CAD Study Guide 2026
Everything you need to pass the CAD exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📋 CAD Exam Format at a Glance
📚 CAD Topics to Study (69)
✍️ Sample CAD Questions & Answers
1. When PTA detects a threat and automatically responds by rotating a compromised account's password, this capability is known as:
PTA's automatic response feature triggers actions such as password rotation or account suspension when a threat is confirmed.
2. Why should SSH keys be managed under a PAM solution in addition to passwords?
Unmanaged SSH keys often have no expiration, are rarely rotated, and can provide root-level access, making them high-risk privileged credentials that belong in a PAM vault.
3. How is access to the Vault controlled?
Access to the CyberArk Vault and its contents is meticulously controlled through a combination of robust access control lists (ACLs) and granular safe permissions. These mechanisms precisely define which users or groups can access specific safes, view, retrieve, or manage credentials, ensuring strict adherence to the principle of least privilege and enhancing security.
4. Which of the following is a fundamental principle of privileged session manager setup as it applies to CyberArk Defender Certification?
A fundamental principle of privileged session manager setup in CyberArk Defender Certification is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
5. Which log file should an administrator review to investigate failed authentication attempts to the Digital Vault?
The vault.log file records all Vault-level events including authentication successes and failures.
6. A CyberArk administrator wants to prevent a specific user from deleting accounts in a Safe while still allowing them to manage passwords. Which permission should be withheld?
The 'Delete accounts' permission is separate from password management permissions, so withholding it prevents deletion while other account management tasks remain available.