Browse all practice questions for the SailPoint Identity Security Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

SailPoint Identity Security Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which tool is necessary for connecting sources to the VA?
  • How can you set the PTA configuration for sign-in methods?
  • Are SoD policies able to stop unauthorized actions from happening?
  • Which REST API requires authentication and a token?
  • Which statement accurately describes the role of cloud executed rules?
  • What does the alert status indicate for a VA state/status with limited resources?
  • When do Certification Reports become available?
  • What is an identity profile primarily used for?
  • In what order should aggregation be performed for accounts and entitlements?
  • What is the significance of using HTTP and HTTPS in REST APIs?
  • What is meant by limiting specific access items?
  • What are personal access token credentials comprised of?
  • What should be set in the va-config-1395-4702.yaml file to match organizational requirements?
  • Which encryption method is used for transport connection encryption?
  • Which of the following is a disadvantage of the all VAs running configuration?
  • What does the term 'OAuth' refer to in the context of identity management?
  • Which of the following is a potential outcome if an access request review is left incomplete?
  • How many customizable email templates are available for access requests?
  • Which of the following event trigger types mandates a response?
  • Which layer allows for web access to the JDBC database?
  • What type of logs does fluent.log handle?
  • What is one of the main functions of the IDNow Cloud services?
  • What is true about the general purpose of the relay.log?
  • What standard is used for issuing access tokens in IdentityNow?
  • When enhancing communication around entitlements, what is recommended?
  • What is one of the potential communication paths between SailPoint and Active Directory?
  • Which type of access removal is associated with user inactivity?
  • What is the default preference for accomplishing tasks in SailPoint?
  • In the context of identity security, why is role-based access important?
  • What does the campaign pre-generation notification signify?
  • What is the main log you should check first on the VA?
  • How does the Identity Security Cloud help save time for organizations?
  • Should Identity Profiles be configured after aggregation?
  • In Active Directory configuration, what can service accounts have?
  • What is the primary difference between Federated Identity and Single Sign-On (SSO)?
  • What is the primary objective of Identity Security Cloud in regards to identities?
  • What is the primary aim of adding relevant business details to entitlement descriptions?
  • Which of the following systems is recognized as a supported identity management system by SailPoint?
  • What aspect of the VA is managed by the va_agent.log?
  • Which of the following is NOT a supported identity management system?
  • Who is usually the first to receive an escalated review request?
  • Which condition is necessary for an identity to be automatically set to active?
  • How does the nature of the HR system impact lifecycle management design?
  • What characterizes filter-based campaign options?
  • What syntax issue is present in the incorrect statement "NOT _exists_..."?
  • What does the canal.log file serve as?
  • What is the primary function of feature flags in microservices?
  • Which authentication method allows end users to access IdNow?
  • Which log is responsible for sending VA and CCG logs to SailPoint?
  • How many steps are in the Federated Identity process?
  • What is the function of the fallback approver in the access review process?
  • Which of the following rule types is applicable for web services before an operation?
  • Which type of rules can be categorized under SailPoint?
  • What best identifies the concept of "Fire and Forget" as it pertains to event triggers?
  • How would you characterize the relationship between loosely coupled microservices?
  • Who can serve as an approver in SailPoint's governance process?
  • How do clients use the Authorization Code Flow in IdentityNow?
  • Should entitlements be marked as privileged if they provide higher access?
  • Which protocol is deemed industry-standard for creating access tokens asserting various claims?
  • What is the primary responsibility of a Certification Administrator?
  • What is the certification status for users without a manager?
  • What is the generic name for event triggers in SailPoint?
  • What must be included in the JDBC source configuration for entitlement aggregation?
  • In the context of identity security, which of the following defines how access is granted?
  • What occurs during the first two escalations of a review request?
  • During which phases of a certification campaign can reassignment of users take place?
  • Which of the following roles allows users to assist with application account issues?
  • What is an immediate action of the "terminated" state?
  • What happens if reviewers do not complete their reviews within the specified time frame?
  • When is a certification document sent to reviewers?
  • Which model does IdentityNow's v3 REST APIs utilize for authorization?
  • What type of identity lifecycle transition occurs after Hired?
  • Who is responsible for managing certification campaigns?
  • What are two disadvantages of Standby Reactive HA configuration?
  • How do roles function within the context of identity profiles?
  • How can you test a TLS connection from the VA command line?
  • What is the first step in implementing an identity model for a given HR Source?
  • What primary authentication method does IDNow implement by default?
  • Can a transform call another transform?
  • Where is the ccg.log file located?
  • Why are segments used in access requests?
  • What is the quick method to acquire a token for testing purposes?
  • What happens after the IdP verifies the user's identity in the Federated Identity process?
  • Which of the following is NOT a component that a user can request in an Access Request?
  • What is the API endpoint used for accessing the Access Request Configuration?
  • What is one method of augmenting data in a certification campaign?
  • Which step follows the creation of a source during the identity model implementation process?
  • Which aspect of microservices allows their capabilities to be customized and transformed efficiently?
  • When adjusting the reminder settings for access requests, which approach is used?
  • What defines whether user identities can have access items in SoD policies?
  • What action should be taken with entitlements providing access to highly confidential data?
  • What is a significant advantage of having all VAs running?
  • What is the role of va_agent.log?
  • What configuration does Single Sign-On (SSO) use within an Identity Profile?
  • How does SailPoint ensure privacy for customer data?
  • What is the purpose of using a refresh token?
  • What is a potential risk of creating too many identity profiles?
  • Which of the following is a valid production tenant URL?
  • Is it necessary to manually configure actions for revocation on direct connections?
  • What type of certifications can be reviewed by a governance group?
  • What does a Manager Correlation Rule typically manage?
  • Which of the following roles is NOT typically part of a Governance Group?
  • Are cloud rule callouts permitted in SailPoint?
  • Which encryption method is utilized for browser form handoff encryption?
  • What is the initial username to log into the VA after installation?
  • What does correlation help IdentityNow determine?
  • Who can request access for applications managed by SailPoint through ServiceNow?
  • What is the relevance of access items in search-based certification campaigns?
  • How can a user obtain access to resources associated with their role?
  • What type of encryption is used for client and server communication?
  • What is the old and new Linux OS used in the VA?
  • What level of access do regular users have in the Identity Security Console (ISC)?
  • Where can you view the original data aggregated from a source system?
  • Where can aggregated source data be viewed within the ISC?
  • What information is typically included in email templates for a certification campaign?
  • What term refers to the method of verifying a user's identity without requiring them to re-enter their credentials every time?
  • What policy applies when no one in the Engineering department should have access to the Accounting System?
  • Is any configuration needed in the admin UI to use Pass-Through Authentication (PTA)?
  • What is the main goal of a Separation of Duties Policy?
  • What command would you use to retrieve the latest 'Networking check' from charon.log?
  • What is one role of SailPoint's integrations with ServiceNow?
  • What occurs when accounts are deleted from an authoritative source in IDNow?
  • Which command can be used to view or edit the network configuration file?
  • What does authentication define?
  • Is account aggregation performed before or after configuring identity profiles?
  • What is the main purpose of certifications within identity security?
  • What is typically encompassed by access profiles in relation to entitlements?
  • Which of the following best describes an entitlement?
  • What is the configuration required for lifecycle states in IdentityNow?
  • Which protocols are commonly used for communication by REST APIs?
  • What kind of accounts does the Active Directory Source support?
  • What is the method for adjusting the escalation and reminder pattern for access requests?
  • During which phase does the generation of a certification campaign occur?
  • What is the validity period of the OAuth 2.0 token before it needs to be refreshed?
  • Is it true that Connector Rules can utilize contextual information?
  • When is a single identity profile preferred in lifecycle design?
  • What does the status 'Connected' signify in a VA?
  • Which encryption services does IDNow utilize to ensure customer data privacy?
  • What actions are triggered when entering the "Leaver" state?
  • What is a birthright access model defined by?
  • What is necessary to configure the JDBC connector for functionality?
  • In identity security, what is a primary focus for the Engineering department?
  • What statement about Connector Rules' access to the ISC data model is accurate?
  • What should be done if an account requires changes that cannot be automated?
  • In what sequence should account adjustments and entitlement adjustments be done for effective identity management?
  • What is the key feature of the Aggregation Process in identity security?
  • When is the SoD Policy appropriate in a payroll system?
  • Which of the following best describes the deployment strategy for microservices?
  • Which of the following would lead to conflicting attribute values?
  • What does the SoD Policy require regarding access lists?
  • What is the primary purpose of Attribute Synchronization?
  • What is the default behavior for revocation actions on sources with a direct connection?
  • What does authorization define?
  • Which of the following terms indicates that a certification process needs to be completed shortly?
  • What functionality does the SailPoint Identity Governance Connector for ServiceNow provide?
  • Which connector category includes Credential Providers?
  • Which of the following is NOT a supported pass-through authentication option?
  • What is the first step in utilizing IdentityNow REST APIs?
  • What advantage does Switch Clusters HA offer?
  • Are uncorrelated accounts considered valid during certifications?
  • What can a HelpDesk user do within the ISC framework?
  • In the encryption framework, what does 'zero knowledge' indicate?
  • What defines the maximum level of access within an organization?
  • What is a characteristic of the ccg.log file?
  • What must be included for IdentityNow to create an identity record successfully?
  • Which encryption methods are used between a browser and the Virtual Appliance?
  • What is the primary function of an event trigger in SailPoint?
  • How is processing power shared in a multi-tenant architecture?
  • Which role is responsible for creating and managing sources and access profiles?
  • Which of the following is NOT supported for pass-through authentication in IdentityNow?
  • What is an example of missing elements in valid search syntax?
  • What additional capability does the VA toolbox provide beyond pre-installed tools?
  • Which items are editable in a role's configuration?
  • What is a disadvantage of Switch Clusters HA configuration?
  • Can identities have both SoD and general policy permissions simultaneously?
  • Which of the following statements is true regarding deploying rules in SailPoint?
  • Which component is responsible for defining access profiles within a system?
  • What can be modified in an email template through the UI?
  • What is a true statement regarding manual account changes by a system administrator?
  • What does SSO stand for in the context of authentication?
  • Where can you find account mappings in Identity Profiles?
  • What feature allows ServiceNow users to request access for applications managed by SailPoint?
  • Which type of source is indicated by "Direct Sources" under categories of connectors?
  • What typically triggers an escalation in the access review process?
  • Which method is used in IdentityNow for token exchange during the Authorization Code Flow?
  • What is the purpose of forms in workflows?
  • Which role in ISC is described as having the highest access privileges?
  • What does it indicate when a certification campaign is activated?
  • What is an access profile?
  • How many sources can be referenced in a single Access Profile?
  • Are federated identity and Single Sign-On (SSO) considered synonymous?
  • What does an identity exception indicate in the identity management process?
  • Which command is not recommended for log viewing in the VM?
  • Under what conditions can personal access tokens be used?
  • What is the main purpose of a Segregation of Duties policy?
  • What are the types of OAuth 2 grant types mentioned?
  • What is the primary reason for configuring TLS on the Virtual Appliance (VA)?
  • Which of the following is described as a supported identity management system?
  • What is the ultimate goal of an identity security program?
  • What lifecycle states are included for a prehire identity?
  • Which are the three main OAuth 2 grant types used in IdentityNow?
  • What is a common characteristic of multiple identity profiles?
  • Can attributes.email be utilized before and after the colon in search queries?
  • What is the primary function of the subscription method in policy automation?
  • What is the outcome when access removal is triggered by unmet role membership requirements?
  • What is one primary reason for implementing multiple clusters in a network?
  • Which is NOT a valid tenant URL?
  • What capabilities do REST APIs provide in microservices architecture?
  • Which tool is recommended to view logs on the VM?
  • Which of the following represents the lifecycle states of an identity?
  • Which step follows the configuration of the target system in event trigger implementation?
  • What is an identity management system that integrates with various web services?
  • Which options are available for reviewers of Access Requests?
  • Which type of SoD policies can confirm the detection of issues?
  • What type of issues does the charon.log file primarily log?
  • What service is associated with the canal.log file on the VA?
  • What is the method used to automatically run a policy?
  • When a role is assigned, what happens to existing access for that user?
  • Are SoD policies considered preventive in nature?
  • What role does the public key play in the encryption process as described?
  • Which encryption algorithm is NOT mentioned as part of the encryption methods?
  • What is the primary purpose of the SailPoint for Service Catalog integration?
  • OpenLdap is classified as what type of system?
  • What type of encryption is employed by Sailpoint Zero Knowledge in the Virtual Appliance?
  • What does the HTTP 340 response code signify?
  • Which types of integration are possible with ServiceNow?
  • Which rule type is essential for identity attribute management?
  • Which of the following represents the four states of a VA within the admin UI?
  • Can an access profile group entitlements from multiple sources?
  • Which type of rule can be triggered before the provisioning of an account?
  • Which two entities are primarily involved in Federated Identity?
  • Where is the authentication method typically configured?
  • What is the location for configuring access requests in the system?
  • Which rule is specifically for building maps in JDBC?
  • What is the first step in creating Segregation of Duties (SoD) policies?
  • What is a secondary communication path for read operations in SailPoint?
  • What is the basis for defining group identities?
  • What is the first step in the Federated Identity process?
  • Which of the following activity types is viewable under the Search > Reports section?
  • What happens during a certification review when Entitlement A is revoked?
  • What best describes the usage of event triggers in SailPoint?
  • What can a Source Administrator do in the ISC platform?
  • What type of operations does SailPoint's Identity Governance Connector for ServiceNow support?
  • What authorization model is utilized with IdNow's v3 REST APIs?
  • Which of the following OAuth 2 grant types is primarily used for server-to-server communication?
  • What occurs when an entitlement already exists in a provisioning plan?
  • What group is responsible for configured approvals in access requests?
  • Which connector is NOT a part of SailPoint for ServiceNow integrations?
  • What is a key control feature of MySailPoint?
  • What must a source have to enable Sub-Admin review certification?
  • Which report shows the status and results of a certification campaign?
  • What is meant by certification reassignment?
  • How does a user’s role affect their entitlement access?
  • Which OAuth grant type is primarily used for system-to-system integration?
  • When should the Joiner process be initiated?
  • What happens to other governance group members after one approves or denies an access request?
  • What is true about attribute sync direction between IDNow and a source?
  • How is the ServiceNow connectivity described in terms of its complexity?
  • Which search query equivalence will return the same search results?
  • What is the purpose of a governance group in relation to access requests?
  • Which rule type is designated for transforming data before account provisioning?
  • Which of the following is NOT a component of IDN Cloud services?
  • Who is the recipient of the request during the third escalation for a review request?
  • How can identity attributes be affected in process flows?
  • What are typical lifecycle states associated with identity management?
  • What is a primary characteristic of connector rules?
  • Can any attribute from a source Create Account Definition be used for Attribute Sync?
  • What framework does building out the Identity Security Cloud create for organizations?
  • What defines the criteria for assigning access in an identity management system?
  • Where can you download the *.yaml file required for the VA?
  • What advantage does a federated identity provide in terms of logins?
  • Which log file is designated for password intercept or PWI proxy operations?
  • Which step involves downloading a configuration file during VA installation?
  • What do OAuth 2 flows primarily focus on regarding token management?
  • For how long does an OAuth 2.0 token remain valid before requiring refresh?
  • What happens to accounts deleted from an authoritative source in IDNow?
  • What is the purpose of the authorization code grant type in OAuth 2?
  • What types of information are read from a source while aggregating?
  • Which group may be considered a role owner in the access request approval process?
  • When are provisioning plans executed?
  • What is the purpose of segments in Access Requests?
  • What is the purpose of ensuring enough VAs are running in a High Availability deployment?
  • What type of token is issued when utilizing JWT in IdentityNow?
  • In the context of IdentityNow, what is the role of the API gateway?
  • What distinguishes SoD policies from general policies?
  • Which state is not typically classified under lifecycle states?
  • What is one of the key features of Active Directory Source?
  • What authentication types are available for event triggers in SailPoint?
  • Which of the following tests can be performed using the VA toolbox?
  • Where can identity exceptions be found in the user interface?
  • Where is the key for zero knowledge encryption generated?
  • Which of the following decisions does the fairness algorithm assist with?
  • What occurs during the data re-aggregation process during verification?
  • Which aspect is NOT typically a part of the details included in certification campaign emails?
  • How is network connectivity checked using the toolbox?
  • What is the role of cloud executed rules in SailPoint?
  • In a connectivity error scenario, which log would be most relevant?
  • What is another communication path used for provisioning operations with Active Directory?
  • Why is it necessary to determine if an event trigger exists for a use case?
  • What determines the passphrase of a zero knowledge encryption key pair in a cluster?
  • Where can you find the identity exceptions in the user interface?
  • Which user profile can view login and user account activity for all identities?
  • What role does automation play in policy detection for SoD policies?
  • What type of accounts might be included in search-based certification campaign options?
  • What is the command used to start the toolbox?
  • What does the term 'certification due' refer to?
  • What does an HTTP 202 response code indicate?
  • Which authentication type involves using Kerberos?
  • Which of the following is NOT a type of customizable email template for access requests?
  • What is NOT a component of Lifecycle State?
  • What is the significance of defining fallback states?
  • Which of these is NOT a grant type in OAuth 2?
  • What does the term 'tightly integrated' refer to in relation to microservices?
  • What is the main function of a refresh token in identity security?
  • Which statement best describes the deployment of microservices?
  • What feature is not typically associated with the JDBC connector?
  • What is true about deprovisioning entitlements?
  • What are the three ways to obtain VA health information?
  • Which of the following rules can be used in SAP HR provisioning?
  • Where is the network configuration file typically located?
  • What is the VA to VM ratio recommended for configuration?
  • What authentication methods were allowed with older OAuth 2 APIs?
  • What does the relay.log primarily capture in relation to SailPoint?
  • What is the order of hierarchy from lowest to highest regarding entitlements, access profiles, and roles?
  • After the VA is installed, what is the first action to take before regular use?
  • What handles API gateway interactions in IdentityNow?
  • Can lifecycle state transitions be designed to trigger provisioning or deprovisioning actions?
  • What happens when a user who has Entitlement A transfers departments and is part of Role B?
  • Which security standard is used to create access tokens that assert various claims?
  • Which of the following roles is able to create, manage, and edit roles within the ISC?
  • Where do you go to enable debugging for the Virtual Appliance?
  • Which application type does SailPoint for ServiceDesk specifically cater to?
  • How many Identity Profiles can be associated with each data source?
  • Which rule processes can be utilized by JDBC?
  • What type of connector is the Active Directory connector categorized as?
  • What is the function of an Identity Provider in Federated Identity?
  • How many phases are there in a certification campaign?
  • What is the primary function of the fairness algorithm in tenant processing determination?
  • What is the default authentication method used in IDNow?
  • What can a Report Admin do within the ISC?
  • Which of the following attributes can be used in search queries to return user information?
  • What is the main purpose of autoscaling in microservices?
  • What is typically involved in the deprovisioning process?
  • What level of access does a regular user possess in ISC?
  • Which methods are most commonly utilized in API requests?
  • What is the purpose of internal documentation links in certification email templates?
  • What is the main log file to reference first when troubleshooting the VA?
  • Does the schema include mappings in each Identity Profile?
  • In the context of SoD policies, what does the term "exclusive access item lists" mean?
  • Which type of operations are Not supported in a transform?
  • How can TLS connection testing be performed?
  • What ensures zero knowledge encryption privacy in SailPoint?
  • What is the purpose of the VA toolbox?
  • What is the correct format for a valid URL in SailPoint?
  • What occurs when a user's lifecycle changes to inactive regarding Entitlement A?
  • What is the primary advantage of Standby Reactive HA?
  • Which of the following is NOT a type of authentication mentioned?
  • What is required for automation with policy detection?
  • What are the authentication options available for end users?
  • In the context of IdNow, what does the term 'pass through' refer to?
  • What term describes the process of granting access to users in an organization?
  • Under what condition will a VA cluster be upgraded?
  • What type of activity can be audited through Search auditing?
  • What is the purpose of the General Policy regarding HR data?
  • Which feature allows for synchronization operations within the Task Processing Engine?
  • What benefit does the Identity Security Cloud provide to organizations?
  • Which of the following is a type of event trigger used by SailPoint?
  • Which element is crucial for a well-formed search query?
  • What is the first step in implementing an event trigger?
  • How should contractor profiles be defined in relation to employee profiles?
  • What type of rule can directly call a transform?
  • What is another term for the 'heartbeat' status of a VA?
  • How do SoD policies differ from general policies?
  • In a disaster recovery strategy, what is ensured by deploying VAs in more than one location?
  • In a certification campaign, who are the users without a manager reassigned to?
  • Can a rule call another rule directly?
  • What does the status of 'active' indicate in a certification campaign?
  • What type of IP address may be set during the installation process of the VA?
  • What does the Create Account definition specify?
  • Which user types are allowed to create a certification campaign?
  • What is the primary purpose of OAuth 2 token request URL/endpoint?
  • What component is part of the AD Connector Architecture?
  • What does the status “Connected” indicate in the context of the system?
  • Who manages the configuration of roles in relation to access profiles?
  • Which of the following is a supported identity management system?
  • Can a certifier alter their decision after signing off on a certification?
  • What is the main purpose of account and entitlement aggregation?
  • How do connector rules typically function within SailPoint?
  • What form of encryption ensures secure communication between client and server?
  • Which of the following is a requirement for JDBC integration?
  • Is automatic mitigation available upon SoD detection?
  • What can data controls in MySailPoint allow users to manage?
  • What happens if data in IDNow is different from the source when attribute sync flow is enabled?
  • In the context of governance, who can make decisions within a Governance Group?
  • Which of the following components is NOT part of the Four Access Model?
  • Which statement about uncorrelated accounts is true regarding certification authority?
  • What is false regarding the review process for deploying cloud executed rules?
  • What is the purpose of a certification due reminder?
  • Where should virtual appliances (VAs) be physically installed for optimal performance?
  • What does the term “advanced” refer to in the context of ServiceNow connectivity?
  • Which identity profile should be prioritized?
  • Which of the following is NOT a supported connector rule type?
  • What command is used to disable the service for cloud VA deployment?
  • What is one of the key responsibilities of an approver in the governance structure?
  • How are Segregation of Duties (SoD) policies created in IDNow?
  • What is the method for storing a 2048-bit private RSA key?
  • What distinguishes the "post-termination" state from the "terminated" state?
  • Which of the following is NOT one of the first five steps for installing a VA?
  • What is one of the advantages of deploying a VA in High Availability (HA) and Disaster Recovery (DR) patterns?
  • What is crucial for selecting between event-based and scheduled lifecycle management design?
  • How many high availability (HA) or disaster recovery (DR) scenarios are detailed in best practices?
  • How can original data from a source system be viewed?
  • Which of the following statements is true regarding the lifecycle state changes?
  • How can lifecycle state changes be initiated?
  • In the context of microservices, what does autoscaling mainly help with?
  • What is the preferred rules modularity setting in the discussed framework?
  • What role does 'Manager' play in filter-based campaign options?
  • What type of data can be controlled by users in MySailPoint?
  • What capabilities does SailPoint for ServiceDesk offer?
  • What does “Resource Forest Topology Exchange Management” in an Active Directory Source entail?
  • What does the ccg.log file primarily relate to on the VA?
  • What is the encryption method used for storage encryption?
  • Which of the following identity management systems is NOT supported for PTA in IdNow?
  • In what situation would a scheduled or polling approach be used?
  • What is the primary function of the role in the object model?
  • What aspect of Identity Security is emphasized through certifications?
  • Where is SSO configured in an Identity Profile?
  • Which components are combined into a federated identity?
  • Where can one find the API documentation for IdentityNow?
  • How long is the validity period of a PAT-generated token?
  • Which log file would you check for general logging purposes?
  • Which vanity URL directs to partner019.identitynow.com?
  • Which grant flow does not involve user interaction for obtaining a JWT access_token?
  • Which statement reflects the essence of REST API communication?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy