Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

CPC-CDE-RECERT CyberArk CDE-CPC Recertification Free Practice Exam Questions (2026 Updated)

Prepare effectively for your CyberArk CPC-CDE-RECERT CyberArk CDE-CPC Recertification certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 99 questions

To disable the PSM default Support for Browser Sessions, which option should be set to 'No* before running Hardening?

A.

SupportWebApplications

B.

SupportBrowsers

C.

SupportWebBrowsers

D.

SupportHTML5Content

Which statements are correct regarding LDAP integration in Privilege Cloud Shared Services? (Choose two.)

A.

LDAP integration can be configured in the Privilege Cloud web interface under Administration > Configuration Options > LDAP Integration.

B.

A Secure Tunnel installation is required to access the on-premises LDAP directory.

C.

The Privilege Cloud PAM leverages the directory services integration of CyberArk Identity.

D.

The CA certificate that issued the LDAP server’s Server Authentication certificate must be trusted on the machine running the CyberArk Identity Connector.

E.

The CA certificate that issued the LDAP server’s Server Authentication certificate must be provided to CyberArk Support.

When creating a new Safe, if you select “Save account versions for a period of days” within Version Retention settings, what is the default number of days that password versions are saved?

A.

7

B.

14

C.

30

D.

90

You want to improve performance on the CPM by restricting accounts for the CYBRWINDAD platform to only the WINDEMEA and WINDEMEA_ADMIN Safes. How do you set this in CyberArk?

A.

In the CYBRWINDAD platform, under Automatic Password Management > General, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEA_ADMIN).

B.

In the settings for Configuration/CPM assigned to the WINDEMEA and WINDEMEAADMIN Safes, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEAADMIN).

C.

In the CYBRWINDAD platform, under UI & Workflows > Properties > Optional, configure AllowedSafes and set it to (WINDEMEA)|(WINDEMEA_ADMIN).

D.

Modify cpm.ini on the relevant CPM(s) and add AllowedSafesCYBRWINDAD and set it to (WINDEMEA)|(WINDEMEAADMIN).

Which statement is correct about using the AllowedSafes platform parameter?

A.

It allows users to access accounts in specific safes.

B.

It prevents the CPM from scanning all safes, restricting it to scan only safes that match the AllowedSafes configuration.

C.

It allows the CPM to access PSM safes to monitor platform configuration and connection component changes.

D.

It prevents the CPM from processing pending items in the Discovery safes enforcing manual intervention to complete the onboarding process.

Which prerequisites are required for installing PSM for SSH (Unix Connector)? (Choose two.)

A.

Create the PSM for SSH parameters file on the Unix server with InstallCyberArkSSHD = Integrated.

B.

Configure the root user to not authenticate to the Unix server remotely through SSH using a password.

C.

Verify that outbound traffic from the Unix server is always routed through the same public-facing IP.

D.

Create an administrative user on the Unix server for future maintenance tasks.

E.

Reset the default root account password before installing the PSM for SSH.

Which statement best describes a PSM server's network requirements?

A.

It must reach the target system using its native protocols.

B.

It requires limited outbound connectivity to Ports 1858 and 443 only.

C.

It requires direct access to the internet.

D.

It requires broad inbound firewall rules and outbound traffic should be limited to Port 1858.

Which components can be installed when running the Privilege Cloud Connector installation package? (Choose two.)

A.

Privileged Session Manager (PSM)

B.

Central Policy Manager (CPM)

C.

Secure Tunnel

D.

Central Credential Provider (CCP)

E.

Privileged Session Manager for SSH (PSM for SSH)

How many assertions are supported by Privilege Cloud in a SAML integration?

A.

1

B.

2

C.

3

D.

Unlimited

Which deployment criteria influences the CyberArk-provided hardening methods that need to be applied to CPM and PSM components?

A.

“In Domain” and “Out of Domain”

B.

“On Premises” and “On Cloud”

C.

“Windows” and “Linux”

D.

“Primary Privilege Cloud Connector” and “additional Privilege Cloud Connector”

What is the correct CyberArk user to use when installing the Privilege Cloud Connector software?

A.

installeruser@

B.

Administrator

C.

_admin

D.

Installer

Which statement is correct regarding the LDAP integration with CyberArk Privilege Cloud Standard?

A.

You must track the expiration date of the directory server certificate and contact CyberArk Support to renew it.

B.

LDAPS integration with Privilege Cloud requires StartTLS for secure and encrypted communication.

C.

For certificate trust to your directory server, only the Issuing CA certificate is required.

D.

The top-level domain entry of the directory must be unique in the chosen Privilege Cloud region.

You have been tasked with deploying a Privilege Cloud PSM for SSH connector When the initial installation has successfully completed, you create and permission several maintenance users to be used for administering the connector.

Which configuration file must be updated to define these maintenance users?

A.

sshd.config

B.

basic_psmpserver.conf

C.

sshd_config

D.

psmpparms

Which authentication methods does PSM for SSH support? (Choose 2.)

A.

OIDC

B.

MFA Caching

C.

SAML

D.

RADIUS

E.

Client Authentication Certificate

What is determined by the MaxConcurrentConnections setting within a platform?

A.

Maximum number of concurrent connections that can be opened between the CPM and the remote machines for the platform

B.

Maximum number of concurrent connections that can be between the PSM and the remote machines for the platform

C.

Maximum number of concurrent connections allowed for a specific account on the platform through the PSM

D.

Maximum number of concurrent connections to the Vault allowed for sending audit activities relating to the platform

You are deploying a CyberArk Identity Connector to integrate Privilege Cloud Shared Services with an Active Directory environment. Which requirement must be met?

A.

The Identity Connector Server must be joined to the Active Directory.

B.

The Server must be a member of the root domain of the Active Directory forest.

C The Identity Connector must be installed on a Domain Controller.

C.

The Identity Connector must be installed using Domain Administrator credentials.

Which statements are correct regarding enabling end users from multiple domains in the same forest to authenticate to CyberArk Privilege Cloud? (Choose two.)

A.

CyberArk does not permit end users from multiple domains to authenticate to CyberArk Privilege Cloud; it only allows users from multiple directory services, such as AD, Azure AD, CyberArk Cloud Directory, etc.

B.

This can be accomplished when the users' Active Directory accounts are in domains with domain controllers that have a two-way, transitive trust relationship with the domain controller to which the connector is connected.

C.

Configuring authentication for users in multiple domains in the same forest is not recommended due to potential performance issues.

D.

To enable authentication for users in multiple domains in the same forest, you should install separate CyberArk Identity Connectors for each independent domain.

E.

CyberArk recommends consolidating users from multiple domains in the same forest into the CyberArk Cloud Directory for this specific use case.

To use SAML authentication in Privilege Cloud Standard Services, users must first be defined in Privilege Cloud. What are correct methods for defining users? (Choose two.)

A.

Integrate Privilege Cloud with your LDAP server.

B.

Integrate Privilege Cloud with SIEM.

C.

Integrate Privilege Cloud with Email System.

D.

Create users in Privilege Cloud with details identical to those who access Privilege Cloud through SAML authentication.

E.

Create users in the CyberArk Privilege Cloud database using the CAVaultManager createuser command.

What are dependencies to update or change the CPM credential? (Choose 2.)

A.

APIKeyManager.exe

B.

CreateCredFile.exe

C.

CPM/nDomain_Hardening.ps1

D.

CyberArk.TPC.exe

E.

Data Execution Prevention

What are the basic network requirements to deploy a CPM server?

A.

Port 1858 to the Privilege Cloud Vault service backend and Port 443 to the Privilege Cloud Portal

B.

Port 1858 only

C.

any ports to the Privilege Cloud Vault service backend

D.

Port UDP/1858 to the Privilege Cloud Vault service backend and all required ports to the targets and Port 3389 to the PSM

Page: 1 / 2
Total 99 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved