CAD Study Guide 2026

Everything you need to pass the CAD exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

๐Ÿ“‹ CAD Exam Format at a Glance

50
Questions
90 min
Time Limit
70.00%
Passing Score

๐Ÿ“š CAD Topics to Study (69)

โœ๏ธ Sample CAD Questions & Answers

1. When PTA detects a threat and automatically responds by rotating a compromised account's password, this capability is known as:
โœ“ Automatic response

PTA's automatic response feature triggers actions such as password rotation or account suspension when a threat is confirmed.

2. Why should SSH keys be managed under a PAM solution in addition to passwords?
โœ“ SSH keys grant privileged access to servers and, if unmanaged, can persist indefinitely without rotation or accountability

Unmanaged SSH keys often have no expiration, are rarely rotated, and can provide root-level access, making them high-risk privileged credentials that belong in a PAM vault.

3. How is access to the Vault controlled?
โœ“ Access control lists and safe permissions

Access to the CyberArk Vault and its contents is meticulously controlled through a combination of robust access control lists (ACLs) and granular safe permissions. These mechanisms precisely define which users or groups can access specific safes, view, retrieve, or manage credentials, ensuring strict adherence to the principle of least privilege and enhancing security.

4. Which of the following is a fundamental principle of privileged session manager setup as it applies to CyberArk Defender Certification?
โœ“ Systematic evaluation and adherence to established industry standards

A fundamental principle of privileged session manager setup in CyberArk Defender Certification is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.

5. Which log file should an administrator review to investigate failed authentication attempts to the Digital Vault?
โœ“ vault.log

The vault.log file records all Vault-level events including authentication successes and failures.

6. A CyberArk administrator wants to prevent a specific user from deleting accounts in a Safe while still allowing them to manage passwords. Which permission should be withheld?
โœ“ Delete accounts

The 'Delete accounts' permission is separate from password management permissions, so withholding it prevents deletion while other account management tasks remain available.

๐ŸŽฏ Free CAD Practice Tests

๐Ÿ“– CAD Guides & Articles

Your CAD Study Path
1. Learn with Flashcards โ†’ 2. Drill Practice Tests โ†’ 3. Take the Full Exam Simulation
Was this helpful?
CAD Study Guide 2026 โ€” Exam Format, Topics & Practice Questions