CAD CyberArk Architecture & Components 2 — Questions and Answers
Question 1: Which CyberArk component is responsible for storing and managing privileged account credentials in an encrypted vault?
- Privileged Session Manager
- Digital Vault (Correct answer)
- Password Upload Utility
- Central Policy Manager
Correct answer: Digital Vault
The Digital Vault (Enterprise Password Vault) is the core encrypted repository that stores and protects privileged credentials.
Question 2: The CyberArk PVWA (Password Vault Web Access) communicates with the Vault Server over which default port?
- 443
- 1858 (Correct answer)
- 8080
- 3389
Correct answer: 1858
CyberArk Vault communication uses TCP port 1858 (the proprietary Vault protocol) by default.
Question 3: In a CyberArk high-availability deployment, what is the role of the Disaster Recovery (DR) Vault?
- It actively serves requests alongside the primary Vault
- It acts as a passive replica that can be promoted if the primary fails (Correct answer)
- It stores only audit logs from the primary Vault
- It manages PSM session recordings independently
Correct answer: It acts as a passive replica that can be promoted if the primary fails
The DR Vault is a passive standby that replicates data from the primary Vault and can be promoted to primary during a failover event.
Question 4: Which CyberArk component manages the automatic rotation of passwords according to platform policies?
- CPM (Central Policy Manager) (Correct answer)
- PVWA
- PSM (Privileged Session Manager)
- PTA (Privileged Threat Analytics)
Correct answer: CPM (Central Policy Manager)
The CPM automates credential rotation, verification, and reconciliation based on the policies defined for each platform.
Question 5: What is the purpose of the CyberArk Vault's 'Safe' object?
- A firewall rule set protecting inbound Vault traffic
- A logical container that groups accounts and controls access permissions (Correct answer)
- A backup archive of encrypted password files
- A scheduled job that verifies credential integrity
Correct answer: A logical container that groups accounts and controls access permissions
A Safe is the fundamental access-control boundary in the Vault, grouping related accounts and defining who can perform which operations on them.
Question 6: Which CyberArk component provides real-time monitoring, session recording, and isolation of privileged sessions?
- CPM
- PVWA
- PSM (Correct answer)
- EPM
Correct answer: PSM
The Privileged Session Manager (PSM) acts as a jump server, recording and isolating RDP, SSH, and other privileged sessions in real time.
Question 7: In CyberArk architecture, what does the term 'Master Policy' refer to?
- The network firewall policy applied to Vault traffic
- A top-level policy in PVWA that sets defaults for all platforms and Safes (Correct answer)
- The DR replication schedule for Vault data
- The password complexity rules enforced by the CPM
Correct answer: A top-level policy in PVWA that sets defaults for all platforms and Safes
The Master Policy is the global policy layer in PVWA that defines baseline access and compliance rules inherited by all platforms unless overridden.
Which CyberArk component is responsible for storing and managing privileged account credentials in an encrypted vault?