Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free SailPoint Certified IdentityIQ Engineer IdentityIQ-Engineer Exam Questions

Page: 1 / 13 Total 122 questions

Want more questions? Get Premium Access.

Question 1

Can this be achieved using Rapid Setup user interface configuration options?

Solution: Disable an account and remove all its entitlements on a particular application during Mover events.

Correct Answer: B. No
Explanation:

The scenario described involves disabling an account and removing all its entitlements on a particular application during Mover events. The Rapid Setup user interface in SailPoint IdentityIQ primarily handles common configurations like enabling or disabling accounts, assigning or unassigning roles, and triggering certifications during lifecycle events.

However, the combination of disabling an account and removing all its entitlements for a Mover event typically involves more detailed configuration that goes beyond the capabilities of the Rapid Setup interface. Achieving this would generally require creating a custom workflow or a specific rule that handles both disabling the account and removing entitlements based on the Mover event triggers.

Thus, the Rapid Setup UI cannot achieve this level of detailed configuration, making the correct answer B. No.

Reference: This conclusion is drawn from the SailPoint IdentityIQ Lifecycle Manager documentation, which specifies the functionalities available through the Rapid Setup interface and the additional configurations possible through custom workflows.


Question 2

Can this be achieved using Rapid Setup user interface configuration options?

Solution: Disable an account on a particular application for one set of users and delete the account for another set of users during administrative Terminations.

Correct Answer: B. No
Explanation:

The Rapid Setup user interface in SailPoint IdentityIQ is designed to simplify and streamline common configuration tasks, particularly during the initial setup of IdentityIQ environments. However, it has certain limitations in terms of granularity and customization.

In this case, the requirement is to disable an account on a particular application for one set of users and delete the account for another set of users during administrative terminations. The Rapid Setup interface does not provide options to differentiate between user groups for different actions (disable vs. delete) within the same termination event.

This level of specificity---applying different actions based on user group membership---would require a more advanced setup, possibly involving custom rules or workflows rather than using the Rapid Setup options. Therefore, the correct answer is B. No.

Reference: This answer is based on the SailPoint IdentityIQ Rapid Setup Guide, which describes the capabilities and limitations of the Rapid Setup interface. The guide indicates that more complex scenarios require customization beyond what Rapid Setup can offer.


Question 3

Is this statement valid regarding the control and usability of the Debug pages in IdentitylQ?

Solution: The application server must be restarted after reloading the logging file through the Debug-Logging page.

Correct Answer: B. No
Explanation:

The statement that the application server must be restarted after reloading the logging file through the Debug-Logging page is incorrect. SailPoint IdentityIQ allows you to reload the logging configuration from the Debug-Logging page without restarting the application server. The Debug-Logging page provides a way to dynamically reload the logging settings, including those in the log4j file, so that changes can take effect immediately without the need for a server restart.

Therefore, the correct answer is B. No.

Reference: This conclusion is supported by the SailPoint IdentityIQ Administration Guide, which details how to use the Debug-Logging page to manage logging settings dynamically without requiring a server restart.


Question 4

Is this statement true about identitylQ's syslog event storage?

Solution: To improve security, items logged through syslog are unable to be sent to Log4j.

Correct Answer: B. No
Explanation:

The statement is false. In SailPoint IdentityIQ, syslog events can indeed be sent to Log4j. The system allows for flexible configuration where logging can be directed to multiple outputs, including both syslog and Log4j. This flexibility enables organizations to route logs according to their needs while maintaining security and compliance.


SailPoint IdentityIQ Logging and Auditing Guide

SailPoint IdentityIQ Administration Guide (Syslog Configuration and Log4j Integration)

Question 5

Can the following be achieved via configuration of control variables in the out-of-the-box Lifecycle Manager (LCM) workflows?

Solution: Disable all notifications.

Correct Answer: A. Yes
Explanation:

Yes, disabling all notifications can be achieved via configuration of control variables in the out-of-the-box Lifecycle Manager (LCM) workflows. In SailPoint IdentityIQ, most workflows, including those in LCM, use control variables to manage various settings, such as whether notifications should be sent. By setting the appropriate control variable (e.g., disabling email notifications) within the workflow configuration, you can effectively suppress all notifications related to that workflow.

