Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sailpoint-Full

Total questions: 259

Worksheet time: 54mins

Name
Class
Date
1.

Is the following statement a true statement about IdentityIQ authentication and authorization?

Option: User can have only authorized scopes

a)
Correct
b)
InCorrect
2.

An engineer is developing an instance of IdentityIQ using the Service Standard Build (SSB) for a client; Is this a valid action the engineer can perform when setting up or using SSB?

Option A: Tokenize text in the XML object that may differ between environments

a)
Correct
b)
InCorrect
3.

An engineer is developing an instance of IdentityIQ using the Service Standard Build (SSB) for a client; Is this a valid action the engineer can perform when setting up or using SSB?

Option B: Place any main identityiq installation zip file in the build’s base/ga folder

a)
Correct
b)
InCorrect
4.

Is this what should be performed in order to generate the database script to extend Managed Attributes in the IdentityIQ database on the initial installation?

Option A: Run the command iiq schema in the IIQ_HOME/WEB-INF/bin directory

a)
Correct
b)
InCorrect
5.

An implementation engineer needs to perform an upgrade of IdentityIQ between releases. Is the following statement true?

Option: Any e-fixes must be removed from the build process as part of an upgrade

a)
Correct
b)
InCorrect
6.
An engineer is assigned to configure an identity attribute, the requirements are: Purpose: Add a user’s security clearance to their identity Read From: Workday, if not found in Workday, Contractor file, otherwise, leave empty Usage 1: Display as an option in Advance Analytics Usage 2: Use when writing rules Usage 3: Can be updated through the Edit Identity Quicklink, but Workday is authoritative (authoritative means that values should be overridden from your source application, even if the value is changed manually in the iiq) Usage 4: List as an entitlement on Identity Cube Does the engineer need to set this configuration option on the identity attribute to meet the requirements?
a)
Option A: Multi-Valued
b)
Option B: Edit Mode - Temporary
c)
Option C:Searchable
d)
Option D: Group Factory
7.
Is this where email templates that ship with the product can be located?
a)
Option A: [IdentityIQ Installation Directory]\WEB-INF\classes
b)
Option B: [IdentityIQ Installation Directory]\WEB-INF\config
8.
Is this a correct procedure for testing generated emails in a non-production system?
a)
Option A: change the E-mail Notification Type to Redirect to file using FTP protocol under Global Settings --> Configure IdentityIQ Settings --> Mail Settings, run the test scenario, and verify that the email text save to the re-directed file
b)
Option B: Change the Email Notification Type to Redirected to file under Global Settings --> Configure IdentityIQ Settings --> Mail Settings, run the test scenario (policy, certification etc.), and verify that the email text was written to the redirected file
9.
Is this a valid step to take when importing SailPoint XML file objects into IdentityIQ?
a)
Option A: when using the Service Standard Build, place all XML objects to be imported into config folder and run build importdynamic
b)
Option B: Move the XML file into the IIQ_HOME\WEB-INF\database
c)
Option C: select the file from Global Settings à import From File
10.

An implementation engineer needs to perform an initial installation of IdentityIQ. Drag the options from the left into the answer area on the right and place them in the correct order:

1. Initialize default IdentityIQ system objects from, iiq console using the “import” command (init.xml etc)

2. Update all necessary Hibernate XML files to include custom attributes

3. Un-jar the IdentityIQ WAR file in the desired directory of each application server

4. Generate database schema to include custom attributes by executing iiq schema

5. Start the application server

6. Create IdentityIQ database

7. Apply the patch

a)
3,2,6,4,1,5,7
b)
3,1,5,6,4,2,7
c)
3,2,4,1,6,5,7
d)
5,1,6,3,2,4,7
e)
3,2,4,6,1,5,7
11.
An IdentityIQ engineer needs to extend attributes in an IdentityIQ database after the database has been created. What are the four minimum steps necessary to achieve this goal?
4 lines
12.
IdentityIQ is using emails to notify users about completion of steps within a process, or actions that need to be addressed. To ensure this notification is working, a mail configuration must be set up in IdentityIQ to provide mail server and mail server authentication details. Is this a required setting that an engineer must setup in IdentityIQ in order to ensure successful communication with the SMTP server?
a)
Option A: Email Protocol
b)
Option B: SMTP Port
c)
Option C: Sender Certificate
13.
IdentityIQ has been installed and setup with the contents of identityExtended.hbm.xml as follows: <IdentityExtended.hbm> file Is this a correct statement about the installation?
a)
Correct
b)
InCorrect
14.
Is this statement true about the IdentityIQ Login configuration?
a)
Option A: IdentityIQ can be configured to enable authorization lockout to the Pass-Through Authentication Application
b)
Option B: Self-Service Password Reset must make use of the configured Pass-Through Authentication Application
15.
It is impossible to have more than 20 extended attributes withing IdentityIQ?
a)
Correct
b)
InCorrect
16.
When you add extended attributes that are not marked searchable to IdentityIQ, where are these new attributes stored by default?
a)
Column in the database
b)
in tomcat
c)
WEB-INF directory
d)
In a CLOB
17.
Before you login to IdentityIQ using your browser, the application server must be running
a)
Correct
b)
InCorrect
18.
The terms Identity Attributes and Account Attributes refer to the same thing
a)
Correct
b)
InCorrect
19.
When an attribute is marked as “searchable”, what does this mean?
a)
1. The attribute is available for groups to be created from its values
b)
2. The attribute is stored in its own column for more efficient access for searching
c)
3. The attribute is stored in the CLOB for more efficient access for searching
20.
What are batch request typically used for within IIQ?
a)
1. Bulk loading identities or identity updates
b)
2. Logging the activity of many identities or accounts
c)
3. Triggering aggregation/refresh tasks for many identities or accounts
21.
What is a capability in IIQ?
a)
1. What a user can do within the HR system from which IIQ aggregate authoritative accounts.
b)
2.     The responsibilities the user has within the organization e.g. accounting
c)
3. Quicklinks a user has access to and how the Quiklinks is configured
d)
4. The rights a user has within IIQ
22.
Which is NOT a valid method for creating Identity Cubes?
a)
1. LCM Create Identity
b)
2. Through Identity Warehouse
c)
3. By running the aggregation tasks to read user accounts from app that are systems of records e.g. HR
d)
4. Bulk Import
23.

(a)   defines which areas of the UI a user can access withing IIQ?

24.
Using extended attributes and loading their data up front can significantly simplify rule creation
a)
Correct
b)
InCorrect
25.
Any role or entitlement attribute marked as searchable, including extended attributes you define for your own installation, can be used for filtering the list
a)
Correct
b)
InCorrect
26.
Does the iiq schema or extendedSchema will have version number in the file name generated?
a)
Correct
b)
InCorrect
27.
Where is the hibernate files located?
a)
identityiq/WEB-INF/classes/sailpoint/object
b)
identityiq/WEB-INF/classes/
c)
identityiq/WEB-INF/classes/sailpoint/hibernate
d)
identityiq/WEB-INF/classes/sailpoint/database
28.
iiqSchema will generate which files?
a)
Create
b)
Drop
c)
Update
d)
Add
29.
iiqExtendSchema will generate which files?
a)
Create
b)
Drop
c)
Update
d)
Add
30.
Where are database scripts files generated or present?
a)
/identityiq/WEB-INF/sailpoint/database
b)
/identityiq/WEB-INF/classes/database
c)
/identityiq/WEB-INF/database
d)
/identityiq/WEB-INF/sailpoint/object/database
31.
When setting up “Redirect to email”, it will require to provide SMTP information i.e. SMTP port, username, password etc. and also the target email address to which all the email will be sent?
a)
Correct
b)
InCorrect
32.
Can you use the “Redirect to Email” to check the email formatting and look i.e. html, header, footer etc. in non-production environment?
a)
Correct
b)
InCorrect
33.
You cannot check the formatting when using “Redirect to File” in non-production testing
a)
Correct
b)
InCorrect
34.
“SMTP” is for production so that email sent to intended recipient
a)
Correct
b)
InCorrect
35.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ? Option: When the application server is running use the Reload Logging Configuration option on the Debug Logging page to load updates made to the log4j.properties file
a)
Correct
b)
InCorrect
36.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ?Option: When creating a new object through the Debug-Object page, IDs, are automatically generated when the object is saved
a)
Correct
b)
InCorrect
37.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ? Option: The “spadmin” identity can be deleted from the Debug-Object page
a)
Correct
b)
InCorrect
38.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ? Option: All users can access the Debug Object page
a)
Correct
b)
InCorrect
39.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ? Option: The Debug-Logging page does not have to be reloaded when the log4j files is altered while the application server is running
a)
Correct
b)
InCorrect
40.
Is this statement valid regarding the control and useability of the Debug pages in IdentityIQ? Option: All objects can be searched by their ID
a)
Correct
b)
InCorrect
41.

The JVM Memory page on the IdentityIQ displays the following information:

Free Memory 631.579 MB (out of point int time memory, this much is free)

Total Memory 845.657 MB (this is point in time memory that is currently in use)

Max Memory 2610.251 MB (this is the max memory that can be allocated)

(a)  

42.

Is this statement true about IdentityIQ’s syslog event searching capabilities?

Option: It is not possible to use more than two filters at a time when searching the syslog events from the Advance Analytics page

a)
Correct
b)
InCorrect
43.

Is this statement true about IdentityIQ’s syslog event searching capabilities?

Option: When searching the syslog events from the Advance Analytics page, a syslog can be filtered by Start Date and End Date

a)
Correct
b)
InCorrect
44.

Is this statement true about IdentityIQ’s syslog event searching capabilities?

Option: It is possible to search the Syslog events using an incident Code from Advance Analytics page

a)
Correct
b)
InCorrect
45.

Can the Provisioning tab under Administrator Console be used to do the following tasks?

Option: View the Request Message queue for the request associated to provisioning transactions

a)
Correct
b)
InCorrect
46.

Is this a benefit of using the Run Rule feature of the Debug-Object page?

Option: It can be used to display the return value of simple code

a)
Correct
b)
InCorrect
47.

Is this a benefit of using the Run Rule feature of the Debug-Object page?

Option: It can be used to update objects in the Services Standard Build (SSB)

a)
Correct
b)
InCorrect
48.
What four steps are necessary for turning on Certification logging at the severity log level of trace? Change the log level to trace and save Edit the file [IdentityIQ-Installation]  WEB-INF  Classes  log4j.properties Restart application server
a)
1,2,3
b)
1,3,2
c)
2,1,3
d)
3,1,2
49.
What are the different System Cache options available to admins?
a)
Reset Miscellaneous Caches
b)
Reset Managed Attribute Cache
c)
Load Managed Attribute Cache
d)
Dump Managed Attribute Cache
e)
Reset IntegrationConfig Cache
50.
It is a best practice to use Java println statements for logging?
a)
Correct
b)
InCorrect
51.
Which of the following log level will provide the most detailed information?
a)
Error
b)
Warn
c)
Info
d)
Debug
e)
Trace
52.
From the Administrator Console, you can view details about the failed provisioning attempts, and create a manual work item to complete the request?
a)
Correct
b)
InCorrect
53.
IdentityIQ can only monitor for password changes request originating from IIQ?
a)
Correct
b)
InCorrect
54.
What does the “-clean” option do when exporting objects?
a)
It deletes all passwords from the exported object.
b)
It creates an empty object of the type being exported
c)
Removes the Object completely from the existing IIQ database in preparing for loading it into the next database
d)
It removes the GUID and creation/modification dates from the Object being exported
55.
When a serious system error occurs, and an incident code is displayed, where would an admin user go to see details of the error?
a)
Java Standard Out Log
b)
Intelligence à Advanced Analytics à Syslog Search
c)
Setup à Lifecycle Events
d)
My work à Work Items
56.
The console commands export and checkout can both be used to export IIQ objects into XML format
a)
Correct
b)
InCorrect
57.
Is this an example of a leaver lifecycle event? Option: A contractor whose contract expire and account were disabled has a new contract with the company, the contractor needs all of the previous accounts enabled
a)
Correct
b)
InCorrect
58.
Is this an example of a leaver lifecycle event? Option: An employee, who has not previously been with the company, is hired and needs all new access and new accounts for company systems
a)
Correct
b)
InCorrect
59.
Is this an example of a leaver lifecycle event? Option: An employee previously left the company, their access was disabled but has been re-installed, the employ needs all of their previous accounts enabled
a)
Correct
b)
InCorrect
60.
Is this an example of a leaver lifecycle event? Option: An employee left the company all of their access must be revoked, and all accounts must be disabled
a)
Correct
b)
InCorrect
61.

