Is this a valid statement regarding role management?
Proposed Solution / Statement:
To test role membership criteria, it is best to keep the role in a disabled state and run a refresh.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement regarding access management valid?
Proposed Solution / Statement:
A reviewer can be required to provide a comment when rejecting a role request.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding uncorrelated accounts?
Proposed Solution / Statement:
An uncorrelated account can be sourced from both authoritative and non-authoritative sources.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about sources?
Proposed Solution / Statement:
A Delimited File Source can automatically aggregate from a file share.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about identity profile?
Proposed Solution / Statement:
Once users are assigned to an identity profile, administrators cannot modify or delete the identity profile.
Does this proposed solution meet the requirement / solve the scenario?
On 4 February 2021, the following error occurred on source Control Central of type Active Directory for identity Clarence.Harper:
Failed to update attributes. There is no such object on the server.
Is this a valid place to look for more information about what caused the error?
Proposed Solution / Statement:
In Identity Security Cloud go to search and query for:
type:event AND subtype:provision AND error:TRUE AND date: > =2021-2-4 AND identity:Clarence.Harper
Open the relevant result for more details.
Does this proposed solution meet the requirement / solve the scenario?
Is this a true statement regarding identity attribute mappings and identity profiles?
Proposed Solution / Statement:
Adding a custom attribute only applies to the identity profile on which it is defined.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement regarding access management valid?
Proposed Solution / Statement:
It is mandatory to make a role requestable.
Does this proposed solution meet the requirement / solve the scenario?
Assuming an access item's approval type is set to "reviewer," does the following statement accurately describe the approval flow behavior?
Proposed Solution / Statement:
When a governance group is set as an approver, the request is automatically approved if the requester is a member of that governance group.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement true regarding Identity Governance and Administration (IGA)?
Proposed Solution / Statement:
Implementing an IGA solution fully automates user access reviews, approvals, and audits.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding different account aggregation types true?
Proposed Solution / Statement:
Disabling optimization during aggregation forces the system to process all accounts.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario where a Separation of Duties policy should be used?
Proposed Solution / Statement:
A user requests a major system configuration and approves the change.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding authentication and authorization?
Proposed Solution / Statement:
Multi-Factor Authentication requires a user to provide 2 or more forms of verification.
Does this proposed solution meet the requirement / solve the scenario?
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"Separation of duties can be enforced using rules that can be configured in the system. These rules look for forbidden combinations of access owned by a single user. The rules can be used in a detective way, meaning actively searching for these forbidden combinations, or a preventative way, meaning that an extra validation step is made when a change in user access is requested."
Does this proposed solution meet the requirement / solve the scenario?
As part of the organization's update to its access request approval and notification process, does the following statement accurately reflect the global reminder and escalation policy?
Proposed Solution / Statement:
If reviewers do not complete their reviews within the specified timeframe, the request will automatically be escalated to a new reviewer; this escalation process can occur up to three times.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding attribute sync valid?
Proposed Solution / Statement:
Attribute sync can be enabled by going to Admin > Connections > Sources and selecting and editing the source.
Does this proposed solution meet the requirement / solve the scenario?
Review the following log entry:
[
{
"id": "2c9180866166b5b0016167c32ef31a66",
"name": "acme AD-TX Cluster",
"description": "acme AD - TX Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": null
},
{
"id": "2c9180846a93ce60016ab29f039944de",
"name": "acme AD-NY Cluster",
"description": "acme AD-NY Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": {
"clientId": null,
"durationMinutes": 60,
"expiration": "2025-12-15T19:13:36.079Z",
"rootLevel": "TRACE",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "TRACE"
}
}
}
]
A source owner for Active Directory has found problems with aggregation and has requested log files for their source.
Is this a valid way for the Administrator to assist in retrieving the correct logs?
Proposed Solution / Statement:
The following REST API call can be used to collect and export logs from the acme AD-NY Cluster:
GET https://acme.api.identitynow.com/v3/sources/2c9180846a93ce60016ab29f039944de/logs
Does this proposed solution meet the requirement / solve the scenario?
In order to secure access to the Identity Security Cloud (ISC) Tenant, the administrator wants to restrict access to the tenant to users in certain geographies and networks.
Is this a valid step towards performing this task?
Proposed Solution / Statement:
Admin has to first go to Identity Management, select an Identity Profile and choose the options under 'Block Access From'.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Cloud tenant is configured to disable all source accounts for an identity that enters the terminated lifecycle state. A database administrator reports they have been noticing that employees who are terminated, still have their database accounts as "Active" in the source system.
Is this a valid troubleshooting option for the scenario above?
Proposed Solution / Statement:
On the Identity, validate that the Lifecycle State attribute value that is set for the affected users is "Terminated".
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario for reviewing access requests in the approval management page?
Proposed Solution / Statement:
It is possible for an administrator to supersede an approver's cancellation of a request.
Does this proposed solution meet the requirement / solve the scenario?
The security team has asked for a technical briefing on how authentication works with SailPoint.
Does the following statement correctly describe authentication methods in SailPoint and industry standards?
Proposed Solution / Statement:
When configuring SAML authentication in SailPoint, the Entity ID must exactly match the SAML metadata EntityID supplied by the identity provider for successful federation.
Does this proposed solution meet the requirement / solve the scenario?
Is the following true regarding User Levels and permissions?
Proposed Solution / Statement:
Role Admin and Source Sub-Admin can be granted to an identity at the same time.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Administrator received a request to audit a distribution list on a monthly cadence.
Place the following steps in the correct order in order to accomplish this task:

Is this a valid statement regarding role management?
Proposed Solution / Statement:
Adding an entitlement to an existing role provisions an entitlement on all the identities that are currently a member of the role.
Does this proposed solution meet the requirement / solve the scenario?
Regarding the Access Certification Process, is the following statement valid?
Proposed Solution / Statement:
A sign-off page becomes visible only after the reviewer has completed all required decisions.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding access request approval processes?
Proposed Solution / Statement:
In a governance group approval process, the majority of the members must approve before the access is granted to the requester.
Does this proposed solution meet the requirement / solve the scenario?