Pre-Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

CPC-CDE-RECERT Sample Questions Answers

Questions 4

Before installing the Privilege Cloud Connector using Connector Management, which network rules should be in place?

Options:

A.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 443

CustomerPortalConnectivity: Port 443

B.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 5589

C.

TunnelConnectivity: Secure Tunnel Port 443

CustomerPortalConnectivity: Port 5589

D.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 22

CustomerPortalConnectivity: Port 3389

Buy Now
Questions 5

When using Connector Management, how do you configure a DR CPM in Privilege Cloud shared services? (Choose two.)

Options:

A.

Stop the CyberArk Password Manager service and set the startup type to Manual.

B.

When prompted for the Vault IP address on the installation windows, leave it blank and proceed.

C.

When prompted to select the CPM mode, select Passive.

D.

When prompted for the Vault administrator credentials on the installation windows, leave it blank and proceed.

E.

Stop the CyberArk Password Manager service and set the startup type to Automatic.

Buy Now
Questions 6

Which group has only View Audit and View Safe permissions?

Options:

A.

Operators

B.

Auditors

C.

Privileged Cloud Admins

D.

Backup Users

Buy Now
Questions 7

What is a requirement when installing the PSM on multiple Privileged Cloud Connector servers?

Options:

A.

Each PSM must have the same path to the same recordings directory.

B.

All PSMs in the environment must be configured to use load balancing.

C.

Additional Privilege Cloud Connector servers cannot have CPM installed.

D.

In-domain servers cannot be used when deploying multiple PSM servers.

Buy Now
Questions 8

To disable the PSM default Support for Browser Sessions, which option should be set to 'No* before running Hardening?

Options:

A.

SupportWebApplications

B.

SupportBrowsers

C.

SupportWebBrowsers

D.

SupportHTML5Content

Questions 9

Which component supports the required communication to send audit logs from Privilege Cloud through the Syslog protocol to a SIEM application?

Options:

A.

CyberArk Syslog Writer

B.

Secure Tunnel

C.

Privilege Cloud Connector

D.

CyberArk Identity Connector

Buy Now
Questions 10

You plan to install the Privilege Cloud Connector on Windows Server 2019 and must leverage your existing RDS Per-user licenses for PSM connections. What must you do?

Options:

A.

Add the UseRDSPerUser=Yes line to the basic_psm.ini parameters file.

B.

Install the RDS License Server Service on Windows 2016.

C.

Migrate the local PSMConnect users to Domain users.

D.

Modify the UseRDSPerUser parameter to Yes on every Windows-related platform.

Buy Now
Questions 11

Refer to the exhibit.

You set up your LDAP Directory in CyberArk Identity, but encountered an error during the connection test.

Which scenarios could represent a valid misconfiguration? (Choose 2.)

Options:

A.

TCP Port 636 could be blocked by a network firewall, preventing communication between the CyberArk Identity Connector and the LDAP Server.

B.

All required CA Certificates have been installed on the CyberArk Identity Connector but the LDAP Bind credentials provided are incorrect.

C.

Verify Server Certificate' is activated but the provided hostname is not listed as a Subject Alternative Name (SAN) in the LDAP server's certificate.

D.

TCP Port 636 could be blocked by a network firewall, preventing communication between the Secure Tunnel and the LDAP Server.

Buy Now
Questions 12

On Privilege Cloud, what can you use to update users' Permissions on Safes? (Choose 2.)

Options:

A.

Privilege Cloud Portal

B.

PrivateArk Client

C.

REST API

D.

PACLI

E.

PTA

Buy Now
Questions 13

Arrange the steps to install a passive CPM using the Privilege Cloud installer in the correct sequence.

Options:

Questions 14

Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?

Options:

A.

vault.ini

B.

user.cred

C.

psmpparms

D.

psmgw.config

Buy Now
Questions 15

Which prerequisites are required for installing PSM for SSH (Unix Connector)? (Choose two.)

Options:

A.

Create the PSM for SSH parameters file on the Unix server with InstallCyberArkSSHD = Integrated.

B.

Configure the root user to not authenticate to the Unix server remotely through SSH using a password.

C.

Verify that outbound traffic from the Unix server is always routed through the same public-facing IP.

D.

Create an administrative user on the Unix server for future maintenance tasks.

E.

Reset the default root account password before installing the PSM for SSH.

Buy Now
Questions 16

Arrange the steps to failover to the passive CPM in the correct sequence.

Options:

Buy Now
Questions 17

When calling the PSM Health Check Webservice to assess the state of a PSM node, which response code does a healthy node return?

Options:

A.

200 (OK)

B.

404 (OK)

C.

500 (OK)

D.

503 (OK)

Buy Now
Questions 18

What are the basic network requirements to deploy a CPM server?

Options:

A.

Port 1858 to the Privilege Cloud Vault service backend and Port 443 to the Privilege Cloud Portal

B.

Port 1858 only

C.

any ports to the Privilege Cloud Vault service backend

D.

Port UDP/1858 to the Privilege Cloud Vault service backend and all required ports to the targets and Port 3389 to the PSM

Buy Now
Questions 19

After correctly configuring reconciliation parameters in the Prod-AIX-Root-Accounts Platform, this error message appears in the CPM log: CACPM410E Ending password policy Prod-AIX-Root-Accounts since the reconciliation task is active but the AllowedSafes parameter was not updated What caused this situation?

Options:

A.

The reconciliation account defined in the Platform is in a locked state and is not accessible.

B.

The CPM is currently configured to use to an unsigned engine.

C.

The AllowedSafes parameter does not include the safe containing the reconciliation account defined in the Platform.

D.

A second CPM is incorrectly configured to manage the reconciliation account's safe which is causing a deadlock situation between the two CPMs.

Buy Now
Questions 20

Which users are Privilege Cloud Standard built-in users? (Choose 2.)

Options:

A.

NASCorp

B.

saascorps

C.

CyberArkAdmin

D.

remoteAccessAppUser

E.

PASReporterUser

Questions 21

Which deployment criteria influences the CyberArk-provided hardening methods that need to be applied to CPM and PSM components?

Options:

A.

“In Domain” and “Out of Domain”

B.

“On Premises” and “On Cloud”

C.

“Windows” and “Linux”

D.

“Primary Privilege Cloud Connector” and “additional Privilege Cloud Connector”

Buy Now
Questions 22

You have been tasked with deploying a Privilege Cloud PSM for SSH connector When the initial installation has successfully completed, you create and permission several maintenance users to be used for administering the connector.

Which configuration file must be updated to define these maintenance users?

Options:

A.

sshd.config

B.

basic_psmpserver.conf

C.

sshd_config

D.

psmpparms

Buy Now
Questions 23

Which statements are correct regarding LDAP integration in Privilege Cloud Shared Services? (Choose two.)

Options:

A.

LDAP integration can be configured in the Privilege Cloud web interface under Administration > Configuration Options > LDAP Integration.

B.

A Secure Tunnel installation is required to access the on-premises LDAP directory.

C.

The Privilege Cloud PAM leverages the directory services integration of CyberArk Identity.

D.

The CA certificate that issued the LDAP server’s Server Authentication certificate must be trusted on the machine running the CyberArk Identity Connector.

E.

The CA certificate that issued the LDAP server’s Server Authentication certificate must be provided to CyberArk Support.

Buy Now
Questions 24

You want to add an additional maintenance user on the PSM for SSH. How can you accomplish this if InstallCyberArkSSHD is set to Integrated?

Options:

A.

Create a local user and add it to the PSMP_MaintenanceUsers group.

B.

Create a local user called proxymaster and add it to /etc/pam.d/auth-password.

C.

Create a local user and add it to the group configured for the parameter AllowGroups in the /etc/ssh/sshd_config file.

D.

Create a local user called psmpmng and add it to the PSMMaintenance group in /etc/pam.d/auth-password.

Buy Now
Questions 25

A support team has asked you to provide the previous password for an account that had its password recently changed by the CPM. In which tab within the account's overview page can you retrieve this information?

Options:

A.

Overview

B.

Activities

C.

Details

D.

Versions

Buy Now
Questions 26

You need to map an enterprise’s Active Directory to Privilege Cloud Shared Services to enable users to log in to CyberArk through their LDAP credentials. What do you need to accomplish this? (Choose two.)

Options:

A.

Read-only domain user to facilitate the LDAP mapping

B.

Installation and configuration of the Identity Connector

C.

Port 636 open to the Privilege Cloud back-end

D.

Trusted certificate for LDAP server installed on Identity Connector

E.

Configuration of a Federated Domain on the Identity Platform

Buy Now
Questions 27

Which authentication methods does PSM for SSH support? (Choose 2.)

Options:

A.

OIDC

B.

MFA Caching

C.

SAML

D.

RADIUS

E.

Client Authentication Certificate

Buy Now
Questions 28

During CPM hardening, which locally created users are granted Logon as a Service rights in the local group policy? (Choose 2.)

Options:

A.

PasswordManager

B.

PluginManagerUser

C.

ScannerUser

D.

PasswordManagerUser

E.

CPMServiceAccount

Questions 29

In large-scale environments, it is important to enable the CPM to focus its search operations on specific Safes instead of scanning all Safes it sees in the Vault. How is this accomplished?

Options:

A.

Administration Options > CPM Settings

B.

AllowedSafes Parameter on each platform policy

C.

MaxConcurrentConnection parameter on each platform policy

D.

Administration > Options > CPM Scanner.

Buy Now
Exam Code: CPC-CDE-RECERT
Exam Name: CyberArk CDE-CPC Recertification
Last Update: Apr 14, 2026
Questions: 99
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now CPC-CDE-RECERT