CYBERARK SENTRY EXAM SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◉ __________ Report is for each user and shows Accounts and Safes
what they can access in the System. Answer: Entitlement Report
◉ File for:
- main configuration file of the Vault.
- any change requests requires a restart of the Vault Service. Answer:
DBParm.ini
◉ PTA Statistics Log Name Answer: Statistics.log
◉ Within the Vault, each password is encrypted by? Answer: Its own
unique key
◉ Good use case for Disaster Recovery module Answer: Offsite
replication is required
◉ What would be a good use case for the Replicate Module? Answer:
Integration with an Enterprise Backup Solution is required
,◉ PTA Utility Log Name Answer: Diamond-Utility.log
◉ What account automatically onboards unmanaged privileged
account? Answer: PTAUser
◉ Provides information about all the privileged accounts in the
system required permissions:
- list accounts
- view safe members Answer: Privileged Accounts Inventory Report
◉ The Vault Internal Safe contains all of the configuration for the
Vault? Answer: False
◉ Who is in the only user that can edit the Directory Mappings?
Answer: Built in Administrator
◉ What is Applocker used for? Answer: Limits the applications that
may be raw on the PSM machine
◉ Can you set the Cluster Vault Debug Level Dynamically without
restarting the Cluster Vault? Answer: Yes
◉ Can the PVWA be load balanced? Answer: Yes
,◉ What happens when multiple discoveries of accounts are on the
same domain accounts? Answer: Multiple discoveries will
synchronize all the shared discovered accounts
◉ Purpose and permissions needed for the Activity Log Report
Answer: - All audit information in the Vault
- View audit and audit users
◉ File for:
- configure Remote Control Agent in the Vault
- SNTP Configuration Answer: PARagent.ini
◉ What is the purpose of the Immediate Interval setting in the CPM
Policy? Answer: To control how often the CPM looks for User
Initiated CPM work
◉ At what point is a transparent user provisioned in the Vault?
Answer: The first time the user logs in
◉ HA, DR, and Replication are mutually exclusive and cannot be
used in the same environment. Answer: False
, ◉ Password Upload Utility must be installed on the CPM server.
Answer: False
◉ File for:
- Configuring Password Policy for users of the Vault Answer:
Passparm.ini
◉ Which report could show all audit data in the Vault? Answer:
Activity Log
◉ What is the primary reason for installing more than one active
CPM? Answer: Installing CPMS in multiple sites prevents complex
rules to manage devices at remote sites
◉ Through which component do you configure the CPM? Answer:
PVWA
◉ Through which component do you manage internal CyberArk
users? Answer: PrivateArk Client
◉ Which file would you modify to configure your Vault server to
forward Activity Logs to a a SIEM or SYSLOG Server? Answer:
DBParm.ini
QUESTIONS WITH SOLUTIONS GRADED A+
◉ __________ Report is for each user and shows Accounts and Safes
what they can access in the System. Answer: Entitlement Report
◉ File for:
- main configuration file of the Vault.
- any change requests requires a restart of the Vault Service. Answer:
DBParm.ini
◉ PTA Statistics Log Name Answer: Statistics.log
◉ Within the Vault, each password is encrypted by? Answer: Its own
unique key
◉ Good use case for Disaster Recovery module Answer: Offsite
replication is required
◉ What would be a good use case for the Replicate Module? Answer:
Integration with an Enterprise Backup Solution is required
,◉ PTA Utility Log Name Answer: Diamond-Utility.log
◉ What account automatically onboards unmanaged privileged
account? Answer: PTAUser
◉ Provides information about all the privileged accounts in the
system required permissions:
- list accounts
- view safe members Answer: Privileged Accounts Inventory Report
◉ The Vault Internal Safe contains all of the configuration for the
Vault? Answer: False
◉ Who is in the only user that can edit the Directory Mappings?
Answer: Built in Administrator
◉ What is Applocker used for? Answer: Limits the applications that
may be raw on the PSM machine
◉ Can you set the Cluster Vault Debug Level Dynamically without
restarting the Cluster Vault? Answer: Yes
◉ Can the PVWA be load balanced? Answer: Yes
,◉ What happens when multiple discoveries of accounts are on the
same domain accounts? Answer: Multiple discoveries will
synchronize all the shared discovered accounts
◉ Purpose and permissions needed for the Activity Log Report
Answer: - All audit information in the Vault
- View audit and audit users
◉ File for:
- configure Remote Control Agent in the Vault
- SNTP Configuration Answer: PARagent.ini
◉ What is the purpose of the Immediate Interval setting in the CPM
Policy? Answer: To control how often the CPM looks for User
Initiated CPM work
◉ At what point is a transparent user provisioned in the Vault?
Answer: The first time the user logs in
◉ HA, DR, and Replication are mutually exclusive and cannot be
used in the same environment. Answer: False
, ◉ Password Upload Utility must be installed on the CPM server.
Answer: False
◉ File for:
- Configuring Password Policy for users of the Vault Answer:
Passparm.ini
◉ Which report could show all audit data in the Vault? Answer:
Activity Log
◉ What is the primary reason for installing more than one active
CPM? Answer: Installing CPMS in multiple sites prevents complex
rules to manage devices at remote sites
◉ Through which component do you configure the CPM? Answer:
PVWA
◉ Through which component do you manage internal CyberArk
users? Answer: PrivateArk Client
◉ Which file would you modify to configure your Vault server to
forward Activity Logs to a a SIEM or SYSLOG Server? Answer:
DBParm.ini