Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free SailPoint Certified IdentityNow Engineer IdentityNow-Engineer Exam Questions

Page: 1 / 11 Total 108 questions

Want more questions? Get Premium Access.

Question 1

Is the following true about custom connectors in IdentityNow?

Solution: Custom connector are developed and compiled inside identityNow.

Correct Answer: B. No
Explanation:

No, custom connectors are not developed and compiled inside IdentityNow. Custom connectors are typically developed outside of the IdentityNow platform using a development environment and then tested and packaged before being uploaded to the platform. These connectors can be developed using tools provided by SailPoint, but the actual development process occurs externally, not directly within the IdentityNow environment.

Key Reference from SailPoint Documentation:

Custom Connector Development: Custom connectors are developed outside of the IdentityNow platform and then integrated into it for use.


Question 2

An engineer needs to troubleshoot the following issue:

Incomplete Identities on authoritative source

Is this a reasonable action for the engineer to take?

Solution: Review the identities without Managers report.

Correct Answer: B. No
Explanation:

Reviewing the Identities without Managers report is not directly related to troubleshooting incomplete identities on an authoritative source. The 'Identities without Managers' report is specifically useful for identifying identities that are missing a manager assignment, which might be relevant for access reviews or other management-related tasks. However, when troubleshooting incomplete identities, the focus is typically on missing attributes or data mappings, not the manager attribute specifically.

Therefore, this report is not the most appropriate action for this particular issue.


SailPoint IdentityNow Reporting and Identity Data Review Documentation.

SailPoint IdentityNow Troubleshooting Incomplete Identities.

Question 3

Does the following use case correctly describe passthrough authentication?

Solution: A user logs into identityNow using a password set in identityNow during registration.

Correct Answer: B. No
Explanation:

Passthrough authentication in SailPoint IdentityNow refers to a method where the authentication process happens through a trusted identity provider (IdP), rather than using credentials stored directly in SailPoint IdentityNow. The key feature of passthrough authentication is that the user's login attempt is authenticated via external authentication mechanisms such as Active Directory, SAML-based Identity Providers (IdPs), or other federated identity providers.

In the given use case, the user is logging into IdentityNow using a password set directly in IdentityNow during registration. This process describes local authentication (where IdentityNow manages the credentials), not passthrough authentication. Since passthrough authentication relies on external IdPs or federated systems, this case does not accurately describe passthrough authentication.


SailPoint IdentityNow Documentation on Authentication Methods.

SailPoint IdentityNow Federation and SSO Configuration Guides.

Question 4

Is this statement true about deploying and configuring IdentityNow's virtual appliance (VA)?

Solution: When deploying the VA in Azure, the identityNow engineer will need to utilize the Azure command --line interface(CLI) to deploy the VA image.

Correct Answer: B. No
Explanation:

No, when deploying the Virtual Appliance (VA) in Azure, the IdentityNow engineer does not necessarily need to use the Azure CLI to deploy the VA image. While using the Azure CLI is one option, SailPoint provides multiple ways to deploy the VA in Azure, including using the Azure portal or ARM (Azure Resource Manager) templates. The process does not mandate using the CLI specifically.

Key Reference from SailPoint Documentation:

Azure VA Deployment Methods: SailPoint supports multiple methods for deploying the VA in Azure, including through the Azure portal or ARM templates, without requiring the CLI.


Question 5

Is this statement correct about security and/or encryption of data?

Solution: When setting up a virtual appliance cluster. SailPoint creates an asymmetnc key pair based on a user-provided passphrase. and then uses this key pair to communication with the IdentityNow tenant.

Correct Answer: A. Yes
Explanation:

Yes, this statement is correct. When setting up a Virtual Appliance (VA) cluster, SailPoint does indeed create an asymmetric key pair based on a user-provided passphrase. This key pair is used for secure communication between the Virtual Appliance and the IdentityNow tenant. The asymmetric encryption model uses a public-private key pair where the private key is stored securely within the VA, and the public key is shared with the IdentityNow tenant to establish a secure, encrypted communication channel. This setup ensures that data exchanged between the VA and the IdentityNow tenant remains protected.


SailPoint IdentityNow Virtual Appliance Security Guide.

SailPoint IdentityNow Asymmetric Encryption and Key Management Documentation.

Question 6

Is this statement true about certification campaigns?

Solution: Search-based certification campaigns are used to review access for non-correlated accounts.

Correct Answer: A. Yes
Explanation:

Yes, search-based certification campaigns can be used to review access for non-correlated accounts. Non-correlated accounts are accounts that do not have a direct link to any identity in the system, which means they may represent orphaned or unmanaged accounts. Search-based certifications allow administrators to create campaigns based on specific criteria, including targeting these non-correlated accounts to ensure they are properly reviewed and addressed within the organization.


SailPoint IdentityNow Search-Based Certification Campaign Guide.

SailPoint IdentityNow Non-Correlated Account Management Documentation.

Question 7

Is the following description of an access profile correct?

Solution: it can be acknowledged during certifications.

Correct Answer: A. Yes
Explanation:

Yes, an access profile can be acknowledged during certifications. During access certification campaigns, reviewers can review access profiles as part of the items that need to be certified. They can either approve or revoke access to the access profiles, just like they would with individual entitlements. This ensures that users' access to these bundled entitlements is regularly reviewed and compliant with organizational policies.


SailPoint IdentityNow Certification Campaigns Guide.

SailPoint IdentityNow Access Profile Certification Documentation.

Question 8

Does the following use case accurately describe provisioning on a source that has provisioning disabled?

Solution: Provisioning is initialed by a process (e.g. Access Request Role Assignments). Provisioning instructions are calculated based on current access, and go through filtering and expansion processes. Provisioning is then assigned to a source for provisioning. Since provisioning is disabled on the source a manual task is opened in IdentityNow A person carries out the provisioning manually.

Correct Answer: A. Yes
Explanation:

In this use case, provisioning is initiated, but the source has provisioning disabled, meaning automated provisioning cannot proceed. The process described is accurate: when provisioning is assigned to a source where provisioning is disabled, IdentityNow does not execute the provisioning through its automated system. Instead, a manual task is generated for a human to complete the provisioning process. This manual intervention ensures that the necessary access changes can still occur, albeit through human oversight rather than an automated connector.

This scenario aligns with how IdentityNow handles sources that are flagged as non-provisionable. The provisioning logic is still calculated within the system, but actual implementation requires manual steps when the source is configured in this way.


SailPoint IdentityNow Provisioning Architecture.

SailPoint IdentityNow Manual Provisioning Workflow Documentation.

Question 9

Is the following true about custom connectors in IdentityNow?

Solution: Custom connector configurations can have account correlation settings defined.

Correct Answer: A. Yes
Explanation:

Yes, custom connector configurations in SailPoint IdentityNow can have account correlation settings defined. Account correlation is used to link accounts from different sources to the correct identity in IdentityNow. When configuring a custom connector, it is possible to define how accounts from the connected system are correlated to existing identities based on attributes like usernames or other unique identifiers.

Key Reference from SailPoint Documentation:

Custom Connector Configuration: SailPoint allows for the definition of account correlation settings in custom connectors to ensure proper linking of external accounts to internal identities.


Question 10

Is this the recommended way to test lifecycle state transitions in IdentityNow?

Solution: Configure and enable lifecycle states. Find a test identity that is not in the target lifecycle state. Manually change the test identity lifecycle state to the target state from the admin user interface Verify the results of the lifecycle slate in the identity's activity page.

Correct Answer: A. Yes
Explanation:

Yes, this is the recommended way to test lifecycle state transitions in IdentityNow. To validate how lifecycle states function, administrators can manually set up and enable lifecycle states for testing purposes. By selecting a test identity that is not already in the target state, manually transitioning that identity to the target state using the admin user interface provides a direct and controlled way to observe the transition. The results can be verified in the identity's activity page, where changes in the lifecycle state will be logged, helping to ensure that the lifecycle state functions as expected.


SailPoint IdentityNow Lifecycle Manager Documentation.

SailPoint IdentityNow Lifecycle State Configuration Guide.