CyberArk ISS · ● Active · Professional · CyberArk
Certification Overview: Professional-level identity and access management credential validating practical and advanced skills in deploying, configuring, and managing CyberArk Identity (formerly Idaptive) solutions including single sign-on, multi-factor authentication, user provisioning, and comprehensive lifecycle management across enterprise environments.
Exam facts
| Field | Value |
|---|---|
| Cost | $200–$250 USD; regional pricing may vary by location and currency |
| Duration | 90 minutes (fixed exam window, no extensions permitted) |
| Questions | 60–70 questions estimated; mix of multiple choice, scenario-based, and configuration tasks |
| Passing Score | ~70% correct answers (exact threshold not publicly specified by vendor; verify with CyberArk) |
| Format | Multiple choice, multiple response, scenario-based (SIM-style) with practical configuration scenarios |
| Delivery | Pearson VUE in-person testing centers exclusively (as of November 1, 2025, no remote testing available) |
| Languages | English only (other languages not currently available for this certification track) |
| Validity | 3 years from certification date; continuous renewal recommended for career advancement |
| Renewal Method | Retake certification exam OR complete approved CyberArk training/CE courses every 3 years |
| Prerequisites | 6+ months hands-on experience with CyberArk Identity recommended; foundational IAM knowledge helpful |
| Release Date | Part of ongoing CyberArk certification framework (2023 onwards); actively updated quarterly |
| Retirement Date | N/A — currently active and expanding certification track with regular content updates |
| Exam Attempts | Maximum 3 attempts in 12-month period; 5-day wait between attempts 1-2, 30+ days between subsequent |
| Proctoring | In-person proctor at Pearson VUE testing center; government ID required for registration and check-in |
Vendor source — CyberArk Certification Program ↗ Exam administration — Pearson VUE CyberArk Exams ↗ Training portal — CyberArk University ↗
About this certification
The CyberArk Identity Security Specialist (ISS) certification, officially part of the Sentry tier in CyberArk's professional certification framework, validates professional-level competency in deploying, configuring, managing, and troubleshooting CyberArk Identity solutions in real-world enterprise environments.
Certification positioning
This credential sits at the specialist/professional level within CyberArk's three-tier certification hierarchy:
- Defender (Entry-level): Installation, basic configuration, daily operations
- Sentry/ISS (Professional): Advanced configuration, architecture, integration, troubleshooting
- Guardian (Expert): Enterprise architecture, strategy, optimization, advanced scenarios
The ISS focuses specifically on the Identity track and covers core competencies including single sign-on (SSO) implementation, adaptive multi-factor authentication (MFA) policy design, user access lifecycle management, and sophisticated integration with enterprise identity platforms including Active Directory, Workday, Okta, ServiceNow, and other third-party systems.
Target audience
This certification serves identity and access management (IAM) professionals, systems administrators, security engineers, IT managers, enterprise architects, and integration specialists working with CyberArk Identity solutions in production enterprise environments. The certification typically requires minimum 6–12 months of real-world CyberArk Identity implementation experience and hands-on platform administration.
Platform context
CyberArk Identity (formerly known as Idaptive before acquisition by CyberArk in 2021) is a cloud-native, zero-trust identity security platform designed to address modern authentication and access control challenges in hybrid work and multi-cloud enterprise environments. The platform emphasizes adaptive authentication, risk-based policies, and seamless integration with existing identity infrastructure. As of 2026, CyberArk Identity remains one of the fastest-growing components of the CyberArk PAM ecosystem.
Differentiation from entry-level
The ISS differs substantially from entry-level Defender certifications. While Defenders validate installation and basic configuration tasks, Identity Security Specialists must demonstrate mastery of advanced configuration, architecture decision-making, integration patterns, troubleshooting methodologies, and alignment with enterprise compliance frameworks including SOC 2 Type II, HIPAA, GDPR, and PCI-DSS compliance requirements.
Domain context — Security (Identity & Access Management)
Identity and access management (IAM) within cloud and on-premises enterprise environments. This domain encompasses zero-trust architecture principles, single sign-on protocols and federation standards, multi-factor authentication frameworks and deployment, user provisioning and deprovisioning workflows, privileged account lifecycle management, and identity governance across hybrid IT infrastructures.
The domain addresses both technical implementation aspects (SSO configuration, MFA policy design, directory integration, compliance automation) and strategic alignment (alignment with NIST Cybersecurity Framework, SOC 2 Type II compliance, HIPAA security rule requirements, GDPR data protection obligations, PCI-DSS access control mandates).
Read full deep dive — CyberArk PAM Ecosystem ↗
Topics covered
Core exam objectives and knowledge domains for CyberArk Identity Security Specialist (Sentry-level certification):
Architecture & Deployment (15-20%)
- Solution architecture patterns and design best practices for enterprise environments
- Cloud deployment models and SaaS-first architecture approach
- On-premises installation and hybrid deployment options and considerations
- Multi-tenancy support and tenant isolation strategies and security
- High availability configuration and disaster recovery design and testing
- Scalability considerations, performance optimization, and load balancing
- Capacity planning and growth management for enterprise deployments
- Network security, firewall configuration, and integration architecture
Single Sign-On Configuration (18-22%)
- Adaptive authentication policies and workflow design and implementation
- Federation trust models and standards (SAML, OAuth, OIDC)
- OAuth 2.0 implementation and token management best practices
- OpenID Connect (OIDC) protocol deployment and configuration
- SAML 2.0 federation with SaaS and enterprise applications
- Custom identity protocol integration and development
- SSO troubleshooting, debugging, and log analysis techniques
- Session management, timeout policies, and security considerations
Multi-Factor Authentication (15-20%)
- Adaptive risk-based MFA policies and thresholds configuration
- Authentication method management and UX optimization
- Push notifications and mobile authentication deployment
- Time-based one-time password (TOTP) implementation and testing
- Passwordless authentication strategies and deployment options
- Device trust and security posture assessment integration
- Behavioral analytics and anomaly detection configuration
- MFA policy exceptions, bypass management, and recovery flows
User Lifecycle Management (15-20%)
- Identity provisioning and onboarding automation workflows
- Deprovisioning and offboarding procedures and best practices
- Access request workflows and approval process configuration
- Automated lifecycle based on HR system events and triggers
- Workday integration, synchronization, and connector management
- Manager-based approval workflows and delegation models
- Access certification and recertification cycle management
- Joiner-mover-leaver (JML) process automation and exception handling
Application & Access Governance (12-15%)
- Application onboarding and catalog management procedures
- Access policy creation, enforcement, and continuous audit
- Entitlement management and access rights assignment
- Application integration patterns and custom connector development
- Access reviews, attestation, and compliance verification workflows
- SaaS application catalog expansion and integration strategies
- Legacy application integration and modernization approaches
- Application access troubleshooting and support procedures
Directory & Identity Store Integration (10-13%)
- Active Directory synchronization and connector configuration
- LDAP and other directory service integration approaches
- Group management and policy inheritance configuration
- Attribute mapping and identity correlation strategies
- Directory schema customization and validation procedures
- Multiple identity store federation approaches and design
- Directory validation and integrity check procedures
- Hybrid identity and cloud directory integration options
Security, Compliance & Audit (12-15%)
- Comprehensive audit logging configuration and review procedures
- Compliance reporting frameworks (SOC 2, HIPAA, GDPR, PCI-DSS, NIST)
- Role-based access control (RBAC) design and implementation
- Risk-based authentication and adaptive policy configuration
- Audit trail analysis and forensic investigation methodologies
- Compliance documentation generation and validation procedures
- Security incident investigation and response procedures
- Privacy requirements and data protection implementation
Administration & Troubleshooting (10-12%)
- User and tenant management procedures and best practices
- Administrative task automation using APIs and automation tools
- Diagnostics and comprehensive log analysis methodologies
- Performance tuning and optimization techniques and tools
- Session troubleshooting and advanced debugging methodologies
- RESTful API usage for automation and integration scenarios
- Backup, restore, and disaster recovery procedures and testing
- Upgrade planning, patching, and change management procedures
Identity Cloud Platform (ICP) (5-10%)
- CyberArk unified identity cloud capabilities and features
- API-first architecture and RESTful service design principles
- Integration with broader CyberArk PAM ecosystem components
- Cloud-native security considerations and best practices
- Future product roadmap and emerging features awareness
Source: CyberArk Identity Security Training ↗
Common skills at Security · Professional
Shared technical and strategic competencies for security professionals at the specialist/professional level — not specific to this cert.
- Zero-trust security architecture principles and enterprise implementation strategies
- RBAC and attribute-based access control (ABAC) policy design and governance
- Multi-factor authentication frameworks, deployment methodologies, and risk assessment
- Single sign-on protocols (SAML 2.0, OAuth 2.0, OpenID Connect) and federation standards
- Identity federation and cross-domain trust models in enterprise environments
- Comprehensive audit logging, event monitoring, and digital forensics capabilities
- Compliance frameworks and regulatory requirements (NIST, SOC 2, HIPAA, GDPR, PCI-DSS)
- Security incident response and access control breach investigation procedures
- Vulnerability assessment, threat modeling, and remediation in identity platforms
- Cloud identity platforms (SaaS IAM solutions) and hybrid IAM architecture design
- Directory services administration and integration (Active Directory, LDAP, eDirectory)
- Risk management and threat modeling specific to access control systems
- Privacy impact assessment and data protection in identity governance
Recommended courses at Security · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| CyberArk Official | CyberArk Identity Administration Fundamentals | Free (account) | ↗ |
| CyberArk Official | CyberArk Identity Advanced Administration | Free (account) | ↗ |
| CyberArk Official | CyberArk Identity Certification Prep | Free (account) | ↗ |
| CyberArk Official | CyberArk Identity Sentry Boot Camp | $500–$1,000 | ↗ |
| IdentitySkills | CyberArk Identity Sentry Complete Course | $299–$499 | ↗ |
| IdentitySkills | CyberArk Identity Hands-On Labs | $199–$299 | ↗ |
| Pluralsight | CyberArk Identity Learning Path | $29/month | ↗ |
| YouTube | CyberArk Identity Configuration Tutorials | Free | ↗ |
Course selection: CyberArk's official training through CyberArk University is the authoritative primary resource for exam preparation. Free content with CyberArk account registration provides comprehensive coverage of all exam domains. Third-party courses supplement but do not replace official materials and should be used for reinforcement. Prioritize hands-on lab experience over lecture-only content.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| CyberArk Official | Official Practice Exam in Training Portal | Free | ↗ |
| Whizlabs | CyberArk Identity Sentry Practice Tests | $49 | ↗ |
| Examtopics | CyberArk Identity Q&A Community | Free / $99 | ↗ |
| KodeKloud | CyberArk Identity Hands-On Labs | $99–$199 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CyberArk Identity Administration Guide | CyberArk | CyberArk (docs) | 2024 | N/A | ↗ |
| CyberArk Identity SSO Best Practices | CyberArk | CyberArk (PDF) | 2023 | N/A | ↗ |
| Zero Trust Identity Security | CyberArk | CyberArk (eBook) | 2024 | N/A | ↗ |
Note: CyberArk does not publish traditional printed textbooks for this certification path. Official online documentation, product administration guides, and technical whitepapers are authoritative study resources.
Typical job titles at Security · Professional
Identity & Access Manager · IAM Engineer · CyberArk Identity Specialist · Security Administrator (IAM) · Directory Services Engineer · Access Governance Analyst · Identity Architect · Systems Integration Engineer (IAM) · Cloud IAM Specialist · Identity Security Engineer · Senior IAM Administrator · Identity & Access Management Consultant · Enterprise Access Management Specialist · IAM Solutions Architect · Identity Platform Administrator · Cloud Access Security Broker (CASB) Specialist
(Job titles drawn from current job-board postings and career sites listing CyberArk Identity certifications as required or strongly preferred qualifications.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $87,000–$163,000 annually (baseline; CyberArk certified +5–15%) | Glassdoor ↗ · Salary.com ↗ · ZipRecruiter ↗ |
| ZAR | R377,000–R645,000 annually (IT Security Specialist to Cyber Security Manager range) | PayScale ZA ↗ · Indeed ZA ↗ · Glassdoor ZA ↗ |
| GBP | £55,000–£85,000 annually (UK) | IT Jobs Watch ↗ |
| EUR | €50,000–€80,000 annually (DACH) | Glassdoor EU ↗ |
| AUD | A$95,000–A$140,000 annually (Australia) | Indeed AU ↗ |
Methodology: Ranges reflect baseline security specialist roles with IAM specialization and platform expertise. CyberArk professional certifications command premium of 5–15% over generalist security salaries. Compensation varies significantly by geographic region, organization size, industry sector, years of IAM experience, and seniority level. Senior roles, architect positions, and consulting/contractor arrangements command higher ranges. Regional data sourced from active job postings and salary surveys dated 2026.
Skills validated
Cert-specific technical competencies and hands-on skills assessed:
- CyberArk Identity architecture and cloud deployment models
- Single Sign-On configuration and troubleshooting (SAML, OAuth 2.0, OIDC)
- Adaptive MFA policy design and implementation
- User provisioning and lifecycle management workflows
- Active Directory and identity store synchronization
- Application catalog management and access enforcement
- Audit logging, compliance reporting, and forensics
- CyberArk Identity API and CLI usage
- Role-based and risk-based access control configuration
- Enterprise platform integration (Workday, Okta, ServiceNow)
- Troubleshooting and performance optimization
- Compliance framework alignment (SOC 2, HIPAA, GDPR, PCI-DSS)
Related certifications
- Stacks with: CyberArk Defender (PAM) ↗ — complementary professional-level PAM credential
- Prerequisite for: CyberArk Guardian (Identity) — file not yet created — expert-level advanced track
- Replaces: N/A — current track; Idaptive Administrator credential (pre-2023)
- Equivalents: Okta Certified Associate, Sailpoint IdentityIQ Certified — not yet created
- Vendor overview: CyberArk Platform Overview ↗
Sources
- CyberArk Certification Program
- Pearson VUE CyberArk Exams
- CyberArk University
- CyberArk Identity Documentation
- CyberArk Resources
- IdentitySkills Guides
- Glassdoor
- Salary.com
- PayScale ZA
- Indeed
- SecApps Learning
- YouTube
Last verified: 2026-05-01 Parent ecosystem: CyberArk PAM Ecosystem Parent domain: Security (Identity & Access Management) Vendor overview: CyberArk Platform Overview
Exam preparation strategy
Study timeline recommendation
For candidates with 6–12 months of CyberArk Identity hands-on experience:
- Weeks 1–2: Review CyberArk Identity architecture, deployment models, and platform capabilities via official training
- Weeks 3–4: Deep dive into SSO protocols (SAML, OAuth 2.0, OIDC) and federation trust models
- Weeks 5–6: Master MFA policies, risk-based authentication, and device trust configuration
- Weeks 7–8: User lifecycle management, provisioning workflows, and Workday integration
- Week 9: Application governance, access policies, and entitlement management
- Week 10: Compliance frameworks, audit logging, and identity forensics
- Weeks 11–12: Practice exams, weak area reinforcement, and exam simulation
Key knowledge domains
Candidates should focus heavily on:
- SSO federation and protocols — SAML, OAuth 2.0, OIDC protocols are heavily tested
- MFA and risk-based policies — Adaptive authentication is core to CyberArk Identity positioning
- User lifecycle management — Provisioning, deprovisioning, and HR integration are critical in enterprise environments
- Integration patterns — Workday, Active Directory, and third-party system integration
- Troubleshooting methodologies — Diagnostic analysis, log reading, and configuration validation
- Compliance and audit — SOC 2, HIPAA, GDPR requirements in identity contexts
Common exam traps
- Confusing OAuth 2.0 authorization flows (implicit vs. authorization code vs. client credentials)
- MFA policy exceptions and bypass scenarios in edge cases
- Workday connector configuration and attribute mapping
- Directory synchronization conflict resolution and identity correlation
- Session timeout and token refresh behavior in SSO contexts
- Audit logging and compliance report generation procedures
Recertification and continuing education
CyberArk certified professionals maintain credentials through:
Option 1: Recertification exam
- Retake the identity Security Specialist exam every 3 years
- Same exam, same rigor, same passing threshold (~70%)
- Cost: $200–$250 USD per attempt
Option 2: Continuing education
- Complete approved CyberArk training courses or webinars
- Earn continuing education (CE) credits through CyberArk University
- Complete required CE hours every 3 years (typically 20–40 hours)
- Track progress in CyberArk's certification portal
Option 3: Upgrade path
- Pursue Guardian-level certification (expert tier)
- Guardian certification extends ISS validity
- Demonstrates continued commitment to advanced skills
Maintaining certification status
- Track renewal deadlines in your professional certification portfolio
- Register for training or exam 60–90 days before expiration
- Update your LinkedIn profile and professional networks upon renewal
- Document continuous learning and hands-on experience