Enterprise Applications

CyberArk Privileged Access Management (PAM) Training

Master Privileged Access Security, Infrastructure Hardening, and Vault Automation

4.8(1,850 students)
40 Hours
Intermediate
CyberArkPAMPrivileged Access ManagementDigital VaultCPMPSMPVWA
CyberArk Privileged Access Management (PAM) Training

Enroll in CyberArk PAM Training

Get started with a free demo class.

By submitting, you agree to our privacy policy. We'll never share your details.

Live Online
Classroom
Weekend Batches Available
Lifetime Access to Recordings

Course Overview

This training course is designed to equip security engineers and system administrators with the technical skills needed to administer the CyberArk Privileged Access Management Security Platform. Participants will explore core components of the Privileged Account Security (PAS) core architecture, managing everything from secure Digital Vault installation and network port configuration to complex, multi-tiered deployments. The curriculum covers major infrastructure pieces including Password Vault Web Access (PVWA), Central Policy Manager (CPM), and Privileged Session Manager (PSM). Attendees will gain hands-on experience establishing safe governance architectures, managing Active Directory integrations, applying multi-factor authentication policies, executing manual or automated password reconciliation, and maintaining robust disaster recovery routines.

Who Should Learn

Information Security Specialists, Cyber Security Engineers, and Consultants
Vault Administrators and System Engineers responsible for corporate access security
Network Engineers, Infrastructure Architects, and IT Operations Managers
Compliance Officers and Security Auditors looking to understand privileged session recording

Prerequisites

  • Basic conceptual understanding of TCP/IP networking, security certificates, and firewall ports
  • Familiarity with enterprise system management workflows across Microsoft Windows and Linux platforms

Learning Outcomes

Install, initialize, and securely configure the CyberArk Digital Vault alongside primary management clients
Deploy core components including CPM, PVWA, and PSM in single-instance or distributed high-availability nodes
Synchronize corporate identity stores by building active LDAP/S, SMTP notification, and Syslog logging pipelines
Enforce fine-grained Access Control Matrices using custom Safes, user populations, and Object-Level Access policies
Construct Master Policies and custom platform rules to automate targeted password complexity rotations
Configure secure Privileged Session Monitoring (PSM) for RDP and SSH connections with live audit tracking
Rebuild damaged administrative user parameters by manually generating encrypted password credential files
Implement high-availability topologies and test failover recovery processes for continuous operational availability

Course Curriculum

1Module 1: Privileged Identity Governance Frameworks
4 topics
  • Analyzing modern enterprise IT security challenges and vulnerable exposure vectors
  • Assessing technical risks stemming from unsecured or unmonitored administrative credentials
  • Overview of the CyberArk Core Privileged Access Security (PAS) suite capabilities
  • Architectural interaction matrix between core hardware and software sub-components
2Module 2: Infrastructure Assembly & Component Deployment
4 topics
  • Evaluating system prereqs, dedicated network routing rules, and strict operating system hardening guidelines
  • Step-by-step assembly: Initializing the secure Digital Vault component layer
  • Deploying web access layers: Setting up the Password Vault Web Access (PVWA) console
  • Installing the Central Policy Manager (CPM) engine and the Privileged Session Manager (PSM)
3Module 3: Enterprise Directory Integration & Directory Sync
3 topics
  • Configuring external communication layers: Connecting Active Directory via secure LDAP/S
  • Setting up the Event Notification Engine (ENE) to push alerts out via SMTP routers
  • Exposing internal security logging profiles to corporate centralized Syslog or SIEM pools
4Module 4: Platform Security Rules & Master Policy Design
3 topics
  • Navigating the central Master Policy panel to dictate password validation standards
  • Creating custom CPM platform rules tailored for unique network environments
  • Configuring scheduled platform tasks, lifecycle rotations, and automatic platform overrides
5Module 5: Vault Safe Engineering & Granular Access Control
4 topics
  • Designing explicit Safe structures applying corporate naming guidelines
  • Onboarding enterprise user identities and mapping security group permissions matrices
  • Configuring multi-user confirmation workflows: Deploying Dual Control authorization gates
  • Enforcing granular Object-Level Access Control (OLAC) restrictions within shared repositories
6Module 6: Multi-Platform Endpoint Integration
3 topics
  • Onboarding and binding local Windows domain administrator credentials
  • Securing Unix/Linux server endpoints using private SSH key management frameworks
  • Overview of managing sensitive access lines for network switches and security appliances
7Module 7: Session Auditing, Recording & Operational Use Cases
4 topics
  • Enabling seamless Privileged Single Sign-On (SSO) links for internal administrators
  • Configuring automated password reconciliation rules utilizing high-privilege emergency accounts
  • Setting up mandatory Two-Factor Authentication (2FA) mechanisms across web entry points
  • Inspecting historical session video captures, Keystroke logging indices, and compliance summaries
8Module 8: System Recovery, Backups & Diagnostic Troubleshooting
4 topics
  • Executing localized data exports using specialized Vault backup application bundles
  • Constructing secure, encrypted password utility key files (`.cred`) for component accounts
  • Unlocking administrative component links and resetting compromised gateway credentials
  • Architecting highly available architectures and recovering service continuity using replication Disaster Recovery (DR) Vaults

Certification

Acquire the SkillSurf Certified CyberArk Privileged Access Specialist designation upon validating all sandbox deployment milestones and clearing the practical infrastructure assessment.

Frequently Asked Questions

This course focuses primarily on the self-hosted CyberArk Privileged Access Security (PAS) solution. It covers structural infrastructure installation mechanics—including installing the Digital Vault, CPM, PVWA, and PSM directly onto servers—which are essential for on-premise or private cloud deployments.
You will gain hands-on practice handling typical platform errors, such as desynchronized component user passwords. You'll learn to recreate encrypted credential files using the CyberArk createcredfile utility to safely restore broker connections for components like PVWA, CPM, and PSM.
Yes. Each student receives isolated access to a multi-server virtualization environment, allowing you to perform the actual step-by-step installation, component hardening, and configuration of CyberArk from scratch.