CyberArk PAM-SEN Practice Test Questions and Exam Dumps Part3 Q41-60

View Full CyberArk PAM-SEN Exam Dumps and Practice Test Dumps

 

Question 41.

A CyberArk administrator wants to confirm that a privileged account password stored in the Vault is still valid on the target system. Which CPM action should be used?

  1. Verify
    2. Reconcile
    3. Suspend
    4. Delete

Correct Answer: 1. Verify

Explanation:

The Verify action checks whether the credential currently stored in CyberArk can successfully authenticate to the managed account on the target system. It does not change the password. Verification is useful for detecting situations where a password was changed outside CyberArk or where the target account has become unavailable. If verification fails because the stored password no longer matches the target system, reconciliation may be necessary. Regular verification helps ensure that managed credentials remain synchronized and usable, supporting reliable privileged-access operations and reducing unexpected authentication failures.

Question 42.

A company wants users to launch RDP sessions to privileged Windows accounts without revealing the password. Which component should be used?

  1. CPM
    2. PSM
    3. Digital Vault backup
    4. Account Discovery

Correct Answer: 2. PSM

Explanation:

Privileged Session Manager can establish an RDP session to a target Windows system while keeping the managed password hidden from the user. CyberArk supplies the credential securely during the connection process, allowing the user to perform authorized administrative work without seeing or copying the password. PSM can also monitor and record the session for audit and investigation. CPM manages credential rotation, while Account Discovery identifies unmanaged accounts. PSM is therefore the appropriate CyberArk component for isolating and controlling interactive privileged sessions.

Question 43.

A managed account password no longer matches the credential stored in CyberArk. Which feature can restore synchronization when the current password is unknown?

  1. Session recording
    2. Safe replication
    3. Reconciliation
    4. Account discovery

Correct Answer: 3. Reconciliation

Explanation:

Reconciliation is designed for situations in which CyberArk cannot authenticate using the password stored in the Vault because the actual target-system credential has changed or become unknown. CPM uses a configured reconcile account with sufficient privileges to reset the managed account’s password and update CyberArk with the new value. This restores synchronization without requiring the administrator to know the old password. Verification only detects the mismatch and cannot correct it. Reconciliation is therefore an important recovery capability for managed privileged accounts that have drifted out of synchronization.

Question 44.

An organization requires users to receive manager approval before accessing a sensitive production account. Which CyberArk control should be configured?

  1. CPM verification
    2. PSM recording
    3. Password history
    4. Dual control**

Correct Answer: 4. Dual control

Explanation:

Dual control introduces an approval workflow before a user can access a privileged account. The user submits an access request, and an authorized approver reviews and approves it according to organizational policy. This provides an additional level of governance for highly sensitive accounts beyond normal Safe permissions. It can be combined with time-limited access, PSM session monitoring, and automated password rotation. Dual control is especially useful for production, financial, or emergency accounts where organizations require documented authorization before privileged access is granted.

Question 45.

A company wants to logically separate privileged accounts for development, test, and production environments. Which CyberArk object should be used?

  1. Safes
    2. Connection components
    3. PSM recordings
    4. CPM logs

Correct Answer: 1. Safes

Explanation:

Safes provide logical secure containers within the CyberArk Digital Vault. Organizations can separate accounts by environment, application, business unit, sensitivity, or other criteria and assign different permissions to each Safe. For example, production accounts can be stored in a separate Safe with stricter access requirements than development accounts. Safe membership determines which users and groups can retrieve, use, manage, or audit the stored objects. This makes Safes a fundamental component for organizing privileged credentials and applying access segmentation within a CyberArk PAM deployment.

Question 46.

A Windows service continues using an old password after CPM rotates the associated privileged account. What should the administrator review?

  1. PSM recording settings
    2. Dependent account configuration
    3. Safe naming policy
    4. PVWA language settings

Correct Answer: 2. Dependent account configuration

Explanation:

A service, scheduled task, or application may depend on a managed privileged credential. If CPM rotates the main account password but the dependent service is not updated, the service may continue using the old credential and cause authentication failures or account lockouts. The administrator should review whether the dependency is correctly defined and whether CyberArk can update it after password changes. Proper dependent-account management helps maintain service continuity during automated credential rotation and prevents operational problems caused by stale passwords.

Question 47.

Which CyberArk component provides the browser-based interface for searching accounts and managing Safe access?

  1. CPM
    2. PSM
    3. PVWA
    4. Digital Vault

Correct Answer: 3. PVWA

Explanation:

Password Vault Web Access provides the web-based interface used by administrators and end users for many CyberArk PAM activities. Through PVWA, authorized users can search for privileged accounts, request access, launch connections, manage Safes, review account information, and perform administrative functions according to their permissions. The Digital Vault securely stores credentials, CPM handles automated password management, and PSM brokers privileged sessions. PVWA therefore serves as the primary browser-based interface through which users interact with the CyberArk environment.

