Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Saviynt Certified IGA Professional Exam (L100) SAVIGA-C01 Exam Questions

Page: 1 / 6 Total 60 questions

Want more questions? Get Premium Access.

Question 1

ABC Company has set up a one-level workflow for an application, where the lone approver is the manager of the beneficiary. Margaret, who is Edward's manager, raised an access request on behalf of Edward. Which of the following statements would be true/applicable?

Correct Answer: A. Manager's approval is auto-approved
Explanation:

In the given scenario, where ABC Company has a one-level workflow with the manager as the sole approver, and Margaret (Edward's manager) raises a request on behalf of Edward, the statement that would be true/applicable is A. Manager's approval is auto-approved. Here's why:

Saviynt's Workflow Configuration: Saviynt allows for the configuration of various workflow scenarios, including auto-approval based on certain conditions.

Self-Approval Prevention/Auto-Approval: A common security best practice is to prevent users from approving their own access requests. However, when a manager requests on behalf of a subordinate, this is considered a delegated request and many organizations find it acceptable to auto-approve since the approval should be implicit in the act of requesting.

Manager Requesting on Behalf: When a manager initiates a request for a subordinate, it's often considered an implicit approval. The manager is essentially saying, 'I approve this access for my team member.'

Saviynt's Default Behavior (Typically): By default, or through common configuration practices, Saviynt is often set up to recognize this scenario and auto-approve the manager's approval step in the workflow. This streamlines the process and avoids unnecessary delays.

Configuration Options: While auto-approval is common, Saviynt's workflow engine is flexible. It's possible to configure it differently, for instance, to still require explicit manager approval even in this scenario. However, this is less typical.

Other Options:

B . Manager's approval is auto-rejected: This is highly unlikely and would defeat the purpose of having a manager initiate the request.

C . Manager must manually approve/reject the request: While possible through configuration, it's not the typical or default behavior in this scenario.

D . None of the above: Option A is the most likely and common outcome.

In summary: In a one-level workflow where the manager is the approver, and the manager requests access on behalf of a subordinate, Saviynt is typically configured to auto-approve the manager's approval step, streamlining the process and reflecting the implicit approval inherent in the manager's action.


Question 2

Which of the following aspects in EIC is regarded as a unique identity of a person?

Correct Answer: D. User
Explanation:

In Saviynt, a User represents the unique identity of a person. It's the central object that ties together all the information about an individual, including their accounts, entitlements, roles, and attributes.

Why other options are incorrect:

Endpoint: Represents a system or application, not a person.

Employee: While many users might be employees, the term 'user' is more general and can include contractors, partners, etc.

Account: Represents a user's access to a specific system, not their overall identity.

Saviynt IGA Reference:

Saviynt Documentation: Throughout the documentation, 'User' consistently refers to the individual's identity within the system.

Saviynt User Interface: The User Management section in Saviynt focuses on managing the lifecycle and access of individual users.


Question 3

John, who recently joined an organization as a full-time employee, is required to work from the Sydney office. He was assigned birthright entitlements as part of the new joiner provisioning. Which of the following Enterprise Roles will be assigned to John from the Birthright Rule?

Correct Answer: A. Birthright - Sydney
Explanation:

In this scenario, where John is a new full-time employee required to work from the Sydney office, the most specific and appropriate Enterprise Role assigned from the Birthright Rule would likely be A. Birthright - Sydney. Here's the reasoning:

Saviynt's Birthright Roles and Rules: Birthright roles are designed to automatically provision access based on specific criteria like location, job role, or employment type. Birthright rules define the conditions for assigning these roles.

Specificity of Role Assignment: The goal is to assign the most relevant and granular role based on the available information. In this case, John's location (Sydney) is the most specific criterion mentioned.

Why Other Options Are Less Likely:

B . Birthright - Permanent - Full-time: While John is a full-time employee, this role might be too broad if there are other location-specific roles.

C . Birthright - All: This role is likely too generic and would grant excessive access. It's generally not good practice to have an 'all-encompassing' birthright role.

D . Birthright - Employee: Similar to the 'Full-time' role, this might be too broad if location-specific roles are available.

Best Practices: It's a best practice in identity governance to use the most specific criteria possible when assigning birthright access. This helps enforce the principle of least privilege.

In summary: The 'Birthright - Sydney' role is the most appropriate choice because it aligns with John's specific work location, ensuring he receives the necessary access for his role while adhering to the principle of least privilege.


Question 4

Which of the following formats is suitable for downloading an Analytics report? (Select all that apply)

Correct Answer: A. CSV file and Excel Sheet
Explanation:

The formats suitable for downloading an Analytics report in Saviynt typically include A. CSV file and Excel Sheet. Here's an explanation:

Saviynt's Reporting Capabilities: Saviynt provides options for exporting and downloading analytics reports in various formats to facilitate data sharing and further analysis.

Common Export Formats:

CSV (Comma Separated Values): A widely used format for storing tabular data in plain text. It's easily imported into various data analysis tools and spreadsheet programs.

