WorksheetsSailpoint-Full
Total questions: 259
Worksheet time: 54mins
Is the following statement a true statement about IdentityIQ authentication and authorization?
Option: User can have only authorized scopes
An engineer is developing an instance of IdentityIQ using the Service Standard Build (SSB) for a client; Is this a valid action the engineer can perform when setting up or using SSB?
Option A: Tokenize text in the XML object that may differ between environments
An engineer is developing an instance of IdentityIQ using the Service Standard Build (SSB) for a client; Is this a valid action the engineer can perform when setting up or using SSB?
Option B: Place any main identityiq installation zip file in the build’s base/ga folder
Is this what should be performed in order to generate the database script to extend Managed Attributes in the IdentityIQ database on the initial installation?
Option A: Run the command iiq schema in the IIQ_HOME/WEB-INF/bin directory
An implementation engineer needs to perform an upgrade of IdentityIQ between releases. Is the following statement true?
Option: Any e-fixes must be removed from the build process as part of an upgrade
An implementation engineer needs to perform an initial installation of IdentityIQ. Drag the options from the left into the answer area on the right and place them in the correct order:
1. Initialize default IdentityIQ system objects from, iiq console using the “import” command (init.xml etc)
2. Update all necessary Hibernate XML files to include custom attributes
3. Un-jar the IdentityIQ WAR file in the desired directory of each application server
4. Generate database schema to include custom attributes by executing iiq schema
5. Start the application server
6. Create IdentityIQ database
7. Apply the patch
(a) defines which areas of the UI a user can access withing IIQ?
The JVM Memory page on the IdentityIQ displays the following information:
Free Memory 631.579 MB (out of point int time memory, this much is free)
Total Memory 845.657 MB (this is point in time memory that is currently in use)
Max Memory 2610.251 MB (this is the max memory that can be allocated)
(a)
Is this statement true about IdentityIQ’s syslog event searching capabilities?
Option: It is not possible to use more than two filters at a time when searching the syslog events from the Advance Analytics page
Is this statement true about IdentityIQ’s syslog event searching capabilities?
Option: When searching the syslog events from the Advance Analytics page, a syslog can be filtered by Start Date and End Date
Is this statement true about IdentityIQ’s syslog event searching capabilities?
Option: It is possible to search the Syslog events using an incident Code from Advance Analytics page
Can the Provisioning tab under Administrator Console be used to do the following tasks?
Option: View the Request Message queue for the request associated to provisioning transactions
Is this a benefit of using the Run Rule feature of the Debug-Object page?
Option: It can be used to display the return value of simple code
Is this a benefit of using the Run Rule feature of the Debug-Object page?
Option: It can be used to update objects in the Services Standard Build (SSB)
An organization is making a change at the regional level. Many users of financial system have incorrect entitlements, some user are missing entitlements, and some users have excess entitlements. Work needs to be done to perform to clean up access. Is this one of the IdentityIQ batch request types that can help meet this goal?
Option: Add Entitlement
Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?
Option: An Identity correlated
Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?
Option: An identity provisioning plan has failed to provision
Excluding the “rule” lifecycle event type is this an action that could trigger a lifecycle event to launch a workflow?
Option: A new change occurs
A client needs a custom quicklink, which only manager can launch, in order to launch a simple work workflow. Is this a valid step to take during the development of the custom quicklink?
Option: Set the category of the quicklink object to a valid category name
Can the following be achieved via configuration of control variables in the out-of-the-box LCM?
Option: Check if an access request would violate any policies, and allow the requester to review before submitting
Is this a default functionality of the Lifecycle Manager (LCM) module?
Option: Create Identity
Is this a default functionality of the Lifecycle Manager (LCM) module?
Option: Edit Identity
Is this a default functionality of the Lifecycle Manager (LCM) module?
Option: Terminate identity
A client wants user who belong to an IdentityIQ workgroup name Management to be able to request entitlements and role, but only for other users whose location attribute is the same as theirs.
Is this population that will achieve this goal?
Option: Create identities population, set the attribute match the and set ------ and use “who can members request for as same attribute with the requester, with attribute set to location
For a user who already has an account on an application and want to be able to request access to a new account through “Manage User Access”, does this configuration need to be performed in LCM?
Option: Select the Enable Account Group management option in the LCM
For a user who already has an account on an application and want to be able to request access to a new account through “Manage User Access”, does this configuration need to be performed in LCM?
Option: Select allow requesting new account on the Manage Accounts Quicklink configuration for the user’s Quicklink population
Is the following true of identity Provisioning Polices?
Option: Identity Provisioning Policies can be used to include allowed-values definitions or validation logic on fields so that only valid/authorized values can be specified for those fields when using the Create Identity feature to add an identity.
Select the method(s) that can disallow users from deleting their accounts on connected systems:
Option: Remove access to the manage account quicklink for the self service quicklink population
Select the method(s) that can disallow users from deleting their accounts on connected systems:
Option: In the LCM configuration disallow the delete option for the my actions category of user
The engineer needs to write some ad-hoc BeanShell code to search for Bundle (role) objects owned by James.Smith, and print their names, is this BeanShell Code correct as written?
Option:
Import sailpoing.object.Application;
Import sailpoint.object.Filter;
Filter filter = Filter.eq(“owner.name”, “James.Smith”);
Iterator itetrator = context.search(Bundle.class, filter, “name”);
While(iterator.hasnext()) {
Object[] data = iterator.next();
String item = (String) data{0};
System.out.println(item);
}
The engineer needs to write some ad-hoc BeanShell code to search for Bundle (role) objects owned by James.Smith, and print their names, is this BeanShell Code correct as written?
Option:
Import sailpoint.object.*;
Filter filter = filter.eq(“owner.name”, “James.Smith”);
QueryOptions qo = new QueryOptions();
Qo.addFilter(filter);
Iterator iterator = context.search(Bundle.class, qo, “name”);
While (iterator.hasnext()) {
Object[] item = iterator.next();
Println((String) item[0]);
}
Is the following statement about IdentityIQ rule inputs and outputs correct?
Option: for ease of implementation, all BeanShell rules in IdentityIQ have the same input and output variables
Option:
for (int i = 0; j < this.variable.lenth; i++){
String name = this.variables[i];
Object value = eval(name);
If (value == void) Println(name + “ : void” );
Else if (value == null) Println (name + “ : null”);
Else Print(name + “ : “ + value.getClass().getSimpleName() + “ : “ + value);
}
This code can be used for debugging to find all available variables for a BeanShell rule?
Can the rule library name “Common Rules Library” be included in a Rule by adding this code?
<ReferenceRules Class=”sailpoint.object.Rule” name=”Common Rules Library”> </ReferenceRules>
Is the following statement about workflows and sub-workflows (sub-process) true?
The output values of a sub-workflows must be explicitly defined by using return argument to return them to variables in the calling workflow.
For example: <Return name=”IdentityRequestId” to “IdentityRequestId” />
The engineer is working on a workflow implementation.
After a form step, the workflow can transition to three steps;
• Stop if the Reject (back) button is used
• Audit of the Approve (next) button is used and field name comments is returned from the form to the workflow variable comment and have a value,
• Provision otherwise The engineer writes the transitions in XML code.
Is this a valid implementation?
<transition>
<source> If (!approved) return “Stop”;
If (comment) return “Audit”; Return “Provision”;
</source>
</transition>
A step in Workflow needs to be added for user interaction. Can the ManualAction Workitem type be used in the following scenario?
Option: An administrator needs to indicate that the provisioning of a request has been complete
Is the following statement about workflow steps type and their usage true?
Option: Place holder steps must have attributes posx and posy to hold their place
A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?
Option: A best practice is to make all style change in the common.css file
A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?
Option: Text on the login page is set through message keys in the messages catalog
A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?
Option: The original HTML file updated to change the settings
A customer wants to make changes in their IdentityIQ user interface. Consider branding and other IdentityIQ UI changes, is this statement valid?
Option: The icons used to represent roles can be replaced
Can this action be performed as part of configuring an application definition in IdentityIQ?
Option: Designate that the values of an account attribute should be represented in the Entitlement Catalog, by marking the attribute as “managed”
The engineer is configuring a new application definition: The customer wants all account attributes with dates formatted the same way. The format must be yyyy-MM-dd, but a source system provides it as dd/MM/yyyy HH:mm:ss Is this the rule an engineer should write to accomplish the goal?
Option: Write a custom rule
Is this configuration option required when an engineer set up an Active Directory application?
Option: Name
Is this configuration option required when an engineer set up an Active Directory application?
Option: Profile Class
Is this configuration option required when an engineer set up an Active Directory application?
Option: Revoker
Is this configuration option required when an engineer set up an Active Directory application?
Option: Application Type
In an identity refresh task, what does Synchronize attributes do?
(a)
In an identity refresh task, what does Provision assignments do?
(a)
In an identity refresh task, what does Promote managed attributes do?
(a)
Is this relationship type available for an IdentityIQ Role that has a multi-level structure?
Option: Inherited
Is the following a valid role option that can be configured?
Option: Configure a role type to be managed in the Entitlement Catalog
Is the following a valid role option that can be configured?
Option: Configure a role type with account profiles
Is the following a valid role option that can be configured?
Option: Configure a role type to include a set of entitlements
Is the following statement true?
Option: An Identity can have multiple Links
Is the following statement true?
Option: All Links must be associated to an Application object
Can the following IdentityIQ object be extended to store client-specific data by updating the corresponding .HBM file?
Option: WorkItem
Is this statement correct about writing and executing source mapping rule to populate identity attributes?
Option: The rule type must be identityAttribute
Is this statement correct about writing and executing source mapping rule to populate identity attributes?
Option: If the rule is set as a global rule, it is only run by an aggregation task
Is this statement correct about writing and executing source mapping rule to populate identity attributes?
Option: Account attribute can be allowed through the Link object
A manager wants to extend the access granted to an employee. Is this default role type that is available for the manager to request in IdentityIQ during the access request process?
Option: Business Role
A manager wants to extend the access granted to an employee. Is this default role type that is available for the manager to request in IdentityIQ during the access request process?
Option: IT Role that is inherited from another Business Role
The maximum value for an identity’s risk scope is --------
(a)
