11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

PAM-SEN Exam Dumps - CyberArk Sentry PAM

Question # 4

Arrange the steps to install the Password Vault Web Access (PVWA) in the correct sequence.

Full Access
Question # 5

Which statements are correct about the PSM HTML5 gateway? (Choose two.)

A.

Smart card redirection is supported

B.

It does not support connections to target system where NLA is enabled on the PSM server

C.

SSH sessions cannot be established

D.

Printer redirection cannot be enabled

E.

It does not support session recording capabilities for applications that run outside a web browser

Full Access
Question # 6

In which configuration file on the Vault can filters be configured to either include or exclude log messages that are sent through SNMP?

A.

PARAgent.ini

B.

DBParm.ini

C.

TSParm.ini

D.

CyberArkv2 MIB file

Full Access
Question # 7

When SAML authentication is used to sign in to the PVWA, which service performs the actual authentication?

A.

Active Directory (AD)

B.

Identity Provider (IdP) Most Voted

C.

Service Provider (SP)

D.

CyberArk Password Vault Web Access (PVWA)

Full Access
Question # 8

Which file would you modify to configure the vault to send SNMP traps to your monitoring solution?

A.

dbparm ini

B.

paragent.ini

C.

ENEConf.ini I

D.

padr ini

Full Access
Question # 9

If a customer has one data center and requires fault tolerance, how many PVWAs should be deployed?

A.

two or more

B.

one PVWA cluster

C.

one

D.

two PVWA clusters

Full Access
Question # 10

Arrange the steps to complete CPM Hardening for Out-of-Domain Deployment in the correct sequence.

Full Access
Question # 11

You are installing PSM for SSH with AD-Bridge and CyberArkSSHD mode set to integrated for your customer.

Which additional packages do you need to install to meet the customer’s needs? (Choose two.)

A.

CARKpsmp-infra

B.

libssh

C.

OpenSSH 7.8 or higher

D.

CARKpsmp-ADBridge

E.

CARKpsmp-SSHD

Full Access
Question # 12

What is the purpose of the CPM_Preinstallation.ps1 script included with the CPM installation package?

A.

It prompts for input parameters that will be used to pre-populate form fields in the installation wizard.

B.

It automatically installs the CPM, requiring no additional user input.

C.

It allows you to install the CPM using a command line approach rather than using the installation wizard.

D.

It verifies the NET version installed on the server and sets the IIS SSL TLS server configuration.

Full Access
Question # 13

The connect button requires PSM to work.

A.

TRUE

B.

FALSE

Full Access
Question # 14

Which utility should be used to register the Vault in Amazon Web Services?

A.

CAVaultManager Most Voted

B.

StorageManager

C.

CloudVaultManager

D.

CACert

Full Access
Question # 15

Which components support load balancing? (Choose two.)

A.

CPM

B.

PVWA

C.

PSM

D.

PTA

E.

EPV

Full Access
Question # 16

Arrange the steps to failover to the DR CPM in the correct sequence.

Full Access
Question # 17

The primary purpose of the CPM is Password Management.

A.

TRUE

B.

FALSE

Full Access
Question # 18

What is the best practice for storing the Master CD?

A.

Copy the files to the Vault server and discard the CD.

B.

Copy the contents of the CD to a Hardware Security Module and discard the CD.

C.

Store the CD in a secure location, such as a physical safe.

D.

Store the CD in a secure location, such as a physical safe, and copy the contents of the CD to a folder (secured with NTFS permissions} on the vault.

Full Access
Question # 19

Which files does the Vault Installation Wizard prompt you for during the Vault install?

A.

Operator CD and License Most Voted

B.

Master CD and License

C.

Operator CD and Vault Certificate

D.

Master CD and DBparm.ini

Full Access
Question # 20

What utility is used to create or update a credential file?

A.

CreateCredFile exe

B.

CAVaultManager.exe

C.

Central Policy Manager

D.

Password Vault Web Access

Full Access
Question # 21

HTML5 Gateway can be installed on which supported UNIX OS versions? (Choose two.)

A.

Red Hat Enterprise Linux 7.x

B.

CentOS 7.x

C.

Ubuntu 20.x

D.

AK 7.x

E.

Android 11.x

Full Access
Question # 22

Which authentication methods does PSM for SSH support?

A.

CyberArk password LDAP, RADIUS, SAML

B.

LDAP, Windows Authentication, SSH keys

C.

RADIUS, Oracle SSO, CyberArk Password

D.

CyberArk Password, LDAP, RADIUS

Full Access
Question # 23

In addition to disabling Windows services or features not needed for PVWA operations, which tasks does PVWA_Hardening.ps1 perform when run? (Choose two.)

A.

performs IIS hardening

B.

configures all group policy settings

C.

renames the local Administrator Account

D.

configures Windows Firewall

E.

imports the CyberArk INF configuration

Full Access
Question # 24

After installing the first PSM server and before installing additional PSM servers, you must ensure the user performing the installation is not a direct owner of which safe?

A.

PSMUnmanagedSessionAccounts Safe

B.

PSMRecordingsSessionAccounts Safe

C.

PSMUnmanagedApplicationAccounts Safe

D.

PSMSessionBackupAccounts Safe

Full Access
Question # 25

You are beginning the post-install process after a manual PSM installation is completed.

What must you do?

A.

Disable screen saver for the PSM local users.

B.

Create a new group called PSMShadowUsers.

C.

Reset the PSMAdminConnect user password.

D.

Enable load balancing on the PSM server.

Full Access
Question # 26

Which of the following are supported authentication methods for CyberArk? Check all that apply

A.

CyberArk Password (SRP)

B.

LDAP

C.

SAML

D.

PKI

E.

RADIUS

F.

OracleSSO

G.

Biometric

Full Access
Question # 27

CyberArk User Neil is trying to connect to the Target Linux server 192.168.1.164 using a domain account ACME/linuxuser01 on domain acme.corp using PSM for SSH server 192.168.65.145.

What is the correct syntax?

A.

ssh neil@linuxuser01:acme.corp@192.168.1.164@192.168.65.145

B.

ssh neil@linuxuser01#acme.corp@192.168.1.164@192.168.65.145 Most Voted

C.

ssh neil@linuxuser01@192.168.1.164@192.168.65.145

D.

ssh neil@linuxuser01@acme.corp@192.168.1.164@192.168.65.145

Full Access
Question # 28

Which of the following are secure options for storing the contents of the Operator CD, while still allowing the contents to be accessible upon a planned Vault restart? Choose all that apply

A.

Store the CD in a physical safe and mount the CD every time vault maintenance is performed.

B.

Copy the contents of the CD to the System Safe on the vault

C.

Copy the contents of the CD to a folder on the vault server and secure it with NTFS permissions.

D.

Store the server key in a Hardware Security Module.

E.

Store the server key in the Provider cache

Full Access
Question # 29

By default, the vault secure protocol uses which IP port and protocol.

A.

TCP/1858

B.

TCP/443

C.

UDP/1858

D.

TCP/80

Full Access
Question # 30

In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?

A.

saml.config

B.

samlconfig.ini

C.

PVWAConfig.xml

D.

PVConfiguration.xml

Full Access
Question # 31

Which SMTP address can be set on the Notification Settings page to re-invoke the ENE setup wizard after the initial Vault installation?

A.

255.255.255.255

B.

8.8.8.8

C.

192.168.1.1

D.

1.1.1.1

Full Access
Question # 32

As a member of a PAM Level-2 support team, you are troubleshooting an issue related to load balancing four PVWA servers at two data centers. You received a note from your Level-1 support team stating “When testing PVWA website from a workstation, we noticed that the “Source IP of last sign-in” was shown as the VIP (Virtual IP address) assigned to the four PVWA servers instead of the workstation IP where the PVWA site was launched from.”

Which step should you take?

A.

Verify the “LoadBalancerClientAddressHeader” parameter setting in PVWA configuration file Web.config is set to “X-Forwarded-For”.

B.

Add the VIP (Virtual IP address) assigned to the four PVWA servers to the certificates issued for all four PVWA servers, if missing.

C.

Add a firewall rule to allow the testing workstation to connect to the VIP (Virtual IP address) assigned to the four PVWA servers on Port TCP 443.

D.

Edit the dbparm.ini file on the Vault server and add the IP or subnet of the workstation to the whitelist.

Full Access
Question # 33

Your customer wants to store the Safes Data on Vault Drive D instead of Drive C.

Which file should you edit?

A.

TSparm.ini Most Voted

B.

Vault.ini

C.

DBparm.ini

D.

user.ini

Full Access
Question # 34

Which parameter must be identical for both the Identity Provider (IdP) and the PVWA?

A.

IdP “EntityID” and “PartnerIdentityProvider Name” in PVWA saml.config file

B.

IdP “User name” and “SingleSignOnServiceUrl” in PVWA saml.config file

C.

IdP “Audience” and “ServiceProviderName” in the PVWA saml.config file

D.

IdP “Secure hash algorithm” and “Certificate” in the PVWA saml.config file

Full Access
Question # 35

You are setting up a Linux host to act as an HTML 5 gateway for PSM sessions.

Which servers need to be trusted by the Linux host to secure communications through the gateway?

A.

PSM and PVWA

B.

PSM and CPM

C.

PVWA and Vault

D.

Vault and PSM

Full Access
Question # 36

Which file would you modify to configure your Vault Server to forward Activity Logs to a SIEM or SYSLOG server?

A.

dbparm.ini

B.

PARagent.ini

C.

ENEConf.ini

D.

padr.ini

Full Access
Question # 37

What must you do to prepare a Windows server for PVWA installation?

A.

In the InstallationAutomation folder, run the PVWA_Prerequisites.ps1 file as an administrator in Powershell. Most Voted

B.

Install the PrivateArk client.

C.

Verify the user performing the installation is Domain Administrator and has logon access to the Vault server.

D.

Enable IPv6.

Full Access
Question # 38

What is the purpose of the PSM health check hardening?

A.

Remove IIS settings which can be considered security vulnerabilities.

B.

Validate that the PSM is ready to be placed behind a load balancer.

C.

Confirm that the Windows Services for PSM are running on the server.

D.

Ensure that the AppLocker script does not have any syntax errors.

Full Access
Question # 39

During the PSM installation process, Safes and a User are created.

In addition to Add Safes, Add/Update Users, Reset Users’ Passwords, and Activate Users, which authorization(s) does the Vault user installing the PSM need to enable them to be successfully created?

A.

Manage Vault File Categories Most Voted

B.

Manage Server File Categories

C.

Manage Directory Mapping, Manage Server File Categories

D.

Manage Directory Mapping, Manage Vault File Categories

Full Access
Question # 40

What is the name of the account used to establish the initial RDP session from the end user client machine to the PSM server?

A.

PSMConnect

B.

PSMAdminConnect

C.

PSM

D.

The credentials the end user retrieved from the vault

Full Access