Browse all practice questions for the SailPoint Identity Security Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

SailPoint Identity Security Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • When adjusting the reminder settings for access requests, which approach is used?
  • How can a user obtain access to resources associated with their role?
  • Which role in ISC is described as having the highest access privileges?
  • Which statement best describes the deployment of microservices?
  • What type of issues does the charon.log file primarily log?
  • Which connector category includes Credential Providers?
  • What happens to accounts deleted from an authoritative source in IDNow?
  • What type of rule can directly call a transform?
  • What can a Source Administrator do in the ISC platform?
  • How can TLS connection testing be performed?
  • What are typical lifecycle states associated with identity management?
  • Are uncorrelated accounts considered valid during certifications?
  • What level of access does a regular user possess in ISC?
  • Which protocol is deemed industry-standard for creating access tokens asserting various claims?
  • In the context of SoD policies, what does the term "exclusive access item lists" mean?
  • What aspect of Identity Security is emphasized through certifications?
  • Which of the following is NOT a supported pass-through authentication option?
  • What role does 'Manager' play in filter-based campaign options?
  • What is a disadvantage of Switch Clusters HA configuration?
  • What is the main goal of a Separation of Duties Policy?
  • How can you test a TLS connection from the VA command line?
  • What type of connector is the Active Directory connector categorized as?
  • What configuration does Single Sign-On (SSO) use within an Identity Profile?
  • What service is associated with the canal.log file on the VA?
  • What should be set in the va-config-1395-4702.yaml file to match organizational requirements?
  • What best describes the usage of event triggers in SailPoint?
  • Where can aggregated source data be viewed within the ISC?
  • What occurs when a user's lifecycle changes to inactive regarding Entitlement A?
  • What standard is used for issuing access tokens in IdentityNow?
  • What ensures zero knowledge encryption privacy in SailPoint?
  • What advantage does Switch Clusters HA offer?
  • What is the role of va_agent.log?
  • What is one method of augmenting data in a certification campaign?
  • When should the Joiner process be initiated?
  • What does the status 'Connected' signify in a VA?
  • What does the term “advanced” refer to in the context of ServiceNow connectivity?
  • Which of the following would lead to conflicting attribute values?
  • What primary authentication method does IDNow implement by default?
  • What action should be taken with entitlements providing access to highly confidential data?
  • What is the method for storing a 2048-bit private RSA key?
  • How many high availability (HA) or disaster recovery (DR) scenarios are detailed in best practices?
  • Can a rule call another rule directly?
  • What defines the maximum level of access within an organization?
  • What authorization model is utilized with IdNow's v3 REST APIs?
  • What occurs when an entitlement already exists in a provisioning plan?
  • In a connectivity error scenario, which log would be most relevant?
  • Is account aggregation performed before or after configuring identity profiles?
  • What is the function of the fallback approver in the access review process?
  • What type of logs does fluent.log handle?
  • Can attributes.email be utilized before and after the colon in search queries?
  • Which of the following identity management systems is NOT supported for PTA in IdNow?
  • Which protocols are commonly used for communication by REST APIs?
  • What best identifies the concept of "Fire and Forget" as it pertains to event triggers?
  • What command is used to disable the service for cloud VA deployment?
  • When is a single identity profile preferred in lifecycle design?
  • Which of the following represents the lifecycle states of an identity?
  • For how long does an OAuth 2.0 token remain valid before requiring refresh?
  • What type of data can be controlled by users in MySailPoint?
  • What defines the criteria for assigning access in an identity management system?
  • What must a source have to enable Sub-Admin review certification?
  • What lifecycle states are included for a prehire identity?
  • What does a Manager Correlation Rule typically manage?
  • What is NOT a component of Lifecycle State?
  • How many steps are in the Federated Identity process?
  • What is the main function of a refresh token in identity security?
  • Which of the following activity types is viewable under the Search > Reports section?
  • What role does automation play in policy detection for SoD policies?
  • Should entitlements be marked as privileged if they provide higher access?
  • What term describes the process of granting access to users in an organization?
  • What type of token is issued when utilizing JWT in IdentityNow?
  • What happens when a user who has Entitlement A transfers departments and is part of Role B?
  • Which search query equivalence will return the same search results?
  • How can identity attributes be affected in process flows?
  • Which step follows the configuration of the target system in event trigger implementation?
  • Which of the following statements is true regarding the lifecycle state changes?
  • What term refers to the method of verifying a user's identity without requiring them to re-enter their credentials every time?
  • What is another communication path used for provisioning operations with Active Directory?
  • How does the Identity Security Cloud help save time for organizations?
  • What does the term 'certification due' refer to?
  • Which rule type is essential for identity attribute management?
  • What is the configuration required for lifecycle states in IdentityNow?
  • Which command is not recommended for log viewing in the VM?
  • Who is the recipient of the request during the third escalation for a review request?
  • Which options are available for reviewers of Access Requests?
  • How many customizable email templates are available for access requests?
  • What aspect of the VA is managed by the va_agent.log?
  • Which of the following is NOT supported for pass-through authentication in IdentityNow?
  • What handles API gateway interactions in IdentityNow?
  • What is the certification status for users without a manager?
  • What is the purpose of using a refresh token?
  • Where can one find the API documentation for IdentityNow?
  • In the context of identity security, why is role-based access important?
  • In the context of governance, who can make decisions within a Governance Group?
  • Which role is responsible for creating and managing sources and access profiles?
  • Which of the following is NOT a component that a user can request in an Access Request?
  • Where is the ccg.log file located?
  • What are the three ways to obtain VA health information?
  • How long is the validity period of a PAT-generated token?
  • What framework does building out the Identity Security Cloud create for organizations?
  • Which of the following statements is true regarding deploying rules in SailPoint?
  • Are cloud rule callouts permitted in SailPoint?
  • What happens after the IdP verifies the user's identity in the Federated Identity process?
  • What is the basis for defining group identities?
  • In identity security, what is a primary focus for the Engineering department?
  • What is one primary reason for implementing multiple clusters in a network?
  • Where is the key for zero knowledge encryption generated?
  • In the encryption framework, what does 'zero knowledge' indicate?
  • What is the default behavior for revocation actions on sources with a direct connection?
  • What is a potential risk of creating too many identity profiles?
  • What is the command used to start the toolbox?
  • What advantage does a federated identity provide in terms of logins?
  • What command would you use to retrieve the latest 'Networking check' from charon.log?
  • Are federated identity and Single Sign-On (SSO) considered synonymous?
  • Which identity profile should be prioritized?
  • Which statement accurately describes the role of cloud executed rules?
  • Which layer allows for web access to the JDBC database?
  • How is processing power shared in a multi-tenant architecture?
  • How do roles function within the context of identity profiles?
  • Which encryption methods are used between a browser and the Virtual Appliance?
  • Should Identity Profiles be configured after aggregation?
  • How can lifecycle state changes be initiated?
  • What does an HTTP 202 response code indicate?
  • What does the canal.log file serve as?
  • What is the role of cloud executed rules in SailPoint?
  • What does authentication define?
  • How are Segregation of Duties (SoD) policies created in IDNow?
  • Which of the following components is NOT part of the Four Access Model?
  • What do OAuth 2 flows primarily focus on regarding token management?
  • What is the encryption method used for storage encryption?
  • What is a birthright access model defined by?
  • What is the preferred rules modularity setting in the discussed framework?
  • What is the primary purpose of Attribute Synchronization?
  • What is the function of an Identity Provider in Federated Identity?
  • What is the primary function of an event trigger in SailPoint?
  • What can data controls in MySailPoint allow users to manage?
  • Which application type does SailPoint for ServiceDesk specifically cater to?
  • Where is SSO configured in an Identity Profile?
  • When a role is assigned, what happens to existing access for that user?
  • What is the purpose of the authorization code grant type in OAuth 2?
  • Which user types are allowed to create a certification campaign?
  • In a certification campaign, who are the users without a manager reassigned to?
  • What authentication types are available for event triggers in SailPoint?
  • In the context of microservices, what does autoscaling mainly help with?
  • What is the primary purpose of OAuth 2 token request URL/endpoint?
  • What must be included in the JDBC source configuration for entitlement aggregation?
  • What occurs during the data re-aggregation process during verification?
  • What is a primary characteristic of connector rules?
  • Which feature allows for synchronization operations within the Task Processing Engine?
  • What form of encryption ensures secure communication between client and server?
  • Which method is used in IdentityNow for token exchange during the Authorization Code Flow?
  • What is a characteristic of the ccg.log file?
  • What is one of the key features of Active Directory Source?
  • Which of the following attributes can be used in search queries to return user information?
  • Which of the following terms indicates that a certification process needs to be completed shortly?
  • What is the old and new Linux OS used in the VA?
  • Which grant flow does not involve user interaction for obtaining a JWT access_token?
  • What is the order of hierarchy from lowest to highest regarding entitlements, access profiles, and roles?
  • What benefit does the Identity Security Cloud provide to organizations?
  • What is an access profile?
  • Which of the following is a supported identity management system?
  • What does the status of 'active' indicate in a certification campaign?
  • What is a significant advantage of having all VAs running?
  • Where can you view the original data aggregated from a source system?
  • Is any configuration needed in the admin UI to use Pass-Through Authentication (PTA)?
  • Which of the following tests can be performed using the VA toolbox?
  • How do clients use the Authorization Code Flow in IdentityNow?
  • Which OAuth grant type is primarily used for system-to-system integration?
  • When is a certification document sent to reviewers?
  • What is typically encompassed by access profiles in relation to entitlements?
  • What role does the public key play in the encryption process as described?
  • What is the primary difference between Federated Identity and Single Sign-On (SSO)?
  • What is the first step in creating Segregation of Duties (SoD) policies?
  • What does it indicate when a certification campaign is activated?
  • What is the purpose of a governance group in relation to access requests?
  • What is true about the general purpose of the relay.log?
  • Which connector is NOT a part of SailPoint for ServiceNow integrations?
  • Who is responsible for managing certification campaigns?
  • What is the main purpose of account and entitlement aggregation?
  • Which group may be considered a role owner in the access request approval process?
  • What is the location for configuring access requests in the system?
  • Who is usually the first to receive an escalated review request?
  • Is it necessary to manually configure actions for revocation on direct connections?
  • Which authentication type involves using Kerberos?
  • What is the first step in implementing an event trigger?
  • What is a secondary communication path for read operations in SailPoint?
  • What occurs when accounts are deleted from an authoritative source in IDNow?
  • Which of the following is a valid production tenant URL?
  • Which components are combined into a federated identity?
  • What functionality does the SailPoint Identity Governance Connector for ServiceNow provide?
  • What is false regarding the review process for deploying cloud executed rules?
  • What is one of the key responsibilities of an approver in the governance structure?
  • What does the campaign pre-generation notification signify?
  • What is the primary purpose of the SailPoint for Service Catalog integration?
  • What does the term 'OAuth' refer to in the context of identity management?
  • What is the primary reason for configuring TLS on the Virtual Appliance (VA)?
  • Which of the following roles is able to create, manage, and edit roles within the ISC?
  • Which of the following decisions does the fairness algorithm assist with?
  • What is the method for adjusting the escalation and reminder pattern for access requests?
  • How many sources can be referenced in a single Access Profile?
  • Is it true that Connector Rules can utilize contextual information?
  • What distinguishes the "post-termination" state from the "terminated" state?
  • Which authentication method allows end users to access IdNow?
  • What is the quick method to acquire a token for testing purposes?
  • What is one of the potential communication paths between SailPoint and Active Directory?
  • What is the main purpose of autoscaling in microservices?
  • What happens if data in IDNow is different from the source when attribute sync flow is enabled?
  • What is an identity management system that integrates with various web services?
  • What is the default authentication method used in IDNow?
  • Which vanity URL directs to partner019.identitynow.com?
  • Which of the following is a requirement for JDBC integration?
  • Which of the following is NOT one of the first five steps for installing a VA?
  • What defines whether user identities can have access items in SoD policies?
  • Which statement about uncorrelated accounts is true regarding certification authority?
  • What is true about deprovisioning entitlements?
  • What type of IP address may be set during the installation process of the VA?
  • Which log file is designated for password intercept or PWI proxy operations?
  • Which of the following is a disadvantage of the all VAs running configuration?
  • What type of accounts might be included in search-based certification campaign options?
  • Which methods are most commonly utilized in API requests?
  • Which state is not typically classified under lifecycle states?
  • What is the primary function of the subscription method in policy automation?
  • How would you characterize the relationship between loosely coupled microservices?
  • What does the SoD Policy require regarding access lists?
  • What is the purpose of ensuring enough VAs are running in a High Availability deployment?
  • Which log file would you check for general logging purposes?
  • What is the main log file to reference first when troubleshooting the VA?
  • Which aspect of microservices allows their capabilities to be customized and transformed efficiently?
  • What is typically involved in the deprovisioning process?
  • Why is it necessary to determine if an event trigger exists for a use case?
  • Which of the following is a type of event trigger used by SailPoint?
  • What can be modified in an email template through the UI?
  • What does the HTTP 340 response code signify?
  • Which element is crucial for a well-formed search query?
  • What is the relevance of access items in search-based certification campaigns?
  • When are provisioning plans executed?
  • What level of access do regular users have in the Identity Security Console (ISC)?
  • What does the Create Account definition specify?
  • Which log is responsible for sending VA and CCG logs to SailPoint?
  • What should be done if an account requires changes that cannot be automated?
  • Which step follows the creation of a source during the identity model implementation process?
  • What is the primary function of the fairness algorithm in tenant processing determination?
  • What is the purpose of internal documentation links in certification email templates?
  • What can a HelpDesk user do within the ISC framework?
  • What does “Resource Forest Topology Exchange Management” in an Active Directory Source entail?
  • Which of the following best describes an entitlement?
  • What type of activity can be audited through Search auditing?
  • In what situation would a scheduled or polling approach be used?
  • What is the primary objective of Identity Security Cloud in regards to identities?
  • What happens to other governance group members after one approves or denies an access request?
  • Who can serve as an approver in SailPoint's governance process?
  • What is true about attribute sync direction between IDNow and a source?
  • What is one role of SailPoint's integrations with ServiceNow?
  • What is a key control feature of MySailPoint?
  • What is the main purpose of certifications within identity security?
  • Which of the following is NOT a supported connector rule type?
  • How many Identity Profiles can be associated with each data source?
  • Where can identity exceptions be found in the user interface?
  • What is an example of missing elements in valid search syntax?
  • What is the purpose of forms in workflows?
  • Under what conditions can personal access tokens be used?
  • Which statement reflects the essence of REST API communication?
  • What capabilities do REST APIs provide in microservices architecture?
  • What is the initial username to log into the VA after installation?
  • What is the outcome when access removal is triggered by unmet role membership requirements?
  • Which security standard is used to create access tokens that assert various claims?
  • What is a common characteristic of multiple identity profiles?
  • What group is responsible for configured approvals in access requests?
  • Which type of rules can be categorized under SailPoint?
  • In a disaster recovery strategy, what is ensured by deploying VAs in more than one location?
  • Which of the following represents the four states of a VA within the admin UI?
  • Which rule is specifically for building maps in JDBC?
  • What is the VA to VM ratio recommended for configuration?
  • How can original data from a source system be viewed?
  • What is a true statement regarding manual account changes by a system administrator?
  • Which type of operations are Not supported in a transform?
  • Which rule type is designated for transforming data before account provisioning?
  • What is the ultimate goal of an identity security program?
  • What is the purpose of a certification due reminder?
  • How does a user’s role affect their entitlement access?
  • Which of the following event trigger types mandates a response?
  • What types of information are read from a source while aggregating?
  • What does an identity exception indicate in the identity management process?
  • How does SailPoint ensure privacy for customer data?
  • What is one of the main functions of the IDNow Cloud services?
  • What happens if reviewers do not complete their reviews within the specified time frame?
  • What is the generic name for event triggers in SailPoint?
  • Which of the following is described as a supported identity management system?
  • What does authorization define?
  • How do connector rules typically function within SailPoint?
  • Which condition is necessary for an identity to be automatically set to active?
