Pass the CyberArk Sentry CPC-SEN Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What are the basic network requirements to deploy a CPM server?

Options:

A.

Port 1858 to the Privilege Cloud Vault service backend and Port 443 to the Privilege Cloud Portal


B.

Port 1858 only


C.

any ports to the Privilege Cloud Vault service backend


D.

Port UDP/1858 to the Privilege Cloud Vault service backend and all required ports to the targets and Port 3389 to the PSM


Expert Solution
Questions # 2:

You plan to install Privilege Cloud Connectors on your AWS and Azure environments.

What is the maximum number of concurrent RDP/SSH sessions that each connector can handle for Large Implementations?

Options:

A.

1-10


B.

31-60


C.

100


D.

200


Expert Solution
Questions # 3:

Refer to the exhibit.

You set up your LDAP Directory in CyberArk Identity, but encountered an error during the connection test.

Which scenarios could represent a valid misconfiguration? (Choose 2.)

Question # 3

Options:

A.

TCP Port 636 could be blocked by a network firewall, preventing communication between the CyberArk Identity Connector and the LDAP Server.


B.

All required CA Certificates have been installed on the CyberArk Identity Connector but the LDAP Bind credentials provided are incorrect.


C.

Verify Server Certificate' is activated but the provided hostname is not listed as a Subject Alternative Name (SAN) in the LDAP server's certificate.


D.

TCP Port 636 could be blocked by a network firewall, preventing communication between the Secure Tunnel and the LDAP Server.


Expert Solution
Questions # 4:

Which option correctly describes the authentication differences between CyberArk Privilege Cloud and CyberArk PAM Self-Hosted?

Options:

A.

CyberArk Privilege Cloud only provides a username and password authentication without third-party IdP integration; CyberArk PAM Self-Hosted uses traditional on-premises methods such as Windows and LDAP. but lacks modern protocols such as SAML or OIDC.


B.

CyberArk Privilege Cloud uses cloud-based methods, integrating with CyberArk Identity for MFA. and supports SAML and OIDC; CyberArk PAM Self-Hosted depends on on-premises methods such as RADIUS and LDAP, but can adopt SAML or OIDC with additional setups.


C.

CyberArk Privilege Cloud requires on-premises components for all authentication and does not support other cloud-based authentication protocols; CyberArk PAM Self-Hosted offers a wide array of methods, including support for SAML. OIDC. and other modern protocols, without needing on-premises components.


D.

Both use the same authentication methods.


Expert Solution
Questions # 5:

Following the installation of the PSM for SSH server, which additional tasks should be performed? (Choose 2.)

Options:

A.

Delete the user.cred file used during installation.


B.

Delete the vault.ini you used during installation.


C.

Delete the psmpparms file you used during installation.


D.

Package all installation log files for upload to CyberArk.


Expert Solution
Questions # 6:

To disable the PSM default Support for Browser Sessions, which option should be set to 'No* before running Hardening?

Options:

A.

SupportWebApplications


B.

SupportBrowsers


C.

SupportWebBrowsers


D.

SupportHTML5Content


Expert Solution
Questions # 7:

In the directory lookup order, which directory service is always looked up first for the CyberArk Privilege Cloud solution?

Options:

A.

Active Directory


B.

LDAP


C.

Federated Directory


D.

CyberArk Cloud Directory


Expert Solution
Questions # 8:

After correctly configuring reconciliation parameters in the Prod-AIX-Root-Accounts Platform, this error message appears in the CPM log: CACPM410E Ending password policy Prod-AIX-Root-Accounts since the reconciliation task is active but the AllowedSafes parameter was not updated What caused this situation?

Options:

A.

The reconciliation account defined in the Platform is in a locked state and is not accessible.


B.

The CPM is currently configured to use to an unsigned engine.


C.

The AllowedSafes parameter does not include the safe containing the reconciliation account defined in the Platform.


D.

A second CPM is incorrectly configured to manage the reconciliation account's safe which is causing a deadlock situation between the two CPMs.


Expert Solution
Questions # 9:

A CyberArk Privileged Cloud Shared Services customer asks you how to find recent failed login events for all users. Where can you do this without generating reports?

Options:

A.

Privileged Cloud Portal


B.

Identity Administration Portal

C both Identity Administration and Identity User Portals


C.

Identity User Portal


Expert Solution
Questions # 10:

What is the correct CyberArk user to use when installing the Privilege Cloud Connector software?

Options:

A.

installeruser@


B.

Administrator


C.

_admin


D.

Installer


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions