Browse all practice questions for the CyberArk Certified Delivery Engineer (CDE) Training Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CyberArk Certified Delivery Engineer (CDE) Training Practice Test 2026 - Free CDE Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Can multiple Password Vault Web Access (PVWAs) be load balanced?
  • What action can users perform with the Retrieve Accounts permission?
  • What does "dual authentication" typically refer to in CyberArk integration?
  • What does the Move Accounts/Folders permission facilitate?
  • What is the outcome of not installing multiple CPMs when needed?
  • Where does the Vault administrator configure the FQDN of the target email server during SMTP integration?
  • What is the purpose of the allowed Safes parameter in a CPM policy?
  • How many permissions can be applied on a safe to a user?
  • What does the Safe permission Create Folders allow users to do?
  • Which permissions are necessary for a vault administrator to update user accounts?
  • The Safe permission "Unlock Accounts" becomes relevant under which policy?
  • What are the two types of reports that can be generated?
  • In cybersecurity, what does the acronym PSM stand for?
  • What does the Users List Report include about disabled users?
  • What capability does the Vault permission Add/Update Users provide?
  • Which servers can receive forwarded records from CyberArk?
  • What is a prerequisite for installing PSM?
  • How does the allowed Safes parameter enhance security in a CPM policy?
  • What can users do with the permission Manage Server File Categories?
  • What is a benefit of managing multiple CPMs across different sites?
  • How can you ensure that vault firewall rules persist after changes?
  • What permissions does a vault administrator need to reset user passwords?
  • What capability does the Safe permission Retrieve Accounts provide to users?
  • What controls the behavior of the CPM in relation to recently completed Dual Control requests?
  • How many CPM and DR vaults should be created for effective management?
  • Can multiple Vault servers be load balanced?
  • What is a key consideration when using wildcards in CPM policy?
  • What is included in the Export Data Vault (EVD) utility?
  • Which permission lets users view account activity within the Safe?
  • Which permission allows users to delete an account?
  • What file is utilized for configuring new firewall rules on the vault?
  • What port does Simple Network Management Protocol (SNMP) use for regular queries?
  • Why might an organization run the Users List Report?
  • What type of reports does PrivateArk offer?
  • What strategy is recommended for creating a CyberArk Recovery Plan?
  • What does the Update Account Properties permission primarily relate to?
  • What port does LDAP utilize for directory services?
  • What type of logs provide component level entries such as service up or down?
  • What could be a possible outcome of running the Active/Nonactive safes report?
  • Which statement accurately describes the function of a PrivateArk report?
  • What is a recommended method for monitoring service health checks in CyberArk?
  • What integration allows the Vault Administrator to forward audit records from the Vault to SIEM?
  • Which permission allows the use of the connect button in conjunction with certain other permissions?
  • Does the Vault require WINS services to operate properly?
  • Where can the Export Data Vault (EVD) be run from?
  • How does the Vault administrator configure the FQDN of the DC during LDAP/S integration?
  • What TCP port is commonly associated with secure communication in networks?
  • What is the function of the Vault permission Activate Users?
  • What does the Safe permission "View Safe Members" enable users to do?
  • What port does Simple Mail Transfer Protocol (SMTP) use?
  • What is the function of the Safe permission "Unlock Accounts"?
  • What is required to launch connections to the PSM Gateway?
  • What are some use cases for installing multiple CPMs?
  • What does the Safe permission "Manage Safe Members/Owners" allow users to do?
  • What action can users take with the Safe permission "Backup Safe"?
  • What type of logs provide only error entries and only exist for some components?
  • How does a Vault Administrator configure the CyberArk Disaster Recovery (DR) solution to perform automatic failover in case of a failure in the Primary Vault?
  • Which port is used by NTP for network time synchronization?
  • What types of records can be forwarded to SIEM or SYSLOG servers from the Vault?
  • How is user password management facilitated in the Vault?
  • What does the permission "Validate Safe Content" require to retrieve an object?
  • What is the purpose of the Vault permission Restore All Safes?
  • What does the Vault permission Add Network Areas allow users to do?
  • What limitation does the CPM have regarding password management on target devices?
  • Which of the following is a key role of a vault administrator?
  • What port is associated with SMB for file sharing services?
  • What is the proper way to allow the Vault to resolve hostnames?
