CyberArk Identity Security Specialist

CyberArk · CyberArk ISS · Professional

CyberArk · CyberArk PAM Ecosystem

CyberArk Identity Security Specialist

CyberArk ISSactiveProfessional
Official CyberArk source · cyberark.com

CyberArk ISS · ● Active · Professional · CyberArk

Certification Overview: Professional-level identity and access management credential validating practical and advanced skills in deploying, configuring, and managing CyberArk Identity (formerly Idaptive) solutions including single sign-on, multi-factor authentication, user provisioning, and comprehensive lifecycle management across enterprise environments.


Exam facts

FieldValue
Cost$200–$250 USD; regional pricing may vary by location and currency
Duration90 minutes (fixed exam window, no extensions permitted)
Questions60–70 questions estimated; mix of multiple choice, scenario-based, and configuration tasks
Passing Score~70% correct answers (exact threshold not publicly specified by vendor; verify with CyberArk)
FormatMultiple choice, multiple response, scenario-based (SIM-style) with practical configuration scenarios
DeliveryPearson VUE in-person testing centers exclusively (as of November 1, 2025, no remote testing available)
LanguagesEnglish only (other languages not currently available for this certification track)
Validity3 years from certification date; continuous renewal recommended for career advancement
Renewal MethodRetake certification exam OR complete approved CyberArk training/CE courses every 3 years
Prerequisites6+ months hands-on experience with CyberArk Identity recommended; foundational IAM knowledge helpful
Release DatePart of ongoing CyberArk certification framework (2023 onwards); actively updated quarterly
Retirement DateN/A — currently active and expanding certification track with regular content updates
Exam AttemptsMaximum 3 attempts in 12-month period; 5-day wait between attempts 1-2, 30+ days between subsequent
ProctoringIn-person proctor at Pearson VUE testing center; government ID required for registration and check-in

Vendor source — CyberArk Certification Program ↗ Exam administration — Pearson VUE CyberArk Exams ↗ Training portal — CyberArk University ↗


About this certification

The CyberArk Identity Security Specialist (ISS) certification, officially part of the Sentry tier in CyberArk's professional certification framework, validates professional-level competency in deploying, configuring, managing, and troubleshooting CyberArk Identity solutions in real-world enterprise environments.

Certification positioning

This credential sits at the specialist/professional level within CyberArk's three-tier certification hierarchy:

  • Defender (Entry-level): Installation, basic configuration, daily operations
  • Sentry/ISS (Professional): Advanced configuration, architecture, integration, troubleshooting
  • Guardian (Expert): Enterprise architecture, strategy, optimization, advanced scenarios

The ISS focuses specifically on the Identity track and covers core competencies including single sign-on (SSO) implementation, adaptive multi-factor authentication (MFA) policy design, user access lifecycle management, and sophisticated integration with enterprise identity platforms including Active Directory, Workday, Okta, ServiceNow, and other third-party systems.

Target audience

This certification serves identity and access management (IAM) professionals, systems administrators, security engineers, IT managers, enterprise architects, and integration specialists working with CyberArk Identity solutions in production enterprise environments. The certification typically requires minimum 6–12 months of real-world CyberArk Identity implementation experience and hands-on platform administration.

Platform context

CyberArk Identity (formerly known as Idaptive before acquisition by CyberArk in 2021) is a cloud-native, zero-trust identity security platform designed to address modern authentication and access control challenges in hybrid work and multi-cloud enterprise environments. The platform emphasizes adaptive authentication, risk-based policies, and seamless integration with existing identity infrastructure. As of 2026, CyberArk Identity remains one of the fastest-growing components of the CyberArk PAM ecosystem.

Differentiation from entry-level

The ISS differs substantially from entry-level Defender certifications. While Defenders validate installation and basic configuration tasks, Identity Security Specialists must demonstrate mastery of advanced configuration, architecture decision-making, integration patterns, troubleshooting methodologies, and alignment with enterprise compliance frameworks including SOC 2 Type II, HIPAA, GDPR, and PCI-DSS compliance requirements.


Domain context — Security (Identity & Access Management)

Identity and access management (IAM) within cloud and on-premises enterprise environments. This domain encompasses zero-trust architecture principles, single sign-on protocols and federation standards, multi-factor authentication frameworks and deployment, user provisioning and deprovisioning workflows, privileged account lifecycle management, and identity governance across hybrid IT infrastructures.

The domain addresses both technical implementation aspects (SSO configuration, MFA policy design, directory integration, compliance automation) and strategic alignment (alignment with NIST Cybersecurity Framework, SOC 2 Type II compliance, HIPAA security rule requirements, GDPR data protection obligations, PCI-DSS access control mandates).

Read full deep dive — CyberArk PAM Ecosystem ↗


Topics covered

Core exam objectives and knowledge domains for CyberArk Identity Security Specialist (Sentry-level certification):

Architecture & Deployment (15-20%)

  • Solution architecture patterns and design best practices for enterprise environments
  • Cloud deployment models and SaaS-first architecture approach
  • On-premises installation and hybrid deployment options and considerations
  • Multi-tenancy support and tenant isolation strategies and security
  • High availability configuration and disaster recovery design and testing
  • Scalability considerations, performance optimization, and load balancing
  • Capacity planning and growth management for enterprise deployments
  • Network security, firewall configuration, and integration architecture

Single Sign-On Configuration (18-22%)

  • Adaptive authentication policies and workflow design and implementation
  • Federation trust models and standards (SAML, OAuth, OIDC)
  • OAuth 2.0 implementation and token management best practices
  • OpenID Connect (OIDC) protocol deployment and configuration
  • SAML 2.0 federation with SaaS and enterprise applications
  • Custom identity protocol integration and development
  • SSO troubleshooting, debugging, and log analysis techniques
  • Session management, timeout policies, and security considerations

Multi-Factor Authentication (15-20%)

  • Adaptive risk-based MFA policies and thresholds configuration
  • Authentication method management and UX optimization
  • Push notifications and mobile authentication deployment
  • Time-based one-time password (TOTP) implementation and testing
  • Passwordless authentication strategies and deployment options
  • Device trust and security posture assessment integration
  • Behavioral analytics and anomaly detection configuration
  • MFA policy exceptions, bypass management, and recovery flows

User Lifecycle Management (15-20%)

  • Identity provisioning and onboarding automation workflows
  • Deprovisioning and offboarding procedures and best practices
  • Access request workflows and approval process configuration
  • Automated lifecycle based on HR system events and triggers
  • Workday integration, synchronization, and connector management
  • Manager-based approval workflows and delegation models
  • Access certification and recertification cycle management
  • Joiner-mover-leaver (JML) process automation and exception handling

Application & Access Governance (12-15%)

  • Application onboarding and catalog management procedures
  • Access policy creation, enforcement, and continuous audit
  • Entitlement management and access rights assignment
  • Application integration patterns and custom connector development
  • Access reviews, attestation, and compliance verification workflows
  • SaaS application catalog expansion and integration strategies
  • Legacy application integration and modernization approaches
  • Application access troubleshooting and support procedures

Directory & Identity Store Integration (10-13%)

  • Active Directory synchronization and connector configuration
  • LDAP and other directory service integration approaches
  • Group management and policy inheritance configuration
  • Attribute mapping and identity correlation strategies
  • Directory schema customization and validation procedures
  • Multiple identity store federation approaches and design
  • Directory validation and integrity check procedures
  • Hybrid identity and cloud directory integration options

Security, Compliance & Audit (12-15%)

  • Comprehensive audit logging configuration and review procedures
  • Compliance reporting frameworks (SOC 2, HIPAA, GDPR, PCI-DSS, NIST)
  • Role-based access control (RBAC) design and implementation
  • Risk-based authentication and adaptive policy configuration
  • Audit trail analysis and forensic investigation methodologies
  • Compliance documentation generation and validation procedures
  • Security incident investigation and response procedures
  • Privacy requirements and data protection implementation

Administration & Troubleshooting (10-12%)

  • User and tenant management procedures and best practices
  • Administrative task automation using APIs and automation tools
  • Diagnostics and comprehensive log analysis methodologies
  • Performance tuning and optimization techniques and tools
  • Session troubleshooting and advanced debugging methodologies
  • RESTful API usage for automation and integration scenarios
  • Backup, restore, and disaster recovery procedures and testing
  • Upgrade planning, patching, and change management procedures

Identity Cloud Platform (ICP) (5-10%)

  • CyberArk unified identity cloud capabilities and features
  • API-first architecture and RESTful service design principles
  • Integration with broader CyberArk PAM ecosystem components
  • Cloud-native security considerations and best practices
  • Future product roadmap and emerging features awareness

Source: CyberArk Identity Security Training ↗


Common skills at Security · Professional

Shared technical and strategic competencies for security professionals at the specialist/professional level — not specific to this cert.

  • Zero-trust security architecture principles and enterprise implementation strategies
  • RBAC and attribute-based access control (ABAC) policy design and governance
  • Multi-factor authentication frameworks, deployment methodologies, and risk assessment
  • Single sign-on protocols (SAML 2.0, OAuth 2.0, OpenID Connect) and federation standards
  • Identity federation and cross-domain trust models in enterprise environments
  • Comprehensive audit logging, event monitoring, and digital forensics capabilities
  • Compliance frameworks and regulatory requirements (NIST, SOC 2, HIPAA, GDPR, PCI-DSS)
  • Security incident response and access control breach investigation procedures
  • Vulnerability assessment, threat modeling, and remediation in identity platforms
  • Cloud identity platforms (SaaS IAM solutions) and hybrid IAM architecture design
  • Directory services administration and integration (Active Directory, LDAP, eDirectory)
  • Risk management and threat modeling specific to access control systems
  • Privacy impact assessment and data protection in identity governance

Recommended courses at Security · Professional

ProviderTitleCostURL
CyberArk OfficialCyberArk Identity Administration FundamentalsFree (account)
CyberArk OfficialCyberArk Identity Advanced AdministrationFree (account)
CyberArk OfficialCyberArk Identity Certification PrepFree (account)
CyberArk OfficialCyberArk Identity Sentry Boot Camp$500–$1,000
IdentitySkillsCyberArk Identity Sentry Complete Course$299–$499
IdentitySkillsCyberArk Identity Hands-On Labs$199–$299
PluralsightCyberArk Identity Learning Path$29/month
YouTubeCyberArk Identity Configuration TutorialsFree

Course selection: CyberArk's official training through CyberArk University is the authoritative primary resource for exam preparation. Free content with CyberArk account registration provides comprehensive coverage of all exam domains. Third-party courses supplement but do not replace official materials and should be used for reinforcement. Prioritize hands-on lab experience over lecture-only content.


Practice exams

ProviderTitleCostURL
CyberArk OfficialOfficial Practice Exam in Training PortalFree
WhizlabsCyberArk Identity Sentry Practice Tests$49
ExamtopicsCyberArk Identity Q&A CommunityFree / $99
KodeKloudCyberArk Identity Hands-On Labs$99–$199

Books

TitleAuthorPublisherYearISBNURL
CyberArk Identity Administration GuideCyberArkCyberArk (docs)2024N/A
CyberArk Identity SSO Best PracticesCyberArkCyberArk (PDF)2023N/A
Zero Trust Identity SecurityCyberArkCyberArk (eBook)2024N/A

Note: CyberArk does not publish traditional printed textbooks for this certification path. Official online documentation, product administration guides, and technical whitepapers are authoritative study resources.


Typical job titles at Security · Professional

Identity & Access Manager · IAM Engineer · CyberArk Identity Specialist · Security Administrator (IAM) · Directory Services Engineer · Access Governance Analyst · Identity Architect · Systems Integration Engineer (IAM) · Cloud IAM Specialist · Identity Security Engineer · Senior IAM Administrator · Identity & Access Management Consultant · Enterprise Access Management Specialist · IAM Solutions Architect · Identity Platform Administrator · Cloud Access Security Broker (CASB) Specialist

(Job titles drawn from current job-board postings and career sites listing CyberArk Identity certifications as required or strongly preferred qualifications.)


Salary

RegionRangeSource
USD$87,000–$163,000 annually (baseline; CyberArk certified +5–15%)Glassdoor ↗ · Salary.com ↗ · ZipRecruiter ↗
ZARR377,000–R645,000 annually (IT Security Specialist to Cyber Security Manager range)PayScale ZA ↗ · Indeed ZA ↗ · Glassdoor ZA ↗
GBP£55,000–£85,000 annually (UK)IT Jobs Watch ↗
EUR€50,000–€80,000 annually (DACH)Glassdoor EU ↗
AUDA$95,000–A$140,000 annually (Australia)Indeed AU ↗

Methodology: Ranges reflect baseline security specialist roles with IAM specialization and platform expertise. CyberArk professional certifications command premium of 5–15% over generalist security salaries. Compensation varies significantly by geographic region, organization size, industry sector, years of IAM experience, and seniority level. Senior roles, architect positions, and consulting/contractor arrangements command higher ranges. Regional data sourced from active job postings and salary surveys dated 2026.


Skills validated

Cert-specific technical competencies and hands-on skills assessed:

  • CyberArk Identity architecture and cloud deployment models
  • Single Sign-On configuration and troubleshooting (SAML, OAuth 2.0, OIDC)
  • Adaptive MFA policy design and implementation
  • User provisioning and lifecycle management workflows
  • Active Directory and identity store synchronization
  • Application catalog management and access enforcement
  • Audit logging, compliance reporting, and forensics
  • CyberArk Identity API and CLI usage
  • Role-based and risk-based access control configuration
  • Enterprise platform integration (Workday, Okta, ServiceNow)
  • Troubleshooting and performance optimization
  • Compliance framework alignment (SOC 2, HIPAA, GDPR, PCI-DSS)

Related certifications

  • Stacks with: CyberArk Defender (PAM) ↗ — complementary professional-level PAM credential
  • Prerequisite for: CyberArk Guardian (Identity) — file not yet created — expert-level advanced track
  • Replaces: N/A — current track; Idaptive Administrator credential (pre-2023)
  • Equivalents: Okta Certified Associate, Sailpoint IdentityIQ Certified — not yet created
  • Vendor overview: CyberArk Platform Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: CyberArk PAM Ecosystem Parent domain: Security (Identity & Access Management) Vendor overview: CyberArk Platform Overview

Exam preparation strategy

Study timeline recommendation

For candidates with 6–12 months of CyberArk Identity hands-on experience:

  • Weeks 1–2: Review CyberArk Identity architecture, deployment models, and platform capabilities via official training
  • Weeks 3–4: Deep dive into SSO protocols (SAML, OAuth 2.0, OIDC) and federation trust models
  • Weeks 5–6: Master MFA policies, risk-based authentication, and device trust configuration
  • Weeks 7–8: User lifecycle management, provisioning workflows, and Workday integration
  • Week 9: Application governance, access policies, and entitlement management
  • Week 10: Compliance frameworks, audit logging, and identity forensics
  • Weeks 11–12: Practice exams, weak area reinforcement, and exam simulation

Key knowledge domains

Candidates should focus heavily on:

  1. SSO federation and protocols — SAML, OAuth 2.0, OIDC protocols are heavily tested
  2. MFA and risk-based policies — Adaptive authentication is core to CyberArk Identity positioning
  3. User lifecycle management — Provisioning, deprovisioning, and HR integration are critical in enterprise environments
  4. Integration patterns — Workday, Active Directory, and third-party system integration
  5. Troubleshooting methodologies — Diagnostic analysis, log reading, and configuration validation
  6. Compliance and audit — SOC 2, HIPAA, GDPR requirements in identity contexts

Common exam traps

  • Confusing OAuth 2.0 authorization flows (implicit vs. authorization code vs. client credentials)
  • MFA policy exceptions and bypass scenarios in edge cases
  • Workday connector configuration and attribute mapping
  • Directory synchronization conflict resolution and identity correlation
  • Session timeout and token refresh behavior in SSO contexts
  • Audit logging and compliance report generation procedures

Recertification and continuing education

CyberArk certified professionals maintain credentials through:

Option 1: Recertification exam

  • Retake the identity Security Specialist exam every 3 years
  • Same exam, same rigor, same passing threshold (~70%)
  • Cost: $200–$250 USD per attempt

Option 2: Continuing education

  • Complete approved CyberArk training courses or webinars
  • Earn continuing education (CE) credits through CyberArk University
  • Complete required CE hours every 3 years (typically 20–40 hours)
  • Track progress in CyberArk's certification portal

Option 3: Upgrade path

  • Pursue Guardian-level certification (expert tier)
  • Guardian certification extends ISS validity
  • Demonstrates continued commitment to advanced skills

Maintaining certification status

  • Track renewal deadlines in your professional certification portfolio
  • Register for training or exam 60–90 days before expiration
  • Update your LinkedIn profile and professional networks upon renewal
  • Document continuous learning and hands-on experience
Rate this cert
Was this helpful?
Comments ()
0/2000