Review the following log entry:
[
{
"id": "2c9180866166b5b0016167c32ef31a66",
"name": "acme AD-TX Cluster",
"description": "acme AD - TX Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": null
},
{
"id": "2c9180846a93ce60016ab29f039944de",
"name": "acme AD-NY Cluster",
"description": "acme AD-NY Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": {
"clientId": null,
"durationMinutes": 60,
"expiration": "2025-12-15T19:13:36.079Z",
"rootLevel": "TRACE",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "TRACE"
}
}
}
]
A source owner for Active Directory has found problems with aggregation and has requested log files for their source.
Is this a valid way for the Administrator to assist in retrieving the correct logs?
Proposed Solution / Statement:
The following REST API call can be used to collect and export logs from the acme AD-NY Cluster:
GET https://acme.api.identitynow.com/v3/sources/2c9180846a93ce60016ab29f039944de/logs
Does this proposed solution meet the requirement / solve the scenario?
Is this a step that can be taken on a certification due date when a certification reviewer has left the organization without completing the review?
Proposed Solution / Statement:
An Administrator can initiate reassignment of a pending certification to a new reviewer.
Does this proposed solution meet the requirement / solve the scenario?
Below are the requirements for configuring user provisioning in an organization's Finance department.
Contractors in the organization MUST NOT be auto-provisioned with the default Office 365 license, as contractors in departments other than Finance have different license requirements.
Every Finance department user — whether employee or contractor — must be assigned one Office 365 E3 license.
No Finance employee or contractor should be provisioned more than one type of Office 365 license.
Is this a valid approach for the Identity Security Administrator to provide the necessary access?
Proposed Solution / Statement:
Create an ISC Role with membership criteria that includes all Finance department users and associate the Office 365 E3 license entitlement with the role. This ensures Finance department users receive E3 license access automatically.
Does this proposed solution meet the requirement / solve the scenario?
An administrator is tasked with restoring configurations in their Identity Security Cloud Tenant after an unexpected configuration error.
Is the following a step that the administrator should take to successfully restore configurations from a backup?
Proposed Solution / Statement:
Ensure that the draft includes all necessary configuration objects by editing and adding any missing objects before deployment.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement about Workflow components valid?
Proposed Solution / Statement:
Every action name (not display name) in a workflow must be unique.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement about entitlements valid?
Proposed Solution / Statement:
Entitlements represent the specific access rights on a source.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding Identity Security Cloud (ISC) policies?
Proposed Solution / Statement:
Separation of duties policies help prevent users from gaining toxic combinations of access.
Does this proposed solution meet the requirement / solve the scenario?
Assuming an access item's approval type is set to "reviewer," does the following statement accurately describe the approval flow behavior?
Proposed Solution / Statement:
When a user requests access for themselves and they are also in the approval chain, the approval flow will route to their manager instead to prevent a conflict of interest.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding attribute sync valid?
Proposed Solution / Statement:
Attribute sync can be enabled by going to Admin > Connections > Sources and selecting and editing the source.
Does this proposed solution meet the requirement / solve the scenario?
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"Separation of duties can be enforced using rules that can be configured in the system. These rules look for forbidden combinations of access owned by a single user. The rules can be used in a detective way, meaning actively searching for these forbidden combinations, or a preventative way, meaning that an extra validation step is made when a change in user access is requested."
Does this proposed solution meet the requirement / solve the scenario?
Is the following true regarding User Levels and permissions?
Proposed Solution / Statement:
Role Admin and Source Sub-Admin can be granted to an identity at the same time.
Does this proposed solution meet the requirement / solve the scenario?
Is this a step that can be taken on a certification due date when a certification reviewer has left the organization without completing the review?
Proposed Solution / Statement:
The reviewer's manager can access the certification campaign and complete all pending reviews.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about common authentication methods?
Proposed Solution / Statement:
The Identity Provider and Service Provider in a SAML setup trust each other based on public keys that have been exchanged as part of the configuration.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about identity profile?
Proposed Solution / Statement:
Once users are assigned to an identity profile, administrators cannot modify or delete the identity profile.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding the objects that represent access of systems managed by Identity Security Cloud?
Proposed Solution / Statement:
When criteria for automatic assignment of a Role are set to Identity List, the names of identities to include can be specified using wildcards, for example "John*".
Does this proposed solution meet the requirement / solve the scenario?
Users are complaining that they would like to request access to groups that have recently been added to the Corporate Directory system, but they are unable to see them. The system feature Enable Entitlement Requests has been enabled and access request segments have not been enabled.
Is this a valid step to debug the problem?
Proposed Solution / Statement:
Open the source configuration and navigate to the Access Profiles page to check if the group is included in it and thus hidden by any Access Profile.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding attribute sync valid?
Proposed Solution / Statement:
Attribute sync synchronizes entitlement information from the sources configured.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario where a Separation of Duties policy should be used?
Proposed Solution / Statement:
A user requests a major system configuration and approves the change.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding sources in Identity Security Cloud?
Proposed Solution / Statement:
Sources primarily serve as backup storage locations for identity data to ensure business continuity in case of system failures.
Does this proposed solution meet the requirement / solve the scenario?
A user requests access for a specific entitlement. The access request shows as pending for the user and seems stuck.
Is this a valid troubleshooting step for the scenario above?
Proposed Solution / Statement:
An administrator can review the access request within Access Request Administration to see where the workflow is paused.
Does this proposed solution meet the requirement / solve the scenario?
On 4 February 2021, the following error occurred on source Control Central of type Active Directory for identity Clarence.Harper:
Failed to update attributes. There is no such object on the server.
Is this a valid place to look for more information about what caused the error?
Proposed Solution / Statement:
Search for the error message on SailPoint Compass or the SailPoint Developer Forums. Check for previous discussions or whitepapers.
Does this proposed solution meet the requirement / solve the scenario?
Is the following a valid configuration item for the identity profile's sign-in and security settings?
Proposed Solution / Statement:
If Multifactor Authentication is configured, the users of the Identity Profile must provide proof of their identity in two ways before they are allowed to unlock their account or reset their password.
Does this proposed solution meet the requirement / solve the scenario?
Users are complaining that they would like to request access to groups that have recently been added to the Corporate Directory system, but they are unable to see them. The system feature Enable Entitlement Requests has been enabled and access request segments have not been enabled.
Is this a valid step to debug the problem?
Proposed Solution / Statement:
Open the source configuration and navigate to the Entitlements page to search for the group and verify the Requestable status.
Does this proposed solution meet the requirement / solve the scenario?
In order to secure access to the Identity Security Cloud (ISC) Tenant, the administrator wants to restrict access to the tenant to users in certain geographies and networks.
Is this a valid step towards performing this task?
Proposed Solution / Statement:
Admin has to first go to Identity Management, select an Identity Profile and choose the options under 'Block Access From'.
Does this proposed solution meet the requirement / solve the scenario?
Does this statement correctly describe a function of the Virtual Appliance (VA)?
Proposed Solution / Statement:
The VAs initiate communication to the VA cluster queue in the Identity Security Cloud tenant.
Does this proposed solution meet the requirement / solve the scenario?