Exam PAM-CDE-RECERT All QuestionsBrowse all questions from this exam
Question 5

Which certificate type do you need to configure the vault for LDAP over SSL?

    Correct Answer: A

    To configure the vault for LDAP over SSL, you need the CA Certificate that signed the certificate used by the External Directory. This is because the Vault needs to validate and trust the certificate presented by the LDAP server, and importing the CA Certificate that signed the LDAP server's certificate is the proper way to establish this trust.

Discussion

6 comments
jconchaOption: A
Aug 9, 2023

the answer is A https://docs.cyberark.com/PAS/12.6/en/Content/PAS%20INST/Configuring-Transparent-User-Management.htm

M4rt1n0Option: A
Nov 19, 2023

the answer is A "On the Vault machine, import the CA Certificate that signed the certificate used by the External Directory into the Windows certificate store to facilitate an SSL connection between the Vault and the External Directory (recommended)." Source: CyberArk Documentation

rayjohn28Option: A
Jul 12, 2024

A is the correct answer

144d6ddOption: A
Jun 21, 2024

Configure LDAP over SSL connections (recommended): On the Vault machine, import the CA Certificate that signed the certificate used by the External Directory into the Windows certificate store to facilitate an SSL connection between the Vault and the External Directory (recommended). ADAC

bumikaOption: A
Apr 9, 2024

The Vault application must validate the LDAPS certificate, so it needs to accept the CA certificate as a trusted issuer.

dru0paOption: B
Mar 18, 2023

Is correct as this is local between the AD and the Vault