About the Exam

CAU301 is the CyberArk Sentry exam in CyberArk’s certification program. It validates theoretical and hands-on skills for deploying and configuring CyberArk solutions, especially in privileged access management. Passing demonstrates you can operate CyberArk technology at the Sentry certification level.

Exam Topics

  • Infrastructure and Network Architecture0%
  • Vault Configuration and Management0%
  • Accounts and Safes Management0%
  • Platform Management0%
  • Session Management and Monitoring0%
  • Troubleshooting and Maintenance0%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated April 4, 2025 at 11:12 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Infrastructure and Network Architecture

What is the PRIMARY reason to install more than 1 active CPM?

  • A Installing CPMs in multiple sites prevents complex firewall rules to manage devices at remote sites.
  • B Multiple instances create fault tolerance.
  • C Multiple instances increase response time.
  • D Having additional CPMs increases the maximum number of devices CyberArk can manage.
Explanation

Concurrent active CPM instances distribute automated credential-management work across the environment, increasing the overall number of target devices that CyberArk can manage. Fault tolerance instead relies on a disaster-recovery, active-passive CPM configuration.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Accounts and Safes Management

What is the purpose of the password Reconcile process?

  • A To test that CyberArk is storing accurate credentials for accounts.
  • B To change the password of an account according to organizationally defined password rules.
  • C To allow CyberArk to manage unknown or lost credentials.
  • D To generate a new complex password.
Explanation

Password reconciliation lets CyberArk regain control of an account when its current credential is unknown, lost, or out of synchronization with the Vault. It resets the account password through a reconciliation mechanism so CyberArk can manage it again.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Vault Configuration and Management

When a DR Vault Server becomes an active vault, it will automatically fail back to its original state once the Primary Vault is back online.

  • A True, this is the default behavior.
  • B False, this is not possible.
  • C True, if the 'AllowFailback' setting is set to yes in the PADR.ini file.
  • D True, if the 'AllowFailback' setting is set to yes in the dbparm.ini file.
Explanation

CyberArk Disaster Recovery automatic failback is enabled by setting AllowFailback to yes in the PADR.ini configuration file. It is not enabled by default, and dbparm.ini does not control this DR failback setting.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Infrastructure and Network Architecture

To prevent conflicts with the hardening process, third-party applications such as Antivirus and Backup Agents should be installed on the Vault server before installing the Vault.

  • A TRUE
  • B FALSE
Explanation

CyberArk best practice is to install the Digital Vault software and run the vault hardening process on a clean, dedicated server before installing any third-party software such as antivirus or backup agents; introducing such agents beforehand risks conflicting with the lockdown changes the hardening script makes to services, registry settings, and file permissions, so the statement describing the reverse installation order is incorrect.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Accounts and Safes Management

When a transparent user matches two separate directory mappings, how does the system decide which user template to apply?

  • A The system will use the template for the mapping listed first.
  • B The system will use the template for the mapping listed last.
  • C The system will grant all of the vault authorizations from the two templates.
  • D The system will grant only the vault authorizations that are listed in both templates.
Explanation

CyberArk applies the user template from the first matching directory mapping in the mapping list. It does not combine or intersect Vault authorizations from multiple matching templates.

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Infrastructure and Network ArchitectureVault Configuration and ManagementAccounts and Safes ManagementPlatform ManagementSession Management and MonitoringTroubleshooting and Maintenance
Know a question that should be here? Contribute to this exam
Back home