Therefore, the correct answer is A. Yes.


Question 6

Is the following a true statement about IdentitylQ authentication and authorization?

Solution: What users can see and do in IdentitylQ can be party controlled by their authorized scope.

Correct Answer: A. Yes
Explanation:

In SailPoint IdentityIQ, what users can see and do is indeed partly controlled by their authorized scope. Authorized scopes define the range of objects (such as identities, roles, applications) that a user has access to. Scopes can be applied to limit access based on specific criteria, ensuring that users only interact with the data and functionalities relevant to their role or responsibility within the organization.

For example, a user with access to a specific scope may only view or manage identities within a certain department or geographical location, depending on how the scope is configured.

Therefore, the correct answer is A. Yes.

Reference: This answer is derived from the SailPoint IdentityIQ Administration Guide, which outlines how scopes are used to manage access control within the platform, influencing both the visibility and actions available to users.


Question 7

Is this statement true about identitylQ's syslog event storage?

Solution: Both logging and auditing can have a negative influence on performance. Logging and auditing both require extra function calls within The application and will generate data that will need to be stored.

Correct Answer: A. Yes
Explanation:

Yes, the statement is true. Both logging and auditing in SailPoint IdentityIQ can have a negative influence on performance because they involve additional function calls within the application. These processes generate data that needs to be stored, which can impact performance if not managed properly. Extensive logging and auditing, particularly at high levels of detail, can lead to increased I/O and storage usage, potentially slowing down system operations.


SailPoint IdentityIQ Performance Tuning Guide

SailPoint IdentityIQ Logging and Auditing Guide (Impact on Performance)

Question 8

Can this be achieved using Rapid Setup user interface configuration options?

Solution: Reassign all object ownership to the user's manager during Leaver and Termination events.

Correct Answer: B. No
Explanation:

Reassigning all object ownership to a user's manager during Leaver and Termination events is a complex process that typically involves custom logic or workflows to ensure that all owned objects (like access, certifications, roles, etc.) are correctly reassigned.

The Rapid Setup interface is primarily designed for standard lifecycle management tasks, such as role assignments, account enabling/disabling, and certifications. It does not inherently support the automatic reassignment of object ownership based on lifecycle events such as Leaver and Termination events.

This kind of reassignment would typically require a custom rule or workflow to track and reassign all owned objects, which falls outside the scope of what Rapid Setup can handle directly. Therefore, the correct answer is B. No.

Reference: This information is supported by the SailPoint IdentityIQ Lifecycle Manager Guide, which outlines what is possible through Rapid Setup and what would require custom development.


Question 9

Is this a benefit of using the Run Rule feature of the Debug-Object page?

Solution: It can be used to create/modify/delete SailPoint database objects.

Correct Answer: B. No
Explanation:

The statement is false. The 'Run Rule' feature on the Debug-Object page is not intended for creating, modifying, or deleting SailPoint database objects. Instead, it is used to execute specific rules for testing and debugging purposes. While it allows you to test the logic of a rule by running it in isolation, it does not directly manipulate database objects. For creating, modifying, or deleting database objects, administrators would typically use the appropriate IdentityIQ APIs or database scripts.


SailPoint IdentityIQ Administration Guide (Debugging and Rule Management Sections)

SailPoint IdentityIQ Developer Guide (Working with Rules and Debugging Tools)

Question 10

A bank is two years into an ongoing project to provide all access through roles. The bank is actively using roles and actively adding to their role model. They need to ensure that all roles include the correct entitlements.

Will this certification type achieve the goal?

Solution: Account Group Membership Certification

Correct Answer: B. No
Explanation:

An Account Group Membership Certification is designed to certify group memberships within accounts, typically focusing on the validation of access within specific account groups (e.g., Active Directory groups).

This type of certification does not directly address the accuracy of role composition or the correctness of entitlements assigned within roles. Since the bank's goal is to ensure that all roles include the correct entitlements, an Account Group Membership Certification is not suitable for this purpose.

Thus, the correct answer is B. No.