Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

CPC-CDE-RECERT CyberArk CDE-CPC Recertification Questions and Answers

Questions 4

What is a supported certificate format for retrieving the LDAPS certificate when not using the Cyberark provided LDAPS certificate tool?

Options:

A.

.der

B.

.p7b

C.

p7c

D.

p12

Buy Now
Questions 5

An end user (external user account) has been removed from the Users tab in CyberArk Identity Administration and tries to log in to the CyberArk Privilege Cloud portal using the correct credentials. What will happen?

Options:

A.

The end user will receive a “User does not exist” error message.

B.

The end user will receive an “Unable to login. Contact your system administrator” error message.

C.

The end user will be able to log in and access the same set of functions as before.

D.

After successful login, the end user will be able to log in, but will encounter a blank page.

Buy Now
Questions 6

When installing PSM on a Windows 2019 Server, under which circumstances should the PSMConnect and PSMAdminConnect users be moved to the domain? (Choose two.)

Options:

A.

When RDS CAL Per User licenses are in use

B.

When the RDS session broker has a value > 1

C.

When you want to extend PSM sessions beyond one hour

D.

When you want to load balance the PSM installation

E.

When you need to enable PSM for Web Support

Buy Now
Questions 7

In addition to the Vault Admins and Auditors , what are the default map roles in the Privilege Cloud LDAP Directory mapping function for the Privilege Cloud Standard Services Model? (Choose two.)

Options:

A.

Safe Managers

B.

Safe Owners

C.

Privileged Cloud Users

D.

Users

Buy Now
Questions 8

Arrange the steps to install passive CPM using Connector Management in the correct sequence

CPC-CDE-RECERT Question 8

Options:

Buy Now
Questions 9

When using Connector Management, how do you configure a DR CPM in Privilege Cloud shared services? (Choose two.)

Options:

A.

Stop the CyberArk Password Manager service and set the startup type to Manual .

B.

When prompted for the Vault IP address on the installation windows, leave it blank and proceed.

C.

When prompted to select the CPM mode, select Passive .

D.

When prompted for the Vault administrator credentials on the installation windows, leave it blank and proceed.

E.

Stop the CyberArk Password Manager service and set the startup type to Automatic .

Buy Now
Questions 10

You want to add an additional maintenance user on the PSM for SSH. How can you accomplish this if InstallCyberArkSSHD is set to Integrated ?

Options:

A.

Create a local user and add it to the PSMP_MaintenanceUsers group.

B.

Create a local user called proxymaster and add it to /etc/pam.d/auth-password.

C.

Create a local user and add it to the group configured for the parameter AllowGroups in the /etc/ssh/sshd_config file.

D.

Create a local user called psmpmng and add it to the PSMMaintenance group in /etc/pam.d/auth-password.

Buy Now
Questions 11

In large-scale environments, it is important to enable the CPM to focus its search operations on specific Safes instead of scanning all Safes it sees in the Vault. How is this accomplished?

Options:

A.

Administration Options > CPM Settings

B.

AllowedSafes Parameter on each platform policy

C.

MaxConcurrentConnection parameter on each platform policy

D.

Administration > Options > CPM Scanner.

Buy Now
Questions 12

How many assertions are supported by Privilege Cloud in a SAML integration?

Options:

A.

1

B.

2

C.

3

D.

Unlimited

Buy Now
Questions 13

Which authentication methods does PSM for SSH support? (Choose 2.)

Options:

A.

OIDC

B.

MFA Caching

C.

SAML

D.

RADIUS

E.

Client Authentication Certificate

Buy Now
Questions 14

What are dependencies to update or change the CPM credential? (Choose 2.)

Options:

A.

APIKeyManager.exe

B.

CreateCredFile.exe

C.

CPM/nDomain_Hardening.ps1

D.

CyberArk.TPC.exe

E.

Data Execution Prevention

Buy Now
Questions 15

The System Health page shows the status of all components related to Privilege Cloud. Which components can administrators monitor on this page? (Choose two.)

Options:

A.

Vault

B.

PTA

C.

PVWA

D.

CPM

E.

PSM

Buy Now
Questions 16

Which users are Privilege Cloud Standard built-in users? (Choose 2.)

Options:

A.

NASCorp

B.

saascorps

C.

CyberArkAdmin

D.

remoteAccessAppUser

E.

PASReporterUser

Buy Now
Questions 17

Before installing the Privilege Cloud Connector using Connector Management , which network rules should be in place?

