Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free SailPoint Certified Identity Security Administrator Identity-Security-Administrator Exam Questions

Page: 1 / 10 Total 99 questions

Want more questions? Get Premium Access.

Question 1

Given the following scenario, is this a valid way to troubleshoot the issue?

A source shows this error during provisioning:

[ InvalidConfigurationException ] | Possible suggestions | You cannot initiate this action

because there are other pending or completed actions for the person that conflict with this one.

[ Error details ] Validation error occurred. Email addresses must be in the format of aaa.bbb@example.com

Proposed Solution / Statement: Check the Create Account policy on the Source to ensure the email address is mapped correctly.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: A. Yes
Explanation:

This is a valid troubleshooting action because the error explicitly identifies an invalid email-address value during provisioning. When Identity Security Cloud creates an account on a source, the Create Account configuration determines which account attributes are populated and how their values are calculated.

SailPoint allows each Create Account attribute to derive its value from an identity attribute, generator, static value, or other supported provisioning configuration. For example, the source's email account attribute can be mapped directly to the identity's Work Email value. If that mapping references the wrong identity attribute, produces an incorrectly formatted value, or uses a defective generator or transformation, the target source can reject the provisioning operation.

The administrator should therefore inspect Admin > Connections > Sources > Account Management > Create Account, locate the email-related source attribute, validate its mapping, and inspect the affected identity's source value. The conflicting-action portion of the error should also be reviewed in Account Activity, but the explicit email validation failure makes the account-creation mapping a direct troubleshooting target.

Study Guide Reference: Provisioning --- Create Account Configuration, Account Attribute Mappings, Provisioning Validation and Provisioning Troubleshooting.


Question 2

Is the following statement about entitlements valid?

Proposed Solution / Statement: Entitlements represent the specific access rights on a source.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: A. Yes
Explanation:

The statement is valid. In Identity Security Cloud, entitlements represent individual access rights or permissions that exist on connected sources. The specific form of an entitlement depends on the target system. Examples can include Active Directory groups, application roles, permission sets, security groups, database privileges, or other source-specific access constructs.

Entitlements form a fundamental layer of SailPoint's access model. Administrators can combine one or more entitlements from the same source into an access profile. Access profiles can then be incorporated into roles to create higher-level business access models.

Because SailPoint aggregates entitlement information from connected sources, administrators can govern these access rights through certifications, access requests, provisioning processes, role management, and policy analysis. Entitlement metadata can also provide meaningful descriptions and ownership information so reviewers understand the access being governed.

Therefore, describing entitlements as specific access rights on a source precisely reflects their role in Identity Security Cloud's access governance architecture.

Study Guide Reference: Access Management --- Entitlements, Access Profiles, Roles and Access Model Fundamentals.


Question 3

Is the following statement regarding the concept of federated identities true?

Proposed Solution / Statement: An identity provider offers specific services or applications to users after verifying their identity.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: B. No
Explanation:

The statement is incorrect because it confuses the responsibilities of an Identity Provider with those of a Service Provider. In a federated authentication architecture, the Identity Provider, commonly called the IdP, is responsible for authenticating the user and issuing trusted identity or authentication information.

The Service Provider is the system, application, or service that the user is attempting to access. It relies on the authentication assertion provided by the IdP and determines whether the authenticated user can access the requested resource.

For example, when Identity Security Cloud is configured to use SAML federation, an external IdP can authenticate the user. The IdP then sends a signed SAML assertion to Identity Security Cloud. Identity Security Cloud acts as the Service Provider and provides the application functionality after accepting the trusted authentication information.

Therefore, the component that offers the application or service is generally the Service Provider, not the Identity Provider. The IdP establishes identity and provides authentication assertions.

Study Guide Reference: Access Management --- Federated Authentication, Identity Providers, Service Providers, SAML Authentication.


Question 4

Is the following statement about entitlements valid?

Proposed Solution / Statement: Entitlements are stored inside of the Virtual Appliance for quick indexing.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: B. No
Explanation:

The statement is incorrect. A Virtual Appliance is primarily a secure connectivity and connector-execution component that enables Identity Security Cloud to communicate with sources located inside an organization's private network or otherwise inaccessible directly from the SailPoint cloud environment.

During aggregation, the VA can communicate with the source and transmit relevant account, identity, group, and entitlement information to Identity Security Cloud. However, the Virtual Appliance is not intended to function as the persistent entitlement repository or search-indexing database.

Entitlement information used for access modeling, certifications, governance, search, roles, access profiles, and policy analysis is managed within the Identity Security Cloud platform. The VA facilitates source communication and executes connector-related operations such as aggregation and provisioning when required.

This architectural distinction is important because Virtual Appliances should not be treated as local databases containing governance data. Their primary responsibilities are secure connectivity, execution of integration workloads, and communication between SailPoint's cloud services and enterprise-managed systems.

Study Guide Reference: Virtual Appliances --- VA Architecture, Source Connectivity, Aggregation and Provisioning Operations.


Question 5

Regarding the Access Certification Process, is the following statement valid?

Proposed Solution / Statement: A sign-off page becomes visible only after the reviewer has completed all required decisions.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: A. Yes
Explanation:

The statement is correct. During an Identity Security Cloud certification, the reviewer evaluates each required access item and records the appropriate decision---for example, approving or revoking access. The certification cannot be properly completed while required review items remain undecided.

SailPoint's current user documentation states that after the reviewer has reviewed each item, the reviewer is taken to the sign-off page to complete the certification. The reviewer then selects Finish to submit the decisions and move the certification into the completed state. SailPoint's certification overview likewise describes the sequence as reviewing assigned access, approving or revoking items, and then signing off on those decisions.

Sign-off has governance significance beyond the user-interface transition. Revocation decisions that have not been signed off are not treated as finalized remediation instructions. SailPoint explicitly warns that unsigned revoke decisions are not applied and can be treated as undecided when a campaign is administratively completed.

Therefore, completion of the required decisions is the prerequisite that brings the reviewer to the certification sign-off stage.

Study Guide Reference: Supporting Governance --- Access Certifications, Review Decisions, Certification Sign-Off and Campaign Completion.


Question 6

Is this a valid statement regarding access request approval processes?

Proposed Solution / Statement: In a governance group approval process, the majority of the members must approve before the access is granted to the requester.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: B. No
Explanation:

The statement is incorrect. Identity Security Cloud does not use majority voting within a Governance Group for an access-request approval step. When a Governance Group is configured as a reviewer, only one eligible member of that Governance Group is required to approve or deny the request on behalf of the group.

SailPoint explains that when an access request reaches a Governance Group, its members receive the applicable review assignment. Once one member makes the decision, the review is treated as completed for that Governance Group and disappears from the other members' pending approval lists.

This should not be confused with a multi-step approval process containing several separate reviewers. If the access item is configured with multiple required reviewer stages, each required stage must approve before provisioning occurs. However, a Governance Group itself represents one reviewer stage, and that stage does not require approval from 50%, a majority, or every member.

Therefore, requiring a majority of Governance Group members is not how standard Identity Security Cloud Governance Group approvals operate.

Study Guide Reference: Access Management --- Governance Group Approvals, Access Requests, Multi-Approver Processes and Group Review Decisions.


Question 7

Review the following log entry:

[

{

"id": "2c9180866166b5b0016167c32ef31a66",

"name": "acme AD-TX Cluster",

"description": "acme AD - TX Cluster",

"clientType": "CCG",

"ccgVersion": "373_535_70.2.0",

"pinnedConfig": true,

"logConfiguration": null

},

{

"id": "2c9180846a93ce60016ab29f039944de",

"name": "acme AD-NY Cluster",

"description": "acme AD-NY Cluster",

"clientType": "CCG",

"ccgVersion": "373_535_70.2.0",

"pinnedConfig": true,

"logConfiguration": {

"clientId": null,

"durationMinutes": 60,

"expiration": "2025-12-15T19:13:36.079Z",

"rootLevel": "TRACE",

"logLevels": {

"sailpoint.connector.ADLDAPConnector": "TRACE"

}

}

}

]

A source owner for Active Directory has found problems with aggregation and has requested log files for their source.

Is this a valid way for the Administrator to assist in retrieving the correct logs?

Proposed Solution / Statement: The Admin can set the log level using the following REST API call and JSON request body:

PUT /v2025/managed-clusters/2c9180866166b5b0016167c32ef31a66/log-config

{

"durationMinutes": 365,

"rootLevel": "DEBUG",

"logLevels": {

"sailpoint.connector.ADLDAPConnector": "DEBUG"

}

}

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: A. Yes
Explanation:

This is a valid method for enabling connector-level logging on the relevant VA managed cluster. The log entry shows that the acme AD-TX Cluster currently has logConfiguration: null, meaning no temporary connector logging configuration is active for that cluster. The Managed Clusters API supports a PUT request to /managed-clusters/{id}/log-config to establish or update logging configuration.