Question 48.

A security team needs to review exactly what commands were entered during a privileged SSH session. Which capability should they use?

  1. CPM password history
    2. Account discovery
    3. Safe membership
    4. PSM session recording**

Correct Answer: 4. PSM session recording

Explanation:

PSM can monitor and record privileged SSH sessions, allowing authorized auditors and security personnel to review activity after the session ends. This capability provides visibility into what the privileged user actually did on the target system, which is useful for incident response, compliance, and forensic analysis. CPM manages passwords rather than interactive activity, while account discovery identifies unmanaged privileged accounts. PSM session recordings strengthen accountability because privileged access can be linked to recorded user actions rather than only to authentication events.

Question 49.

A CyberArk administrator wants to enforce different password rules for Oracle database accounts and Windows administrator accounts. What should be configured?

  1. Different account platforms
    2. Separate browsers
    3. Different PSM servers only
    4. Separate PVWA themes

Correct Answer: 1. Different account platforms

Explanation:

CyberArk platforms define how different account types are managed. They can specify password complexity, change frequency, verification, reconciliation, and other management behaviors appropriate to the target technology. Oracle database accounts may require different password rules and connection parameters than Windows administrator accounts, so separate platforms can be configured for each. CPM uses the assigned platform when performing credential-management operations. Browser settings and interface themes do not determine password policy. Correct platform design allows CyberArk to manage diverse technologies consistently while respecting their individual requirements.

Question 50.

A user is allowed to connect through PSM but should not be able to copy or display the managed account password. What should the administrator configure?

  1. Full Safe ownership
    2. Connection rights without password retrieval rights
    3. CPM administrator permissions
    4. Vault backup permissions

Correct Answer: 2. Connection rights without password retrieval rights

Explanation:

CyberArk supports separation between the ability to use an account and the ability to retrieve its password. A user can be granted permission to connect through PSM while being denied direct credential retrieval. PSM can then provide the credential to the target system transparently during the session. This reduces the risk of password disclosure and reuse outside the PAM environment. The design supports least privilege by giving users only the access required for their responsibilities. Broad Safe ownership or administrative permissions would provide unnecessary capabilities.

Question 51.

A company wants to identify privileged accounts that exist on servers but are not yet managed by CyberArk. What should be used?

  1. Account Discovery
    2. Session recording
    3. Password reconciliation
    4. Safe replication

Correct Answer: 1. Account Discovery

Explanation:

Account Discovery helps organizations identify privileged accounts that exist in their infrastructure but are not currently managed by CyberArk. These accounts can then be reviewed, classified, and prioritized for onboarding. Discovery is important because unmanaged privileged accounts may use static passwords, have excessive permissions, or remain unknown to security teams. Once identified, accounts can be added to the appropriate Safe and assigned a platform for CPM management. Session recording and reconciliation serve different functions and do not identify previously unmanaged accounts.

Question 52.

A company wants an application to obtain a privileged database credential without storing the password in a configuration file. What approach should be used?

  1. Store the password in source code
    2. Use an appropriate CyberArk application credential retrieval capability
    3. Give the application a human user’s password
    4. Disable credential rotation

Correct Answer: 2. Use an appropriate CyberArk application credential retrieval capability

Explanation:

Applications should retrieve privileged secrets securely at runtime rather than storing passwords in configuration files or source code. CyberArk provides application-oriented credential-management capabilities that can authenticate the application and return authorized secrets from protected storage. This allows credentials to be rotated independently of application code and reduces the risk of secrets being exposed in repositories, backups, or configuration files. Access should be restricted to the approved application identity. Centralized application credential management improves both security and operational control over non-human privileged accounts.

Question 53.

A company wants to restrict an audit team to reviewing privileged activity without allowing them to change passwords. Which security principle should guide the Safe permissions?

  1. Shared administration
    2. Full control
    3. Least privilege
    4. Anonymous access

Correct Answer: 3. Least privilege

Explanation:

Least privilege means users receive only the permissions required to perform their assigned duties. An audit team may need to review logs, reports, session recordings, or account activity but usually does not require password-management or Safe-administration privileges. CyberArk’s granular permission model supports this separation. Limiting auditor access reduces the risk of accidental changes and supports separation of duties between administrators and independent reviewers. Granting full control simply for convenience would weaken the security model and reduce accountability.

Question 54.

A privileged account is repeatedly locked after password rotation. What is the MOST likely area to investigate first?

