Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

CPC-CDE-RECERT CyberArk CDE-CPC Recertification Questions and Answers

Questions 4

You are deploying a CyberArk Identity Connector to integrate Privilege Cloud Shared Services with an Active Directory environment. Which requirement must be met?

Options:

A.

The Identity Connector Server must be joined to the Active Directory.

B.

The Server must be a member of the root domain of the Active Directory forest.

C The Identity Connector must be installed on a Domain Controller.

C.

The Identity Connector must be installed using Domain Administrator credentials.

Buy Now
Questions 5

'What is a default authentication profile to access CyberArk Identity?

Options:

A.

Default New User Login Profile

B.

Default New Device Login Profile

C.

Default New Authenticator Profile

D.

Default New Password Profile

Buy Now
Questions 6

To use SAML authentication in Privilege Cloud Standard Services, users must first be defined in Privilege Cloud. What are correct methods for defining users? (Choose two.)

Options:

A.

Integrate Privilege Cloud with your LDAP server.

B.

Integrate Privilege Cloud with SIEM.

C.

Integrate Privilege Cloud with Email System.

D.

Create users in Privilege Cloud with details identical to those who access Privilege Cloud through SAML authentication.

E.

Create users in the CyberArk Privilege Cloud database using the CAVaultManager createuser command.

Buy Now
Questions 7

(Typing correction / missing stem noted)

Your last item only lists answer choices (no question text). Based on Privilege Cloud documentation, these choices most commonly appear with the question:

“Which tools can be used to upgrade Privilege Cloud Connector components (CPM/PSM)?” (Choose two.)

Options:

A.

Connector Configurator

B.

Connector Management Installer

C.

Privilege Cloud Installer

D.

Privilege Cloud Auto Installer

E.

Component Installer

Buy Now
Questions 8

Which Safe(s) does the AllowedSafes=Win platform parameter configuration match? (Choose two.)

Options:

A.

WindowsPasswords

B.

win-ssh-keys

C.

CXD-WIN-ADMINS

D.

SQL-Win-SA

E.

WiNdOwS_Accts

Buy Now
Questions 9

After correctly configuring reconciliation parameters in the Prod-AIX-Root-Accounts Platform, this error message appears in the CPM log: CACPM410E Ending password policy Prod-AIX-Root-Accounts since the reconciliation task is active but the AllowedSafes parameter was not updated What caused this situation?

Options:

A.

The reconciliation account defined in the Platform is in a locked state and is not accessible.

B.

The CPM is currently configured to use to an unsigned engine.

C.

The AllowedSafes parameter does not include the safe containing the reconciliation account defined in the Platform.

D.

A second CPM is incorrectly configured to manage the reconciliation account's safe which is causing a deadlock situation between the two CPMs.

Buy Now
Questions 10

Which users are Privilege Cloud Standard built-in users? (Choose 2.)

Options:

A.

NASCorp

B.

saascorps

C.

CyberArkAdmin

D.

remoteAccessAppUser

E.

PASReporterUser

Buy Now
Questions 11

Which statement describes the MFA integration capabilities of CyberArk Privilege Cloud (shared services model) compared to CyberArk PAM Self-Hosted?

Options:

A.

CyberArk Privilege Cloud and CyberArk PAM Self-Hosted offer identical MFA capabilities and integration methods.

B.

CyberArk Privilege Cloud leverages CyberArk Identity, while CyberArk PAM Self-Hosted needs additional integrations for MFA.

C.

CyberArk Privilege Cloud does not support MFA, while CyberArk PAM Self-Hosted does support a broad band of MFA integrations.

D.

CyberArk Privilege Cloud has limited MFA capabilities, whereas CyberArk PAM Self-Hosted offers an extensive range of MFA integration options.

Buy Now
Questions 12

Which actions must be performed when manually hardening a SUSE server with PSM for SSH? (Choose two.)

Options:

A.

Update settings in the sshd_config file on the server.

B.

Add the PSM for SSH gateway user to the passwd file.

C.

Validate that the psmpgwuser.cred file has correct permissions.

D.

Remove all users and groups from the passwd file.

E.

Add the PSM gateway user to the wheel group.

Buy Now
Questions 13

How should you configure PSM for SSH to support load balancing?

Options:

A.

by using a network load balancer

B.

in PVWA > Options > PSM for SSH Proxy > Servers

C.

in PVWA > Options > PSM for SSH Proxy > Servers > VIP

D.

by editing sshd.config on the all the PSM for SSH servers

Buy Now
Questions 14

What must be done to configure the syslog server IP address(es) for SIEM integration? (Choose 2.)

Options:

A.

Submit a service request to CyberArk Support.

B.

Update the syslog server IP address through the Privilege Cloud Portal.

C.

Update the DBPARM.ini file with the correct syslog server IP address.

D.

Update the vault.ini file with the correct syslog server IP address.

E.

Configure the Secure Tunnel for SIEM integration.

Buy Now
Questions 15

Which option correctly describes the authentication differences between CyberArk Privilege Cloud and CyberArk PAM Self-Hosted?

Options:

A.

CyberArk Privilege Cloud only provides a username and password authentication without third-party IdP integration; CyberArk PAM Self-Hosted uses traditional on-premises methods such as Windows and LDAP. but lacks modern protocols such as SAML or OIDC.

B.

CyberArk Privilege Cloud uses cloud-based methods, integrating with CyberArk Identity for MFA. and supports SAML and OIDC; CyberArk PAM Self-Hosted depends on on-premises methods such as RADIUS and LDAP, but can adopt SAML or OIDC with additional setups.

C.

CyberArk Privilege Cloud requires on-premises components for all authentication and does not support other cloud-based authentication protocols; CyberArk PAM Self-Hosted offers a wide array of methods, including support for SAML. OIDC. and other modern protocols, without needing on-premises components.

D.

Both use the same authentication methods.

Buy Now
Questions 16

Which ports do the CyberArk Identity Connector require to be opened to support using Active Directory for LDAP authentication to Privileged Cloud Shared Services? (Choose two.)

Options:

A.

TCP 636 from the connector host to the domain controller

B.

TCP 443 from the connector host to the CyberArk Tenant

C.

TCP 636 from the CyberArk Tenant to the domain controller

D.

TCP 443 from the CyberArk Tenant to the connector host

E.

TCP 636 from the domain controller to the CyberArk Tenant

Buy Now
Questions 17

What is the default username for the PSM for SSH maintenance user?

Options:

A.

proxymng

B.

psmp_maintenance

C.

psmpmaintenanceuser

D.

proxyusr

Buy Now
Questions 18

Arrange the steps to complete CPM Hardening for out-of-Domain deployment in the correct sequence.

CPC-CDE-RECERT Question 18

Options:

Buy Now
Questions 19

How can a platform be configured to work with load-balanced PSMs?

Options:

A.

Remove all entries from configured PSM Servers except for the ID of the PSMs with load balancing.

B.

Create a new PSM definition that targets the load balancer IP address and assign to the platform.

C.

Include details of the PSMs with load balancing in the Basic_psm.ini file on each PSM server.

D.

Use the Privilege Cloud Portal to update the Session Management settings for the platform in the Master Policy.

Buy Now
Questions 20

What is the recommended method to enable load balancing and failover of the CyberArk Identity Connector?

Options:

A.

Setup IIS based Application Request Routing on two or more CyberArk Identity Connector servers.

B.

Set up a network load balancer between two or more CyberArk Identity Connector servers.

C.

Set up two or more CyberArk Identity Connector servers only.

D.

Set up a Microsoft Failover Cluster on two or more CyberArk Identity Connector servers.

Buy Now
Questions 21

In the directory lookup order, which directory service is always looked up first for the CyberArk Privilege Cloud solution?

Options:

A.

Active Directory

B.

LDAP

C.

Federated Directory

D.

CyberArk Cloud Directory

Buy Now
Questions 22

In addition to CyberArk, which additional licensing implication does the PSM have?

Options:

A.

RDS CALs

B.

Microsoft Office

C.

GCP

D.

AWS

Buy Now
Questions 23

According to best practice, when considering the location of PSM Connector servers in Privilege Cloud environments, where should the PSM be placed?

Options:

A.

near the CPM servers

B.

near the target devices

C.

near the Vault (closer to the external internet connection)

D.

near the Users

Buy Now
Questions 24

What is the purpose of the HTML5 Gateway in CyberArk Remote Access Architecture when integrated with Privilege Cloud?

Options:

A.

It tunnels the session between the Remote Access Connector and the Privileged Session Manager.

B.

It authenticates connections between the Remote Access Cloud Service and the customer's Privilege Cloud environment.

C.

It provides VPN access to critical target systems.

D.

It combines Zero Trust access along with biometric authentication and seamless just-in-time provisioning for remote vendors connecting to CyberArk Privilege Cloud.

Buy Now
Questions 25

What must be done before configuring directory mappings in the CyberArk Privilege Cloud Standard Portal for LDAP integration?

Options:

A.

Retrieve the LDAPS certificate and deliver it to CyberArk.

B.

Create a new domain in the Privilege Cloud Portal.

C.

Make sure HTTPS (443/tcp) is reachable over the Secure Tunnel.

D.

Ensure the user connecting to the domain has administrative privileges.

Buy Now
Questions 26

You are configuring an integration to provision users based on LDAP directory services for Privilege Cloud Shared Services. Which component must first be installed and configured in the environment to support this?

Options:

A.

CyberArk Identity Connector

B.

Secure Tunnel

C.

Privilege Cloud Connector

D.

Linux Connector Server

Buy Now
Questions 27

Following the installation of the PSM for SSH server, which additional tasks should be performed? (Choose 2.)

Options:

A.

Delete the user.cred file used during installation.

B.

Delete the vault.ini you used during installation.

C.

Delete the psmpparms file you used during installation.

D.

Package all installation log files for upload to CyberArk.

Buy Now
Questions 28

What is a requirement when installing the PSM on multiple Privileged Cloud Connector servers?

Options:

A.

Each PSM must have the same path to the same recordings directory.

B.

All PSMs in the environment must be configured to use load balancing.

C.

Additional Privilege Cloud Connector servers cannot have CPM installed.

D.

In-domain servers cannot be used when deploying multiple PSM servers.

Buy Now
Questions 29

You want to add an additional maintenance user on the PSM for SSH. How can you accomplish this if InstallCyberArkSSHD is set to Integrated?

Options:

A.

Create a local user and add it to the PSMP_MaintenanceUsers group.

B.

Create a local user called proxymaster and add it to /etc/pam.d/auth-password.

C.

Create a local user and add it to the group configured for the parameter AllowGroups in the /etc/ssh/sshd_config file.

D.

Create a local user called psmpmng and add it to the PSMMaintenance group in /etc/pam.d/auth-password.

Buy Now
Exam Code: CPC-CDE-RECERT
Exam Name: CyberArk CDE-CPC Recertification
Last Update: Apr 11, 2026
Questions: 99

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99