Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free CyberArk CPC-SEN Practice Exam with Questions & Answers

Questions 1

How should you configure PSM for SSH to support load balancing?

Options:
A.

by using a network load balancer

B.

in PVWA > Options > PSM for SSH Proxy > Servers

C.

in PVWA > Options > PSM for SSH Proxy > Servers > VIP

D.

by editing sshd.config on the all the PSM for SSH servers

CyberArk CPC-SEN Premium Access
Questions 2

You are planning to configure Multi-Factor Authentication (MFA) for your CyberArk Privilege Cloud Shared Service. What are the available authentication methods?

Options:
A.

LDAR RADIUS. SAML OpenID Connect (OIDC)

B.

Windows. PKI. RADIUS. CyberArk, LDAP. SAML. OpenID Connect (OIDC)

C.

Privilege Cloud Shared Services fully utilize CyberArk Identity and its MFA options.

D.

Only RADIUS can be used to achieve MFA across all components, such as PSM for RDP and PSM for SSH.

Questions 3

'What is a default authentication profile to access CyberArk Identity?

Options:
A.

Default New User Login Profile

B.

Default New Device Login Profile

C.

Default New Authenticator Profile

D.

Default New Password Profile

Questions 4

You are creating a PSM Load Balanced Virtual Server Configuration.

What are the default service ports / protocols used for RDS and the PSM Health Check service?

Options:
A.

RDP/389 HTTP/443

B.

RDP/3389 HTTPS/443

C UDP/53 HTTPS/389

C.

RDP/636 HTTPS/443

Questions 5

What must be done to configure the syslog server IP address(es) for SIEM integration? (Choose 2.)

Options:
A.

Submit a service request to CyberArk Support.

B.

Update the syslog server IP address through the Privilege Cloud Portal.

C.

Update the DBPARM.ini file with the correct syslog server IP address.

D.

Update the vault.ini file with the correct syslog server IP address.

E.

Configure the Secure Tunnel for SIEM integration.

Questions 6

Which option correctly describes the authentication differences between CyberArk Privilege Cloud and CyberArk PAM Self-Hosted?

Options:
A.

CyberArk Privilege Cloud only provides a username and password authentication without third-party IdP integration; CyberArk PAM Self-Hosted uses traditional on-premises methods such as Windows and LDAP. but lacks modern protocols such as SAML or OIDC.

B.

CyberArk Privilege Cloud uses cloud-based methods, integrating with CyberArk Identity for MFA. and supports SAML and OIDC; CyberArk PAM Self-Hosted depends on on-premises methods such as RADIUS and LDAP, but can adopt SAML or OIDC with additional setups.

C.

CyberArk Privilege Cloud requires on-premises components for all authentication and does not support other cloud-based authentication protocols; CyberArk PAM Self-Hosted offers a wide array of methods, including support for SAML. OIDC. and other modern protocols, without needing on-premises components.

D.

Both use the same authentication methods.

Questions 7

When installing the PSM and CPM components on the same Privilege Cloud Connector, what should you consider when hardening?

Options:
A.

PSM settings override the CPM settings when referring to the same parameter.

B.

CPM settings override the PSM settings when referring to the same parameter

C.

They can only be installed on the same Privilege Cloud Connector when installed 'in Domain'.

D.

They can only be installed on the same Privilege Cloud Connector when installed 'out of Domain'.

Questions 8

Which statement best describes a PSM server's network requirements?

Options:
A.

It must reach the target system using its native protocols.

B.

It requires limited outbound connectivity to Ports 1858 and 443 only.

C.

It requires direct access to the internet.

D.

It requires broad inbound firewall rules and outbound traffic should be limited to Port 1858.

Questions 9

On the CPM, you want to verify if DEP is disabled for the required executables According to best practices, which executables should be listed? (Choose 2.)

Options:
A.

Telnet.exe

B.

Plink.exe

C.

putty.exe

D.

mstsc.exe

Questions 10

Which statement is correct regarding the LDAP integration with CyberArk Privilege Cloud Standard?

Options:
A.

You must track the expiration date of the directory server certificate and contact CyberArk Support to renew it.

B.

LDAPS integration with Privilege Cloud requires StartTLS for secure and encrypted communication.

C.

For certificate trust to your directory server, only the Issuing CA certificate is required.

D.

The top-level domain entry of the directory must be unique in the chosen Privilege Cloud region.