Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

PAM-SEN CyberArk Sentry PAM Questions and Answers

Questions 4

Before the hardening process, your customer identified a PSM Universal Connector executable that will be required to run on the PSM.

Which file should you update to allow this to run?

Options:

A.

PSMConfigureAppLocker.xml

B.

PSMHardening.xml

C.

PSMAppConfig.xml

D.

PSMConfigureHardening.xml

Buy Now
Questions 5

You are designing the number of PVWAs a customer must deploy. The customer has three data centers with a distributed Vault in each, requires high availability, and wants to use all Vaults at all times.

How many PVWAs does the customer need?

Options:

A.

six or more

B.

four

C.

two or less

D.

three

Buy Now
Questions 6

Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation?

Options:

A.

255.255.255.255

B.

8.8.8.8

C.

192.168.1.1

D.

1.1.1.1

Buy Now
Questions 7

You want to add an additional maintenance user on the PSM for SSH.

How can you accomplish this if InstallCyberarkSSHD is set to Integrated?

Options:

A.

Create a local user and add it to the PSMMaintenance Group.

B.

Create a local user called proxymng.

C.

Create a local user and add it to group configured for the parameter AllowGroups in the /etc/sshd_config file

D.

Create a local user, called psmpmng.

Buy Now
Questions 8

When performing “In Domain” hardening of a PSM server, which steps must be performed? (Choose two.)

Options:

A.

Import CyberArk policy settings from the provided file into a new GPO. Most Voted

B.

Apply advanced audit on the PSM server.

C.

Link GPO to a dedicated OU containing CyberArk PSM servers. Most Voted

D.

Import an INF file to the local machine.

E.

Configure AppLocker rules to block running unknown executables.

Buy Now
Questions 9

Which step is required to register a Vault manually in Amazon Web Services using CAVaultManager?

Options:

A.

Specify Amazon as the cloud vendor using the /CloudVendor Flag

B.

After running the postinstall utility, restart the "PrivateArk Server" service

C.

Specify the Cloud region using the /CloudRegion flag

D.

Specify whether the Vault is distributed or stand alone

Buy Now
Questions 10

PAM-SEN Question 10

Arrange the steps to failover to the DR CPM in the correct sequence.

Options:

Buy Now
Questions 11

In order to avoid conflicts with the hardening process, third party applications like Antivirus and Backup Agents should be installed on the Vault server before installing the Vault.

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 12

A customer has two data centers and requires a single PVWA url.

Which deployment provides the fastest time to reach the PVWA and the most redundancy?

Options:

A.

Deploy two PVWAs behind a global traffic manager.

B.

Deploy one PVWA only.

C.

Deploy two PVWAs in an active/standby mode.

D.

Deploy two PVWAs using DNS round robin.

Buy Now
Questions 13

Which keys are required to be present in order to start the PrivateArk Server Service? Select all that apply.

Options:

A.

Server Key

B.

Recovery Public Key

C.

Recovery Private Key

D.

Safe Key

Buy Now
Questions 14

When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?

Options:

A.

5 - number of primary and satellite Vaults can be specified during installation

B.

3 - all primary

C.

6 - 1 primary and 5 satellite

D.

10 - 2 primary and 8 satellite

Buy Now
Questions 15

When configuring RADIUS authentication, which utility is used to create a file containing an encrypted version of the RADIUS secret?

Options:

A.

CAVaultManager

B.

CACert

C.

CreateAuthFile

D.

CreateCredFile

Buy Now
Questions 16

The connect button requires PSM to work.

Options:

A.

TRUE

B.

FALSE

Buy Now
Questions 17

What authentication methods can be implemented to enforce Two-Factor Authentication (2FA) for users authenticating to CyberArk using both the PVWA (through the browser) and the PrivateArk Client?

Options:

A.

LDAP and RADIUS Most Voted

B.

CyberArk and RADIUS

C.

SAML and Cyber Ark

D.

SAML and RADIUS

Buy Now
Questions 18

Which utility should be used to register the Vault in Amazon Web Services?

Options:

A.

