
CyberArkは2026年最新のCPC-CDE-RECERTサンプル問題は信頼され続けるCPC-CDE-RECERTテストエンジン
無料お試しCyberArk CPC-CDE-RECERT問題集PDFは必ずベストの問題集オプションを使おう
質問 # 36
What is a requirement when installing the PSM on multiple Privileged Cloud Connector servers?
- A. Additional Privilege Cloud Connector servers cannot have CPM installed.
- B. All PSMs in the environment must be configured to use load balancing.
- C. In-domain servers cannot be used when deploying multiple PSM servers.
- D. Each PSM must have the same path to the same recordings directory.
正解:D
解説:
When installing the Privileged Session Manager (PSM) on multiple servers, it is required that each PSM installation has the same path to the same recordings directory. This is necessary to ensure that session recordings are stored consistently across different PSM instances, which is important for high availability and load balancing implementations, as well as for maintaining a unified audit trail.
:
CyberArk documentation on installing multiple PSM servers
質問 # 37
Which components can be installed when running the Privilege Cloud Connector installation package?
(Choose two.)
- A. Privileged Session Manager (PSM)
- B. Central Credential Provider (CCP)
- C. Central Policy Manager (CPM)
- D. Privileged Session Manager for SSH (PSM for SSH)
- E. Secure Tunnel
正解:A、C
解説:
In the Privilege Cloud Installer (Standard) procedure, the Connector installer explicitly prompts you to select which components you want to install: "CPM/PSM/Both." That means the installation package supports installing:
* PSM (Windows connector)
* CPM
Why the other options are not correct for this installer package:
* C (Secure Tunnel) is treated as a separate component (downloaded as a Secure Tunnel Client Installer package), not one of the "CPM/PSM/Both" choices in the Connector installer step.
* D (CCP) is not listed as an installable component in the Privilege Cloud Connector installer flow shown in the official procedure.
* E (PSM for SSH) is selected/downloaded as a separate component to support UNIX/Linux, not installed via the Connector installer's "CPM/PSM/Both" selection.
質問 # 38
A CyberArk Privileged Cloud Shared Services customer asks you how to find recent failed login events for all users. Where can you do this without generating reports?
- A. Privileged Cloud Portal
- B. Identity Administration Portal
C both Identity Administration and Identity User Portals - C. Identity User Portal
正解:B
質問 # 39
Following the installation of the PSM for SSH server, which additional tasks should be performed? (Choose
2.)
- A. Package all installation log files for upload to CyberArk.
- B. Delete the vault.ini you used during installation.
- C. Delete the user.cred file used during installation.
- D. Delete the psmpparms file you used during installation.
正解:B、C
解説:
https://docs.cyberark.com/pam-self-hosted/14.0/en/content/pas%20inst/following-installation-of-psmp.htm
質問 # 40
How can a platform be configured to work with load-balanced PSMs?
- A. Use the Privilege Cloud Portal to update the Session Management settings for the platform in the Master Policy.
- B. Include details of the PSMs with load balancing in the Basic_psm.ini file on each PSM server.
- C. Create a new PSM definition that targets the load balancer IP address and assign to the platform.
- D. Remove all entries from configured PSM Servers except for the ID of the PSMs with load balancing.
正解:C
解説:
To configure a platform to work with load-balanced Privileged Session Managers (PSMs), you should:
* Create a new PSM definition that targets the load balancer IP address and assign it to the platform (Option B). This approach involves configuring the platform settings to direct session traffic through a load balancer that distributes the load across multiple PSM servers. This is effective in environments where high availability and fault tolerance are priorities.
Reference: CyberArk's setup guidelines for high-availability environments typically recommend configuring platforms to utilize load balancers to ensure continuous availability and optimal distribution of session management tasks.
質問 # 41
The Secure Tunnel component of CyberArk Privilege Cloud connects to which services in the CyberArk Privilege Cloud? (Choose two.)
