ExamDumpster

Free CPC-SEN sample questions

Real questions from the Cyberark Sentry - Privilege Cloud practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A financial services firm uses Privilege Cloud with on-premises Connectors running CPM and PSM, and must plan disaster recovery for password management at a secondary site. According to CyberArk, how is disaster recovery provided for the CPM component?

Question 2Choose one

A security administrator is configuring Privilege Cloud to manage the password of a Cisco IOS user account with the "Cisco router via SSH" platform. The Cisco user does not have the privileges needed to change passwords, so the CPM must switch to Enable mode on the router to change the password. What must be configured for the CPM to do this?

Question 3Choose 2

During a security audit of a Privilege Cloud deployment, an auditor notices that the PSM servers on the Connectors write session recordings to a local folder and asks whether recordings are retained on the PSM hosts. Which TWO statements accurately describe how PSM handles session recordings in Privilege Cloud? (Select TWO)

Question 4Choose one

A consultant uses the Privilege Cloud REST API to onboard several hundred Active Directory service accounts. The accounts are added successfully, but the CPM's password changes fail because the domain password policy prevents these users from changing their own passwords (for example, a minimum password age). A reconcile account that is allowed to reset passwords is linked to the platform. What should the consultant configure so that the CPM can rotate these passwords?

Question 5Choose one

True or False: When integrating CyberArk Privilege Cloud with an external SIEM system, the Secure Tunnel on the Privilege Cloud Connector must be used to forward audit logs.

Question 6Choose one

A healthcare organization is deploying Privilege Cloud and has a strict requirement that all privileged sessions to their Electronic Health Record (EHR) database servers must be monitored in real-time by a security analyst. The connection must also be terminated immediately if suspicious activity is detected. Which Privilege Cloud feature directly supports this requirement?

Question 7Choose one

An administrator uses the out-of-the-box "Amazon Web Services - AWS - Access Keys" platform to manage the access key of an AWS IAM user. The key has become unsynchronized, and the administrator plans to add a reconcile account to the platform so that the CPM can reconcile it. What should the administrator know about this plugin?

Question 8Choose one

A university is configuring SAML authentication for Privilege Cloud with its central Shibboleth Identity Provider (IdP). After the integration is configured, users receive an 'Invalid Assertion' SAML error when they are redirected back to the Privilege Cloud portal. The IdP logs show successful authentication, the IdP's clock is synchronized with a reliable NTP source, and the Audience value configured in the IdP matches the value provided for the Privilege Cloud SAML configuration. What is the most likely misconfiguration?

Question 9Choose 2

In a Privilege Cloud Standard deployment, which two functions does the optional Secure Tunnel client provide? (Choose two.)

Question 10Choose one

**Case Study** A rapidly growing e-commerce company is deploying CyberArk Privilege Cloud to manage access to its production AWS environment and on-premises legacy systems. The company has a large, distributed DevOps team that requires just-in-time (JIT) access to EC2 instances for troubleshooting. The security team has mandated that all access must be temporary, request-based, and fully audited. The legacy systems are managed by a separate IT operations team that requires persistent, standing access. **Current Situation:** The company uses Okta as its corporate Identity Provider (IdP) and has integrated it with Privilege Cloud for user authentication. The DevOps team members are part of an 'AWS-Admins' group in Okta. The IT operations team is in an 'IT-Ops' group. A single Safe named 'Production-Servers' has been created to store all privileged accounts. **Requirements:** 1. DevOps users must request access to specific EC2 instances for a limited time (e.g., 4 hours). 2. Access for DevOps users must require approval from a team lead. 3. IT-Ops users should have immediate, non-expiring access to the legacy system accounts. 4. All session activity for both teams must be recorded. Which combination of configurations will meet all these requirements?

10 more free samples are waiting

Create a free account to unlock the whole CPC-SEN sample bank, or get full access to all 253 practice questions in the simulator.

Create account