Options:

A.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 443

CustomerPortalConnectivity: Port 443

B.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 5589

C.

TunnelConnectivity: Secure Tunnel Port 443

CustomerPortalConnectivity: Port 5589

D.

VaultConnectivity: Privilege Cloud backend Port 1858

TunnelConnectivity: Secure Tunnel Port 22

CustomerPortalConnectivity: Port 3389

Buy Now
Questions 18

After a scripted installation has successfully installed the PSM, which post-installation task is performed?

Options:

A.

The screen saver for the PSM local users is disabled.

B.

A new group called PSMShadowUsers is created.

C.

The PSMAdminConnect user password is reset.

D.

Remote desktop services are installed.

Buy Now
Questions 19

Which file must you edit to ensure the PSM for SSH server is not hardened automatically after installation?

Options:

A.

vault.ini

B.

user.cred

C.

psmpparms

D.

psmgw.config

Buy Now
Questions 20

After the session has ended, where is the default final recording storage located?

Options:

A.

CyberArk Privilege Cloud

B.

Privilege Cloud Connector

C.

Network attached storage

D.

User workstation

Buy Now
Questions 21

Which method can be used to directly authenticate users to PSM for SSH? (Choose three.)

Options:

A.

CyberArk authentication

B.

LDAP authentication

C.

RADIUS authentication

D.

Windows authentication

E.

SAML authentication

F.

OpenID Connect (OIDC) authentication

Buy Now
Questions 22

When creating a new Safe, if you select “Save account versions for a period of days” within Version Retention settings, what is the default number of days that password versions are saved?

Options:

A.

7

B.

14

C.

30

D.

90

Buy Now
Questions 23

Which actions must be performed when manually hardening a SUSE server with PSM for SSH ? (Choose two.)

Options:

A.

Update settings in the sshd_config file on the server.

B.

Add the PSM for SSH gateway user to the passwd file.

C.

Validate that the psmpgwuser.cred file has correct permissions.

D.

Remove all users and groups from the passwd file.

E.

Add the PSM gateway user to the wheel group.

Buy Now
Questions 24

What must be specified when authenticating to Privilege Cloud during the Secure Tunnel install?

Options:

A.

Vault IP Address

B.

Subdomain or Customer ID

C.

Privilege Cloud URL

D.

CaseID

Buy Now
Questions 25

Arrange the steps to failover to the passive CPM in the correct sequence.

CPC-CDE-RECERT Question 25

Options:

Buy Now
Questions 26

You plan to install Privilege Cloud Connectors on your AWS and Azure environments.

What is the maximum number of concurrent RDP/SSH sessions that each connector can handle for Large Implementations?

Options:

A.

1-10

B.

31-60

C.

100

D.

200

Buy Now
Questions 27

Which statement is correct regarding the LDAP integration with CyberArk Privilege Cloud Standard?

Options:

A.

You must track the expiration date of the directory server certificate and contact CyberArk Support to renew it.

B.

LDAPS integration with Privilege Cloud requires StartTLS for secure and encrypted communication.

C.

For certificate trust to your directory server, only the Issuing CA certificate is required.

D.

The top-level domain entry of the directory must be unique in the chosen Privilege Cloud region.

Buy Now
Questions 28

Following the installation of the PSM for SSH server, which additional tasks should be performed? (Choose 2.)

Options:

A.

Delete the user.cred file used during installation.

B.

Delete the vault.ini you used during installation.

C.

Delete the psmpparms file you used during installation.

D.

Package all installation log files for upload to CyberArk.

Buy Now
Questions 29

CyberArk User Neil is trying to connect to the Target Linux server 192.168.1.164 using a domain user ACME\linuxuser01 on domain acme.corp using PSM for SSH server

192.168.65.145.

What is the correct syntax?

Options:

A.

ssh neil@linuxuser01:acme.corp@ 192.168.1.164@192.168.65.145

B.

ssh neil@linuxuser01#acme.corp@ 192.168.1.164@192.168.65.145

C.

sshneil@linuxuser01@ 192.168.1.164@192.168.65.145

D.

ssh neil@linuxuser01@acme.corp@ 192.168.1.164@192.168.65.145

Buy Now
Exam Code: CPC-CDE-RECERT
Exam Name: CyberArk CDE-CPC Recertification
Last Update: May 30, 2026
Questions: 99

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11