An organization is making a change at the regional level. Many users of financial system have incorrect entitlements, some user are missing entitlements, and some users have excess entitlements. Work needs to be done to perform to clean up access. Is this one of the IdentityIQ batch request types that can help meet this goal?

Option: Add Entitlement

a)
Correct
b)
InCorrect
62.
Can this be achieved using Rapid Setup user interface configuration options? Option: Disable an account on a particular application and delete 30 days later during Movers events
a)
Correct
b)
InCorrect
63.

Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?

Option: An Identity correlated

a)
Correct
b)
InCorrect
64.

Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?

Option: An identity provisioning plan has failed to provision

a)
Correct
b)
InCorrect
65.

Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?

Option: A new change occurs

a)
Correct
b)
InCorrect
66.

A client needs a custom quicklink, which only manager can launch, in order to launch a simple work workflow. Is this a valid step to take during the development of the custom quicklink?

Option: Set the category of the quicklink object to a valid category name

a)
Correct
b)
InCorrect
67.

Can the following be achieved via configuration of control variables in the out-of-the-box LCM?

Option: Check if an access request would violate any policies, and allow the requester to review before submitting

a)
Correct
b)
InCorrect
68.

Is this a default functionality of the Lifecycle Manager (LCM) module?

Option: Create Identity

a)
Correct
b)
InCorrect
69.

Is this a default functionality of the Lifecycle Manager (LCM) module?

Option: Edit Identity

a)
Correct
b)
InCorrect
70.

Is this a default functionality of the Lifecycle Manager (LCM) module?

Option: Terminate identity

a)
Correct
b)
InCorrect
71.

A client wants user who belong to an IdentityIQ workgroup name Management to be able to request entitlements and role, but only for other users whose location attribute is the same as theirs.

Is this population that will achieve this goal?

Option: Create identities population, set the attribute match the and set ------ and use “who can members request for as same attribute with the requester, with attribute set to location

a)
Correct
b)
InCorrect
72.

For a user who already has an account on an application and want to be able to request access to a new account through “Manage User Access”, does this configuration need to be performed in LCM?

Option: Select the Enable Account Group management option in the LCM

a)
Correct
b)
InCorrect
73.

For a user who already has an account on an application and want to be able to request access to a new account through “Manage User Access”, does this configuration need to be performed in LCM?

Option: Select allow requesting new account on the Manage Accounts Quicklink configuration for the user’s Quicklink population

a)
Correct
b)
InCorrect
74.
Is the following true of identity Provisioning Polices? Option: An installation can define multiple Create Identity Provisioning Policies to support creation of different classification of users e.g. Employee, Contractors, services, employees in different regions etc.
a)
Correct
b)
InCorrect
75.

Is the following true of identity Provisioning Polices?

Option: Identity Provisioning Policies can be used to include allowed-values definitions or validation logic on fields so that only valid/authorized values can be specified for those fields when using the Create Identity feature to add an identity.

a)
Correct
b)
InCorrect
76.
In an identity refresh task, does Process Events enable event certifications (access added, removed etc) and lifecycle events (leaver, joiner and mover)?
a)
Correct
b)
InCorrect
77.
On a per Quicklink population basis, a rule can be implemented to constrain what members can request?
a)
Correct
b)
InCorrect
78.
A Quicklink population allows you to define a set of users who can make access requests for other set of users
a)
Correct
b)
InCorrect
79.
Quicklink behaviour can be configured per quicklink population
a)
Correct
b)
InCorrect
80.
All identities details options are controlled by their corresponding quicklink population settings
a)
Correct
b)
InCorrect
81.

Select the method(s) that can disallow users from deleting their accounts on connected systems:

Option: Remove access to the manage account quicklink for the self service quicklink population

a)
Correct
b)
InCorrect
82.

Select the method(s) that can disallow users from deleting their accounts on connected systems:

Option: In the LCM configuration disallow the delete option for the my actions category of user

a)
Correct
b)
InCorrect
83.
Password policies must be defined for each application for which managing password is supported
a)
Correct
b)
InCorrect
84.
The Process Events option directs IIQ to initiate the lifecycle event workflows
a)
Correct
b)
InCorrect
85.
In the aggregation/refresh process, Lifecyle events can be launched when a data change is detected during aggregation. Which option on the refresh task causes the refresh to trigger the lifecycle event workflows?
a)
a. The provision assignments
b)
b. Process events
c)
c. Check active policies
d)
d. Refresh assigned, detected roles and promote additional entitlements
e)
e. Refresh identity attributes
86.
You can use an Advance Analytics audit search to view details about past lifecycle events
a)
Correct
b)
InCorrect
87.
You can specify multiple triggers for the mover lifecycle event, for example, watching for changes in job title, department, or manager
a)
Correct
b)
InCorrect
88.
You can use the Edit Identity Quicklink to modify an identity’s attributes and trigger attribute synchronization to other application?
a)
Correct
b)
InCorrect
89.
Lifecyle Events can be created based on native changes. What is native change?
a)
a.     A change detected stemming from a rule
b)
b.     A change detected during application aggregation
c)
c.     A change detected in identity attributes
90.
In the standard IdentityIQ access request workflow (LCM Provisioning), the default approver is the owner?
a)
Correct
b)
InCorrect
91.
The only users who can track an access request are the requesters themselves?
a)
Correct
b)
InCorrect
92.
Rapid Setup Joiner configuration defines the operations that are launched when a user joins a new group within your organization, such as department transfer
a)
Correct
b)
InCorrect
93.
Identity Cubes only store data that has been discovered during aggregation or requested via lifecycle manager
a)
Correct
b)
InCorrect
94.
Workflows and provisioning policies are configured per quicklink population
a)
Correct
b)
InCorrect
95.
A quicklink population allows you to define a set of users who can make access requests for other sets of users
a)
Correct
b)
InCorrect
96.
Through the Mange User Access quicklink, a user can disable or enable their account on a connected application
a)
Correct
b)
InCorrect
97.
Is this a true statement about localization support in IdentityIQ? Option: By default all out-of-the-box languages for object description are enabled
a)
Correct
b)
InCorrect
98.
Is this a true statement about localization support in IdentityIQ? Option: The language displayed in the user interface is always based on the default language selected in the global settings
a)
Correct
b)
InCorrect
99.

The engineer needs to write some ad-hoc BeanShell code to search for Bundle (role) objects owned by James.Smith, and print their names, is this BeanShell Code correct as written?

Option:

Import sailpoing.object.Application;

Import sailpoint.object.Filter;

Filter filter = Filter.eq(“owner.name”, “James.Smith”);

Iterator itetrator = context.search(Bundle.class, filter, “name”);

While(iterator.hasnext()) {

Object[] data = iterator.next();

String item = (String) data{0};

System.out.println(item);

}

a)
Correct
b)
InCorrect
100.

The engineer needs to write some ad-hoc BeanShell code to search for Bundle (role) objects owned by James.Smith, and print their names, is this BeanShell Code correct as written?

Option:

Import sailpoint.object.*;

Filter filter = filter.eq(“owner.name”, “James.Smith”);

QueryOptions qo = new QueryOptions();

Qo.addFilter(filter);

Iterator iterator = context.search(Bundle.class, qo, “name”);

While (iterator.hasnext()) {

Object[] item = iterator.next();

Println((String) item[0]);

}

a)
Correct
b)
InCorrect
101.

Is the following statement about IdentityIQ rule inputs and outputs correct?

Option: for ease of implementation, all BeanShell rules in IdentityIQ have the same input and output variables

a)
Correct
b)
InCorrect
102.

Option:

for (int i = 0; j < this.variable.lenth; i++){

String name = this.variables[i];

Object value = eval(name);

If (value == void) Println(name + “ : void” );

Else if (value == null) Println (name + “ : null”);

Else Print(name + “ : “ + value.getClass().getSimpleName() + “ : “ + value);

}

This code can be used for debugging to find all available variables for a BeanShell rule?

a)
Correct
b)
InCorrect
103.

Can the rule library name “Common Rules Library” be included in a Rule by adding this code?

<ReferenceRules Class=”sailpoint.object.Rule” name=”Common Rules Library”> </ReferenceRules>

a)
Correct
b)
InCorrect
104.

Is the following statement about workflows and sub-workflows (sub-process) true?

The output values of a sub-workflows must be explicitly defined by using return argument to return them to variables in the calling workflow.

For example: <Return name=”IdentityRequestId” to “IdentityRequestId” />

a)
Correct
b)
InCorrect
105.

The engineer is working on a workflow implementation.

After a form step, the workflow can transition to three steps;

• Stop if the Reject (back) button is used

• Audit of the Approve (next) button is used and field name comments is returned from the form to the workflow variable comment and have a value,

• Provision otherwise The engineer writes the transitions in XML code.

Is this a valid implementation?

<transition>

<source> If (!approved) return “Stop”;

If (comment) return “Audit”; Return “Provision”;

</source>

</transition>

a)
Correct
b)
InCorrect
106.

A step in Workflow needs to be added for user interaction. Can the ManualAction Workitem type be used in the following scenario?

Option: An administrator needs to indicate that the provisioning of a request has been complete

a)
Correct
b)
InCorrect
107.

Is the following statement about workflow steps type and their usage true?

Option: Place holder steps must have attributes posx and posy to hold their place

a)
Correct
b)
InCorrect
108.

A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?

Option: A best practice is to make all style change in the common.css file

a)
Correct
b)
InCorrect
109.

A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?

Option: Text on the login page is set through message keys in the messages catalog

a)
Correct
b)
InCorrect
110.

A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?

Option: The original HTML file updated to change the settings

a)
Correct
b)
InCorrect
111.

A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?

Option: The icons used to represent roles can be replaced

a)
Correct
b)
InCorrect
112.
Implementers can add custom business logic to Identity IQ using what functionality?
a)
Access Review
b)
Rules
c)
Work Items
113.
Provisioning plans are passed to tasks to implement the provisioning
a)
Correct
b)
InCorrect
114.
What is a workflow case?
a)
The object that represent a running instance of a workflow
b)
The object assigned to a user by the workflow when the workflow require input from a user (ManualItem)
115.
What is the difference between a task and a workflow?
a)
a.     They can be used interchangeably, but task is pre-compiled and a workflow is interpreted
b)
b. A task can interact with a user and is typically activated in response to a user action or data changes; a workflow performs batch process and it can be scheduled
c)
c. A task performs batch processing and it can be scheduled; a workflow can interact with a user and is typically activated in response to a user action or data change
116.
Provisioning plan is passed to a workflow to start the provisioning process. What is included in provisioning plan?
a)
a.     One or more requests for one identity
b)
b.     One request for multiple identities
c)
c.     One or more requests for multiple identities
d)
d.     A set of provision policies
117.
Once workflow has been launched, what is the name of the object that represent the execution of the workflow?
a)
.a. SailPoint Context
b)
b. UI Config
c)
c. Workflow
d)
d. Workflow Case
118.
Which of these arguments are automatically provided to all rules and scripts? – choose all that apply
a)
a. currentUSer
b)
b. context
c)
c. application
d)
d. config
e)
e. log
119.
How can you add a BeanShell rule to IdentityIQ? Choose all that apply
a)
a. Wrap the BeanShell logic in a Rule XML object and import it
b)
b. Enter and save the BeanShell logic through a Rule Editor UI page
c)
c. Compile and deploy it into a rule library
d)
d. Type the BeanShell logic into the IdentityIQ Console
120.
When you need to access data stored in IdentityIQ’s database in your rule and script extensions, you will write SQL statements to query the tables that hold the data
a)
Correct
b)
InCorrect
121.
Which of these methods is helpful for viewing the full contents of any SailPointObject and is often used in develop process for debugging purposes? Choose one
a)
a. toXML()
b)
b. viewObject()
c)
c. getAllAttributes
122.
Which one of these SailPoint Context methods supports a projection query, providing for better memory management efficiency?
a)
a. getObject()
b)
b. search
c)
c. query
d)
d. getObjectById
123.
Which of these functions does a QueryOptions provide in a search operation? Choose all that apply
a)
a. Distinct Search
b)
b. Ordering
c)
c. Filtering
d)
d. Result limit set
124.
-- Identity objects contain attributes that allow you to directly connect to the user’s account, represented as Link objects, or assigned or detected roles, represented as Bundle objects, through the API
a)
Correct
b)
InCorrect
125.
Which of these objects represent an entitlement in the Entitlement Catalog?
a)
a. Managed Attributes
b)
b. Certification Item
c)
c. Bundle
d)
d. Provision Plan
126.
It’s a good idea to call context.decache periodically to clear objects you are no longer using in your code. This method leaves any open database cursor intact, so it is safe to do inside a loop you are using to process through an iterator from a search
a)
Correct
b)
InCorrect
127.
Which of these is the best choice for logging in BeanShell rules, for giving you the most granular control on when and where the systems writes messages to your log files?
a)
a. Define custom logger in your rule and configure it’s log level in the log4j properties file
b)
b. Use the log variable that is passed to the rule automatically and control it’s log level in the log4j.properties file
c)
c. Write System.out.prinln statements in your rule logic and turn them on and off through system configuration
128.
The Services Standard Build (SSB) is:
a)
a.     A basis for deploying IIQ, however it is mostly incomplete
b)
b.     A tool for generating custom workflows within IIQ
c)
c.     A deployment process provided by SailPoint that is required when deploying IIQ
d)
d.     A deployment process provided by SailPoint that is recommended when deploying IIQ
129.
Rules can only be created in the UI Rule Editor withing IIQ
a)
Correct
b)
InCorrect
130.
Of you find yourself writing the same segment of code over and over, best practice would be to include the code in ___
a)
a. A Rule Library
b)
b. Log4j Object
c)
c.IIQ Deployment Accelerator
d)
d. Run Rule Task
131.
The IIQ Deployment Accelerator is a plug-in for writing rules in which IDE?
a)
a. IntelliJ
b)
b. NetBeans
c)
c. Eclipse
d)
d. Visual Studio
132.
Partitioning is a performance improvement option for all tasks
a)
Correct
b)
InCorrect
133.
IIQ supports both a delta aggregation and a delta refresh
a)
Correct
b)
InCorrect
134.
The makeup of a task includes deployed java code and task definition object
a)
Correct
b)
InCorrect
135.
What class is the starting point for using the SailPoint API, providing mechanisms for a wide variety of actions such as searching for items and getting the system configuration?
a)
a. Sailpoint Context
b)
b. Custom Connectors
c)
c. Identity Object
d)
d. Util Object
136.
It is a best practice to use search() with properties wherever possible over using getObjects()
a)
Correct
b)
InCorrect
137.
Where can you research methods available on the objects on the objects in IIQ object model?
a)
a. Java Docs
b)
b. Compass Form
c)
c. Web Search
138.
The report configuration supports emailing PDF representations of a report
a)
Correct
b)
InCorrect
139.

Can this action be performed as part of configuring an application definition in IdentityIQ?

Option: Designate that the values of an account attribute should be represented in the Entitlement Catalog, by marking the attribute as “managed”

a)
Correct
b)
InCorrect
140.
Can this action be performed as part of configuring an application definition in IdentityIQ? Option: Define account correlation via a rule
a)
Correct
b)
InCorrect
141.
Can this action be performed as part of configuring an application definition in IdentityIQ? Option: Designate that the values of an account attribute should be represented in the Entitlement Catalog, by marking the attribute as “Entitlement”
a)
Correct
b)
InCorrect
142.
Is this valid statement about connector rules? Option: The main purpose of the Web Service - After Operation Rule is to close the connection to the web service and cleanup any dangling pointers to prevent a memory leak
a)
Correct
b)
InCorrect
143.
Can the following action be performed using Rapid Setup application onboarding? Option: Specify the account attribute and value filter that identifies an employee account
a)
Correct
b)
InCorrect
144.

The engineer is configuring a new application definition: The customer wants all account attributes with dates formatted the same way. The format must be yyyy-MM-dd, but a source system provides it as dd/MM/yyyy HH:mm:ss Is this the rule an engineer should write to accomplish the goal?

Option: Write a custom rule

a)
Correct
b)
InCorrect
145.

Is this configuration option required when an engineer set up an Active Directory application?

Option: Name

a)
Correct
b)
InCorrect
146.

Is this configuration option required when an engineer set up an Active Directory application?

Option: Profile Class

a)
Correct
b)
InCorrect
147.

Is this configuration option required when an engineer set up an Active Directory application?

Option: Revoker

a)
Correct
b)
InCorrect
148.

Is this configuration option required when an engineer set up an Active Directory application?

Option: Application Type

a)
Correct
b)
InCorrect
149.
In an identity refresh task, what do Process Events do?
a)
a. Enable Certification
b)
b. Enable Lifecycle Events
c)
c. Enable both
d)
d. Enable None
150.

In an identity refresh task, what does Synchronize attributes do?

(a)  

151.

In an identity refresh task, what does Provision assignments do?

(a)  

152.

In an identity refresh task, what does Promote managed attributes do?

(a)  

153.
What is the term for reading application data into Identity IQ from external sources?
a)
a. Aggregation
b)
b. Application
c)
c.Certification
d)
d. Refresh
154.
What is the term for writing to applications within your enterprise?
a)
a. Provisioning
b)
b. Aggrgation
c)
c. Refresh
d)
d. Certification
155.
What is the difference between a task and a business process (workflow)?
a)
1.     Tasks interact with users and are usually activated in response to a user action/data change; workflow do batch processing and are schedule
b)
2.     Tasks perform batch processing and can be schedule; workflows interact with users and are activated in response to user actions/data change.
c)
3.     They can be used interchangeably, but a task is pre-compiled and a workflow is interpreted.
156.
Authoritative Identity Cubes are created for each account read from all applications
a)
Correct
b)
InCorrect
157.
Refresh tasks process data on Identity Cubes and updates them, aggregation tasks read account information into IdentityIQ from external applications
a)
Correct
b)
InCorrect
158.
Account schemas define which account attributes to read from an application when aggregating account with IIQ
a)
Correct
b)
InCorrect
159.
If we want to add entitlement(s) to entitlement catalog, what should we mark the corresponding account attribute as?
a)
a. Entitlement
b)
b. Multi-Valued
c)
c. Managed
160.
After aggregating, entitlements (managed) are added to the Entitlement Catalog, but they are not fully promoted on Identity Cubes until a refresh task has been run
a)
Correct
b)
InCorrect
161.
The JDBC connector requires a provisioning rule to be written when provisioning to applications of this type
a)
Correct
b)
InCorrect
162.
Many IdentityIQ connectors include pre-defined account and groups schemas
a)
Correct
b)
InCorrect
163.
What are two ways to view your application data prior to aggregation?
a)
a. Preview
b)
b. Debug Connector
c)
c. Both
d)
d. None
164.
Accounts are correlated to existing Identity Cubes when the Prune Identity task is run
a)
Correct
b)
InCorrect
165.
Manual correlation will link an account to an identity cube, but only until the next aggregation of that app
a)
Correct
b)
InCorrect
166.
You can use the Administrator Console to postpone a scheduled task
a)
Correct
b)
InCorrect
167.
An application connector can be forced to provision via IdentityIQ work items by removing “PROVISIONG” from the application features strings.
a)
Correct
b)
InCorrect
168.
Which of these option defines how the account attributes within a provisioning plan are populated?
a)
a. Application Schema
b)
b. Provisioning Policy
c)
c. Policy Definition
d)
d. Build Map Rule
169.
_____ define which account attributes to read from an application when aggregating accounts with IIQ
a)
a. Account Schema
b)
b. Delimited File
c)
c. Group Schema
d)
d. Connectors
170.
There are five important tasks that are shipped pre-scheduled in IdentityIQ. Which task advances certifications through their phases and restarts backgrounded workflows?
a)
a.     A check expired items daily
b)
b.     Perform maintenance
c)
c.     Perform Identity Request Maintenance
d)
d.     Check expired mitigation daily
e)
e.     Check sunset requests for notifications daily
171.
which connector requires a provisioning rule to be written when provision to applications of this type?
a)
a. LDAP
b)
b. Active Directory
c)
c. JDBC
d)
d. Delimited File
172.
Why might someone using IdentityIQ to aggregate accounts set the option “Disable optimization of unchanged accounts = true” on application aggregation tasks?
a)
a. It is never a good idea to disable the built-in native aggregation optimization
b)
b.     It is a best practice during the development phase, because it allows the developer to test the changes made to how the data is being processed.
c)
c.     It is best practice for Production systems if IdentityIQ aggregation performance is not a concern.
173.
If an application is marked as “authoritative”, what does this mean within IIQ?
a)
a.     An authoritative application is the source of authoritative identities for the IIQ based on accounts aggregated from this application
b)
b.     An authoritative application is the source of non-authoritative identities for the IIQ based on accounts aggregated from the application
c)
c. An authoritative application is the source of authoritative identities withing IIQ, but they have to be created manually.
174.
What is the difference between a refresh task and aggregation task?
a)
a.     Refresh tasks process data on identity cubes and update them. Aggregation reads account info into IIQ from external applications.
b)
b.     Aggregation process the data on Identity Cubes and update the Cubes. Refresh tasks read in account info from external applications.
175.
Which of the following is not an option on the identity refresh task?
a)
a. Promote account attributes to identity attributes (per identity mappings)
b)
b.     Detect deleted accounts
c)
c.     Mark manager status for each identity
d)
d.     Update role assignments/detections
176.
Most important job of a provisioning policy is to specify the attributes required to complete a provisioning request
a)
Correct
b)
InCorrect
177.
Password Policies must be defined for each application for which managing password is supported
a)
Correct
b)
InCorrect
178.
Which of the following is NOT a way that accounts can be correlated to existing accounts withing IIQ
a)
a. Corelation Wizard
b)
b. Manual Corelation
c)
c. Writing Rule
d)
d. Pruning Identities
179.
After aggregating, entitlements are added to the Entitlement Catalog, but they are not fully promoted on Identity Cube until a refresh task has been run
a)
Correct
b)
InCorrect
180.
The LDAP connector provides the schemas for account and 3 types of LDAP groups: posix, nistnet, and group
a)
Correct
b)
InCorrect
181.
The JDBC connector requires a provisioning rule to be written when provisioning to application of this type
a)
Correct
b)
InCorrect
182.
Typically applications with published standard schema(s) have connectors that offer less functionality and are more difficult to configure overall
a)
Correct
b)
InCorrect
183.
Multiplexed application definitions contain rules that set two special, reserved attributes. What are these attributes?
a)
a.     Identity, IIQSourceApplication
b)
b.     IIQMultiplexIdentity, Source
c)
c.     IIQMultiplexIdentity, IIQSourceApplication
d)
d.     Identity, Source
184.
Is this relationship type available for an IdentityIQ Role that has a multi-level structure? Option: Permitted
a)
Correct
b)
InCorrect
185.

Is this relationship type available for an IdentityIQ Role that has a multi-level structure?

Option: Inherited

a)
Correct
b)
InCorrect
186.

Is the following a valid role option that can be configured?

Option: Configure a role type to be managed in the Entitlement Catalog

a)
Correct
b)
InCorrect
187.

Is the following a valid role option that can be configured?

Option: Configure a role type with account profiles

a)
Correct
b)
InCorrect
188.

Is the following a valid role option that can be configured?

Option: Configure a role type to include a set of entitlements

a)
Correct
b)
InCorrect
189.

Is the following statement true?

Option: An Identity can have multiple Links

a)
Correct
b)
InCorrect
190.

Is the following statement true?

Option: All Links must be associated to an Application object

a)
Correct
b)
InCorrect
191.

Can the following IdentityIQ object be extended to store client-specific data by updating the corresponding .HBM file?

Option: WorkItem

a)
Correct
b)
InCorrect
192.

Is this statement correct about writing and executing source mapping rule to populate identity attributes?

Option: The rule type must be identityAttribute

a)
Correct
b)
InCorrect
193.

Is this statement correct about writing and executing source mapping rule to populate identity attributes?

Option: If the rule is set as a global rule, it is only run by an aggregation task

a)
Correct
b)
InCorrect
194.

Is this statement correct about writing and executing source mapping rule to populate identity attributes?

Option: Account attribute can be allowed through the Link object

a)
Correct
b)
InCorrect
195.

A manager wants to extend the access granted to an employee. Is this default role type that is available for the manager to request in IdentityIQ during the access request process?

Option: Business Role

a)
Correct
b)
InCorrect
196.

A manager wants to extend the access granted to an employee. Is this default role type that is available for the manager to request in IdentityIQ during the access request process?

Option: IT Role that is inherited from another Business Role

a)
Correct
b)
InCorrect
197.
A best practice is to assign ownership of objects, such as applications, to workgroups
a)
Correct
b)
InCorrect
198.
Entitlements define which area of the UI a user can access withing IdentityIQ
a)
Correct
b)
InCorrect
199.
By adding an identity to a workgroup, the identity inherits capability assigned to the workgroup
a)
Correct
b)
InCorrect
200.
IdentityIQ doesn’t support multi-factor authentication
a)
Correct
b)
InCorrect
201.
What is the purpose of groups and populations?
a)
a.     To specify identities that share responsibilities for actions in IdentityIQ, such as “owning” an application
b)
b. To specify additional IdentityIQ user rights for identities, such as Compliance Officer
c)
c. To specify identities to include when performing and IdentityIQ activity, such as running a report
202.
A group can be defined based on multiple attributes; a population is based on a single attribute
a)
Correct
b)
InCorrect
203.
In IdentityIQ, where and how are new Population created?
a)
a.     In Advance Analytics, using identity search criteria
b)
b.     In Setup à Groups, on the Population tab
c)
c.     In the Identity Warehouse, using filtering criteria
204.
Which statement best describes what happens when you click Save Identities as Population?
a)
a.     Both the list of identities and the search criteria used to select them are saved
b)
b.     The list of identities in the population is saved
c)
c.     The search criteria for the population is saved
205.
Business roles are detected, while IT roles are assigned
a)
Correct
b)
InCorrect
206.
Business roles are detected for an identity if that user has all of the entitlements that are associated with that role
a)
Correct
b)
InCorrect
207.
Required relationships define the IT roles that are mandatory for any user who has a certain business role; while permitted relationship define the IT roles which a user is allowed to have, based on having certain business role
a)
Correct
b)
InCorrect
208.
Through the Manage User Access Quicklink, a user can:
a)
a.     Disable or enable accounts on a connected application
b)
b.     Request or remove entitlement and/or roles
c)
c.     Manage password on connected applications
209.
The request ability of an entitlement is configured in the Entitlement Catalog
a)
Correct
b)
InCorrect
210.
While requesting access, you can search for an entitlement using the extended attributes you have added to IIQ
a)
Correct
b)
InCorrect
211.
Roles can be configured to automatically be enable at a specified future date
a)
Correct
b)
InCorrect
212.
In IIQ, new groups can be created and provisioned in a connected app by using the “Add New Entitlement” button located in the Entitlement Catalog
a)
Correct
b)
InCorrect
213.
When you add extended attributes that are not marked searchable to IdentityIQ, where are these attributes stored by default
a)
The WEB-INF directory
b)
In a CLOB
c)
In the application server
d)
The owner column in the database
214.
Entitlements and groups that are included in the Entitlement Catalog have many uses within IdentityIQ. Which one of the following is NOT a use of items in the Entitlement Catalog
a)
a.     Available for defining policies
b)
b.     Available as group factories
c)
c.     Requestable through Lifecyle Manage
d)
d.     Available for defining risk
e)
e. Available to include in roles
215.
Roles encapsulate sets of access a user has into a single unit, which simplifies many common operations across IdentityIQ
a)
Correct
b)
InCorrect
216.
Roles can help increase efficiency of access requests, but in access reviews, entitlements must be individually examined
a)
Correct
b)
InCorrect
217.
IdentityIQ enables organizations to separate the tasks of certifying who should have certain roles from the task of certifying what access should be granted by the role
a)
Correct
b)
InCorrect
218.
Inheritance is supported at the --------- role level
a)
a. Business
b)
b. IT
c)
c. All
d)
d. None
219.
The only way to create roles in IdentityIQ is through role mining
a)
Correct
b)
InCorrect
220.
Roles created through Business Role mining automatically include assignment rules which correspond to the filter used to create the roles
a)
Correct
b)
InCorrect
221.
Business roles must be defined prior to creating IT roles
a)
Correct
b)
InCorrect
222.
A role’s composition cannot be certified, only its membership
a)
Correct
b)
InCorrect
223.
The cleaner your identity data, the better the results from your role mining activities
a)
Correct
b)
InCorrect
224.
Roles can be assigned automatically via assignment logic and manually via access requests
a)
Correct
b)
InCorrect
225.
Which of the following is an option withing the Identity refresh task that instructs IdentityIQ to provision the entitlement for required IT roles to target applications?
a)
a.     Refresh assigned, detected roles
b)
b.     Disable de-provisioning of de-assigned roles
c)
c.     Provision assignments
d)
d.     Refresh role metadata for each identity
226.
When are IT roles entitlements attached to a business role not provision with the business role?
a)
a.     When the entitlement span multiple applications
b)
b.     Never – that is automatic
c)
c.     When the IT roles is “permitted” by the business role and the business role is assigned through and assignment rule.
d)
d.     When the business role is assigned through and Identity refresh task, but “Provision assignments” is not selected
227.
Roles can be configured to automatically be enable at a specified future date
a)
Correct
b)
InCorrect
228.
Roles with “OR” relationship between entitlements should include a ----------, which provides instructions for granted the appropriate access to identities
a)
a. Role Provisioning Policy
b)
b. Schema
c)
c. WorkItem
229.
If a user has more than one account on an application, IdentityIQ will always provision roles to the account listed first on their identity cube
a)
Correct
b)
InCorrect
230.
IdentityIQ 2 tier role model cannot be change or extended
a)
Correct
b)
InCorrect
231.
You can create a role type that grants IdentityIQ capabilities
a)
Correct
b)
InCorrect
232.
It is good practice to model and mine for roles in a representative staging or pre-production environment
a)
Correct
b)
InCorrect
233.
The only way to maintain version history of role definition changes is to enable role archiving in IdentityIQ
a)
Correct
b)
InCorrect
234.
Deleting from your role model can be propagate through your identities by the Identities Refresh task
a)
Correct
b)
InCorrect
235.
Role owners are not an important part of configuration and do not have an responsibilities
a)
Correct
b)
InCorrect
236.
It’s a good practice to periodically run Role Membership and Role Composition certifications to help confirm your role model is current
a)
Correct
b)
InCorrect
237.
What are the benefits of using roles instead of logical applications?
a)
a.     Roles scale significantly better than logical applications
b)
b.     Roles have an extended set of features not available to logical applications
c)
c.     Roles leverage existing connector pathways
d)
d.     All of above
238.
Every role and entitlement in your IIQ installation must include a risk score
a)
Correct
b)
InCorrect
239.

The maximum value for an identity’s risk scope is --------

(a)  

240.
The composite scoring category percentage have to add up to 100%
a)
Correct
b)
InCorrect
241.
Identity Risk Scoring is based on Roles/Entitlements, Violation, Certification Age, and whether an identity is authoritative or non-authoritative
a)
Correct
b)
InCorrect
242.
You should always update the application risk scores before you update the identity risk score
a)
Correct
b)
InCorrect
243.
You can adjust a baseline risk score up or down, to account for follow-up actions, using compensating controls
a)
Correct
b)
InCorrect
244.
Roles encapsulate sets of access a user has into a single unit, which simplifies many common operations across IIQ
a)
Correct
b)
InCorrect
245.
Role Based Access Control (RBAC) is the simplest goal for implementing roles
a)
Correct
b)
InCorrect
246.
Using roles for birthright provisioning is an example of a ___ approach to designing roles
a)
a. RBAC
b)
b. Project Based
c)
c. Targeted
247.
There is one-to-one correspondence between business roles and IT roles
a)
Correct
b)
InCorrect
248.
An IT role is detected on an Identity Cube by IIQ when a user has all of the entitlements which are included in the IT role definition
a)
Correct
b)
InCorrect
249.
An IT roles can be associated to a business role as either requirement access (the user must have the access) or permitted access (the user can have the access but it’s not required)
a)
Correct
b)
InCorrect
250.
Business roles can be assigned to a user based on an assignment rule configured on the business role
a)
Correct
b)
InCorrect
251.
When using assignment rules, entitlements encapsulated withing a role are provisioned only when a Refresh task is run with the “Provision Assignments” option selected
a)
Correct
b)
InCorrect
252.
Two separate process available for creating IT roles through mining; Entitlement Analysis and IT Role Mining
a)
Correct
b)
InCorrect
253.
Roles created through Business Role mining automatically include assignment rules which correspond to the filters used to create the roles
a)
Correct
b)
InCorrect
254.
A result of running the refresh task is that business roles are assigned to the users, and IT roles where the user holds the listed entitlements, are marked as detected
a)
Correct
b)
InCorrect
255.
When certifying identity access, the certifier has the option to revoke IT roles held within Business Roles
a)
Correct
b)
InCorrect
256.
Role inheritance is a method for defining the relationship between business roles and IT roles
a)
Correct
b)
InCorrect
257.
The only way to automatically propagate the removal of an entitlement from an IT role is through the Propagate Role Changes task
a)
Correct
b)
InCorrect
258.
Business roles must be defined prior to creating IT roles
a)
Correct
b)
InCorrect
259.
A good practice to use Role Membership and Role Composition certifications to help confirm your role definitions
a)
Correct
b)
InCorrect