  • OpenLdap is classified as what type of system?
  • Which of the following is NOT a component of IDN Cloud services?
  • What are the authentication options available for end users?
  • What feature is not typically associated with the JDBC connector?
  • What actions are triggered when entering the "Leaver" state?
  • Which of the following OAuth 2 grant types is primarily used for server-to-server communication?
  • What is an identity profile primarily used for?
  • Which model does IdentityNow's v3 REST APIs utilize for authorization?
  • What is the significance of defining fallback states?
  • Where can you download the *.yaml file required for the VA?
  • What is necessary to configure the JDBC connector for functionality?
  • What is the method used to automatically run a policy?
  • Which of the following best describes the deployment strategy for microservices?
  • What does the term 'tightly integrated' refer to in relation to microservices?
  • What is the API endpoint used for accessing the Access Request Configuration?
  • What is the first step in utilizing IdentityNow REST APIs?
  • After the VA is installed, what is the first action to take before regular use?
  • During which phase does the generation of a certification campaign occur?
  • When is the SoD Policy appropriate in a payroll system?
  • What is the first step in the Federated Identity process?
  • Which are the three main OAuth 2 grant types used in IdentityNow?
  • Which types of integration are possible with ServiceNow?
  • Which type of access removal is associated with user inactivity?
  • What is the default preference for accomplishing tasks in SailPoint?
  • What is meant by certification reassignment?
  • Does the schema include mappings in each Identity Profile?
  • What is the primary responsibility of a Certification Administrator?
  • Which tool is necessary for connecting sources to the VA?
  • What authentication methods were allowed with older OAuth 2 APIs?
  • Which of the following systems is recognized as a supported identity management system by SailPoint?
  • What information is typically included in email templates for a certification campaign?
  • Which type of source is indicated by "Direct Sources" under categories of connectors?
  • Can an access profile group entitlements from multiple sources?
  • Which encryption services does IDNow utilize to ensure customer data privacy?
  • In the context of IdentityNow, what is the role of the API gateway?
  • Can identities have both SoD and general policy permissions simultaneously?
  • Where is the authentication method typically configured?
  • Which aspect is NOT typically a part of the details included in certification campaign emails?
  • Under what condition will a VA cluster be upgraded?
  • What is the primary advantage of Standby Reactive HA?
  • Can lifecycle state transitions be designed to trigger provisioning or deprovisioning actions?
  • What type of operations does SailPoint's Identity Governance Connector for ServiceNow support?
  • What type of encryption is used for client and server communication?
  • Which rule processes can be utilized by JDBC?
  • What does the relay.log primarily capture in relation to SailPoint?
  • Which encryption method is used for transport connection encryption?
  • How is the ServiceNow connectivity described in terms of its complexity?
  • Can any attribute from a source Create Account Definition be used for Attribute Sync?
  • What is the purpose of segments in Access Requests?
  • What is the purpose of the VA toolbox?
  • What is an immediate action of the "terminated" state?
  • What is required for automation with policy detection?
  • What characterizes filter-based campaign options?
  • What does the ccg.log file primarily relate to on the VA?
  • Which encryption method is utilized for browser form handoff encryption?
  • What is the significance of using HTTP and HTTPS in REST APIs?
  • What statement about Connector Rules' access to the ISC data model is accurate?
  • In Active Directory configuration, what can service accounts have?
  • What are two disadvantages of Standby Reactive HA configuration?
  • Are SoD policies able to stop unauthorized actions from happening?
  • Can a certifier alter their decision after signing off on a certification?
  • Which type of rule can be triggered before the provisioning of an account?
  • Where do you go to enable debugging for the Virtual Appliance?
  • What type of encryption is employed by Sailpoint Zero Knowledge in the Virtual Appliance?
  • Which of the following is NOT a type of customizable email template for access requests?
  • In the context of identity security, which of the following defines how access is granted?
  • What is another term for the 'heartbeat' status of a VA?
  • How can you set the PTA configuration for sign-in methods?
  • Which type of SoD policies can confirm the detection of issues?
  • What capabilities does SailPoint for ServiceDesk offer?
  • What does the status “Connected” indicate in the context of the system?
  • What is the first step in implementing an identity model for a given HR Source?
  • How does the nature of the HR system impact lifecycle management design?
  • Which of the following is NOT a type of authentication mentioned?
  • Which items are editable in a role's configuration?
  • Which of the following rules can be used in SAP HR provisioning?
  • What is one of the advantages of deploying a VA in High Availability (HA) and Disaster Recovery (DR) patterns?
  • What determines the passphrase of a zero knowledge encryption key pair in a cluster?
  • What happens during a certification review when Entitlement A is revoked?
  • What are personal access token credentials comprised of?
  • Which report shows the status and results of a certification campaign?
  • What is the main log you should check first on the VA?
  • When enhancing communication around entitlements, what is recommended?
  • In what sequence should account adjustments and entitlement adjustments be done for effective identity management?
  • Which of these is NOT a grant type in OAuth 2?
  • What component is part of the AD Connector Architecture?
  • When do Certification Reports become available?
  • What is the key feature of the Aggregation Process in identity security?
  • What is the validity period of the OAuth 2.0 token before it needs to be refreshed?
  • Which of the following roles is NOT typically part of a Governance Group?
  • Which REST API requires authentication and a token?
  • What occurs during the first two escalations of a review request?
  • Which component is responsible for defining access profiles within a system?
  • Why are segments used in access requests?
  • Which of the following is NOT a supported identity management system?
  • What syntax issue is present in the incorrect statement "NOT _exists_..."?
  • Which encryption algorithm is NOT mentioned as part of the encryption methods?
  • In the context of IdNow, what does the term 'pass through' refer to?
  • What is crucial for selecting between event-based and scheduled lifecycle management design?
  • How many phases are there in a certification campaign?
  • What distinguishes SoD policies from general policies?
  • Where can you find account mappings in Identity Profiles?
  • Which user profile can view login and user account activity for all identities?
  • What does the alert status indicate for a VA state/status with limited resources?
  • Which of the following roles allows users to assist with application account issues?
  • Where should virtual appliances (VAs) be physically installed for optimal performance?
  • Where is the network configuration file typically located?
  • Which of the following is a potential outcome if an access request review is left incomplete?
  • What is the primary function of feature flags in microservices?
  • What additional capability does the VA toolbox provide beyond pre-installed tools?
  • What typically triggers an escalation in the access review process?
  • How should contractor profiles be defined in relation to employee profiles?
  • Which is NOT a valid tenant URL?
  • Where can you find the identity exceptions in the user interface?
  • What does SSO stand for in the context of authentication?
  • How do SoD policies differ from general policies?
  • Which two entities are primarily involved in Federated Identity?
  • What is the main purpose of a Segregation of Duties policy?
  • What is meant by limiting specific access items?
  • Can a transform call another transform?
  • In what order should aggregation be performed for accounts and entitlements?
  • Who can request access for applications managed by SailPoint through ServiceNow?
  • How is network connectivity checked using the toolbox?
  • Which of the following rule types is applicable for web services before an operation?
  • Is automatic mitigation available upon SoD detection?
  • What is the primary aim of adding relevant business details to entitlement descriptions?
  • What feature allows ServiceNow users to request access for applications managed by SailPoint?
  • Which command can be used to view or edit the network configuration file?
  • What can a Report Admin do within the ISC?
  • During which phases of a certification campaign can reassignment of users take place?
  • What kind of accounts does the Active Directory Source support?
  • What must be included for IdentityNow to create an identity record successfully?
  • What is the primary function of the role in the object model?
  • Which step involves downloading a configuration file during VA installation?
  • Who manages the configuration of roles in relation to access profiles?
  • What are the types of OAuth 2 grant types mentioned?
  • What is the purpose of the General Policy regarding HR data?
  • Are SoD policies considered preventive in nature?
  • What policy applies when no one in the Engineering department should have access to the Accounting System?
  • What type of identity lifecycle transition occurs after Hired?
  • What is the correct format for a valid URL in SailPoint?
  • Which tool is recommended to view logs on the VM?
  • What does correlation help IdentityNow determine?
  • What type of certifications can be reviewed by a governance group?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy