Correct Answers 2026-2027 Updated.
AllowNonStandardFWAddresses Firewall Exception Syntax - Answer
AllowNonStandardFWAddresses=[HSM-IP],Yes,1024:inbound/tcp,1024:outbound/tcp
Syntax Command CAVaultManager uses to store a secret - Answer CAVaultManager.exe
/SecretType HSM /Secret password
Syntax command to install a server key to an HSM device using CAVaultManager - Answer
CaVaultManager.exe LoadServerKeyToHSM
Syntax command to re-generate a key on the HSM where the new value is unknown to the
operator - Answer CAVaultManager.exe GenerateKeyOnHSM /ServerKey.
Then, ChangeServerKeys.exe
Any changes made to the DBParms.ini configuration file require a _________ - Answer reboot
What should you do to complete a post-install hardening of the Vault? - Answer 1.) Identify
appropriate services are started.
2.) Check that firewall exceptions have been made in the DBParms.ini file.
3.) Ensure the server key is running successfully on the HSM.
4.) Ensure the Operator disk is correctly secured with NTFS permissions.
Steps to complete a Vault installation - Answer 1.) Check that the server rebooted properly
2.) Ensure that the ITALog displays the following message: ITAFW001I Firewall is open for client
communication"
3.) Ensure the three safes: System, VaultInternal, Notification Engine were created.
4.) Ensure the 6 services were installed and started. (Later flash card)
5.) Test master login
6.) Network Areas should be configured to only allow connections from the planned IP
addresses for CyberArk Components
What 6 services are installed and started after installing the Vault? - Answer 1.) Cyber-Ark
Event Notification Engine
2.) Cyber-Ark Hardened Windows Firewall
, 3.) CyberArk Logic Container
4.) PrivateArk Database
5.) PrivateArk Remote Control Agent
6.) PrivateArk Server
How do you prepare a Windows server for Vault installation? - Answer 1.) Ensure it meets the
minimum requirements for CyberArk.
2.) Ensure the server is of type Workstation and has never been connected to a domain.
3.) Load installation files into the server.
4.) Disable all network components aside from IPv4 and optionally IPv6.
4.) Disable DNS lookup and LMHosts lookup for WINS. Disable NetBios as well.
Four Stages of PVWA Installation - Answer 1.) Pre-Installation Tasks
2.) Installation
3.) Post-Install Tasks
4.) Hardening
PVWA Pre-Installation Tasks - Answer 1.) Review Requirements
2.) Close Applications and Log On
3.) Run Prerequisites Script
PVWA Installation Tasks - Answer 1.) Run the PVWA Installation Script
2.) Registration (Connecting to the Vault)
PVWA Post-Installation Tasks - Answer 1.) Check Installation Log Files
2.) Check User Permissions on Web Server
3.) Add Restrictions to Credential Files
4.) Set API Throttling
PVWA Hardening Tasks - Answer 1.) Run Hardening Script
2.) Apply Post Hardening Configurations
3.) *Harden server in a Domain environment
*Only perform this task if your PVWA server is part of a domain