CyberArk Defender - PAM (PAM-DEF) — Questions and Answers
Question 1: Which Safe permission must be granted to allow a user to view audit activity logs for a specific Safe in CyberArk?
- Retrieve Accounts
- Manage Safe
- List Accounts
- View Audit Log (Correct answer)
Correct answer: View Audit Log
The 'View Audit Log' permission grants a user the ability to see all audit activity recorded for a given Safe.
Question 2: What is the maximum recommended network latency between the primary CyberArk Vault and its DR Vault to ensure synchronous replication performance?
- 50 ms
- 5 ms
- 100 ms
- 20 ms (Correct answer)
Correct answer: 20 ms
CyberArk recommends no more than 20 ms round-trip latency between the primary and DR Vault to maintain acceptable synchronous replication performance.
Question 3: In AWS, what is the primary risk associated with overly permissive IAM roles attached to Lambda functions?
- Increased Lambda execution time
- Excessive access if the function is compromised or misconfigured (Correct answer)
- Higher AWS billing costs
- Reduced Lambda concurrency limits
Correct answer: Excessive access if the function is compromised or misconfigured
Overly permissive IAM roles on Lambda functions can allow an attacker to pivot across AWS services if the function is exploited.
Question 4: What is the purpose of a 'Reconcile' account in CyberArk CPM?
- To verify the password stored in the Vault against the target system
- To reset an account's password when the CPM cannot change it using the regular account credentials (Correct answer)
- To merge duplicate account entries found in the Vault
- To synchronize passwords between multiple Vault instances
Correct answer: To reset an account's password when the CPM cannot change it using the regular account credentials
A reconcile account is used to forcibly reset a managed account's password when the CPM cannot change it directly, such as when the password has been manually changed outside of CyberArk.
Question 5: What is the primary purpose of the CyberArk Application Identity Manager (AIM)?
- Eliminate hardcoded credentials in applications (Correct answer)
- Rotate passwords for privileged accounts
- Monitor application user behavior
- Enforce MFA for application logins
Correct answer: Eliminate hardcoded credentials in applications
AIM eliminates hardcoded credentials by allowing applications to retrieve secrets dynamically from the Vault.
Question 6: What happens to active PSM sessions during a CyberArk primary Vault failover to the DR Vault?
- Sessions are paused and resume after failover completes
- Sessions are gracefully migrated to the DR Vault
- Active sessions are terminated and users must reconnect (Correct answer)
- Sessions continue uninterrupted automatically
Correct answer: Active sessions are terminated and users must reconnect
Active PSM sessions are dropped during a Vault failover; users must re-authenticate and initiate new sessions once the DR Vault is promoted.
Question 7: When documenting activities related to cyberark architecture & components, which practice is considered essential for CAD certification holders?
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in cyberark architecture & components. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 8: In CyberArk, which backup method creates a point-in-time copy of the Vault data that can be used to restore a completely failed primary Vault?
- Safe export via PVWA
- Database dump via SQL tools
- PrivateArk Client export
- Vault Backup Utility (PABackup) (Correct answer)
Correct answer: Vault Backup Utility (PABackup)
PABackup is CyberArk's official Vault Backup Utility that creates encrypted, consistent backups of all Vault data for disaster recovery restoration.
Question 9: Which Safe permission must an AAM application's Vault user have to retrieve an account's credentials?
- Manage Safe
- Add Accounts
- Retrieve Accounts (Correct answer)
- Authorize Account Requests
Correct answer: Retrieve Accounts
The 'Retrieve Accounts' permission allows the AAM provider user to fetch the credential value from the Safe.
Question 10: Which metric does PTA use to prioritize which security alerts require the most immediate attention?
- Number of analyst comments attached to the alert
- The geographic location of the source IP address
- Alert creation timestamp (oldest first)
- Risk score assigned to the event based on account sensitivity and behavior severity (Correct answer)
Correct answer: Risk score assigned to the event based on account sensitivity and behavior severity
PTA assigns a risk score to each alert by combining the privilege level of the involved account with the severity of the detected behavior to drive prioritization.
Question 11: CyberArk's EPM (Endpoint Privilege Manager) primarily addresses which security challenge?
- Recording privileged sessions to cloud infrastructure
- Rotating service account passwords in Active Directory
- Removing local admin rights and controlling application execution on endpoints (Correct answer)
- Securing SSH keys in the Digital Vault
Correct answer: Removing local admin rights and controlling application execution on endpoints
EPM enforces least-privilege on endpoints by removing unnecessary local admin rights and controlling which applications can execute.
Question 12: Which file on the CyberArk Vault server controls the maximum number of concurrent Vault connections?
- DBParm.ini
- Vault.ini (Correct answer)
- PVWA.ini
- PARAgent.ini
Correct answer: Vault.ini
The Vault.ini file contains configuration parameters including connection limits that control how many concurrent client connections the Vault accepts.
Question 13: CyberArk CEM integrates with cloud providers' native logging services to analyze usage. Which AWS service does it primarily leverage for this?
- AWS CloudTrail (Correct answer)
- Amazon GuardDuty
- Amazon CloudWatch Metrics
- AWS Config
Correct answer: AWS CloudTrail
CEM uses AWS CloudTrail event logs to determine which API calls each identity actually makes, enabling accurate least-privilege recommendations.
Question 14: What happens to a Safe's contents when the Safe retention period expires in CyberArk?
- All passwords are automatically rotated
- All objects in the Safe are permanently deleted (Correct answer)
- The Safe is archived and becomes read-only
- Access is suspended pending administrator review
Correct answer: All objects in the Safe are permanently deleted
When the retention period of a Safe expires, all objects stored within it are permanently and irreversibly deleted from the Vault.
Question 15: When configuring CyberArk Safe permissions during initial setup, what does the 'Owner' permission level grant?
- The ability to retrieve passwords but not modify Safe settings
- Read-only access to account passwords
- Access to view audit logs for the Safe only
- Full control including the ability to manage Safe members and permissions (Correct answer)
Correct answer: Full control including the ability to manage Safe members and permissions
The Owner permission level grants full control over the Safe including adding/removing members, modifying permissions, and managing all Safe-level settings.
Question 16: What is the primary ethical obligation of a CAD professional when a conflict of interest arises during cyberark cloud entitlements activities?
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in cyberark cloud entitlements is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 17: In AAM, what does 'AllowedMachines' define in an application definition?
- Machines excluded from AAM policy
- Servers allowed to run PVWA
- IP addresses or hostnames permitted to request credentials for that application (Correct answer)
- Machines that can host the Vault
Correct answer: IP addresses or hostnames permitted to request credentials for that application
AllowedMachines restricts credential retrieval to specific IPs or hostnames associated with the registered application.
Question 18: What is the significance of 'cross-account access' risk in AWS as identified by CyberArk CEM?
- It increases S3 storage costs
- It automatically disables CloudTrail logging
- A compromised identity in one account can leverage permissions to access resources in other accounts (Correct answer)
- It prevents VPC peering from functioning
Correct answer: A compromised identity in one account can leverage permissions to access resources in other accounts
Cross-account roles allow an identity compromised in one AWS account to pivot and access resources in other accounts, expanding the blast radius of a breach.
Question 19: Which Safe permission allows a user to see a list of passwords stored in a Safe without being able to retrieve the actual password values?
- Retrieve accounts
- List accounts (Correct answer)
- Access Safe without confirmation
- View Safe members
Correct answer: List accounts
The 'List accounts' permission allows users to see account names and metadata within a Safe, but not the actual password content.
Question 20: A CAD professional encounters an unfamiliar situation while performing privileged access management concepts duties. What is the most appropriate first action?
- Proceed based on general assumptions to avoid delays
- Apply a solution from an unrelated field without verification
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Skip the task entirely and move to the next assignment
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in privileged access management concepts, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 21: Which CyberArk CEM capability allows security teams to simulate the impact of removing permissions before applying changes?
- Canary deployments
- Live traffic mirroring
- What-if analysis / impact simulation (Correct answer)
- A/B policy testing
Correct answer: What-if analysis / impact simulation
CEM's what-if analysis lets administrators model the effects of permission removals on workloads before committing changes, reducing the risk of operational disruption.
