About the Exam

CyberArk Sentry PAM is the Sentry-level certification for CyberArk’s privileged access management solution. CyberArk says the Sentry level validates practical knowledge and technical skills to deploy, install, and configure the relevant CyberArk solution. Passing demonstrates hands-on and theoretical ability to work with CyberArk PAM at the deployment and configuration level.

Exam Topics

  • Architecture & Component Overview0%
  • Installation & Configuration0%
  • Safe Management0%
  • Platform & Account Onboarding0%
  • Central Policy Manager Operations0%
  • Privileged Session Manager (PSM)0%
  • Privileged Access Security (PAS)0%
  • User Provisioning & Role Assignment0%
  • Troubleshooting & Diagnostics0%
  • Security & Compliance Framework0%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 21, 2026 at 7:49 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Installation & Configuration

This value must be added to the PVWA configuration file:

Assuming that all CyberArk PVWA servers were installed with the default paths/folders, which configuration file should you find and edit to do this?

  • A c:\inetpub\wwwroot\passwordvault\web.config
  • B c:\inetpub\wwwroot\passwordvault\services\web.config
  • C c:\cyberark\password vault web access\env\web.config
  • D c:\program files\cyberark\password vault web access\web.config
Explanation

The default PVWA IIS web application resides in the PasswordVault directory under C:\inetpub\wwwroot, and its application-level settings are stored in that directory’s web.config file.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Installation & Configuration

What must be done to synchronize a newly deployed Vault server with an organization’s NTP server?

  • A Configure an AllowNonStandardFWAddresses rule for the organization’s NTP server in DBParm.ini on the Vault server.
  • B Use the Windows Firewall console to configure a rule on the Vault server which allows communication with the organization’s NTP server.
  • C Ensure the organization’s NTP server is installed in the same location as the Vault server requiring synchronization.
  • D Update the AutoSyncExternalObjects configuration in DBParm.ini on the Vault server to schedule regular synchronization.
Explanation

CyberArk Vault configuration uses the AllowNonStandardFWAddresses setting in DBParm.ini to permit the required network communication with an NTP server. NTP time synchronization depends on allowing that server’s NTP traffic through the Vault’s configured firewall rules.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Installation & Configuration

What must be in place before the first CPM can be installed?

  • A The environment must have at least one Vault and one PVWA installed.
  • B The Vault environment must have at least one account stored in a safe.
  • C Custom platforms must be downloaded from the CyberArk Marketplace.
  • D The PSM component must be installed and proper functionality validated.
Explanation

A CyberArk Vault and the Privileged Account Security Web Access (PVWA) component must be installed before CPM. CyberArk specifically requires PVWA to be installed before CPM, and CPM is installed and registered against a Vault.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Installation & Configuration

You are installing PSM for SSH with AD-Bridge, with CyberArkSSHD mode configured as integrated for a customer.

Which additional packages must be installed to satisfy the customer’s requirements?

Choose two
  • A CARKpsmp-infra
  • B libssh
  • C OpenSSH 7.8 or higher
  • D CARKpsmp-ADBridge
  • E CARKpsmp-SSHD
Explanation

PSM for SSH requires the libssh dependency in all CyberArkSSHD modes. Integrated CyberArkSSHD mode also requires the CARKpsmp-infra package, which supplies the integration infrastructure for use with the native SSHD service.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Central Policy Manager Operations

Arrange the steps for failing over to the DR CPM in the proper order.

Drag & Drop
Enable the CPM services on the DR CPM.
Validate that the Primary CPM's services are stopped and set to manual.
On the DR CPM, confirm details in the Vault.ini configuration file, reset the password for the CPM user, and recreate the credential file.
Review logs to confirm the DR CPM services are running as expected.
Explanation

Failing over to the DR CPM requires first validating that the primary CPM's services are stopped and set to manual so the two CPMs cannot both act as the active password manager against the Vault. The DR CPM machine is then prepared by confirming its Vault.ini configuration, resetting the CPM application user's password, and recreating the credential file so it can authenticate to the Vault. Only after that preparation are the CPM services enabled/started on the DR CPM, and the change is confirmed by reviewing the DR CPM's logs to verify the services came up and are running as expected.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home