CAVaultManager Most Voted

B.

StorageManager

C.

CloudVaultManager

D.

CACert

Buy Now
Questions 19

If a transparent user matches two different directory mappings, how does the system determine which user template to use?

Options:

A.

The system will use the template for the mapping listed first.

B.

The system will use the template for the mapping listed last.

C.

The system will grant all of the vault authorizations from the two templates.

D.

The system will grant only the vault authorizations that are listed in both templates

Buy Now
Questions 20

Your customer wants to store the Safes Data on Vault Drive D instead of Drive C.

Which file should you edit?

Options:

A.

TSparm.ini Most Voted

B.

Vault.ini

C.

DBparm.ini

D.

user.ini

Buy Now
Questions 21

What is the purpose of the PSM health check hardening?

Options:

A.

Remove IIS settings which can be considered security vulnerabilities.

B.

Validate that the PSM is ready to be placed behind a load balancer.

C.

Confirm that the Windows Services for PSM are running on the server.

D.

Ensure that the AppLocker script does not have any syntax errors.

Buy Now
Questions 22

After installing the Vault, you need to allow Firewall Access for Windows Time service to sync with NTP servers 10.1.1.1 and 10.2.2.2.

What should you do?

Options:

A.

Edit DBParm.ini to add: AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2],Yes,123:outbound/udp. Most Voted

B.

Edit DBParm.ini to add: NTPServer=[10.1.1.1:123/UDP,10.2.2.2:123/UDP].

C.

Edit DBParm.ini to add: AllowNonStandardFWAddresses=[10.1.1.1,10.2.2.2],Yes,123:outbound/udp,123:inbound/udp.

D.

Edit the Windows Firewall configuration to add a rule for Port 123/udp outbound to 10.1.1.1 and 10.2.2.2.

Buy Now
Questions 23

Which parameter must be provided when registering a primary Vault in Azure, but not in Amazon Web Services?

Options:

A.

/RecPub

B.

/AdminPass

C.

/MasterPass

D.

/RDPGateway

Buy Now
Questions 24

Which statement is correct about CPM behavior in a distributed Vault environment?

Options:

A.

CPMs should only access the primary Vault. When it is unavailable, CPM cannot access any Vault until another Vault is promoted as the new primary Vault.

B.

CPMs should access only the satellite Vaults.

C.

CPMs should only access the primary Vault. When it is unavailable, CPM cannot access any Vault until the original primary Vault is operational again.

D.

CPM should access all Vaults - primary and the satellite.

Buy Now
Questions 25

You are successfully managing passwords in the alpha cyberark com domain; however, when you attempt to manage a password in the beta cyberark com domain, you receive the 'network path not found' error. What should you check first?

Options:

A.

That the username and password are correct

B.

That the CPM can successfully resolve addresses in the beta cyberark com domain

C.

That the end user has the correct permissions on the safe.

D.

That an appropriate trust relationship exists between alpha.cyberark com and beta cyberark.com

Buy Now
Questions 26

What would be a good use case for a High Availability vault?

Options:

A.

Recovery Time Objectives or Recovery Point Objectives are at or near zero.

B.

Integration with an Enterprise Backup Solution is required.

C.

Off site replication is required

D.

PSM is used.

Buy Now
Questions 27

Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?

Options:

A.

IdP “EntityID” and “PartnerIdentityProvider Name” in PVWA saml.config file

B.

IdP “User name” and “SingleSignOnServiceUrl” in PVWA saml.config file

C.

IdP “Audience” and “ServiceProviderName” in the PVWA saml.config file

D.

IdP “Secure hash algorithm” and “Certificate” in the PVWA saml.config file

Buy Now
Questions 28

What is the best practice for storing the Master CD?

Options:

A.

Copy the files to the Vault server and discard the CD.

B.

Copy the contents of the CD to a Hardware Security Module and discard the CD.

C.

Store the CD in a secure location, such as a physical safe.

D.

Store the CD in a secure location, such as a physical safe, and copy the contents of the CD to a folder (secured with NTFS permissions} on the vault.