Question 22: In CyberArk EPV, which platform policy setting controls how frequently the CPM automatically rotates a privileged account password?
- MinValidityPeriod
- AllowedSafes
- ChangeFrequency (Correct answer)
- ImmediateInterval
Correct answer: ChangeFrequency
ChangeFrequency (also called 'Interval') in the platform policy defines how often the CPM automatically changes the password.
Question 23: An administrator runs the PrivateArk Client and attempts to create a new Safe but the option is grayed out. What is the most likely cause?
- The administrator lacks the 'Add Safes' Vault-level permission (Correct answer)
- The Safe quota has been reached for that administrator's account
- The Vault license has expired
- The PrivateArk Client version is incompatible with the Vault version
Correct answer: The administrator lacks the 'Add Safes' Vault-level permission
The ability to create Safes requires the 'Add Safes' permission at the Vault level, which is separate from Safe-level or user-level permissions.
Question 24: What is the purpose of the 'Safes' directory within the Digital Vault installation path?
- Holds temporary session files during active connections
- Contains encrypted safe database files (.rdb) for all created safes (Correct answer)
- Stores Vault license and configuration files
- Stores Vault binary executables and libraries
Correct answer: Contains encrypted safe database files (.rdb) for all created safes
The Safes directory contains the encrypted .rdb database files that hold the actual content of each safe created in the Vault.
Question 25: What happens to a privileged account password by default after it is checked back into CyberArk?
- It is archived in an audit log
- It remains unchanged until the next scheduled rotation
- The CPM automatically rotates it to a new value (Correct answer)
- It is deleted and re-created
Correct answer: The CPM automatically rotates it to a new value
Upon check-in, the CPM rotates the password immediately (if configured for immediate change) so the checked-out value is no longer valid.
Question 26: When troubleshooting a failed AAM credential retrieval, which log file on the Credential Provider server should you check first?
- pvwaConfig.log
- ITALog.log
- AppProvider.log (Correct answer)
- IISLogs\W3SVC
Correct answer: AppProvider.log
AppProvider.log records all Credential Provider activity including authentication failures and retrieval errors.
Question 27: Which CyberArk AAM feature allows Kubernetes pods to retrieve secrets without storing credentials in the pod specification?
- Conjur Secrets Provider for Kubernetes (Correct answer)
- Secrets Manager Credential Provider
- PVWA REST API sidecar
- PSM Jump Client
Correct answer: Conjur Secrets Provider for Kubernetes
The Conjur Secrets Provider runs as an init or sidecar container to inject secrets into pods at runtime.
Question 28: Which principle does PAM primarily enforce when granting privileged access?
- Defense in depth
- Separation of duties
- Least privilege (Correct answer)
- Zero trust network access
Correct answer: Least privilege
PAM enforces least privilege by ensuring users have only the minimum level of access required to complete their tasks.
Question 29: In a CyberArk HA environment, which Vault component manages the distribution of requests across multiple Vault cluster nodes?
- Vault Load Dispatcher
- CyberArk Cluster Vault Manager (CVM) (Correct answer)
- PrivateArk HA Engine
- PrivateArk Client Cluster Manager
Correct answer: CyberArk Cluster Vault Manager (CVM)
The CyberArk Cluster Vault Manager (CVM) coordinates node membership, heartbeat monitoring, and request routing across Vault cluster nodes.
Question 30: Which Safe permission must the CPM user account have on a Safe in order to perform automatic password management for accounts stored in that Safe?
- Access Safe without confirmation
- Unlock accounts
- Initiate CPM password management operations (Correct answer)
- Manage Safe
Correct answer: Initiate CPM password management operations
The 'Initiate CPM password management operations' permission explicitly grants the CPM user account the ability to trigger password change, verify, and reconcile operations on accounts in the Safe.
Question 31: What is the minimum number of Vault nodes recommended in a CyberArk Cluster Vault Manager (CVM) deployment to avoid split-brain scenarios?
- 3 (Correct answer)
- 2
- 5
- 4
Correct answer: 3
A minimum of 3 nodes is recommended in a CVM cluster to achieve quorum and prevent split-brain, where two equal partitions each claim to be primary.
Question 32: In a CyberArk cluster (high-availability) setup, which component provides load balancing and failover for PVWA connections?
- Vault Cluster Broker
- CyberArk Cluster Vault Manager
- PrivateArk Replication Engine
- An external load balancer (e.g., F5, HAProxy) (Correct answer)
Correct answer: An external load balancer (e.g., F5, HAProxy)
An external load balancer is placed in front of multiple PVWA nodes to distribute user connections and provide failover for the web interface tier.
Question 33: Which CyberArk component enforces password policies and performs automatic password changes on target systems?
- PVWA (Password Vault Web Access)
- PSM (Privileged Session Manager)
- PTA (Privileged Threat Analytics)
- CPM (Central Policy Manager) (Correct answer)
Correct answer: CPM (Central Policy Manager)
The CPM is responsible for enforcing platform-specific password policies and executing automated credential rotation on managed accounts.
Question 34: When 'Enforce check-in/check-out exclusive access' is enabled in the Master Policy, what is the typical CPM behavior for a currently checked-out account?
- CPM rotates the password immediately regardless of check-out status
- CPM is permanently disabled for accounts with exclusive access enabled
- CPM sends a change request to the Vault administrator for approval
- CPM respects the check-out state and waits until the account is checked in before changing the password (Correct answer)
Correct answer: CPM respects the check-out state and waits until the account is checked in before changing the password
With exclusive access enforced, the CPM waits for the account to be checked in before rotating its password, preventing a mid-session password change that would lock out the active user.
Question 35: Which PTA deployment component is responsible for analyzing raw security events and generating risk-scored alerts?
- CPM (Central Policy Manager)
- PTA Sensor
- PVWA Console
- PTA Server (Correct answer)
Correct answer: PTA Server
The PTA Server is the core analytics engine that processes ingested data, applies behavioral models, and produces risk-scored security alerts.
Question 36: Which CyberArk component is responsible for recording and storing all audit logs generated by the Digital Vault?
- Central Policy Manager
- Vault Audit Log (Correct answer)
- Password Manager
- Privileged Session Manager
Correct answer: Vault Audit Log
The Vault Audit Log captures every action taken on the Digital Vault, providing a tamper-evident record for compliance purposes.
Question 37: What does the CyberArk Vault's 'Private Ark' security model prevent even a Vault administrator from doing by default?
- Creating new safes and user accounts
- Viewing Vault audit logs
- Directly reading or decrypting the contents of passwords stored in safes they do not own (Correct answer)
- Viewing safe member lists
Correct answer: Directly reading or decrypting the contents of passwords stored in safes they do not own
CyberArk's security architecture prevents even Vault administrators from directly reading password values in safes they are not explicitly authorized to access, ensuring separation of duties.
Question 38: A CyberArk Safe has 'Enforce one-time password' enabled in the Master Policy. A user retrieves the password and does NOT use it. What does the CPM do?
- Disables the account on the target system
- Waits for the next scheduled rotation
- Nothing; the password changes only after actual use
- Changes the password immediately after check-in, regardless of use (Correct answer)
Correct answer: Changes the password immediately after check-in, regardless of use
With OTP enforced, the CPM rotates the password upon check-in regardless of whether the password was actually used, ensuring each checkout yields a unique credential.
Question 39: When reviewing Safe membership, an administrator notices a user has the 'Manage Safe' permission. What does this specifically allow?
- Authorizing dual-control access requests
- Adding and removing Safe members and changing their permissions (Correct answer)
- Modifying Safe properties such as retention period and number of versions
- Full control including credential retrieval and Safe deletion
Correct answer: Adding and removing Safe members and changing their permissions
The 'Manage Safe' permission specifically grants the ability to add/remove Safe members and modify their permission sets, not to retrieve credentials or delete the Safe.
Question 40: In the CyberArk Vault, what is a 'Safe Owner' permission that allows a user to add other members to a safe?
- Manage Safe Members (Correct answer)
- Manage Safe
- Add Accounts
- Administer Safe
Correct answer: Manage Safe Members
The 'Manage Safe Members' permission allows a safe owner to add, remove, or modify the permissions of other members within that safe.
Question 41: When documenting activities related to enterprise password vault policies, which practice is considered essential for CAD certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in enterprise password vault policies. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 42: What is 'privilege creep' in the context of cloud entitlements, and how does CEM address it?
- The gradual accumulation of permissions over time beyond operational needs; CEM identifies and recommends removal of unused rights (Correct answer)
- An increase in cloud costs; CEM generates cost reports
- A bug in cloud IAM APIs; CEM reports it to AWS
- A type of network intrusion; CEM blocks it via firewalls
Correct answer: The gradual accumulation of permissions over time beyond operational needs; CEM identifies and recommends removal of unused rights
Privilege creep occurs as identities accumulate permissions through role changes and project needs without cleanup; CEM continuously monitors and recommends right-sizing.
Question 43: In a CyberArk deployment, which component must be updated with the DR Vault's address so that CPM can continue rotating passwords after a failover?
- Vault.ini on all components
- PSM connections.xml
- PVWA appsettings.json
- CPM PVConfiguration.xml (Correct answer)
Correct answer: CPM PVConfiguration.xml
The CPM's PVConfiguration.xml file contains the Vault address used for password rotation; it must reference the new active (former DR) Vault address after failover.
Question 44: Which of the following is a key benefit of session recording in PAM?
- It prevents administrators from running unauthorized commands in real time
- It provides a full audit trail of privileged activity for forensic investigation and compliance (Correct answer)
- It speeds up privileged sessions by caching frequently used commands
- It automatically generates password rotation requests after each session
Correct answer: It provides a full audit trail of privileged activity for forensic investigation and compliance
Session recordings create an immutable audit trail of all privileged activity, supporting incident response, forensics, and regulatory compliance requirements.
Question 45: In the context of privileged session manager setup, what role does continuous professional development play for CAD practitioners?
- It serves primarily as a networking opportunity with no practical benefit
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It is optional and only needed for career advancement
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in privileged session manager setup because it ensures CAD practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 46: Which of the following is a fundamental principle of enterprise password vault policies as it applies to CyberArk Defender Certification?
- Relying solely on personal experience without reference to guidelines
- Avoiding documentation to streamline workflow efficiency
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of enterprise password vault policies in CyberArk Defender Certification is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 47: What does CyberArk's Privileged Threat Analytics (PTA) primarily do?
- Proxies and records privileged sessions in real time
- Detects anomalous privileged account behavior and generates alerts for potential threats (Correct answer)
- Rotates passwords based on a fixed schedule
- Provides a web interface for users to check out credentials
Correct answer: Detects anomalous privileged account behavior and generates alerts for potential threats
PTA analyzes privileged account activity against behavioral baselines and raises security alerts when anomalies suggest a potential compromise or insider threat.
Question 48: In the context of CyberArk CEM, what is an 'identity risk' associated with federated users accessing cloud environments?
- Federated users cannot use MFA
- Federation increases cloud billing unpredictably
- Federated users bypass all IAM policies automatically
- External identity provider compromise could grant attackers cloud access without direct cloud credential theft (Correct answer)
Correct answer: External identity provider compromise could grant attackers cloud access without direct cloud credential theft
Federated access links cloud permissions to an external IdP, meaning a compromised IdP can yield cloud access to attackers without needing cloud-native credentials.
Question 49: Which Safe member permission is required to add new accounts to a CyberArk Safe?
- List accounts
- Update account properties
- Add accounts (Correct answer)
- Retrieve accounts
Correct answer: Add accounts
The 'Add accounts' permission specifically allows a Safe member to onboard new privileged accounts into the Safe.
Question 50: In CyberArk, what is the purpose of the 'MinValidityPeriod' platform parameter?
- Prevents password change for a minimum number of days after last change (Correct answer)
- Sets the maximum age of a password before expiration
- Defines the minimum password length
- Controls how long a checkout session lasts
Correct answer: Prevents password change for a minimum number of days after last change
MinValidityPeriod ensures the CPM will not change a password again until the specified number of days have passed since the last change.
CyberArk Defender - PAM (PAM-DEF)
The CyberArk Defender certification validates the technical skills to maintain day-to-day operations of the CyberArk Privileged Access Management (PAM) solution, including vault administration, account onboarding, password management, and session management configuration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds