▸case-06 We are onboarding 500 Enterprise Linux servers into CyberArk. Management wants root passwords changed weekly, but security wants a tighter interval along with key management. What exact rotation period and key control mechanism should be configured for Linux root platforms? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Our database team wants to set a 4-hour automatic rotation on all SQL service accounts across application clusters. What operational risk does this aggressive schedule introduce, and how should service account rotation be configured? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 We are configuring log forwarding from CyberArk to our enterprise SIEM for real-time threat monitoring. Which log formats should be configured for forwarding vault audit events? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 We are configuring BeyondTrust Password Safe for automatic asset discovery using Smart Rules and Active Directory domain scanning. How do we set up BeyondTrust Smart Rule filters and worker nodes? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are planning an enterprise deployment of CyberArk to secure our privileged infrastructure accounts, including domain admins, root accounts, databases, and cloud keys. Could you draft a comprehensive deployment guide detailing the vault network architecture setup, safe access roles, platform rotation intervals for each account type, PSM session recording configuration, and SIEM logging integration? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An administrator manually changed an Oracle database sys account password directly on the server, causing CyberArk's CPM rotation task to fail. Which account type and mechanism prevents perpetual lockouts when vault and target credentials become out of sync? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 Our security compliance policy mandates strict controls for accessing domain admin secrets in CyberArk. How should Master Policy settings be configured regarding access concurrency and authorization workflows for sensitive accounts? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 We are deploying CyberArk Privileged Threat Analytics (PTA) to supplement standard vault audit logging. What specific behavioral anomaly categories and risk indicators should PTA be configured to monitor? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We are creating a new safe structure for our finance department's admin credentials. We need to define standard role tiers for safe members to adhere to least privilege. What specific role names and operational responsibilities should be assigned? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 Our network engineering team uses CyberArk to manage Cisco router and switch privilege credentials. They argued for 90-day rotation, but security standards require a tighter cadence. What rotation schedule should be applied to network device platforms? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We are configuring Microsoft Entra Privileged Identity Management (PIM) for active directory administrative roles like Global Administrator. How should we configure approval workflows, activation durations, and alert thresholds in Entra ID admin center? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 Our compliance team is preparing a SOC2 and NIST 800-53 audit crosswalk for our CyberArk deployment. Which specific NIST 800-53 sub-control corresponds directly to privileged access account controls, and which corresponds to session recording? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 During a major network outage, local systems cannot contact the primary or DR CyberArk vault. What critical deployment item must be established and tested beforehand to ensure emergency access to administrative accounts? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 We are setting up dynamic database credential generation using HashiCorp Vault's PostgreSQL secrets engine inside a Kubernetes cluster with Vault Agent sidecars. How do we configure the dynamic lease TTL and database secret engine roles via Vault HCL? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When managing AWS and Azure privileged API access keys in CyberArk, administrators proposed rotating keys every 30 days without backup keys. What exact rotation schedule and key architecture strategy should be applied for Cloud IAM keys? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 I need a complete technical specification for configuring account platforms and session management in CyberArk. Please write a document that lists the credential lifecycle stages, maps out platform rotation and verification parameters for various target platforms, details PSM session recording requirements, and includes a summary of common setup pitfalls. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 We are deploying a primary CyberArk Vault server in our DMZ segment and setting up firewall rules for Central Policy Manager and PVWA communication. Which specific inbound TCP port should be opened on the vault server for component traffic, and what OS services should be restricted? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 Our auditing team requires a formal specification for PSM session logs to comply with legal record-keeping standards. What session activity data types must be captured, and what is the required retention duration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 Before making CyberArk Privileged Session Manager live for production administrative access, what network deployment pattern must PSM servers use and what pre-deployment verification step is critical? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 We are setting up platform policies for Oracle and SQL Server high-privilege DBA accounts. System administrators proposed rotating passwords every 30 days. What exact rotation interval should be enforced for Database Admin platforms? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 We have multiple related administrative accounts that share hard-coded dependency schedules across several application servers. Which CyberArk structural concept should be used to link these accounts together? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Our enterprise security baseline requires verifying cryptography standards on stored secrets vault databases. What specific cryptographic standard compliance must the CyberArk Digital Vault hold? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |