About the Exam

This Sentry-level exam is for professionals who deploy, install, and configure CyberArk Privilege Cloud. Passing demonstrates practical knowledge and technical skills with the solution’s implementation and configuration tasks. CyberArk groups it under its technical certifications for identity security solutions.

Exam Topics

  • CyberArk Privilege Cloud deployment and administration100%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 7, 2026 at 12:34 PM

Topic filter
Retired questions
Question sort

QuestionQ1

CyberArk Privilege Cloud deployment and administration

You are creating a PSM load-balanced virtual server configuration.

What default service ports/protocols are used for RDS and for the PSM Health Check service?

  • A RDP/389 HTTP/443
  • B RDP/3389 HTTPS/443
  • C UDP/53 HTTPS/389
  • D RDP/636 HTTPS/443
Explanation

The PSM virtual service is configured for Remote Desktop Protocol on port 3389, while the dedicated PSM Health Check virtual service uses HTTPS on port 443. The LoadMaster CyberArk deployment documentation specifies PSM virtual services on port 3389 and a health-check service on TCP/443.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

CyberArk Privilege Cloud deployment and administration

Why could dual-control requests become invalid?

Choose two
  • A The user specified an incorrect project code in the request.
  • B The access period the user specified in the request has passed.
  • C The user did not define the access period in the dual control request.
  • D The safe or object specified in the request has been deleted.
  • E Another user has requested access to the same account for a later time period.
Explanation

A dual-control request is invalid if its requested access period has expired or if the referenced safe or object has been deleted, because the request can no longer be fulfilled for its defined resource and time window.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

CyberArk Privilege Cloud deployment and administration

What actions are required to configure the syslog server IP address(es) for SIEM integration?

Choose two
  • A Submit a service request to CyberArk Support.
  • B Update the syslog server IP address through the Privilege Cloud Portal.
  • C Update the DBPARM.ini file with the correct syslog server IP address.
  • D Update the vault.ini file with the correct syslog server IP address.
  • E Configure the Secure Tunnel for SIEM integration.
Explanation

Privilege Cloud SIEM connectivity requires configuring the Secure Tunnel for SIEM. The SIEM server endpoint information must also be provided to CyberArk Support so the integration can be configured. Local Vault configuration files such as DBPARM.ini and vault.ini are not the configuration mechanism for this Privilege Cloud service. CyberArk: Privilege Cloud – Connect to SIEM

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

CyberArk Privilege Cloud deployment and administration

Which default authentication profile is used to access CyberArk Identity?

  • A Default New User Login Profile
  • B Default New Device Login Profile
  • C Default New Authenticator Profile
  • D Default New Password Profile
Explanation

The Default New User Login Profile is the baseline login profile applied to new users and defines the authentication policy used to access CyberArk Identity.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

CyberArk Privilege Cloud deployment and administration

When creating a new safe, what is the default number of password versions retained when using Save latest account versions in the Version Management settings?

  • A 5
  • B 10
  • C 30
  • D 90
Explanation

CyberArk Safe Version Management retains the latest 10 password versions by default when Save latest account versions is selected.

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home