Free SECRET-SEN Exam Braindumps (page: 6)

Page 5 of 16

What is the correct command to import the root CA certificate into Conjur?

  1. docker exec <ContainerName> evoke ca import ­ ­no-restart ­ ­root <rootCcer>
  2. docker exec <ContainerName> evoke import ­ ­no-restart ­ ­root <rootCA.cer>
  3. docker exec <ContainerName> evoke ca import ­ ­no-restart <rootCA.cer>
  4. docker exec <ContainerName> ca import <rootCA.cer>

Answer(s): C



You start up a Follower and try to connect to it with a REST call using the server certificate, but you get an SSL connection refused error.
What could be the problem and how should you fix it?

  1. The certificate does not contain the Follower hostname as a Subject Alternative Name (SAN).
    Generate a new certificate for the Follower.
  2. One of the PostgreSQL ports (5432. 1999) is blocked by the firewall Open those ports.
  3. Port 443 is blocked; open that port.
  4. The certificate is unnecessary. Use the command option to suppress SSL certificate checking.

Answer(s): A



When loading policy, you receive a 422 Response from Conjur with a message.
What could cause this issue?

  1. malformed Policy file
  2. incorrect Leader URL
  3. misconfigured Load Balancer health check
  4. incorrect Vault Conjur Synchronizer URL

Answer(s): A



After manually failing over to your disaster recovery site (Site B) for testing purposes, you need to failback to your primary site (Site A).
Which step is required?

  1. Contact CyberArk for a new license file.
  2. Reconfigure the Vault Conjur Synchronizer to point to the new Conjur Leader.
  3. Generate a seed for the new Leader to be deployed in Site A.
  4. Trigger autofailover to promote the Standby in Site A to Leader.

Answer(s): C






Post your Comments and Discuss CyberArk SECRET-SEN exam with other Community members:

SECRET-SEN Discussions & Posts