- A. https://console.privilegecloud.cyberark.cloud
- B. https://update.privilegecloud.cyberark.cloud
- C. https://connector-<subdomain>.privilegecloud.cyberark.cloud
- D. https://telemetry.privilegecloud.cyberark.cloud
- E. https://backend-services.privilegecloud.cyberark.cloud
正解:A、C
解説:
CyberArk's official outbound traffic/network requirements explicitly list the two Privilege Cloud cloud- side endpoints that are required for Secure Tunnel communications (for REST/API calls over HTTPS/443):
* Backend service management (Required for Secure Tunnel): https://console.privilegecloud.
cyberark.com
* Connector (Required for Secure Tunnel): https://connector-<subdomain>.privilegecloud.cyberark.
com
These map directly to answer choices A (console) and B (connector-<subdomain>).
Note: Your options use the .cyberark.cloud domain, while CyberArk's network requirements documentation shows these endpoints in the .cyberark.com domain for Privilege Cloud. The service roles (Console + Connector endpoint) are what Secure Tunnel must reach, and those are the two "Required for Secure Tunnel" services in the official requirements.
Why the other options are not selected (based on what's "required for Secure Tunnel" in the official allowlist guidance):
* C (backend-services...): Not listed in CyberArk's published "Required for Secure Tunnel" FQDN allowlist entries (console + connector are).
* D (telemetry...): Telemetry is a separate capability (dashboards / utilization tracking) and is not documented as the required Secure Tunnel service endpoint.
* E (update...): Secure Tunnel upgrade/download processes are documented, but "update.*" is not listed as a required Secure Tunnel cloud endpoint in the outbound allowlist table.
質問 # 42
On Privilege Cloud, what can you use to update users' Permissions on Safes? (Choose 2.)
- A. Privilege Cloud Portal
- B. PTA
- C. REST API
- D. PrivateArk Client
- E. PACLI
正解:A、C
解説:
On CyberArk Privilege Cloud, updating users' permissions on safes can be done through the Privilege Cloud Portal and the REST API. The Privilege Cloud Portal provides a user-friendly graphical interface where administrators can manage user permissions directly within the portal's safe management settings.
Additionally, the REST API offers a programmable way to automate permission updates across safes, which is especially useful for bulk changes or integrating with other management tools. Both methods provide effective means to manage and customize access controls in a CyberArk environment, allowing for detailed permission settings per user on specific safes.
質問 # 43
In the directory lookup order, which directory service is always looked up first for the CyberArk Privilege Cloud solution?
- A. LDAP
- B. CyberArk Cloud Directory
- C. Active Directory
- D. Federated Directory
正解:B
解説:
In the directory lookup order for the CyberArk Privilege Cloud solution, the "CyberArk Cloud Directory" is always looked up first. This directory service is a part of the CyberArk Privilege Cloud infrastructure and is specifically designed to handle identity and access management within the cloud environment efficiently. It prioritizes the CyberArk Cloud Directory for authentication and identity resolution before consulting any external directory services.
Reference: CyberArk's architectural documentation usually emphasizes the role of the CyberArk Cloud Directory in managing and authenticating user access in cloud-based deployments, highlighting its precedence in the directory lookup process.
質問 # 44
How many assertions are supported by Privilege Cloud in a SAML integration?
- A. Unlimited
- B. 0
- C. 1
- D. 2
正解:B
解説:
CyberArk's Privilege Cloud SAML configuration documentation explicitly states: Privilege Cloud supports only one assertion and instructs you to ensure only one assertion is configured in the IdP.
質問 # 45
You have been tasked with deploying a Privilege Cloud PSM for SSH connector When the initial installation has successfully completed, you create and permission several maintenance users to be used for administering the connector.
Which configuration file must be updated to define these maintenance users?
- A. sshd.config
- B. sshd_config
- C. basic_psmpserver.conf
- D. psmpparms
正解:B
解説:
The sshd_config file is the correct configuration file that must be updated to define maintenance users for administering the Privilege Cloud PSM for SSH connector. This file contains configurations for the SSH daemon, including user permissions and group settings. When adding maintenance users, their user accounts are created on the PSM server, and then they are added to the AllowGroups parameter within the sshd_config file to grant them the necessary permissions.
:
CyberArk documentation on the PSM for SSH environment1.
CyberArk Sentry guide on how to add maintenance users for SSH PSM
When deploying a Privilege Cloud PSM for SSH connector, the configuration file that must be updated to define maintenance users is "sshd_config". This file is used to configure options specific to the SSH daemon, which includes user permissions, authentication methods, and other security-related settings. To add and configure maintenance users for the PSM for SSH, you will need to modify this file to specify allowed users and their respective privileges.
Reference: The configuration of SSH-related components typically involves the "sshd_config" file, as outlined in SSH and PSM for SSH setup guides. This is a standard practice in systems that utilize SSH for secure communications and management.
質問 # 46
Before installing the Privilege Cloud Connector using Connector Management, which network rules should be in place?
- A. VaultConnectivity: Privilege Cloud backend Port 1858
TunnelConnectivity: Secure Tunnel Port 5589 - B. TunnelConnectivity: Secure Tunnel Port 443
CustomerPortalConnectivity: Port 5589 - C. VaultConnectivity: Privilege Cloud backend Port 1858
TunnelConnectivity: Secure Tunnel Port 22
CustomerPortalConnectivity: Port 3389 - D. VaultConnectivity: Privilege Cloud backend Port 1858
TunnelConnectivity: Secure Tunnel Port 443
CustomerPortalConnectivity: Port 443
正解:D
解説:
CyberArk's Connector Management prerequisites check defines the exact network connectivity rules that must pass before installation:
* VaultConnectivity # Connect to the Privilege Cloud backend on TCP 1858
* TunnelConnectivity # Connect to the Secure Tunnel on TCP 443
* CustomerPortalConnectivity # Connect to the service backend URL on TCP 443 This matches option A exactly.
質問 # 47
Which statements are correct regarding enabling end users from multiple domains in the same forest to authenticate to CyberArk Privilege Cloud? (Choose two.)
- A. Configuring authentication for users in multiple domains in the same forest is not recommended due to potential performance issues.
- B. This can be accomplished when the users' Active Directory accounts are in domains with domain controllers that have a two-way, transitive trust relationship with the domain controller to which the connector is connected.
- C. CyberArk does not permit end users from multiple domains to authenticate to CyberArk Privilege Cloud; it only allows users from multiple directory services, such as AD, Azure AD, CyberArk Cloud Directory, etc.
- D. CyberArk recommends consolidating users from multiple domains in the same forest into the CyberArk Cloud Directory for this specific use case.
- E. To enable authentication for users in multiple domains in the same forest, you should install separate CyberArk Identity Connectors for each independent domain.
正解:B、E
解説:
CyberArk's official connector guidance (CyberArk Identity / Identity Administration-used with Privilege Cloud Shared Services for AD user authentication) says that for trusted domains in a single forest, you use this model when the domain controllers have a two-way, transitive trust relationship with the domain controller the connector is joined to.
It also clarifies that a single connector can be used for the entire domain tree or forest in that trusted- domain model, and authentication requests are handled according to AD trust relationships within the forest
/tree.
https://docs.cyberark.com/identity/latest/en/content/coreservices/connector/userauthmultdomain.htm
質問 # 48
Your customer recently merged with a smaller organization. The customer's connector has no network connectivity to the smaller organization's infrastructure. You need to map LDAP users from both your customer and the smaller organization. How is this achieved?
- A. Switch all users to SAML authentication as there can only be one Identity Connector.
- B. Create the required users in one directory and configure the Identity Connector to read that directory, as there can only be one Identity Connector.
- C. Create mappings for both directories from the original Identity Connector.
- D. Deploy Identity Connectors in the newly acquired infrastructure and create user mappings.
正解:D
解説:
To map LDAP users from both your customer and the smaller organization they have merged with, especially when there is no network connectivity between the two infrastructures, the best approach is to:
* Deploy Identity Connectors in the newly acquired infrastructure and create user mappings (Option C). This involves setting up additional Identity Connectors within the smaller organization's network. These connectors will facilitate the integration of user directories from both organizations into the customer's Privilege Cloud environment.
Reference: CyberArk documentation on Identity Connectors often outlines the capability of deploying multiple connectors to manage different user directories, especially useful in scenarios involving mergers or acquisitions where separate infrastructures need integration.
質問 # 49
Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?
- A. user.cred
- B. vault.ini
- C. psmgw.config
- D. psmpparms
正解:D
解説:
CyberArk documents that automatic hardening can be bypassed by setting the Hardening parameter in the PSM for SSH parameters file. The PSM for SSH parameters file used during installation is the psmpparms file (created by copying psmpparms.sample and renaming it to psmpparms).
質問 # 50
Which prerequisites are required for installing PSM for SSH (Unix Connector)? (Choose two.)
- A. Reset the default root account password before installing the PSM for SSH.
- B. Create an administrative user on the Unix server for future maintenance tasks.
- C. Create the PSM for SSH parameters file on the Unix server with InstallCyberArkSSHD = Integrated.
- D. Configure the root user to not authenticate to the Unix server remotely through SSH using a password.
- E. Verify that outbound traffic from the Unix server is always routed through the same public-facing IP.
正解:C、E
解説:
CyberArk's "Before you install PSM for SSH (Standard)" prerequisites include:
* Verify public access: "Verify that outbound traffic from the PSM for SSH server is always routed through the same public-facing IP." This directly supports C.
* Create the PSM for SSH parameters file: The parameters file is required for the installation process
, and the documentation specifies InstallCyberArkSSHD = Integrated as a mandatory parameter value. This supports A (with the corrected value "Integrated").
Why the other options are not "installation prerequisites" as written:
* B: CyberArk documents that after installation, the root user will not be able to authenticate remotely using a password (security behavior), not as a prerequisite step to perform before installation.
* D: The docs mention you can use a different administrative/maintenance user, but it is not listed as a required prerequisite in the "Before you install" checklist.
* E: Resetting the root password is not listed as a prerequisite in the Privilege Cloud "Before you install PSM for SSH (Standard)" documentation.
質問 # 51
Which actions must be performed when manually hardening a SUSE server with PSM for SSH? (Choose two.)
- A. Add the PSM for SSH gateway user to the passwd file.
- B. Add the PSM gateway user to the wheel group.
- C. Remove all users and groups from the passwd file.
- D. Update settings in the sshd_config file on the server.
- E. Validate that the psmpgwuser.cred file has correct permissions.
正解:D、E
解説:
CyberArk's hardening instructions for SUSE (manual hardening) explicitly require:
* Updating the SSH daemon configuration in /etc/ssh/sshd_config (for example, removing SFTP subsystem definitions and setting multiple hardening-related attributes such as disabling forwarding features).
* Ensuring the credential file for the PSM for SSH gateway user (psmpgwuser.cred) has the required permissions 640 (default path shown as /etc/opt/CARKpsmp/Vault/psmpgwuser.cred).
Those map directly to A and C.
質問 # 52
......
有効な問題最新版を試そうCPC-CDE-RECERTテスト解釈CPC-CDE-RECERT有効な試験ガイド:https://jp.fast2test.com/CPC-CDE-RECERT-premium-file.html
CPC-CDE-RECERT試験資料CyberArk学習ガイド:https://drive.google.com/open?id=1A3dK4k0wXqk_krjZUeha5b6SuHIEMe8A