SAILPOINT IDENTITY
SECURITY ENGINEER
PRACTICE EXAM 73
QUESTIONS
Question 1: An organization has employees from Workday and contractors from a
separate vendor system. Their lifecycle rules and authoritative attributes dier signicantly. What is the best Identity Security Cloud design?
Choices:
1) Use one identity prole for both populations and resolve dierences with access proles 2) Create separate identity proles for employees and contractors and set prole priority appropriately 3) Create one identity prole for every target application 4) Model contractors only as accounts and exclude them from identities Correct Answer: Create separate identity proles for employees and contractors and set prole priority appropriately Explanation: Separate identity proles are appropriate when authoritative populations require dierent identity mappings or lifecycle logic. Prole priority determines which prole is evaluated rst when an identity could match more than one prole.Page 1
Question 2: Which source is normally the best choice to drive creation of workforce identities in an identity prole?
Choices:
1) An authoritative HR source 2) A downstream nance application 3) A certication campaign 4) An access request approval queue
Correct Answer: An authoritative HR source
Explanation: An authoritative source such as an HR system provides trusted person data used to create and maintain workforce identities. Downstream applications are usually governed targets rather than the system of record for identity creation.Question 3: A company wants new hires to exist in Identity Security Cloud before their start date but receive production access only on the start date. Which design best supports this requirement?
Choices:
1) Create a prehire lifecycle state with limited actions and transition to an active state on the hire date 2) Delay identity aggregation until the start date 3) Give prehires all role access and certify it later 4) Use a certication campaign to activate the identity Correct Answer: Create a prehire lifecycle state with limited actions and transition to an active state on the hire date Explanation: Lifecycle states can represent prehire and active stages with dierent access behavior. A scheduled or attribute-driven transition on the hire date can then trigger the access appropriate for an active employee.Page 2
Question 4: What is the primary purpose of manager correlation in Identity Security Cloud?
Choices:
1) To determine which Virtual Appliance owns a source 2) To associate an identity with the correct manager identity for governance and approvals 3) To match entitlements to access proles 4) To encrypt identity attributes before aggregation Correct Answer: To associate an identity with the correct manager identity for governance and approvals Explanation: Manager correlation links a worker's manager attribute to an existing identity. This relationship is important for manager approvals, manager certications, and organizational context.Question 5: An identity attribute must be derived from rst name and last name with normalization and fallback logic. What is generally the preferred approach when built-in capabilities can express the logic?
Choices:
1) Use a transform 2) Install custom software on a Virtual Appliance 3) Create a new authoritative source 4) Use a certication campaign lter
Correct Answer: Use a transform
Explanation: Transforms are designed to derive and manipulate identity attribute values using declarative logic. They are preferred over custom rules when the requirement can be satised without custom code.Page 3