CyberArk PAM-SEN Exam Practice Questions (P. 4)
- Full Access (97 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
When creating a distributed Vault environment architecture, what is the maximum number of Vault servers that can be deployed?
- A5 - number of primary and satellite Vaults can be specified during installation
- B3 - all primary
- C6 - 1 primary and 5 satelliteMost Voted
- D10 - 2 primary and 8 satellite
Correct Answer:
D
D
send
light_mode
delete
Question #17
To enable LDAP over SSL for a Vault when DNS lookups are blocked, which step must be completed?
- AAdd the FQDN & IP details for each LDAP host into the local hosts file of the Vault server.Most Voted
- BConfigure an AllowNonStandardFWAddresses rule in DBParm.ini on the Vault to allow outbound TCP 53 to the organization’s DNS servers.
- CEnsure LDAP hosts added to the directory mapping configuration are defined using only IP addresses.
- DSet the ReferralsDNSLookup parameter value to “No” in the directory configuration.
Correct Answer:
C
C
send
light_mode
delete
Question #18
In which file must the attribute ‘SignAuthnRequest=”true”’ be added to the PartnerIdentityProvider element to support signed SAML requests?
- Asaml.configMost Voted
- Bsamlconfig.ini
- CPVWAConfig.xml
- DPVConfiguration.xml
Correct Answer:
C
C
send
light_mode
delete
Question #19
A customer is moving from an on-premises to a public cloud deployment.
What is the best and most cost-effective option to secure the server key?
What is the best and most cost-effective option to secure the server key?
- AInstall the Vault in the cloud the same way you would in an on-premises environment. Place the server key in a password protected folder on the operating system.
- BInstall the Vault in the cloud the same way you would in an on-premises environment. Purchase a Hardware Security Module to secure the server key.
- CInstall the Vault using the native cloud images and secure the server key using native cloud Key Management Systems.Most Voted
- DInstall the Vault using the native cloud images and secure the server key with a Hardware Security Module.
Correct Answer:
C
C
send
light_mode
delete
Question #20
Your customer upgraded recently to version 12.2 to allow the Linux team to use the new MFA caching feature. The PSM for SSH was installed with default configuration settings. After setting the Authentication to SSH key and enabling MFA Caching from the PVWA interface, the Linux Team cannot connect successfully using the new MFA caching feature.
What is the most probable cause?
What is the most probable cause?
- AOpenSSH 7.8 or above is not installed.Most Voted
- BThe MFACaching parameter in the psmpparms file is not set to True.
- CA passphrase policy must be added.
- DMFA caching is not supported when the PSM for SSH is deployed with default settings.
Correct Answer:
D
D
send
light_mode
delete
All Pages