Buy Now
Questions 29

You are setting up a Linux host to act as an HTML 5 gateway for PSM sessions.

Which servers need to be trusted by the Linux host to secure communications through the gateway?

Options:

A.

PSM and PVWA

B.

PSM and CPM

C.

PVWA and Vault

D.

Vault and PSM

Buy Now
Questions 30

What is a step to enable NTP synchronization on a stand-alone Vault?

Options:

A.

Run Powershell and add the NTP module.

B.

Restart the organization's NTP servers.

C.

Edit dbparm.ini and add a Firewall rule for the NTP address.

D.

Restart the Vault Event Notification Engine service.

Buy Now
Questions 31

Which configuration file and Vault utility are used to migrate the server key to an HSM?

Options:

A.

DBparm.ini and CAVaultManager.exe

B.

VaultKeys.ini and CAVaultManager.exe

C.

DBparm.ini and ChangeServerKeys.exe

D.

VaultKeys.ini and ChangeServerKeys.exe

Buy Now
Questions 32

What must you do to prepare a Windows server for PVWA installation?

Options:

A.

In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell. Most Voted

B.

Install the PrivateArk client.

C.

Verify the user performing the installation is Domain Administrator and has logon access to the Vault server.

D.

Enable IPv6.

Buy Now
Questions 33

Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?

Options:

A.

vault.ini

B.

user.cred

C.

psmpparms

D.

psmgw.config

Buy Now
Questions 34

You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_Admin safes.

How do you set this in CyberArk?

Options:

A.

In the CYBRWINDAD platform, under Automatic Password Management/General, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN). Most Voted

B.

In the settings for Configuration/CPM assigned to the WINDEMEA and WINDEMEAADMIN safes, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEAADMIN).

C.

In the CYBRWINDAD platform, under UI&Workflows/Properties/Optional, configure AllowedSafes and set to (WINDEMEA)|(WINDEMEA_ADMIN).

D.

Modify cpm.ini on the relevant CPM/s and add the setting AllowedSafesCYBRWINDAD and set to (WINDEMEA)|(WINDEMEAADMIN).

Buy Now
Questions 35

A first PSM server has been installed.

What should you confirm before installing any additional PSM servers?

Options:

A.

The PSM ID of the first installed PSM server was changed and the additional PSM server can use the same PSM ID.

B.

The user performing the installation is a direct owner in the PSMUnmanagedSessionAccounts Safe, PSM safe and member of PVWAMonitor group.

C.

The user performing the installation is not a direct owner in the PSMUnmanagedSessionAccounts Safe. Most Voted

D.

The path of the Recordings Folder must be different on all PSM installations.

Buy Now
Questions 36

What is the default username for the PSM for SSH maintenance user when InstallCyberarkSSHD is set to yes?

Options:

A.

proxymng

B.

psmp_maintenance

C.

psmpmaintenanceuser

D.

psmpmnguser

Buy Now
Questions 37

Which service must be set to Automatic (delayed start) after the Vault is installed and configured?

Options:

A.

Windows Time service

B.

PrivateArk Database

C.

Windows Update service

D.

PrivateArk Server

Buy Now
Questions 38

Which of the following are prerequisites for installing PVWA Check all that Apply.

Options:

A.

Web Services Role

B.

NET 4.5.1 Framework Feature

C.

Remote Desktop Services Role

D.

Windows BitLocker

Buy Now
Questions 39

In addition to bit rate and estimated total duration of recordings per day, what is needed to determine the amount of storage required for PSM recordings?

Options:

A.

retention period

B.

number of PSMs

C.

number of users

D.

number of targets

Buy Now
Questions 40

The security of the Vault Server is entirely dependent on the security of the network.

Options:

A.

TRUE

B.

FALSE

Buy Now
Exam Code: PAM-SEN
Exam Name: CyberArk Sentry PAM
Last Update: Apr 26, 2024
Questions: 136

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now PAM-SEN testing engine

PDF (Q&A)

$35  $99.99
buy now PAM-SEN pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 26 Apr 2024