CyberArk Defender - PAM PAM-DEF Exam Questions

Page: 1 / 14
Total 239 questions
Question 1

You have been asked to identify the up or down status of Vault services.

Which CyberArk utility can you use to accomplish this task?



Answer : C

The Remote Control Agent (PARAgent) is a CyberArk utility that can be used to monitor the status of Vault services remotely. It can also perform other tasks, such as starting and stopping the Vault, backing up and restoring the Vault, and running other utilities. The PARAgent communicates with the Remote Control Client (PARClient), which is a graphical user interface that displays the Vault status and allows the user to execute commands on the Vault. The PARAgent can also send SNMP traps to a remote terminal if the Vault service is down.Reference:How do I monitor the Vault status remotely?,Monitor system health


Question 2

Where can you check that the LDAP binding is using TCP/636?



Answer : D

To check that the LDAP binding is using TCP/636, you can use the Test-NetConnection cmdlet from the PVWA to connect to the domain controller on Port 636.This method allows you to verify that the LDAP service is listening on the secure port and that the connection can be established using SSL/TLS, which is typically associated with port 6361.


CyberArk Docs - LDAP Integration2

CyberArk Knowledge Article - How to test outgoing LDAP external directory connectivity to the vault

Question 3

Customers who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, still need to request approval to use the account.



Answer : B

Customers who have the 'Access Safe without confirmation' safe permission on a safe where accounts are configured for Dual control, do not need to request approval to use the account.The 'Access Safe without confirmation' safe permission allows users to access accounts without confirmation from authorized users, even if the Master Policy or an exception enforces Dual Control1. This means that users who have this permission can bypass the workflow process and access the account password or connect to the target system immediately.This permission can be granted to users or groups on a safe level by the safe owner or another user with the Manage Safe authorization2.Reference:

1:Dual Control, Advanced Settings subsection

2:CyberArk Privileged Access Security Implementation Guide, Chapter 3: Managing Safes, Section: Safe Authorizations, Table 2-1: Safe Authorizations


Question 4

It is possible to restrict the time of day, or day of week that a [b]reconcile[/b] process can occur



Answer : A

It is possible to restrict the time of day, or day of week that a reconcile process can occur by using theReconcile Safeoption in thePlatform Managementsection of thePrivateArk Client. This option allows the administrator to define thereconcile schedulefor each platform, which specifies when the reconcile process can run and how often it should be performed. The reconcile schedule can be set to run daily, weekly, monthly, or on specific days and times. By restricting the reconcile process, the administrator can reduce the risk of unauthorized access to the accounts and improve the performance of the system.Reference:

[Defender PAM Course], Module 5: Reconcile and Rotate, Lesson 1: Reconcile and Rotate Overview, Slide 9: Reconcile Safe

[Defender PAM Study Guide], Section 5.1: Reconcile and Rotate Overview, Page 24: Reconcile Safe

[CyberArk Documentation], Privileged Access Security Implementation Guide, Chapter 5: Configure the Vault, Section 5.4: Configure Platforms, Subsection 5.4.2: Reconcile Safe


Question 5

You are configuring a Vault HA cluster.

Which file should you check to confirm the correct drives have been assigned for the location of the Quorum and Safes data disks?



Answer : A

When configuring a Vault High Availability (HA) cluster, theClusterVault.inifile is the one you should check to confirm the correct drives have been assigned for the location of the Quorum and Safes data disks.This file contains the configuration settings for the cluster, including the drive assignments for the Quorum disk and the Vault data1.


CyberArk Community: HA Cluster Vault - How do I configure multiple Storage Drives?

Question 6

Where can you assign a Reconcile account? (Choose two.)



Answer : A, B

A Reconcile account can be assigned in the Privileged Vault Web Access (PVWA) at both the account level and within the platform configuration.At the account level, a Reconcile account password can be defined which will override the account specified in the platform1.In the platform configuration, you can navigate to Platform Management, select the platform, edit it, and then expand Automatic Password Management to enter the values in the 'ReconcileAccountSafe' and 'ReconcileAccountName' fields, which will apply to all accounts attached to that specific platform2.


CyberArk Docs - Reconcile Password1

CyberArk Community - Associate reconcile account with a specific platform

Question 7

How do you create a cold storage backup?



Answer : A

To create a cold storage backup, you would install thePAReplicateutility on the DR Vault as per the installation guide. This utility is part of the CyberArk Vault's backup solution and is used to export the encrypted contents of your Safes securely to a computer outside the Vault environment. After installation, you would configure the logon ini file with the necessary credentials and define the scheduled tasks for both full and incremental backups.This ensures that the Safes are regularly backed up and that the data is available for recovery if needed1.


CyberArk's official documentation on using the CyberArk Backup Process, which includes details on the PAReplicate utility and how to configure it for cold storage backups1.

Additional information on installing the Vault Backup Utility and configuring backup options, which provides context for the correct answer

Page:    1 / 14   
Total 239 questions