CAD Cheat Sheet 2026

The 30 highest-yield CAD facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

50 questions
90 min time limit
70.00% to pass
  1. What is the primary purpose of the CyberArk Digital Vault? Secure and store privileged credentials
  2. Which log file should an administrator review to investigate failed authentication attempts to the Digital Vault? vault.log
  3. Which user permission is required to manage other user roles in CyberArk? Manage Users
  4. How are Vault activities typically audited? Activity logs and audit reports
  5. A company policy requires that privileged accounts used for database administration cannot be used outside business hours. How is this enforced in CyberArk? By configuring time-frame restrictions in the Master Policy for the relevant platform
  6. Which CyberArk component is responsible for recording and storing all audit logs generated by the Digital Vault? Vault Audit Log
  7. What happens to a CyberArk managed account password after a one-time retrieval configured with 'change password after check-in'? The CPM rotates the password immediately after the user checks the credential back in
  8. Which SIEM platforms does CyberArk PTA natively support for forwarding security events? Splunk and IBM QRadar, with syslog-based forwarding for others
  9. A privileged user checks out an exclusive account but their workstation crashes before they check it in. What is the recommended administrative action? Manually release the account checkout from the PVWA as an administrator
  10. Which Master Policy rule, when enabled, instructs the CPM to periodically rotate account passwords on a scheduled basis? Require periodic password change
  11. What is the role of the PTA sensor deployed in the network? It captures and forwards network traffic metadata to the PTA server for analysis
  12. In CyberArk PTA, what does a 'suspected credential theft' alert typically indicate? Credentials were extracted from memory using tools like Mimikatz
  13. In CyberArk's hierarchical permission model, which level takes the highest precedence when there is a conflict between Vault, Safe, and folder permissions? The most restrictive permission at any level wins
  14. A CAD professional encounters an unfamiliar situation while performing enterprise password vault policies duties. What is the most appropriate first action? Consult relevant standards, guidelines, or a qualified supervisor before proceeding
  15. What is the primary ethical obligation of a CAD professional when a conflict of interest arises during cyberark cloud entitlements activities? Disclose the conflict to all relevant parties and recuse from the decision if necessary
  16. Which of the following is a fundamental principle of cyberark architecture & components as it applies to CyberArk Defender Certification? Systematic evaluation and adherence to established industry standards
  17. A security policy mandates that all password retrievals require a ticket number from the ITSM system. Which CyberArk feature enforces this? Ticketing system integration with reason requirement
  18. A PTA alert shows 'Suspected DCSync attack.' What does this indicate? An attacker is synchronizing Active Directory replication to extract all password hashes
  19. What is the primary purpose of a Privileged Session Manager (PSM) in CyberArk? To proxy and record privileged sessions without exposing credentials to end users
  20. In CyberArk, what file contains replication configuration parameters for the Disaster Recovery Vault, including the primary Vault address? PADR.ini
  21. In a high-availability PSM deployment, what is typically placed in front of multiple PSM servers to distribute session load? Network Load Balancer (NLB) or Application Delivery Controller
  22. What is the function of the CyberArk 'Reconcile Account' feature? It resets a target account password when the CPM-managed password is out of sync
  23. Which data source does CyberArk PTA use to detect suspicious Kerberos activity such as Golden Ticket attacks? Windows Event Logs from domain controllers
  24. When configuring CyberArk Vault clustering for high availability, which component manages the automatic failover between primary and secondary Vault nodes? Windows Server Failover Clustering (WSFC)
  25. Which Safe member permission allows a user to see the list of accounts in a Safe but NOT retrieve their passwords? List accounts
  26. Which setting can enforce session approval in CyberArk? Dual control
  27. What type of credential does CyberArk AAM support retrieving for SSH-based applications? Passwords and SSH private keys
  28. When a platform has 'One Time Password' (OTP) enabled, what occurs after the privileged session ends? The CPM immediately rotates the password to a new random value
  29. Where are PSM session recordings stored by default after a privileged session ends? In the CyberArk Vault as secure files linked to the account
  30. What CyberArk feature allows auditors to watch a live or recorded privileged session without interrupting the active user? Session Monitoring
Turn these facts into recall:
Was this helpful?