SailPoint Certified IdentityIQ Engineer Questions and Answers
An engineer is assigned to configure an account attribute. The requirements are:
Purpose: Flag privileged accounts
Read from: Financial application, privileged attribute
Calculate from: Keystore application, responsibility-code attribute
Usage 1: Display as option in Advanced Analytics
Usage 2: Use when writing rules
Usage 3: Include in policies
Does the engineer need to set this configuration option on the account attribute to meet the requirements?
Proposed Solution:
Multi-Valued
Is this statement true about identitylQ ' s syslog event storage?
Solution: Both logging and auditing can have a negative influence on performance. Logging and auditing both require extra function calls within The application and will generate data that will need to be stored.
An engineer needs to trigger a workflow when a Division attribute changes from IT to Senior IT, but only when the user is a manager.
Is this a valid process that the engineer could use to launch a workflow for a lifecycle event?
Proposed Solution:
Create a trigger with an event type of attribute change on the managerStatus attribute with the previous value of true and the new value of false, and add an included identities rule for when the user ' s division attribute had a previous value of IT and a new value of Senior IT.
The engineer is analyzing on a workflow Transition.

The following variable values are known:
Will the workflow continue to this step?
Solution: Approve
An engineer is assigned to configure an account attribute. The requirements are:
Purpose: Flag privileged accounts
Read from: Financial application, privileged attribute
Calculate from: Keystore application, responsibility-code attribute
Usage 1: Display as option in Advanced Analytics
Usage 2: Use when writing rules
Usage 3: Include in policies
Does the engineer need to set this configuration option on the account attribute to meet the requirements?
Proposed Solution:
Attribute Type: boolean
An engineer needs to first create a custom audit event and then set up an associated report.
What are four steps to accomplish this goal?
Proposed Solution:
From the Intelligence > Reports page, configure and schedule the newly-created report.
A customer wants to make changes in their IdentitylQ user interface. Consider branding and other IdentitylQ Ul changes. Is this statement valid?
Solution: Primary and secondary colors are set through the IdentitylQ Configuration > Miscellaneous page.
Is this statement true about certifications?
Solution: The staging period is required.
The engineer uses the sailpoint.api.IdentityService in a BeanShell method to look up and return all account names for an identity on the application ' MagicBox ' . Is this a correct implementation?
Proposed Solution:
import sailpoint.api.IdentityService;
import sailpoint.api.SailPointContext;
import sailpoint.object.Identity;
import sailpoint.object.Link;
import sailpoint.tools.GeneralException;
public List getAccountNames(SailPointContext context, Identity identity) throws GeneralException {
IdentityService service = new IdentityService(context);
List < String > accountNames = new ArrayList < String > ();
Link link = service.getLink(identity, " MagicBox " );
while (link != null) {
accountNames.add(link.getNativeIdentity());
}
return accountNames;
}
For a user who wants to be able to unlock an account for a subordinate or themselves through Manage Accounts, does this configuration need to be performed in Lifecycle Manager (LCM)?
Proposed Solution:
Select " Allow managing existing accounts " in the Manage Accounts QuickLink configuration for the user ' s QuickLink population.
Assuming that the policy violation owner has the necessary permissions, is this a valid option for the policy violation owner to use when acting on a policy violation of type ' Account Policy ' ?
Proposed Solution:
Allow
Is this a question that an engineer should ask the customer when initially setting up a new IdentitylQ test environment?
Solution: Does the customer need a deployment accelerator? "
Can this action be performed as part of configuring an application definition in IdentityIQ?
Proposed Solution:
Designate that the values of an account attribute should be represented in the Entitlement Catalog, by marking the attribute as " managed " .
Is the following statement true about out-of-the-box reporting?
Proposed Solution:
All out-of-the-box reports in IdentityIQ are stored as TaskDefinition objects.
Is the following statement about IdentityIQ rule inputs and outputs correct?
Proposed Solution:
The default description of a Rule, which originates from the Rule Registry, usually provides information about the Rule ' s purpose and its expected output.
A customer wants to make changes in their IdentitylQ user interface. Consider branding and other IdentitylQ Ul changes. Is this statement valid?
Solution: Text on the login page is set through message keys in the message catalog.
Can a Workgroup be used for the following scenario?
Solution: Providing a group of users with specific capabilities.
Is this a purpose of an IdentityIQ certification?
Proposed Solution:
to ensure SailPoint is in compliance with the ISO 9001 government regulation
Can the following be achieved via configuration of control variables in the out-of-the-box Lifecycle Manager (LCM) workflows?
Proposed Solution:
Specify which applications support password change requests through the IdentityIQ user interface.
Is the following statement true?
Proposed Solution:
All ManagedAttribute objects must be associated to an Application object.
Can the search type in Identity be used to accomplish this result?
Proposed Solution:
Identifying the number of certifications that are currently in the revocation phase
Is the following statement about IdentitylQ rule inputs and outputs correct?
Solution: A BeanShell rule in IdentitylQ must always return an object derived from the abstract class sailpoint.object.saiipointobject.
Is the following a true statement about IdentitylQ authentication and authorization?
Solution: What users can see and do in IdentitylQ can be party controlled by their authorized scope.
Can the following be achieved via configuration of control variables in the out-of-the-box Lifecycle Manager (LCM) workflows?
Solution: Disable all notifications.
Is the following a true statement about IdentityIQ authentication and authorization?
Proposed Solution:
An Identity can be a member of, at most, one QuickLink population.
Is this statement true about identitylQ ' s syslog event storage?
Solution: To improve security, items logged through syslog are unable to be sent to Log4j.
Can the Provisioning tab under " Administrator Console " be used to do the following task?
Proposed Solution:
View the connection status of the application the provisioning status is associated to.
Is this configuration option required when an engineer sets up a SCIM 2.0 application?
Solution: Name
The engineer uses the sailpoint.api.IdentityService in a BeanShell method to look up and return all account names for an identity on the application ' MagicBox ' . Is this a correct implementation?
Proposed Solution:
import sailpoint.api.IdentityService;
import sailpoint.api.SailPointContext;
import sailpoint.object.Application;
import sailpoint.object.Identity;
import sailpoint.object.Link;
import sailpoint.tools.GeneralException;
public List getAccountNames(SailPointContext context, Identity identity) throws GeneralException {
Application application = context.getObjectByName(Application.class, " MagicBox " );
IdentityService service = new IdentityService(context);
List < String > accountNames = new ArrayList < String > ();
List < Link > links = service.getLinks(identity, application);
if (links != null) {
for (Link link : links) {
accountNames.add(link.getNativeIdentity());
}
}
return accountNames;
}
Can the following IdentitylQ object be extended to store client-specific data by updating the corresponding .HBM file?
Solution: Link
Is this a piece of information that an engineer needs when initially setting up a new IdentityIQ sandbox environment?
Proposed Solution:
the number of identities the customer has
Can the Provisioning tab under " Administrator Console ' be used to do the following task?
Solution: View the specific operations on each attribute being provisioned.
For a user who wants to be able to enable an account for a subordinate or themselves through Manage Accounts, does this configuration need to be performed in Lifecycle Manager (LCM)?
Select the Rehire action under Manage Accounts Options in the LCM Configuration.
Solution: Select the Rehire action under Manage Accounts Options in the LCM Configuration.
Is the following statement true?
Proposed Solution:
A Bundle profile must be associated to an Identity object.
Is the following a valid role option that can be configured?
Proposed Solution:
Configure a role to include a set of permissions.
The engineer is configuring a new application definition.
The customer wants an Audit record to be created with the error message, if provisioning fails.
Is this the rule an engineer should write to accomplish the goal?
Solution: Configure a Postlterate rule
Can the following IdentitylQ object be extended to store client-specific data by updating the corresponding .HBM file?
Solution: WorkItem
Is the following statement true?
Proposed Solution:
All ManagedAttribute objects associated to an Identity can be viewed on the ‘Policy’ tab from ‘View Identity’ QuickLink.
Is this statement correct about writing and executing source mapping rules to populate identity attributes?