  • Which permission allows users to manage locations in the vault hierarchy?
  • What is a primary reason for installing multiple active CPMs?
  • What is the function of the Safe permission List?
  • Is the installation of PSM dependent on Remote Desktop Services?
  • What can users do with the permission "Manage Safe Members/Owners"?
  • Which report type is specifically aimed at assessing user activity in the vault?
  • The PrivateArk report Safes List provides what type of information?
  • What does the immediate interval setting in a CPM policy primarily affect?
  • Is it possible to configure multiple dual authentication methods when accessing the Vault via PVWA?
  • Are exceptions for DEP created for all CyberArk components?
  • Which file is essential for integrating the Vault with a RADIUS server?
  • What does the PrivateArk report license Capacity (LC) show?
  • What is the purpose of the credentials provided during the installation of CPM?
  • What is the role of the Vault permission Manage Directory Mapping?
  • What does the PrivateArk report Active/Non-Active users report show?
  • What is the purpose of the Safe permission "Specify Next Account Content"?
  • Which authentication method is NOT typically categorized as primary?
  • What port does SAML use for security assertions?
  • Does the Vault support dual-factor authentication?
  • What port is used by RDP for remote desktop connections?
  • What does the Safe permission Add Accounts allow users to do?
  • How does the system determine which user template to use if a transparent user matches two different directory mappings?
  • Which services are running on the passive node of a CyberArk High Availability Cluster?
  • What is one of the main functions of the Add Accounts permission?
  • Which parameter controls how often the CPM looks for exclusive passwords that need to be changed?
  • Which report detail is important for compliance and auditing in CyberArk?
  • In which report would you find information about safes that haven't had any activity?
  • Can multiple Privileged Session Managers (PSMs) be load balanced?
  • When working with CyberArk Cluster, how do the vault nodes exchange keep-alive messages?
  • Which parameter controls how often the CPM looks for one-time passwords that need to be changed?
  • Which report would be useful for auditing user activity over a specific time period?
  • To support a fault-tolerant and high-availability architecture, which file needs to be changed on the PVWA to enable communication with the Primary Vault and Satellite Vaults?
  • What is the intent of the ImmediateInterval parameter in a CPM configuration?
  • What file is used to configure the ENE Service?
  • What capability does the Safe permission "Validate Safe Content" provide?
  • Which port does SSH use for secure shell access?
  • Can Italogs be forwarded to SIEM or SYSLOG servers?
  • What information is provided by the PrivateArk report Users List Report?
  • Can multiple Vault Servers be load balanced?
  • What type of logs provide detailed entries of workflows related to a component?
  • What does the Safe permission Authorize Account Request/Confirm Request allow users to do?
  • How many permissions can be assigned to a user in the Vault?
  • What does the Safe permission "Delete Accounts" allow users to do?
  • What does the Safe permission Delete Folders allow users to do?
  • Does the vault use DNS for hostname resolution?
  • What file is updated to perform an automatic failover in a CyberArk Disaster Recovery (DR) solution?
  • What is the primary authentication method for Windows in CyberArk?
  • What port is typically used by Security Information and Event Management (SIEM) solutions?
  • What does the Vault permission Backup All Safes allow users to do?
  • Which service, when failed, does not mandate a failover and is considered optional when working with a CyberArk High Availability Cluster?
  • Which file is used to configure the IP Address of the SNMP Server?
  • To which port does the SMB protocol relate?
  • What permissions are required to create a directory mapping in CyberArk?
  • Which of the following best describes the function of a CPM?
  • Which parameter controls how often the CPM looks for soon-to-be-expired passwords that need to be changed?
  • The Safes List report is essential for managing what aspect of CyberArk?
  • Which of the following is a secondary authentication type used in CyberArk?
  • What capability does the Safe permission Initiate CPM Account Management Operations provide?
  • What is a key feature of the Safe permission Access Safe Without Confirmation?
  • What is a requirement for forwarding activity records to SIEM or SYSLOG servers?
  • What is the purpose of the Safe permission Delete Folders?
  • What is the main purpose of load balancing in a privileged access management environment?
  • Does the CyberArk Disaster Recovery module integrate with enterprise backup software?
  • Which command allows configuration of a non-standard firewall port?
  • Which report would you use to see users who have not logged in recently?
  • Where are PrivateArk reports located?
  • Which statement is accurate regarding monitoring of target devices by CPM?
  • Which port does KERBEROS use for authentication?
  • What is the purpose of the interval setting in a CPM policy?
  • What important components are needed for PTA and PSM integration?
  • What does the Safe permission Use Accounts allow users to do?
  • What can users do with the Safe permission Update Account Properties?
  • What does the Update Account Content permission allow in terms of file management?
  • The Active/Non-Active users report helps in identifying which of the following?
  • What does the Safe permission Access Safe Without Confirmation allow users to do?
  • What are Network Areas in the context of CyberArk?
  • What happens after the Vault administrator configures syslog integration on the Vault?
  • What is an example of a proactive account onboarding process?
  • Which port number is associated with LDAPS, the secure version of LDAP?
  • What is a common reason for configuring directory mappings in CyberArk?
  • What role does the Vault administrator play during CPM installation?
  • Who is the target audience of PrivateArk reports?
  • What does the Safe permission Move Accounts/Folders allow users to do?
  • What type of authenticators does CyberArk require for 2-factor authentication?
  • What key detail does the Safes List report provide?
  • What are the types of logs available in CyberArk?
  • What outcome is provided by the Vault permission Add Safes?
  • Can the PSM Gateway be installed on the same server as PSM for SSH?
  • Which file is used to open up a non-standard firewall port to the vault?
  • What is the purpose of the Vault permission Add Safes?
  • What type of logs come from different sources and may include trace files or separate files depending on the component?
  • What is a key benefit of REST API integration in account onboarding?
  • Which services should be running on the DR vault of a CyberArk Disaster Recovery (DR) solution?
  • Which .ini file supports PrivateArk Remote Control Agent?
  • What type of accounts does the Account Feeds contain?
  • What report would you reference to understand the properties of all safes?
  • Which CyberArk utility can be used in conjunction with enterprise backup software?
  • What is the primary action associated with the permission "Backup Safe"?
  • Can multiple Central Policy Managers (CPMs) be load balanced?
  • Which values are acceptable in the address field of an account?
  • In a Disaster Recovery (DR) environment, which component should NEVER be configured for automatic failover due to the possibility of split-brain phenomenon?
  • What does the Export Data Vault (EVD) utility do?
  • Does the PSM require the Remote Desktop Web Access role?
  • What permission would allow a user to track activities within the Vault?
  • Can the Vault operate without a secure DNS configuration?
  • What should be considered when managing accounts in multiple VLANs?
  • Which protocol is primarily used for two-factor authentication in CyberArk?
  • What port does SNMP use specifically for receiving traps?
  • Which characteristic is NOT associated with the PasswordManager_Pending safe?
  • Which capability is associated with the Safe permission "Manage Safe"?
  • Which of the following services is considered optional on the Vault?
  • For which component hardening does CyberArk create exceptions for DEP on selected executable files?
  • What is the purpose of Directory Mapping in CyberArk?
  • Can multiple Privileged Session Management Proxies (PSMPs) be load balanced?
  • Over which port does the EVD communicate?
  • Can the Vault be integrated with multiple SIEM or SYSLOG servers?
  • Is it true that the Microsoft Windows Defender firewall can be edited after being taken over by the vault?
  • In a Distributed Vaults environment, which component will not be communicating with the Satellite Vaults?
  • What is one purpose of the dbparm.ini file in CyberArk?
  • Which action can users perform with the Safe permission "Rename Accounts"?
  • What does the Vault permission Reset Users Passwords allow users to do?
  • What type of load balancing does CyberArk recommend?
  • Which CyberArk component is critical for protecting sensitive operations?
  • Which of the following is NOT one of the Eight Security Fundamentals for Privileged Account Security?
  • What does the Safe permission Update Account Content allow users to change?
  • Which type of passwords does the parameter for 'Interval' specifically monitor?
  • What can users do with the Vault permission Audit Users?
  • What type of client is needed for users to access the PSM Gateway?
  • Which measure is recommended for protecting accounts and encryption keys?
  • Which authentication type is associated with LDAP within CyberArk?
  • When using multiple CPMs, which safe is shared by all CPMs?
  • What does the PrivateArk report Active/Nonactive safes report indicate?
  • Who can use the permission Manage Directory Mapping?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy