Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Saviynt Certified Advanced IGA Professional (Level 200) SCAIP Exam Questions

Page: 1 / 6 Total 60 questions

Want more questions? Get Premium Access.

Question 1

In EIC Duplicate Identity Management, what are the different filter options available in Global Configurations? (Multi-Select)

Correct Answer: A. Coarse Matching; C. Fine Matching
Explanation:

In Saviynt EIC'sDuplicate Identity Management (DIM), Global Configurations provide filtering mechanisms to identify potential duplicate identities efficiently. The two primary matching strategies used areCoarse MatchingandFine Matching, which together form the backbone of duplicate detection logic.

Coarse Matching (A)is used as an initial filtering mechanism. It applies broader criteria such as matching on common attributes like first name, last name, or email domain to quickly identify a pool of potential duplicate identities. This helps in reducing the dataset size before applying more detailed checks.

Fine Matching (C)is a more refined and precise comparison that evaluates stricter conditions such as exact matches on email ID, employee ID, or other unique identifiers. This step ensures higher accuracy in identifying true duplicates from the coarse match results.

Option B (Identity Matching) is not a standard configurable filter in DIM Global Configuration, and Option D (Merger Query) relates to post-identification actions rather than filtering criteria.

Thus, the correct answers areCoarse Matching and Fine Matching, which together enable effective duplicate identity detection.


Question 2

What is the use of the Show XML option in a workflow?

Correct Answer: D. It enables users to open and view the Workflow XML script in a read-only mode
Explanation:

In Saviynt EIC, workflows are internally represented inXML format, which defines the sequence of approval steps, conditions, and actions. The''Show XML''option is specifically designed to allow administrators toview the underlying XML structure of a workflow. However, this view is provided in aread-only mode, meaning administrators can inspect the configuration but cannot directly modify it from this option.

This feature is particularly useful fordebugging, auditing, and understanding workflow logic, especially in complex approval processes involving multiple steps and conditions. It helps administrators verify how a workflow is constructed without risking accidental changes to the configuration.

Option C is incorrect because editing workflow XML is not typically done directly through the ''Show XML'' view in Saviynt UI; modifications are handled through workflow configuration screens or controlled import/export processes. Option A is unrelated since Saviynt workflows are XML-based, not JSON-based. Option B is also incorrect because version history is managed separately and not through the Show XML option.

Thus, the correct purpose of ''Show XML'' is toview workflow configuration safely in read-only format.


Question 3

An EIC Administrator has a requirement to filter the list of roles based on user location, for example: A user from country A should be able to request only roles for country A. What configuration administrator can use here?

Correct Answer: B. Global Configuration -> Role Request Query
Explanation:

In Saviynt EIC, the correct configuration for controlling which roles appear in the Access Request screen is theRequest Roles Query / Role Request QueryunderGlobal Configuration. Saviynt's official documentation forConfiguring Role Requestsstates that this setting is used tospecify a query to control the display of roles in Access Request, meaning only roles returned by that query are shown to the requester. That is exactly the use case in this question: filtering the visible role list by a user attribute such as country or location. A query can be written so that users from Country A see only the roles mapped for Country A.

The other options are not correct in this context.SAV Rolecontrols administrative UI permissions in Saviynt, not end-user role catalog filtering.Role Configuration -> User Queryis not the standard setting used to drive request-time role visibility for this scenario. Option D is incorrect because Saviynt explicitly supports this use case through the Request Roles Query capability.


Question 4

In EIC Service Account Management, when the current owner is terminated, how does EIC identify the new owner?

Correct Answer: B. The new owner is defined in the current owner's user attribute: 'Owner On Terminate'
Explanation:

In Saviynt EIC,Service Account Managementincludes mechanisms to ensure continuity of ownership when an account owner leaves the organization. When a user is terminated, the system automatically determines the new owner based on a predefined configuration.

The correct approach is through theuser attribute ''Owner On Terminate''(Option B). This attribute is maintained at the user level and specifies who should inherit ownership of service accounts if the current owner is terminated. During the termination process, Saviynt checks this attribute and transfers ownership accordingly, ensuring there is no orphaned service account and maintaining accountability.

Option A is incorrect because SQL queries in Global Configuration are not typically used for ownership reassignment in this context. Option C (Manage Owners Page) is used for manual updates, not automatic reassignment upon termination. Option D is incorrect because the ownership transfer logic is driven by theuser attribute, not a service account attribute.

Thus, using the''Owner On Terminate'' user attributeensures automated, policy-driven ownership transitions in Saviynt.


Question 5

Schema based account import job failed with Schema definition file not found and No SAV file found. Which of the following could be the possible reasons for the same? (Multi-Select)

Correct Answer: A. SAV file with .sav extension is missing in the File Directory -> SAV files location; D. SAV file format is incorrect
Explanation:

In Saviynt EIC, schema-based account import jobs rely heavily on theSAV file, which acts as the schema definition for interpreting incoming data. The error message''Schema definition file not found and No SAV file found''specifically indicates that Saviynt is unable to locate or process the required SAV file.

Option Ais correct because the SAV file must be placed in the designatedFile Directory SAV files location. If the file is missing from this directory, the system cannot read the schema definition, resulting in job failure.

Option Dis also correct because even if the SAV file is present, anincorrectly formatted or corrupted SAV filewill prevent Saviynt from parsing it properly, leading to the same error.

OptionBis incorrect since SAV files are not expected in the Data files directory. OptionCis unrelated to this specific error, as missing CSV files would generate a different error related to missing data, not schema definition.

Thus, the issue is specifically tied to missing or invalid SAV schema files.


Question 6

Administrator created a custom SAV role, ROLE_CUSTOM_READ, with the "Read Only" option set to true. If the user is assigned both ROLE_ADMIN and ROLE_CUSTOM_READ, what actions can the user perform?

Correct Answer: D. User will have full view/edit access as user is part of ROLE_ADMIN
Explanation:

In Saviynt EIC,SAV Roles are additive in nature, meaning that when a user is assigned multiple roles, the system grants theunion of all permissionsacross those roles. There is no restrictive override where one role limits another; instead, the highest level of access prevails.

In this scenario, the user is assigned bothROLE_ADMINandROLE_CUSTOM_READ (Read Only). While ROLE_CUSTOM_READ restricts access to read-only, theROLE_ADMIN role provides full administrative privileges, including both view and edit capabilities across modules.

Saviynt does not enforce precedence based on role assignment order, nor does a read-only role override an admin role. Instead, permissions are cumulative, and the most permissive access is effectively granted.

Therefore,Option Dis correct: the user will havefull view and edit accessbecause ROLE_ADMIN includes comprehensive permissions that supersede the limitations of the read-only role.

This behavior ensures flexibility in role assignments but also requires careful governance to avoid over-provisioning of administrative access.


Question 7

What are the different actions supported by User Update rule?

Correct Answer: D. All the above
Explanation:

In Saviynt EIC,User Update Rulesare powerful automation mechanisms used to perform actions based on user attribute changes or conditions defined through SQL queries. These rules support multiple actions that help streamline identity lifecycle management.

Option A is correct because User Update Rules cantrigger Technical Rules, enabling further downstream processing such as provisioning, deprovisioning, or executing custom logic. This allows modular and scalable automation.

Option B is also valid since User Update Rules can be used togenerate usernames dynamicallybased on defined patterns or business logic, especially during onboarding or identity updates.

Option C is correct as well because these rules supportsending email notifications, which can be used for alerts, approvals, or informing stakeholders about identity changes.

Since all these actions are supported within User Update Rules, Option D (All the above) is correct. This highlights the flexibility of User Update Rules in handling automation, communication, and identity data transformations within Saviynt EIC.


Question 8

What parameters are necessary for configuring acctEntMappings in the REST Connector? (Multi-Select)

Correct Answer: A. listPath; B. idPath; C. keyField
Explanation:

In Saviynt REST connector configuration,acctEntMappingsis used to define how account-entitlement relationships are extracted and mapped from the target system response. This configuration is critical when importing entitlements associated with accounts, such as groups, roles, or permissions.

The required parameters for configuring acctEntMappings includelistPath, idPath, and keyField.listPath (Option A)specifies the JSON path where the entitlement list is located within the API response. This allows Saviynt to identify the array or collection containing entitlement data.idPath (Option B)defines the unique identifier for each entitlement within that list, ensuring proper tracking and mapping.keyField (Option C)is used to associate the entitlement back to the account, effectively linking account and entitlement records.

OptionD (accountID)is not a valid parameter within acctEntMappings configuration. While account identifiers are important in overall mapping, acctEntMappings specifically uses keyField instead of accountID to establish relationships.

Thus, the correct parameters required for acctEntMappings are listPath, idPath, and keyField, as per Saviynt REST connector configuration standards.


Question 9

In the Saviynt App for ServiceNow, what options are available to refresh the RITM status in the ServiceNow app based on the respective Saviynt's status? (Multi-Select)

Correct Answer: B. Click Refresh button on the RITM page in ServiceNow; C. It will be automatically updated in 1 minute via Request item history job in ServiceNow
Explanation:

In Saviynt--ServiceNow integration, the synchronization ofRITM (Request Item) statusbetween Saviynt and ServiceNow is handled through bothmanual and automated mechanisms.

Option B is correct because users or administrators can manuallyclick the Refresh button on the RITM page in ServiceNowto immediately fetch the latest status from Saviynt. This is useful for real-time validation when monitoring request progress.

Option C is also correct as ServiceNow includes aRequest Item History Job, which runs periodically (commonly every minute) to automatically sync and update the RITM status based on the latest state in Saviynt. This ensures near real-time consistency between both systems without manual intervention.

Option A is incorrect because Postman API calls are not a standard or supported operational method for end users to refresh RITM status. Option D is unrelated, as regenerating catalog items does not impact ticket status synchronization.

Thus, the correct answers aremanual refresh and automated job-based synchronization.


Question 10

Which of the following scenarios are True to trigger Technical Rule Execution in EIC? (Multi-Select)

Correct Answer: B. When users are imported through Import Job and the condition in the rule matches; C. A new user is registered or created from the UI and the condition in the rule matches; D. The existing user is updated and satisfies a user update rule with action as Re-run provisioning rules
Explanation:

In Saviynt EIC,Technical Rulesare triggered based on lifecycle events related to user creation, updates, and imports, provided the defined conditions evaluate to true. The correct answers areB, C, and D.

Option Bis correct because duringImport Jobs, when users are brought into Saviynt from authoritative sources, Technical Rules are evaluated, and if conditions match, they are executed. This is a common mechanism for provisioning access during onboarding.

Option Cis also correct since when anew user is created via the UI, Technical Rules can be triggered if the user attributes meet the rule conditions. This ensures consistent provisioning regardless of how users are created.

Option Dis correct because when anexisting user is updated, and a User Update Rule is configured tore-run provisioning rules, it can trigger associated Technical Rules again.

Option Ais incorrect because deletion events typically trigger deprovisioning workflows rather than standard Technical Rule execution.

Thus, Technical Rules are triggered during import, creation, and update events---not deletion.