Solution: The Identity object is passed to the rule.
IdentityIQ has been installed and set up with the contents of IdentityExtended.hbm.xml as follows:

Is this a correct statement about the installation?
Proposed Solution:
IdentityIQ comes with firstname, lastname, email, display name, and manager as the searchable attributes that are defined out of the box.
Is the following true of Identity Provisioning Policies?
Solution: Identity Provisioning Policies can be used to include allowed-values definitions or validation logic on fields so that only valid/authorized values can be specified for those fields when using the Create Identity feature to add an identity.
An engineer is developing an instance of IdentitylQ using the Services Standard Build (SSB) for a client. Is this a valid action the engineer can perform when setting up or using the SSB?
Solution: Place the client ' s identityiq. War file in the home directory of the build.
Is this statement valid regarding the control and usability of the Debug pages in IdentityIQ?
Proposed Solution:
Objects can be deleted on a singular basis or in bulk.
Is this a benefit of using the Run Rule feature of the Debug-Object page?
Solution: It can be used to create/modify/delete SailPoint database objects.
Assuming that the policy violation owner has the necessary permissions, is this a valid option for the policy violation owner to use when acting on a policy violation of type ' Risk Policy ' ?
Proposed Solution:
Certify
Is the following statement about workflows and sub-workflows (subprocesses) true?
Proposed Solution:
Many standard LCM sub-workflows can be leveraged in custom workflows, with their behavior controlled via input variables.
Is this a default functionality of the Lifecycle Manager (LCM) module?
Solution: Define Application
Is the following statement about workflow step types and their usage true?
Proposed Solution:
A script or rule step uses BeanShell code to perform the step action.
Is this a valid statement about connector rules?
Solution: A Post-Iterate Rule, if configured, is run after reading accounts from a SQL Loader application.
Is this statement true about IdentityIQ ' s syslog event searching capabilities?
Proposed Solution:
When searching the syslog events from the Advanced Analytics page, it is not possible to search syslog events by attributes other than an Incident Code.
Can the following action be performed using Rapid Setup application onboarding?
Proposed Solution:
Specify manager correlation by mapping an identity attribute to an account attribute.
Is the following statement about workflows and sub-workflows (subprocesses) true?
Proposed Solution:
Sub-workflows can be used to simplify large workflows.
Is this statement valid regarding the control and usability of the Debug pages in IdentityIQ?
Proposed Solution:
When creating a new object through the Debug-Object page, IDs are automatically generated when the object is saved.
Is the following statement true?
Solution: Every Link object must be associated to an Identity object
Is the following statement about IdentityIQ rule inputs and outputs correct?
Proposed Solution:
for (int i = 0; i < this.variables.length; i++) {
String name = this.variables[i];
Object value = eval(name);
if (value == void)
print(name + " = void " );
else if (value == null)
print(name + " = null " );
else
print(name + " : " + value.getClass().getSimpleName() + " = " + value);
}
This debug code will print all available inputs and outputs for a BeanShell rule.
The engineer is writing code to modify Policy objects. Is this the correct way to get, lock, modify and save the object, given the name of the object?
Proposed Solution:
public void updateObject(SailPointContext context, String objectName) throws GeneralException {
Policy object = context.getObjectByName(Policy.class, objectName);
// ... modify object ...
context.lockObject(object);
context.decache(object);
context.commitTransaction();
}
Assuming that the policy violation owner has the necessary permissions, is this a valid option for the policy violation owner to use when acting on a policy violation of type ' Account Policy ' ?
Proposed Solution:
Export CSV / Import CSV
Can the following action be performed using Rapid Setup application onboarding?
Solution: Specify account correlation using a rule.
The engineer needs to write some ad-hoc BeanShell code to search for GroupDefmition objects owned by Randy.Knight and print their names. Is this BeanShell code correct as written?
Solution:

Is this statement true about the IdentityIQ Audit functionality and/or options?
Proposed Solution:
The majority of IdentityIQ ' s auditing is managed through the Administrators Console page in the UI.
Is this a valid step to take when importing SailPoint XML file objects into IdentityIQ?
Proposed Solution:
Select the file from Global Settings > Import From File.
Is the following true of Identity Provisioning Policies?
Proposed Solution:
If no Update Identity Provisioning Policy is defined for the installation, the Create Identity Provisioning Policy will be used in Edit Identity operations.
Is this an example of a mover lifecycle event?
Solution: A contractor whose contract expired and accounts were disabled has a new contract with the company; the contractor needs all of their previous accounts enabled.
Is the following statement true about out-of-the-box reporting?
Proposed Solution:
All IdentityIQ report results are stored on IdentityIQ application servers.
Is this a valid step to take when importing SailPoint XML file objects into IdentitylQ?
Solution: Move the XML file into the IIQ_HOME/WEB-INF/database.
IdentityIQ is using emails to notify users about completion of steps within a process, or actions that need to be addressed. To ensure this notification is working, a main configuration must be set up in IdentityIQ to provide mail server and mail server authentication details.
Is this a required setting that an engineer must set up in IdentityIQ in order to ensure successful communication with the SMTP server?
Proposed Solution:
SMTP Port
Is this statement true about certifications?
Solution: All certifications include generation, the active period, sign-off, and the end period.
An engineer needs to first create a custom audit event and then set up an associated report.
What are four steps to accomplish this goal?
Proposed Solution:
Set up a new AuditAction in the AuditConfig object XML:
< ObjectAttribute displayName= " User Type " editMode= " Permanent " extendedNumber= " 2 " name= " userType " type= " string " / >
Is this statement true about certifications?
Proposed Solution:
A certification cannot be signed off until after the challenge period ends.
Is this a correct procedure for testing generated emails in a non-production system?
Solution: Change the Email Notification Type to Redirect to file using FTP protocol under Global Settings > Configure IdentitylQ Settings > Mail Settings, run the test scenario, and verify that the email text saved to the redirected file.
Is the following statement true?
Proposed Solution:
A Bundle owner must be associated to an Application object.
Is this a purpose of an IdentitylQ certification?
Solution: to attest lo a user ' s system access
An engineer needs to first create a custom audit event and then set up an associated report. What are four steps to accomplish this goal?
Solution:
The engineer is configuring a new application definition.
Due to company mergers, the customer has several different formats for employee number. The customer needs to match on the manager employee number to the manager identity, taking all of these formats into account.
Is this the rule an engineer should write to accomplish the goal?
Proposed Solution:
Write a Correlation rule.
How should an engineer schedule the tasks to most efficiently achieve the following goals?
Goals:
• Process the Employee Authoritative application at 5:00 AM and 12:00 PM.
• Process the Contractor Authoritative application at 5:10 AM and 12:10 PM.
• Process the Active Directory application at 5:20 AM and 12:20 PM.
• Process the Finance application at 8:00 PM.
• Check for expired work items at 12:00 AM.
• Perform identity request maintenance at 2:00 AM.
Schedule parameters:
• Each application aggregation takes anywhere between 30 minutes and 2 hours.
• The run schedule is for a 24-hour period, which begins at 12:00 AM.
Instructions:
• Drag the required tasks from the left into the answer area on the right, and place them in the correct order, starting at 12:00 AM.
• Ordinal numbers (such as 1st, 2nd, and 3rd) in the options indicate which run of the day it is for the task type.
• There will be unused task options.

Can the following action be performed using Rapid Setup application onboarding?
Solution: Specify the account attribute and value filter that identifies a secondary account.
Is this an example of a joiner lifecycle event?
Proposed Solution:
An employee, who has not previously been with the company, is hired and needs all new access and new accounts for company systems.
Can the search type in Identity be used to accomplish this result?
Proposed Solution:
Identifying details of a system error presented in the UI
The JVM Memory page on IdentitylQ displays the following information:
Solution: How much memory is currently allocated to the JVM heap?
Type your numerical response into the box below.
Which four steps are necessary for turning on Certifications logging at the severity log level of trace? Drag four options from the left into the answer area on the right, and place them in the correct order.


