password management no longer run for that account until management is re-enabled
- The account is automatically deleted from the Safe
- PSM can no longer record sessions for any account
- All Safe members lose access immediately
Correct Answer: 1. Automated CPM operations such as password management no longer run for that account until management is re-enabled
Explanation:
Privilege Cloud can display an account as Disabled when automatic management for that account has been turned off by a user or by CPM. This means the account remains present, but automatic credential-management actions are no longer being performed normally. It does not imply that the Safe itself has been deleted or that all other accounts are affected. Administrators should investigate why management was disabled, because leaving privileged accounts unmanaged for long periods can result in stale passwords, failed verification, or credentials that no longer meet organizational policy.
Question 32. What does the “Error” status for a managed account indicate?
- The account is awaiting dual-control approval
- A user has locked the account for exclusive access
- CPM failed to complete an automatic management task
- The account is being used through PSM normally
Correct Answer: 3. CPM failed to complete an automatic management task
Explanation:
The Error account status indicates that CPM encountered a failure while attempting an automatic management operation. The underlying cause could involve authentication, permissions, connectivity, password-policy mismatch, target availability, or another configuration problem. This differs from Disabled, where automatic management is intentionally turned off, or Locked, where account use is restricted because another user holds the account. Administrators should review the relevant account-management details and logs to determine which CPM action failed and whether a Verify, Change, or Reconcile workflow is required.
Question 33. What does a “Locked” status indicate for a privileged account?
- The account has no assigned platform
- The Vault is offline
- CPM is performing a verification
- The account is locked, typically because another user currently holds exclusive access
Correct Answer: 4. The account is locked, typically because another user currently holds exclusive access
Explanation:
A Locked account status indicates that the privileged account is currently unavailable for ordinary use because it has been locked. Privilege Cloud can show the identity of the user holding the lock. This behavior is closely associated with exclusive check-in/check-out workflows, where a shared privileged account is reserved for one user at a time. The lock improves accountability and prevents simultaneous use of the same underlying account. Administrators should distinguish this intentional access state from a CPM Error or Disabled status, both of which relate to credential-management health rather than account reservation.
Question 34. What does a user normally provide when submitting a dual-control connection request?
- A new target password
- Information such as a reason for access and requested timeframe
- The PSM server’s administrator password
- The Safe encryption key
Correct Answer: 2. Information such as a reason for access and requested timeframe
Explanation:
A dual-control request can include contextual information that helps the approver evaluate whether the requested privileged access is legitimate. Current Privilege Cloud guidance lists fields such as Reason and Request Timeframe, along with an option indicating whether multiple accesses are required. Additional account-specific information may also be requested. This context gives the approver more than a simple yes-or-no prompt and creates a more useful audit trail. The user does not provide the managed privileged password itself because CyberArk is designed to protect that credential from unnecessary exposure.
Question 35. What happens after an authorized approver confirms a valid dual-control request?
- The requester can use the account according to the approved request conditions
- CPM deletes the account password
- The Safe becomes public
- PSM is disabled for that account
Correct Answer: 1. The requester can use the account according to the approved request conditions
Explanation:
Once an authorized approver confirms the request, the requester receives the right to access the protected account according to the approved timeframe and other configured restrictions. Privilege Cloud marks the request as confirmed, and the user can proceed with the authorized connection workflow. Approval does not grant permanent unrestricted rights unless policy explicitly allows them. The dual-control model is intended to make sensitive privileged access intentional, documented, time-bound where appropriate, and subject to independent approval rather than turning approval into a permanent bypass of governance.
Question 36. What does an automatic onboarding rule in modern CyberArk Privilege Cloud help accomplish?
- Automatically onboard discovered accounts that satisfy defined management criteria
- Disable all discovery scans
- Convert PSM recordings into passwords
- Replace Safe permissions with network ACLs
Correct Answer: 3. Automatically onboard discovered accounts that satisfy defined management criteria
Explanation:
CyberArk has introduced an automatic onboarding rule builder that allows administrators to define conditions for automatically bringing discovered privileged accounts under management. This reduces manual effort in large environments where new accounts may continuously appear. CyberArk describes the rule builder as a flexible mechanism for applying accurate, secure account-management rules to discovered accounts. Automated discovery and onboarding also help reduce privileged-account blind spots because newly identified accounts can be evaluated and remediated consistently instead of waiting for administrators to locate and onboard each account manually.
Question 37. What is a key benefit of CyberArk’s modern discovery capabilities?
- They eliminate the need for account ownership decisions
- They continuously improve visibility into privileged human and machine accounts across environments
- They require all accounts to share one Safe
- They prevent new privileged accounts from ever being created
Correct Answer: 2. They continuously improve visibility into privileged human and machine accounts across environments
Explanation:
Modern CyberArk discovery capabilities are intended to identify privilege across distributed environments rather than relying solely on administrators already knowing where privileged accounts exist. CyberArk highlights continuous visibility into shared, personal, built-in, and newly created accounts, including both human and machine identities. Discovery helps security teams identify unmanaged privilege and decide which controls should be applied. It does not automatically eliminate every account or remove the need for ownership and policy decisions; instead, it creates the visibility necessary to manage privileged identities systematically.
Question 38. What is the role of the Privilege Cloud Connector Server in the Privilege Cloud architecture?
- It establishes an encrypted tunnel between customer-operated systems and the Privilege Cloud backend service
- It acts as the organization’s primary Active Directory domain controller
- It replaces every managed target system
- It stores all enterprise email
Correct Answer: 1. It establishes an encrypted tunnel between customer-operated systems and the Privilege Cloud backend service
Explanation:
CyberArk identifies the Privilege Cloud Connector Server as infrastructure that establishes an encrypted tunnel between customer-operated systems and the Privilege Cloud backend service. This allows the SaaS service to securely interact with systems inside the customer’s environment while maintaining separation between CyberArk-hosted services and customer-operated resources. Connector infrastructure can also host or support components involved in password management and session management, depending on the deployment architecture. Proper connectivity, hardening, and monitoring of connector infrastructure are therefore essential to reliable Privilege Cloud operations.
Question 39. Which CyberArk administrative area is directly associated with discovering and bringing unmanaged privileged accounts under control?
- PSM recording retention only
- Safe auditing only
- Discovery and Onboarding
- Session video playback only
Correct Answer: 3. Discovery and Onboarding
Explanation:
CyberArk’s official administration curriculum includes Discovery and Onboarding as a dedicated functional area, reflecting its importance in privileged access management. Discovery identifies privileged accounts and credentials that may not yet be under CyberArk control, while onboarding associates appropriate accounts with Safes, platforms, policies, credential management, and access workflows. This is distinct from PSM session management, which focuses on controlling and monitoring use after privileged access has been granted. A strong PAM program needs both capabilities: discovery to find privilege and secure management to control it.
Question 40. A shared domain administrator account is highly sensitive. The organization wants users to justify access, obtain manager approval, prevent simultaneous use, rotate the credential after use, and avoid exposing the password during normal administration. Which design BEST meets these requirements?
- Give every administrator the domain administrator password
- Use only MFA and leave the privileged password unchanged
- Store the password in a spreadsheet and restrict the file
- Manage the account in CyberArk with dual control, exclusive access, one-time password behavior, and PSM-brokered sessions
Correct Answer: 4. Manage the account in CyberArk with dual control, exclusive access, one-time password behavior, and PSM-brokered sessions
Explanation:
The requirements map to several complementary CyberArk controls. Dual control requires independent approval and can capture a reason and requested timeframe. Exclusive access limits simultaneous use of the shared account, strengthening accountability. One-time password behavior reduces credential reuse by rotating the password after use according to policy. PSM brokers the session so the administrator can perform the required work without routinely learning the underlying password while CyberArk can monitor and record activity. Together, these controls provide stronger governance than MFA or password storage alone because they address approval, concurrency, credential lifecycle, exposure, and session accountability.