PAM-CDE-RECERT Exam QuestionsBrowse all questions from this exam

PAM-CDE-RECERT Exam - Question 5


Which certificate type do you need to configure the vault for LDAP over SSL?

Show Answer
Correct Answer: A

To configure the vault for LDAP over SSL, you need the CA Certificate that signed the certificate used by the External Directory. This is because the Vault needs to validate and trust the certificate presented by the LDAP server, and importing the CA Certificate that signed the LDAP server's certificate is the proper way to establish this trust.

Discussion

6 comments
Sign in to comment
jconchaOption: A
Aug 9, 2023

the answer is A https://docs.cyberark.com/PAS/12.6/en/Content/PAS%20INST/Configuring-Transparent-User-Management.htm

M4rt1n0Option: A
Nov 19, 2023

the answer is A "On the Vault machine, import the CA Certificate that signed the certificate used by the External Directory into the Windows certificate store to facilitate an SSL connection between the Vault and the External Directory (recommended)." Source: CyberArk Documentation

dru0paOption: B
Mar 18, 2023

Is correct as this is local between the AD and the Vault

bumikaOption: A
Apr 9, 2024

The Vault application must validate the LDAPS certificate, so it needs to accept the CA certificate as a trusted issuer.

144d6ddOption: A
Jun 21, 2024

Configure LDAP over SSL connections (recommended): On the Vault machine, import the CA Certificate that signed the certificate used by the External Directory into the Windows certificate store to facilitate an SSL connection between the Vault and the External Directory (recommended). ADAC

rayjohn28Option: A
Jul 12, 2024

A is the correct answer