Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > CyberArk > Sentry > CPC-CDE-RECERT

CPC-CDE-RECERT CyberArk CDE-CPC Recertification Question and Answers

Question # 4

When installing the first CPM within Privilege Cloud using the Connector Management Agent, what should you set the Installation Mode to in the CPM section?

A.

Active

B.

Passive

C.

Default

D.

Primary

Full Access
Question # 5

To disable the PSM default Support for Browser Sessions, which option should be set to 'No* before running Hardening?

A.

SupportWebApplications

B.

SupportBrowsers

C.

SupportWebBrowsers

D.

SupportHTML5Content

Full Access
Question # 6

Which browser is supported for PSM Web Connectors developed using the CyberArk Plugin Generator Utility (PGU)?

A.

Internet Explorer

B.

Google Chrome

C.

Opera

D.

Firefox

Full Access
Question # 7

On Privilege Cloud, what can you use to update users' Permissions on Safes? (Choose 2.)

A.

Privilege Cloud Portal

B.

PrivateArk Client

C.

REST API

D.

PACLI

E.

PTA

Full Access
Question # 8

Which group has only View Audit and View Safe permissions?

A.

Operators

B.

Auditors

C.

Privileged Cloud Admins

D.

Backup Users

Full Access
Question # 9

In which platform configuration section under Automatic Password Management is the AllowedSafes platform parameter found?

A.

Privileged Account Management

B.

Additional Policy Settings

C.

General

D.

CPM plugin

Full Access
Question # 10

Your customer is using Privilege Cloud Shared Services. What is the correct CyberArk Vault address for this customer?

A.

carkvault-.privilegecloud.cyberark.cloud

B.

vault-.privilegecloud.cyberark.cloud

C.

v-.privilegecloud.cyberark.cloud

D.

carkvlt- privilegecloud.cyberark.cloud

Full Access
Question # 11

You are creating a PSM Load Balanced Virtual Server Configuration.

What are the default service ports / protocols used for RDS and the PSM Health Check service?

A.

RDP/389 HTTP/443

B.

RDP/3389 HTTPS/443

C UDP/53 HTTPS/389

C.

RDP/636 HTTPS/443

Full Access
Question # 12

What must be specified when authenticating to Privilege Cloud during the Secure Tunnel install?

A.

Vault IP Address

B.

Subdomain or Customer ID

C.

Privilege Cloud URL

D.

CaseID

Full Access
Question # 13

Which statement is correct regarding the LDAP integration with CyberArk Privilege Cloud Standard?

A.

You must track the expiration date of the directory server certificate and contact CyberArk Support to renew it.

B.

LDAPS integration with Privilege Cloud requires StartTLS for secure and encrypted communication.

C.

For certificate trust to your directory server, only the Issuing CA certificate is required.

D.

The top-level domain entry of the directory must be unique in the chosen Privilege Cloud region.

Full Access
Question # 14

Which Safe(s) does the AllowedSafes=Win platform parameter configuration match? (Choose two.)

A.

WindowsPasswords

B.

win-ssh-keys

C.

CXD-WIN-ADMINS

D.

SQL-Win-SA

E.

WiNdOwS_Accts

Full Access
Question # 15

After the session has ended, where is the default final recording storage located?

A.

CyberArk Privilege Cloud

B.

Privilege Cloud Connector

C.

Network attached storage

D.

User workstation

Full Access
Question # 16

How many assertions are supported by Privilege Cloud in a SAML integration?

A.

1

B.

2

C.

3

D.

Unlimited

Full Access
Question # 17

On the CPM, you want to verify if DEP is disabled for the required executables According to best practices, which executables should be listed? (Choose 2.)

A.

Telnet.exe

B.

Plink.exe

C.

putty.exe

D.

mstsc.exe

Full Access
Question # 18

What must be done before configuring directory mappings in the CyberArk Privilege Cloud Standard Portal for LDAP integration?

A.

Retrieve the LDAPS certificate and deliver it to CyberArk.

B.

Create a new domain in the Privilege Cloud Portal.

C.

Make sure HTTPS (443/tcp) is reachable over the Secure Tunnel.

D.

Ensure the user connecting to the domain has administrative privileges.

Full Access
Question # 19

Which actions must be performed when manually hardening a SUSE server with PSM for SSH? (Choose two.)

A.

Update settings in the sshd_config file on the server.

B.

Add the PSM for SSH gateway user to the passwd file.

C.

Validate that the psmpgwuser.cred file has correct permissions.

D.

Remove all users and groups from the passwd file.

E.

Add the PSM gateway user to the wheel group.

Full Access
Question # 20

After a scripted installation has successfully installed the PSM, which post-installation task is performed?

A.

The screen saver for the PSM local users is disabled.

B.

A new group called PSMShadowUsers is created.

C.

The PSMAdminConnect user password is reset.

D.

Remote desktop services are installed.

Full Access
Question # 21

Which component supports the required communication to send audit logs from Privilege Cloud through the Syslog protocol to a SIEM application?

A.

CyberArk Syslog Writer

B.

Secure Tunnel

C.

Privilege Cloud Connector

D.

CyberArk Identity Connector

Full Access
Question # 22

You have been tasked with deploying a Privilege Cloud PSM for SSH connector When the initial installation has successfully completed, you create and permission several maintenance users to be used for administering the connector.

Which configuration file must be updated to define these maintenance users?

A.

sshd.config

B.

basic_psmpserver.conf

C.

sshd_config

D.

psmpparms

Full Access
Question # 23

To use SAML authentication in Privilege Cloud Standard Services, users must first be defined in Privilege Cloud. What are correct methods for defining users? (Choose two.)

A.

Integrate Privilege Cloud with your LDAP server.

B.

Integrate Privilege Cloud with SIEM.

C.

Integrate Privilege Cloud with Email System.

D.

Create users in Privilege Cloud with details identical to those who access Privilege Cloud through SAML authentication.

E.

Create users in the CyberArk Privilege Cloud database using the CAVaultManager createuser command.

Full Access
Question # 24

In the directory lookup order, which directory service is always looked up first for the CyberArk Privilege Cloud solution?

A.

Active Directory

B.

LDAP

C.

Federated Directory

D.

CyberArk Cloud Directory

Full Access
Question # 25

You are planning to configure Multi-Factor Authentication (MFA) for your CyberArk Privilege Cloud Shared Service. What are the available authentication methods?

A.

LDAR RADIUS. SAML OpenID Connect (OIDC)

B.

Windows. PKI. RADIUS. CyberArk, LDAP. SAML. OpenID Connect (OIDC)

C.

Privilege Cloud Shared Services fully utilize CyberArk Identity and its MFA options.

D.

Only RADIUS can be used to achieve MFA across all components, such as PSM for RDP and PSM for SSH.

Full Access
Question # 26

You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_ADMIN Safes. How do you set this in CyberArk?

A.

In the CYBRWINDAD platform, under Automatic Password Management > General, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEA_ADMIN).

B.

In the settings for Configuration/CPM assigned to the WINDEMEA and WINDEMEAADMIN Safes, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEAADMIN).

C.

In the CYBRWINDAD platform, under UI & Workflows > Properties > Optional, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEA_ADMIN).

D.

Modify cpm.ini on the relevant CPM(s) and add AllowedSafesCYBRWINDAD and set it to (WINDEMEA)|(WINDEMEAADMIN).

Full Access
Question # 27

When installing the PSM and CPM components on the same Privilege Cloud Connector, what should you consider when hardening?

A.

PSM settings override the CPM settings when referring to the same parameter.

B.

CPM settings override the PSM settings when referring to the same parameter

C.

They can only be installed on the same Privilege Cloud Connector when installed 'in Domain'.

D.

They can only be installed on the same Privilege Cloud Connector when installed 'out of Domain'.

Full Access
Question # 28

What must be done to configure the syslog server IP address(es) for SIEM integration? (Choose 2.)

A.

Submit a service request to CyberArk Support.

B.

Update the syslog server IP address through the Privilege Cloud Portal.

C.

Update the DBPARM.ini file with the correct syslog server IP address.

D.

Update the vault.ini file with the correct syslog server IP address.

E.

Configure the Secure Tunnel for SIEM integration.

Full Access
Question # 29

You plan to install the Privilege Cloud Connector on Windows Server 2019 and must leverage your existing RDS Per-user licenses for PSM connections. What must you do?

A.

Add the UseRDSPerUser=Yes line to the basic_psm.ini parameters file.

B.

Install the RDS License Server Service on Windows 2016.

C.

Migrate the local PSMConnect users to Domain users.

D.

Modify the UseRDSPerUser parameter to Yes on every Windows-related platform.

Full Access