Excel Sheet (e.g., .xlsx): A popular spreadsheet format that allows for data organization, formatting, and calculations.

Why These Formats Are Suitable:

Data Analysis: Both CSV and Excel formats are well-suited for further data analysis and manipulation.

Reporting: They are commonly used for creating reports and sharing data with stakeholders.

Compatibility: Most data analysis and reporting tools support these formats.

Other Less Common Options: While less frequent, Saviynt might offer other export formats like PDF, depending on the specific version and configuration.

B . Text file: Although technically a text file, a raw .txt export might not be as useful for structured data like analytics reports. CSV would be preferred.

In conclusion: CSV and Excel are the most common and practical formats for downloading analytics reports from Saviynt, offering flexibility for data analysis, reporting, and sharing.


Question 5

Which of the following Account statuses is not considered in a User Manager Campaign certification?

Correct Answer: D. Manually Provisioned
Explanation:

The Account status that is not typically considered in a User Manager Campaign certification in Saviynt is D. Manually Provisioned. Here's why:

Saviynt's User Manager Campaign Focus: User Manager Campaigns primarily focus on reviewing and certifying access that is actively managed and tracked within Saviynt.

Account Statuses and Their Relevance:

A . Manually Suspended: Indicates an account that has been intentionally disabled within Saviynt. These accounts are often included in reviews to ensure the suspension is still valid.

B . Inactive: Indicates an account that has not been used for a certain period. These accounts are often included in reviews to determine if they should be disabled or removed.

C . Suspended from Import Service: Indicates an account that has been suspended due to issues during an import process. These accounts are typically reviewed to resolve the import problem and determine the appropriate account status.

Manually Provisioned Accounts: These accounts are created directly in the target system, bypassing Saviynt's provisioning processes. As such, they might not be fully tracked or managed within Saviynt.

Out-of-Band Access: Manually provisioned accounts represent a form of out-of-band access, which is often excluded from standard User Manager Campaigns.

Separate Review Process: Organizations might have separate processes for reviewing manually provisioned accounts, such as using the RevokeOutOfBandAccessJob or a different type of campaign.

In conclusion: While other account statuses like Manually Suspended, Inactive, and Suspended from Import Service are relevant to access management within Saviynt and are often included in User Manager Campaigns, Manually Provisioned accounts might be excluded because they represent access granted outside of Saviynt's control and might require a different review process.


Question 6

As an Admin, you are required to set up an Entitlement Owner Campaign for Entitlements belonging to an Oracle ERP Endpoint by the Internal Audit team. The Campaign should be launched at the beginning of every month, and only Accounts and Entitlements that meet the prerequisites should be included in the Campaign.

Which of the following 2-key configurations would you recommend for achieving this?

Correct Answer: A. Use Campaign Template and the Schedule Later option
Explanation:

To set up an Entitlement Owner Campaign for Entitlements belonging to an Oracle ERP Endpoint that launches at the beginning of every month, and includes only Accounts and Entitlements that meet the prerequisites, the 2-key configurations you should recommend are A . Use Campaign Template and the Schedule Later option. Here's a breakdown:

Campaign Template:

Purpose: Templates allow you to save a set of campaign configurations as a reusable template. This is ideal for recurring campaigns with consistent settings.

Benefits: Using a template saves time and ensures consistency across multiple campaign instances. You can define the scope (Oracle ERP Endpoint), Certifier type (Entitlement Owners), and other settings within the template.

Prerequisites: You can include logic within the template to filter for Accounts and Entitlements that meet the defined prerequisites.

Schedule Later option:

Purpose: This option allows you to schedule the campaign to launch at a specific date and time in the future.

Recurring Scheduling: You can configure the campaign to run on a recurring schedule, such as the beginning of every month.

Automation: This automates the campaign launch process, eliminating the need for manual intervention each month.

Why Other Options Are Less Suitable:

B . Use Advanced Configurations and Preview mode and create the Campaign at the beginning of each month: This approach is manual and prone to errors. It doesn't leverage the automation benefits of templates and scheduling.

C . Use Advanced Configurations and set the Campaign expiry to 31 days: While setting an expiry is important, it doesn't address the need for recurring monthly launches or using a template for consistent configuration.

D . Cannot be achieved: This is incorrect; the scenario can be easily achieved using Campaign Templates and the Schedule Later option.


Question 7

Marty, an Administrator, reconciled Oracle Accounts into Saviynt. During the import, the incoming accounts were required to be mapped to the existing users in Saviynt. Which of the following Rules should be used to successfully associate Accounts to the correct users?

Correct Answer: D. User Account Correlation Rule
Explanation:

User Account Correlation Rules in Saviynt are specifically designed to map imported accounts to existing users within the system. These rules define the logic for matching accounts to users based on various attributes, such as employee ID, email address, or username.

Why other options are incorrect:

Account to User Rule: This is not a standard rule type in Saviynt.

Account Name Rule: This might focus on naming conventions for accounts, not correlating them to users.

