CyberArk Architecture & Components Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 CyberArk Architecture & Components flashcards as text
Which CyberArk architecture component is responsible for securing DevOps secrets and application credentials through an API-centric model?
Answer: Conjur
Conjur is CyberArk's secrets management solution designed for DevOps pipelines, CI/CD tools, and applications that consume secrets via API.
In a CyberArk deployment, what is the 'Vault Address' parameter used for during component installation?
Answer: The IP or FQDN of the Vault Server that components (CPM, PSM, PVWA) connect to
Every CyberArk component (CPM, PSM, PVWA) must be configured with the Vault Server's IP or FQDN to establish its authenticated connection.
What is the role of the CyberArk 'PrivateArk Client' application?
Answer: A thick-client administrative interface for direct Vault management
PrivateArk Client is the desktop administrative interface that provides direct Vault management capabilities, typically used by Vault administrators.
Which CyberArk component collects syslog events from external systems and correlates them with Vault activity to detect threats?
Answer: PTA
PTA (Privileged Threat Analytics) ingests syslog data from external sources and correlates it with CyberArk Vault audit logs to detect anomalous privileged behavior.
In CyberArk, which object type represents an individual set of credentials (username, password, and target details) stored inside a Safe?
Answer: Account
An Account (also called a password object) stores the actual credential — username, password, address, and platform association — inside a Safe.
What is the maximum number of concurrent PSM sessions limited by in a CyberArk environment?
Answer: PSM server capacity and the CyberArk license
PSM concurrent session limits are governed by both the hardware capacity of the PSM server(s) and the session capacity defined in the CyberArk license.
Which CyberArk feature allows an application to retrieve its own credentials from the Vault without requiring a human to check them out?
Answer: Application Identity Manager (AIM) / Central Credential Provider (CCP)
AIM/CCP enables applications and scripts to programmatically retrieve credentials from the Vault using API calls, eliminating hardcoded passwords in application code.