and All Correct Answers 2026-2027
Updated.
The account feed contains - Answer Accounts that were discovered by CyberArk that have not
yet been onboarded
Account discovery allows secure connections to domain controllers - Answer True
Which of these onboarding methods is considered proactive? - Answer A Rest API integration
with account provisioning software
When creating an onboarding rule, it will be executed upon... - Answer Any future accounts
discovered by a discovery process
What are the functions of the Remote Control Agent Service? - Answer -Allows remote
monitoring of the vault -Allows CyberArk services to be managed remotely -Sends SNMP traps
from the vault
The vault administrator can change the vault license by uploading the new license to the system
Safe - Answer True
CyberArk implements license limits by controlling the number and types of users that can be
provisioned in the vault - Answer True
PSM for Windows(previously known as RDP Proxy) supports connections to which of the
following target systems? - Answer Windows, Unix, Oracle
PSM for SSH(previously known as PSM-SSH Proxy) supports connections to which of the
following target systems? - Answer Unix
Within the Vault each password is encrypted by: - Answer Its own unique key
Which utilities could a Vault administrator use to change debugging levels on the Vault without
having to restart the Vault? - Answer PAR Agent, PrivateArk Server Central Administration
How does the Vault administrator apply a new license file? - Answer Upload the license.xml
file to the system safe
, Which keys are required to be present in order to start the PrivateArk Server service? - Answer
Server key, Recovery public key
What is the purpose of the CyberArk ENE service? - Answer It sends email messages from the
vault
What is the purpose of the PrivateArk Database service? - Answer Maintains Vault metadata
What is the purpose of the PrivateArk Server Service? - Answer Makes Vault data accessible to
components
Select the best practice for storing the Master CD - Answer Store the CD in a secure location,
such as a physical safe
Which of the following are secure options for storing the contents of the Operator CD, while still
allowing the contents to be accessible upon a planned vault restart? - Answer -Store the CD in
a physical safe and mount the CD every time Vault maintenance is performed
-Copy the entire contents of the CD to a folder on the Vault server and secure it with NTFS
permissions
-Store the server key in an HSM and copy the rest of the keys from the CD to a folder on the
Vault server and secure it with NTFS permissions
Which service should NOT be running on the DR Vault when the primary Production Vault is up?
- Answer PrivateArk Server
Which of the following logs contains information about errors related to the PTA? - Answer
Diamond.log
When a DR Vault Server becomes an active vault, it will automatically fail back to the original
state once the Primary Vault comes back online. - Answer False; this is not possible
When a DR Vault Server becomes an active vault, it will automatically revert back to DR mode
once the Primary Vault comes back online. - Answer False, the vault administrator must
manually set the DR Vault to DR mode by setting "FailoverMode=no" in the padr.ini file
Which of the following components can be used to create a tape backup of the Vault? - Answer
Replicate