Technical Rule: This is a broader category of rules and doesn't specifically address account-user mapping.

Saviynt IGA Reference:

Saviynt Documentation: The section on Account Correlation Rules provides detailed information on how to configure these rules for different scenarios.

Saviynt Use Cases: Saviynt often provides examples and use cases demonstrating how to use User Account Correlation Rules to automate account mapping during imports.


Question 8

Which of the following bulk operations is not a supported feature?

Correct Answer: C. Bulk Approval - Single-click approval for multiple entitlements in a single request
Explanation:

The bulk operation that is not typically a supported feature in the same way as the others is C. Bulk Approval - Single-click approval for multiple entitlements in a single request. Here's why:

Saviynt's Bulk Operations: Saviynt supports various bulk operations to streamline administration and user experience, especially when dealing with multiple users or requests.

Supported Bulk Operations:

A . Bulk Request Access: Saviynt allows users to request access for multiple users in a single request. This is a common and supported feature.

B . Disabling multiple users and their access: Administrators can disable multiple user accounts and revoke their access in bulk.

D . Deleting multiple users: Saviynt supports the bulk deletion of user accounts.

Bulk Approval - Granularity: While Saviynt supports bulk approvals (approving multiple requests at once), it typically operates at the request level, not at the individual entitlement level within a single request. Approving multiple separate requests in one go is a standard bulk approval action.

Each request (even if it's a bulk request for multiple users or contains multiple entitlements) is usually treated as a single unit for approval.

Approvers typically approve or reject the entire request, not individual entitlements within it.

Security and Control: This approach maintains better control and auditability. Approving each entitlement within a single request individually would require a more complex interface and potentially increase the risk of accidental approvals.

Possible Workarounds:

Separate Requests: To achieve a similar outcome, users could submit separate requests for each entitlement, allowing the approver to approve them individually (and potentially in bulk if they are separate requests).

Custom Workflows: In theory, it might be possible to create highly customized workflows to handle this scenario, but it's not a standard out-of-the-box feature.

In summary: While Saviynt excels at bulk operations for users and requests, single-click approval of individual entitlements within a single request is not a typical supported feature due to the need for granular control and a clear audit trail. Bulk approvals usually apply to entire requests, not to individual entitlements within them.


Question 9

What does the following image signify?

Assigning of Enterprise Role based on a dynamic variable city.

Correct Answer: B. Assigning of Enterprise Role based on users' location
Explanation:

The image signifies B. Assigning of Enterprise Role based on users' location. Here's a breakdown, assuming the image depicts a portion of a Saviynt User Update Rule configuration:

Dynamic Variable 'City': The image highlights the use of a dynamic variable called 'city.' This strongly suggests that the rule is using the user's location (city) as a key factor in determining role assignment.

Saviynt's User Update Rules and Dynamic Variables: User Update Rules in Saviynt allow for the use of dynamic variables, which represent user attributes. These variables can be used in conditions and actions within the rule.

Enterprise Role Assignment: The context of the question implies that the rule is assigning an Enterprise Role based on the value of this 'city' variable.

Example: The rule might be configured to assign an Enterprise Role like 'Sydney-Users' to users whose 'city' attribute is 'Sydney.'

Why Other Options Are Less Likely:

A . Assigning of Enterprise Role based on users' department: There's no mention of 'department' in the provided information.

C . Assigning of Enterprise Role based on concatenation of dynamic variable city and Finance: While concatenation is possible in Saviynt, there's no indication that 'Finance' is involved here. The focus seems to be solely on the 'city' variable.

In conclusion: Based on the information given, the image most likely represents a Saviynt User Update Rule that assigns an Enterprise Role based on the user's location, as indicated by the dynamic variable 'city.


Question 10

An Application Owner Campaign can have multiple primary Certifiers and a single secondary Certifier.

Correct Answer: B. False
Explanation:

The statement 'An Application Owner Campaign can have multiple primary Certifiers and a single secondary Certifier' is generally False in Saviynt. Here's why:

Saviynt's Application Owner Campaign: This campaign type is designed for Application Owners to review and certify access to their applications.

Primary Certifier: There is usually a single designated Application Owner for each application. This is because application ownership is typically a single point of accountability. While it is technically possible to assign multiple owners, it is not considered a best practice.

Secondary Certifiers (Backup/Delegates): Application Owner Campaigns can have multiple secondary certifiers. These are often used as:

Backup: To ensure the campaign can proceed if the primary certifier is unavailable.

Delegates: To allow the primary certifier to delegate some of the certification tasks.

Consultants: Other stakeholders, such as security or compliance teams, who can be consulted during the decision-making process.

Why the Statement Is Generally False: The core principle of application ownership implies a single point of accountability. While multiple secondary certifiers can assist, having multiple primary certifiers can lead to confusion and conflicting decisions.

Possible Exceptions (Less Common):

Highly Customized Configurations: In some very specific scenarios, organizations might customize Saviynt to allow multiple primary certifiers for an application, but this is not a standard or recommended practice.