  1. PVWA page formatting
    2. PSM recording storage
    3. Safe description text
    4. Systems or dependencies still using the old credential**

Correct Answer: 4. Systems or dependencies still using the old credential

Explanation:

Repeated lockouts after password rotation often indicate that a service, scheduled task, application, or other dependency continues attempting to authenticate using the previous password. The administrator should identify where the account is used and verify whether dependent-account updates are configured correctly. CPM and target-system logs can help locate repeated failed attempts. Simply unlocking the account will not solve the underlying cause. Properly managing dependencies ensures that related services receive the updated credential when the primary account password changes.

Question 55.

A company wants to rotate the password of a privileged account immediately after an approved use. Which component performs the password change?

  1. CPM
    2. PSM
    3. PVWA
    4. Digital Vault backup service

Correct Answer: 1. CPM

Explanation:

The Central Policy Manager performs password changes for managed accounts according to the settings defined in the assigned platform. If organizational policy requires the credential to be changed after use, CPM handles the target-system password update and stores the new value securely in the Vault. PSM controls the privileged session, while PVWA provides the user interface. This separation enables CyberArk to combine controlled access, session monitoring, and automated credential rotation. CPM is therefore the component responsible for the actual credential-management operation.

Question 56.

A user can find an account in PVWA but the expected SSH connection option is missing. What should the administrator review first?

  1. Browser bookmarks
    2. Platform connection components and user permissions
    3. Safe description length
    4. Account creation date

Correct Answer: 2. Platform connection components and user permissions

Explanation:

The availability of a PSM connection option depends on the account platform, enabled connection components, and the user’s authorization. If an SSH option is missing, the administrator should verify that the appropriate connection component is associated with the platform and that the user has the required permissions to use it. The account and target-system configuration should also be checked. Interface details such as browser bookmarks or Safe descriptions do not determine connection availability. Reviewing platform and permission settings is therefore the appropriate first troubleshooting step.

Question 57.

Which CyberArk component is the hardened repository that securely stores privileged credentials?

  1. PVWA
    2. PSM
    3. Digital Vault
    4. CPM

Correct Answer: 3. Digital Vault

Explanation:

The Digital Vault is the secure repository at the center of CyberArk Privileged Access Management. It stores privileged credentials and other protected objects while enforcing strong authentication and access controls. CPM interacts with the Vault when managing passwords, PSM obtains credentials to broker sessions, and PVWA provides users with controlled access to the environment. The Vault is designed specifically to protect sensitive secrets from unauthorized access. Its role is storage and protection, while the other CyberArk components provide management, session control, and user-interface capabilities.

Question 58.

A security team wants to require approval only for access to highly sensitive accounts while allowing normal access to lower-risk accounts. What should the CyberArk engineer configure?

  1. Disable all Safe permissions
    2. Turn off PSM
    3. Use identical access rules for every account
    4. Apply dual control selectively to the sensitive accounts**

Correct Answer: 4. Apply dual control selectively to the sensitive accounts

Explanation:

Dual control can be applied where additional approval is justified by the sensitivity of an account. Highly privileged production or financial accounts may require manager approval before access, while lower-risk accounts can follow normal Safe permissions. This risk-based approach provides stronger controls without introducing unnecessary approval overhead for every privileged account. Dual control can also be combined with time-limited access, PSM session monitoring, and password rotation. Selective use helps organizations align privileged-access controls with the actual risk associated with each account.

Question 59.

A company wants to ensure that passwords are automatically changed every 60 days. Where should this behavior primarily be defined?

  1. In the account platform policy
    2. In the user’s browser configuration
    3. In the PSM recording policy only
    4. In the Safe name

Correct Answer: 1. In the account platform policy

Explanation:

CyberArk platforms define password-management behavior for managed accounts, including change frequency, password complexity, verification settings, and reconciliation behavior. If passwords must be rotated every 60 days, the appropriate platform policy should be configured so CPM performs the change according to that schedule. Browser settings, Safe names, and session-recording policies do not control credential age. Centralizing these rules in platforms allows CyberArk to apply consistent password-management standards across groups of similar privileged accounts.

Question 60.

Before assigning a newly created platform to hundreds of production accounts, what should the CyberArk engineer validate?

  1. Only the platform name
    2. Only account visibility in PVWA
    3. Only the Safe membership list
    4. Verification, password change, reconciliation, connection, and dependency behavior**

Correct Answer: 4. Verification, password change, reconciliation, connection, and dependency behavior

Explanation:

A new platform should be tested comprehensively before it is assigned to large numbers of production accounts. The engineer should verify that CPM can authenticate, change passwords, and reconcile accounts correctly. PSM connection behavior should also be validated where applicable, along with dependent-account updates for services or scheduled tasks. Testing should use representative target systems and realistic scenarios. A platform that works only partially can cause account lockouts or service outages at scale. End-to-end validation reduces operational risk and confirms that the platform is ready for production use.