The proposed durationMinutes value of 365 is valid because SailPoint supports a logging duration from 5 through 1,440 minutes. DEBUG is also a supported Log4j level, and sailpoint.connector.ADLDAPConnector is the appropriate connector logging class for Active Directory/LDAP connector activity. Once enabled, the administrator can reproduce the problematic aggregation and obtain substantially more diagnostic information than would be available under normal logging.

Importantly, enhanced logging should generally be enabled only for the troubleshooting period because verbose connector logging increases log volume. SailPoint's current API explicitly supports this managed-cluster logging operation and temporary duration control.

Study Guide Reference: Virtual Appliances --- Connector Logging, Managed Cluster Log Configuration, Active Directory Troubleshooting.


Question 8

An Identity Security Cloud tenant is configured to disable all source accounts for an identity that enters the terminated lifecycle state. A database administrator reports they have been noticing that employees who are terminated, still have their database accounts as "Active" in the source system.

Is this a valid troubleshooting option for the scenario above?

Proposed Solution / Statement: Reset the database source and re-aggregate all of the users.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: B. No
Explanation:

Resetting the source and re-aggregating users is not the appropriate initial remediation. Aggregation is primarily an inbound data collection process: it reads account information from the source into Identity Security Cloud. It does not, by itself, perform the outbound disable operation that should occur when an identity enters the Terminated lifecycle state.

The administrator should first verify that the affected identities actually entered the expected lifecycle state and that the Terminated lifecycle-state configuration specifies that the database source account is to be disabled. SailPoint allows a lifecycle state to enable, disable, or delete accounts on selected sources. The source must also support the required account-disable operation.

The administrator should then review provisioning/account activity for failures and validate that provisioning is enabled and operating correctly for the database connector. Re-aggregation could later be useful to confirm the source's actual account state, but resetting the entire source is unnecessarily disruptive and does not correct the root cause of a failed lifecycle provisioning operation.

Therefore, the proposed troubleshooting action does not directly address why the Terminated lifecycle event failed to disable the account.

Study Guide Reference: Provisioning --- Lifecycle-State Provisioning, Account Disable Operations, Provisioning Troubleshooting and Source Aggregation.


Question 9

Is this a valid statement about how an administrator reviews provisioning activity?

Proposed Solution / Statement: By default, account activity information is presented in a descending sequence based on the Last Modified Date. However, the administrator can sort ascending or descending by any column.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: A. Yes
Explanation:

Yes. Identity Security Cloud's Account Activity view is designed to provide administrators with a chronological operational view of provisioning actions. SailPoint documents that account activities are displayed by default in descending order of Last Modified date, which places the most recently updated provisioning activity first. This is useful during troubleshooting because current or recently failed operations are immediately visible.

The activity table exposes operational fields such as Status, Action, Requester, Recipient, Sources, Last Modified, and Stage. Administrators can use the tabular controls to reorganize the displayed information for analysis, including changing sort direction on sortable columns. This makes it possible to investigate provisioning operations from perspectives other than chronological order---for example, grouping similar requesters, recipients, sources, statuses, or actions.

Selecting an individual activity exposes additional request information, including provisioning errors and the progression of the request through its processing stages. This capability is important when determining whether an account create, modify, enable, disable, or entitlement operation completed successfully or stalled.

Study Guide Reference: Provisioning --- Monitoring Provisioning, Account Activity, Last Modified Sorting and Provisioning Troubleshooting.


Question 10

Is this a valid scenario for reviewing access requests in the approval management page?

Proposed Solution / Statement: It is possible for an administrator to supersede an approver's cancellation of a request.

Does this proposed solution meet the requirement / solve the scenario?

Correct Answer: B. No
Explanation:

This is not a valid description of how a canceled access request is handled. A cancellation terminates the request before it completes. Once an access request has entered a concluded Canceled state, it is no longer simply a pending approval waiting for an administrator to substitute a decision for the assigned reviewer.

Approval Management does give administrators powerful controls over pending governance work. Administrators can inspect requests, reassign current approvers, send reminders, cancel requests, and, where supported, overwrite the current approval step. Overwriting an approver is fundamentally different from reversing an already canceled request: the administrator is acting on the current approval step of an active request.

SailPoint documentation explicitly identifies Canceled as a concluded status and defines cancellation as termination of the request. The administrator's overwrite capability applies to an approval step, not to resurrecting a request after cancellation. A new request would normally be required when access is still needed after the original request has been terminated.

Study Guide Reference: Access Management --- Approval Management, Access Request Status, Administrative Approval Actions.