CAD Cheat Sheet 2026
The 30 highest-yield CAD facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
90 min time limit
70.00% to pass
- What is the primary purpose of the CyberArk Digital Vault? → Secure and store privileged credentials
- Which log file should an administrator review to investigate failed authentication attempts to the Digital Vault? → vault.log
- Which user permission is required to manage other user roles in CyberArk? → Manage Users
- How are Vault activities typically audited? → Activity logs and audit reports
- A company policy requires that privileged accounts used for database administration cannot be used outside business hours. How is this enforced in CyberArk? → By configuring time-frame restrictions in the Master Policy for the relevant platform
- Which CyberArk component is responsible for recording and storing all audit logs generated by the Digital Vault? → Vault Audit Log
- What happens to a CyberArk managed account password after a one-time retrieval configured with 'change password after check-in'? → The CPM rotates the password immediately after the user checks the credential back in
- Which SIEM platforms does CyberArk PTA natively support for forwarding security events? → Splunk and IBM QRadar, with syslog-based forwarding for others
- A privileged user checks out an exclusive account but their workstation crashes before they check it in. What is the recommended administrative action? → Manually release the account checkout from the PVWA as an administrator
- Which Master Policy rule, when enabled, instructs the CPM to periodically rotate account passwords on a scheduled basis? → Require periodic password change
- What is the role of the PTA sensor deployed in the network? → It captures and forwards network traffic metadata to the PTA server for analysis
- In CyberArk PTA, what does a 'suspected credential theft' alert typically indicate? → Credentials were extracted from memory using tools like Mimikatz
- In CyberArk's hierarchical permission model, which level takes the highest precedence when there is a conflict between Vault, Safe, and folder permissions? → The most restrictive permission at any level wins
- A CAD professional encounters an unfamiliar situation while performing enterprise password vault policies duties. What is the most appropriate first action? → Consult relevant standards, guidelines, or a qualified supervisor before proceeding
- What is the primary ethical obligation of a CAD professional when a conflict of interest arises during cyberark cloud entitlements activities? → Disclose the conflict to all relevant parties and recuse from the decision if necessary
- Which of the following is a fundamental principle of cyberark architecture & components as it applies to CyberArk Defender Certification? → Systematic evaluation and adherence to established industry standards
- A security policy mandates that all password retrievals require a ticket number from the ITSM system. Which CyberArk feature enforces this? → Ticketing system integration with reason requirement
- A PTA alert shows 'Suspected DCSync attack.' What does this indicate? → An attacker is synchronizing Active Directory replication to extract all password hashes
- What is the primary purpose of a Privileged Session Manager (PSM) in CyberArk? → To proxy and record privileged sessions without exposing credentials to end users
- In CyberArk, what file contains replication configuration parameters for the Disaster Recovery Vault, including the primary Vault address? → PADR.ini
- In a high-availability PSM deployment, what is typically placed in front of multiple PSM servers to distribute session load? → Network Load Balancer (NLB) or Application Delivery Controller
- What is the function of the CyberArk 'Reconcile Account' feature? → It resets a target account password when the CPM-managed password is out of sync
- Which data source does CyberArk PTA use to detect suspicious Kerberos activity such as Golden Ticket attacks? → Windows Event Logs from domain controllers
- When configuring CyberArk Vault clustering for high availability, which component manages the automatic failover between primary and secondary Vault nodes? → Windows Server Failover Clustering (WSFC)
- Which Safe member permission allows a user to see the list of accounts in a Safe but NOT retrieve their passwords? → List accounts
- Which setting can enforce session approval in CyberArk? → Dual control
- What type of credential does CyberArk AAM support retrieving for SSH-based applications? → Passwords and SSH private keys
- When a platform has 'One Time Password' (OTP) enabled, what occurs after the privileged session ends? → The CPM immediately rotates the password to a new random value
- Where are PSM session recordings stored by default after a privileged session ends? → In the CyberArk Vault as secure files linked to the account
- What CyberArk feature allows auditors to watch a live or recorded privileged session without interrupting the active user? → Session Monitoring
Turn these facts into recall:
Was this helpful?