CyberArk Defender - PAM (PAM-DEF) — Questions and Answers
Question 1: Which configuration file contains the Vault address and connection parameters used by the CPM to connect to the Digital Vault?
- CPMparm.ini
- basic.ini
- pvconfig.ini
- vault.ini (Correct answer)
Correct answer: vault.ini
The vault.ini file contains the Vault address, port, and connection parameters required by CyberArk components, including the CPM, to connect to the Digital Vault.
Question 2: Which CyberArk platform property must be configured to allow the CPM to log on to a target Windows server and change a local account password?
- TargetAddressType
- ChangeCommand
- ConnectionComponent
- ManageAs (Correct answer)
Correct answer: ManageAs
The ManageAs property (or associated reconcile/logon account) tells the CPM which privileged account to use when connecting to the target to perform the change.
Question 3: CyberArk CEM can integrate with which of the following to automatically create tickets for entitlement remediation?
- AWS Cost Explorer
- ITSM tools such as ServiceNow or Jira (Correct answer)
- Only email notifications
- Azure DevOps pipelines exclusively
Correct answer: ITSM tools such as ServiceNow or Jira
CEM integrates with ITSM platforms like ServiceNow and Jira to automatically open remediation tickets, enabling workflow-driven least-privilege enforcement.
Question 4: In CyberArk PVWA, which section allows administrators to generate reports showing all accounts that have never been accessed?
- Administration tab
- Accounts tab
- Reports tab (Correct answer)
- Policies tab
Correct answer: Reports tab
The Reports tab in PVWA provides built-in reports including inactive and never-accessed account listings for compliance auditing.
Question 5: What is the significance of Vault Disaster Recovery (DR)?
- Speeds up login
- Ensures business continuity (Correct answer)
- Updates firewall settings
- Improves UI performance
Correct answer: Ensures business continuity
Vault Disaster Recovery (DR) is critical for ensuring the continuous availability and resilience of privileged access management services. In the event of a primary Vault failure, the DR solution allows for a rapid and seamless failover to a secondary Vault, preventing service disruptions and maintaining secure access to critical systems, thus ensuring business continuity.
Question 6: In a CyberArk high-availability deployment, what is the role of the Disaster Recovery Vault?
- It serves as the primary authentication provider
- It manages password rotation for all accounts
- It maintains a real-time replica of the primary Vault and activates if the primary fails (Correct answer)
- It hosts the PVWA interface as a failover
Correct answer: It maintains a real-time replica of the primary Vault and activates if the primary fails
The Disaster Recovery Vault continuously replicates data from the primary Vault and can be promoted to become the active Vault if the primary is unavailable.
Question 7: In the context of CyberArk CEM, what is an 'identity risk' associated with federated users accessing cloud environments?
- Federated users bypass all IAM policies automatically
- Federated users cannot use MFA
- Federation increases cloud billing unpredictably
- External identity provider compromise could grant attackers cloud access without direct cloud credential theft (Correct answer)
Correct answer: External identity provider compromise could grant attackers cloud access without direct cloud credential theft
Federated access links cloud permissions to an external IdP, meaning a compromised IdP can yield cloud access to attackers without needing cloud-native credentials.
Question 8: Where are PSM session recordings stored by default after a privileged session ends?
- On the PSM server's local disk indefinitely
- Directly in the SIEM platform
- In a network file share defined in PVWA
- In the CyberArk Vault as secure files linked to the account (Correct answer)
Correct answer: In the CyberArk Vault as secure files linked to the account
By default, PSM uploads session recordings to the CyberArk Vault, where they are stored securely and linked to the relevant account.
Question 9: In CyberArk, what does the 'DBParm.ini' file primarily control?
- PSM session recording settings
- CPM password policy rules
- Digital Vault server parameters and tuning settings (Correct answer)
- PVWA web server configuration
Correct answer: Digital Vault server parameters and tuning settings
DBParm.ini is the main configuration file for the Digital Vault server, containing parameters for performance, security, and operational behavior.
Question 10: What does the 'PasswordNeverExpires' flag in CyberArk account properties indicate to the CPM?
- The Safe is locked from modification
- The password cannot be retrieved via PVWA
- The account is exempt from all CPM management
- The CPM should not automatically rotate the password based on schedule (Correct answer)
Correct answer: The CPM should not automatically rotate the password based on schedule
Setting PasswordNeverExpires tells the CPM to skip scheduled automatic rotation while still allowing manual changes.
Question 11: When documenting activities related to application access manager, which practice is considered essential for CAD certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Recording only outcomes while omitting the methods and processes used
- Keeping documentation in personal notes that are not accessible to other team members
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in application access manager. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 12: Which principle does PAM primarily enforce when granting privileged access?
- Separation of duties
- Defense in depth
- Least privilege (Correct answer)
- Zero trust network access
Correct answer: Least privilege
PAM enforces least privilege by ensuring users have only the minimum level of access required to complete their tasks.
Question 13: In AWS, what is the primary risk associated with overly permissive IAM roles attached to Lambda functions?
- Higher AWS billing costs
- Increased Lambda execution time
- Excessive access if the function is compromised or misconfigured (Correct answer)
- Reduced Lambda concurrency limits
Correct answer: Excessive access if the function is compromised or misconfigured
Overly permissive IAM roles on Lambda functions can allow an attacker to pivot across AWS services if the function is exploited.
Question 14: In CyberArk, which backup method creates a point-in-time copy of the Vault data that can be used to restore a completely failed primary Vault?
- PrivateArk Client export
- Safe export via PVWA
- Vault Backup Utility (PABackup) (Correct answer)
- Database dump via SQL tools
Correct answer: Vault Backup Utility (PABackup)
PABackup is CyberArk's official Vault Backup Utility that creates encrypted, consistent backups of all Vault data for disaster recovery restoration.
Question 15: What is the role of the CyberArk 'PrivateArk Client' application?
- The agent installed on target servers for session isolation
- A command-line tool for CPM policy configuration
- A thick-client administrative interface for direct Vault management (Correct answer)
- A mobile app for approving Dual Control requests
Correct answer: A thick-client administrative interface for direct Vault management
PrivateArk Client is the desktop administrative interface that provides direct Vault management capabilities, typically used by Vault administrators.
Question 16: What is the primary function of the CPM in CyberArk?
- Web authentication
- Password management (Correct answer)
- Logging user keystrokes
- Session monitoring
Correct answer: Password management
The CyberArk Central Policy Manager (CPM) is primarily responsible for automated, policy-based management of privileged account passwords. It enforces password rotation, complexity, and other security policies across a wide range of target systems, ensuring credentials remain secure and compliant without requiring manual intervention.
Question 17: Which Safe permission allows a user to see a list of passwords stored in a Safe without being able to retrieve the actual password values?
- Access Safe without confirmation
- Retrieve accounts
- View Safe members
- List accounts (Correct answer)
Correct answer: List accounts
The 'List accounts' permission allows users to see account names and metadata within a Safe, but not the actual password content.
Question 18: In CyberArk Conjur, which entity represents the non-human identity of an application requesting a secret?
- Role
- Workload
- Host (Correct answer)
- Principal
Correct answer: Host
In Conjur, a 'Host' represents a machine or application identity that can authenticate and retrieve secrets.
Question 19: Which CyberArk access control concept ensures that the team that manages Safe membership is different from the team that uses the credentials stored in that Safe?
- Object Level Access Control
- Just-In-Time provisioning
- Dual control
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties in CyberArk is enforced by granting Safe management rights (add/remove members) to one group while credential retrieval rights go to a separate group.
Question 20: Which CyberArk Vault component is responsible for enforcing access control policies and logging all activity?
- PrivateArk Client
- Central Policy Manager
- Digital Vault (Correct answer)
- Password Vault Web Access
Correct answer: Digital Vault
The Digital Vault is the core component that enforces access control, encrypts stored credentials, and maintains an immutable audit log of all activity.
Question 21: In CyberArk, which object type stores the connection parameters, password policy rules, and plugin configurations for a specific account type?
- Platform (Correct answer)
- Safe
- Account
- Policy
Correct answer: Platform
A Platform in CyberArk is a template that defines how passwords are managed, rotated, and connected for a specific target system type (e.g., Windows Domain, Oracle DB).
Question 22: Which CyberArk service on the DR Vault machine handles the ongoing replication process from the primary Vault?
- PrivateArk Database
- CyberArk Vault Disaster Recovery (Correct answer)
- PrivateArk Server
- CyberArk Event Notification Engine
Correct answer: CyberArk Vault Disaster Recovery
The 'CyberArk Vault Disaster Recovery' Windows service runs on the DR Vault and continuously pulls replicated data from the primary Vault.
Question 23: What is the primary reason CyberArk recommends remediating 'toxic combinations' of cloud permissions flagged by CEM?
- They increase cloud storage costs significantly
- They prevent CloudFormation stacks from deploying
- Certain permission combinations together enable dangerous attack paths that neither permission enables alone (Correct answer)
- They cause AWS service quotas to be exceeded
Correct answer: Certain permission combinations together enable dangerous attack paths that neither permission enables alone
Toxic combinations are permission pairings (e.g., `iam:CreatePolicy` + `iam:AttachUserPolicy`) that together enable privilege escalation paths neither permission creates individually.
Question 24: What is the 'Vault' in CyberArk's architecture, and what makes it secure?
- A cloud HSM service used to store encryption keys for Active Directory
- A DMZ-hosted web server that proxies all privileged account requests
- A hardened server with a proprietary protocol (PVWA), layered encryption, and strict firewall rules that stores all privileged credentials (Correct answer)
- A Linux server running a standard PostgreSQL database with encrypted columns
Correct answer: A hardened server with a proprietary protocol (PVWA), layered encryption, and strict firewall rules that stores all privileged credentials
The CyberArk Vault uses a proprietary protocol, multiple encryption layers, and hardened OS configuration to protect credentials stored within it.
Question 25: What is the default port used by the Central Credential Provider (CCP) web service for HTTPS requests?
- 443 (Correct answer)
- 1858
- 8443
- 8080
Correct answer: 443
CCP listens on the standard HTTPS port 443 by default when hosted in IIS.
Question 26: What CyberArk PADR.ini parameter controls how frequently the DR Vault polls the primary Vault to check replication health?
- ReplicationInterval
- SyncFrequency
- PollPrimaryInterval
- HeartbeatInterval (Correct answer)
Correct answer: HeartbeatInterval
The HeartbeatInterval parameter in PADR.ini defines how often the DR Vault sends a heartbeat to the primary to verify connectivity and replication status.
Question 27: In CyberArk EPV, what does enabling 'Require dual control password access approval' in the Master Policy accomplish?
- Requires two approvers before a password can be retrieved (Correct answer)
- Mandates MFA for all Vault logins
- Forces two CPM nodes to confirm rotation
- Prevents PSM sessions without a second admin present
Correct answer: Requires two approvers before a password can be retrieved
Dual-control approval requires at least two authorized users to approve a password request before it can be checked out.
Question 28: Which CyberArk component stores the Master Policy and enforces it across all Safes by default?
- CPM
- Digital Vault Server (Correct answer)
- PVWA
- PSM
Correct answer: Digital Vault Server
The Digital Vault Server (Vault) is the authoritative source that stores and enforces the Master Policy governing all Safes.
Question 29: Why is it important to back up the CyberArk Vault?
- To avoid software updates
- To improve user performance
- To reduce storage costs
- To prevent data loss (Correct answer)
Correct answer: To prevent data loss
Backing up the CyberArk Vault is critically important to prevent data loss, as it stores all essential privileged credentials and security policies. Regular backups ensure business continuity and recoverability in case of hardware failure, data corruption, or disaster, preventing the catastrophic loss of access to critical privileged accounts and systems.
CyberArk Defender - PAM (PAM-DEF)
The CyberArk Defender certification validates the technical skills to maintain day-to-day operations of the CyberArk Privileged Access Management (PAM) solution, including vault administration, account onboarding, password management, and session management configuration.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds