SailPoint Certified Identity Security Administrator Questions and Answers
Reference the following search query:
created:[now-24h TO now] AND (@access(displayName:New_Hire_Access) OR @access(source.name:Acme_HRMS)) AND @entitlements(name:Manager_Access)
Is this statement true about the search query above?
Proposed Solution / Statement:
Removing the AND @entitlements(name:Manager_Access) from the query makes it valid, returning users who were created within the last 24 hours and either have access to the source Acme_HRMS or have the New_Hire_Access access profile assigned.
Does this proposed solution meet the requirement / solve the scenario?
Below are the requirements for configuring user provisioning in an organization's Finance department.
Contractors in the organization MUST NOT be auto-provisioned with the default Office 365 license, as contractors in departments other than Finance have different license requirements.
Every Finance department user — whether employee or contractor — must be assigned one Office 365 E3 license.
No Finance employee or contractor should be provisioned more than one type of Office 365 license.
Is this a valid approach for the Identity Security Administrator to provide the necessary access?
Proposed Solution / Statement:
Create an ISC Role with membership criteria that includes all Finance department users and associate the Office 365 E3 license entitlement with the role. This ensures Finance department users receive E3 license access automatically.
Does this proposed solution meet the requirement / solve the scenario?
The security team has asked for a technical briefing on how authentication works with SailPoint.
Does the following statement correctly describe authentication methods in SailPoint and industry standards?
Proposed Solution / Statement:
When configuring SAML authentication in SailPoint, the Entity ID must exactly match the SAML metadata EntityID supplied by the identity provider for successful federation.
Does this proposed solution meet the requirement / solve the scenario?
Users are complaining that they would like to request access to groups that have recently been added to the Corporate Directory system, but they are unable to see them. The system feature Enable Entitlement Requests has been enabled and access request segments have not been enabled.
Is this a valid step to debug the problem?
Proposed Solution / Statement:
Open the source configuration and navigate to the Access Profiles page to check if the group is included in it and thus hidden by any Access Profile.
Does this proposed solution meet the requirement / solve the scenario?
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"Separation of duties can be enforced using rules that can be configured in the system. These rules look for forbidden combinations of access owned by a single user. The rules can be used in a detective way, meaning actively searching for these forbidden combinations, or a preventative way, meaning that an extra validation step is made when a change in user access is requested."
Does this proposed solution meet the requirement / solve the scenario?
Does this statement correctly describe a function of the Virtual Appliance (VA)?
Proposed Solution / Statement:
The VAs initiate communication to the VA cluster queue in the Identity Security Cloud tenant.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about sources?
Proposed Solution / Statement:
A source contains its own set of user accounts.
Does this proposed solution meet the requirement / solve the scenario?
Is the following a valid configuration item for the identity profile's sign-in and security settings?
Proposed Solution / Statement:
If Multifactor Authentication is configured, the users of the Identity Profile must provide proof of their identity in two ways before they are allowed to unlock their account or reset their password.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario where a Separation of Duties policy should be used?
Proposed Solution / Statement:
A user requests a major system configuration and approves the change.
Does this proposed solution meet the requirement / solve the scenario?
Match each one of the following examples with the appropriate term.

Is this a valid scenario for reviewing access requests in the approval management page?
Proposed Solution / Statement:
It is possible for an administrator to supersede an approver's cancellation of a request.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Administrator notices that a Virtual Appliance (VA) is no longer communicating with Identity Security Cloud.
Is this an appropriate step to take to troubleshoot the issue?
Proposed Solution / Statement:
Test the connection with the VPN enabled and disabled to exclude it as the root cause of the issue.
Does this proposed solution meet the requirement / solve the scenario?
On 4 February 2021, the following error occurred on source Control Central of type Active Directory for identity Clarence.Harper:
Failed to update attributes. There is no such object on the server.
Is this a valid place to look for more information about what caused the error?
Proposed Solution / Statement:
Search for the error message on SailPoint Compass or the SailPoint Developer Forums. Check for previous discussions or whitepapers.
Does this proposed solution meet the requirement / solve the scenario?
A certification campaign was created for manager review. However, the user's certification campaign was assigned to an admin instead of their manager.
Is this a valid reason for why the campaign could have been reassigned?
Proposed Solution / Statement:
User does not have a manager assigned from HR.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement regarding access management valid?
Proposed Solution / Statement:
A reviewer can be required to provide a comment when rejecting a role request.
Does this proposed solution meet the requirement / solve the scenario?
Does the following event trigger the de-provisioning of a user's access?
Proposed Solution / Statement:
The department of a user changes, and the new department does not have access to an application that was previously assigned.
Does this proposed solution meet the requirement / solve the scenario?
Test connection for the Active Directory source fails when Transport Layer Security (TLS) is on:
java.lang.Exception: [s0100] Failed to connect to server ...
PKIX path validation failed
sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Is this a valid step towards analyzing and resolving this issue?
Proposed Solution / Statement:
Ensure that the correct AD certificate has been imported in the VA certificates folder.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding authentication and authorization?
Proposed Solution / Statement:
Multi-Factor Authentication requires a user to provide 2 or more forms of verification.
Does this proposed solution meet the requirement / solve the scenario?
As part of the organization's update to its access request approval and notification process, does the following statement accurately reflect the global reminder and escalation policy?
Proposed Solution / Statement:
For governance groups, access requests will be sent only to the manager of an active member.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding different account aggregation types true?
Proposed Solution / Statement:
Disabling optimization during aggregation forces the system to process all accounts.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding the objects that represent access of systems managed by Identity Security Cloud?
Proposed Solution / Statement:
When criteria for automatic assignment of a Role are set to Identity List, the names of identities to include can be specified using wildcards, for example "John*".
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding access request approval processes?
Proposed Solution / Statement:
A governance group should have members before using it in the approval process to ensure that it can be approved.
Does this proposed solution meet the requirement / solve the scenario?
Review the following log entry:
[
{
"id": "2c9180866166b5b0016167c32ef31a66",
"name": "acme AD-TX Cluster",
"description": "acme AD - TX Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": null
},
{
"id": "2c9180846a93ce60016ab29f039944de",
"name": "acme AD-NY Cluster",
"description": "acme AD-NY Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": {
"clientId": null,
"durationMinutes": 60,
"expiration": "2025-12-15T19:13:36.079Z",
"rootLevel": "TRACE",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "TRACE"
}
}
}
]
A source owner for Active Directory has found problems with aggregation and has requested log files for their source.
Is this a valid way for the Administrator to assist in retrieving the correct logs?
Proposed Solution / Statement:
The Admin can set the log level using the following REST API call and JSON request body:
PUT /v2025/managed-clusters/2c9180866166b5b0016167c32ef31a66/log-config
{
"durationMinutes": 365,
"rootLevel": "DEBUG",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "DEBUG"
}
}
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement true about the characteristics of different connector types in Identity Security Cloud (ISC)?
Proposed Solution / Statement:
Active Directory (AD) connectors can handle both authentication and identity lifecycle management, including user provisioning.
Does this proposed solution meet the requirement / solve the scenario?
Is this authentication method description correct?
Proposed Solution / Statement:
Certificate-based authentication can be used to verify users and devices.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding account deletion in Identity Security Cloud true?
Proposed Solution / Statement:
Once an account is deleted during aggregation, it cannot be re-aggregated or recreated in Identity Security Cloud.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about common authentication methods?
Proposed Solution / Statement:
The Identity Provider and Service Provider in a SAML setup trust each other based on public keys that have been exchanged as part of the configuration.
Does this proposed solution meet the requirement / solve the scenario?
Review the following log entry:
[
{
"id": "2c9180866166b5b0016167c32ef31a66",
"name": "acme AD-TX Cluster",
"description": "acme AD - TX Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": null
},
{
"id": "2c9180846a93ce60016ab29f039944de",
"name": "acme AD-NY Cluster",
"description": "acme AD-NY Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": {
"clientId": null,
"durationMinutes": 60,
"expiration": "2025-12-15T19:13:36.079Z",
"rootLevel": "TRACE",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "TRACE"
}
}
}
]
A source owner for Active Directory has found problems with aggregation and has requested log files for their source.
Is this a valid way for the Administrator to assist in retrieving the correct logs?
Proposed Solution / Statement:
The following REST API call can be used to collect and export logs from the acme AD-NY Cluster:
GET
Does this proposed solution meet the requirement / solve the scenario?
Given the following scenario, is this a suitable option for performing a certification campaign?
A company wants to have managers certify all access of their subordinates that have any privileged access.
Proposed Solution / Statement:
Create a search-based certification for Access Items.
Use the option All Access Items Returned by a Query.
Use the query privileged:true and add all access items and related identities to the campaign.
Let the reviewer be the manager.
Does this proposed solution meet the requirement / solve the scenario?
