Is this a valid statement regarding Identity Security Cloud (ISC) policies?
Proposed Solution / Statement:
Governance Groups can only be assigned as the owner of the policy.
Does this proposed solution meet the requirement / solve the scenario?
Is this a true statement regarding identity attribute mappings and identity profiles?
Proposed Solution / Statement:
Username, last name, and work email must have a value.
Does this proposed solution meet the requirement / solve the scenario?
The security team has asked for a technical briefing on how authentication works with SailPoint.
Does the following statement correctly describe authentication methods in SailPoint and industry standards?
Proposed Solution / Statement:
When configuring SAML authentication in SailPoint, the Entity ID must exactly match the SAML metadata EntityID supplied by the identity provider for successful federation.
Does this proposed solution meet the requirement / solve the scenario?
A new employee's identity is not correctly created and shows in the Identity Exceptions report on the Identity Profile.
Is this a correct step towards analyzing and resolving the problem?
Proposed Solution / Statement:
Ensure the account attributes mapped to the identity attributes User Name (uid), Work Email (email), and Last Name are populated correctly.
Does this proposed solution meet the requirement / solve the scenario?
Does this statement accurately describe the purpose of the Virtual Appliance (VA)?
Proposed Solution / Statement:
The VA allows the tenant to connect to on-prem sources.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding role management?
Proposed Solution / Statement:
To test role membership criteria, it is best to keep the role in a disabled state and run a refresh.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Administrator received a request to audit a distribution list on a monthly cadence.
Place the following steps in the correct order in order to accomplish this task:

Is this a valid statement about common authentication methods?
Proposed Solution / Statement:
The Identity Provider and Service Provider in a SAML setup trust each other based on public keys that have been exchanged as part of the configuration.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario for reviewing access requests in the approval management page?
Proposed Solution / Statement:
It is possible for an administrator to supersede an approver's cancellation of a request.
Does this proposed solution meet the requirement / solve the scenario?
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"Separation of duties can be enforced using rules that can be configured in the system. These rules look for forbidden combinations of access owned by a single user. The rules can be used in a detective way, meaning actively searching for these forbidden combinations, or a preventative way, meaning that an extra validation step is made when a change in user access is requested."
Does this proposed solution meet the requirement / solve the scenario?
Does this statement correctly describe a function of the Virtual Appliance (VA)?
Proposed Solution / Statement:
SaaS-based applications require a cloud-based VA.
Does this proposed solution meet the requirement / solve the scenario?
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"The vendor has provided proof that the tool complies with HIPAA, PCI-DSS, SoX, ISO 27002 and the GDPR. The fact that we use this IGA tool is sufficient legal proof for the auditors that we comply with all regulations."
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding the objects that represent access of systems managed by Identity Security Cloud?
Proposed Solution / Statement:
Criteria for automatic assignment of a Role can be set to Standard Criteria or Identity List.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario where a Separation of Duties policy should be used?
Proposed Solution / Statement:
One team member assumes the role of user administration, application administration, and data backup management.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about identity profile?
Proposed Solution / Statement:
The priority of an identity profile can be updated via REST API.
Does this proposed solution meet the requirement / solve the scenario?
Is the following a valid configuration item for the identity profile's sign-in and security settings?
Proposed Solution / Statement:
If Multifactor Authentication is configured, the users of the Identity Profile must provide proof of their identity in two ways before they are allowed to unlock their account or reset their password.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement regarding access management valid?
Proposed Solution / Statement:
A reviewer can be required to provide a comment when rejecting a role request.
Does this proposed solution meet the requirement / solve the scenario?
In order to secure access to the Identity Security Cloud (ISC) Tenant, the administrator wants to restrict access to the tenant to users in certain geographies and networks.
Is this a valid step towards performing this task?
Proposed Solution / Statement:
Admin has to first go to Identity Management, select an Identity Profile and choose the options under 'Block Access From'.
Does this proposed solution meet the requirement / solve the scenario?
Below is a search command in Identity Security Cloud.
Does the description accurately match the outcome of the search command?
Proposed Solution / Statement:
accountCount:[1 to 4
will search for identities that have 1, 2, 3, or 4 accounts.
Does this proposed solution meet the requirement / solve the scenario?
On 4 February 2021, the following error occurred on source Control Central of type Active Directory for identity Clarence.Harper:
Failed to update attributes. There is no such object on the server.
Is this a valid place to look for more information about what caused the error?
Proposed Solution / Statement:
Search for the error message on SailPoint Compass or the SailPoint Developer Forums. Check for previous discussions or whitepapers.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement true about the characteristics of different connector types in Identity Security Cloud (ISC)?
Proposed Solution / Statement:
Active Directory (AD) connectors can handle both authentication and identity lifecycle management, including user provisioning.
Does this proposed solution meet the requirement / solve the scenario?
An Administrator needs to monitor the health of Virtual Appliances (VA) and make sure the appropriate actions are taken if an alert message appears.
Is the following action appropriate in order to accomplish this task?
Proposed Solution / Statement:
If the VA status badge text shows "Connected", no action is required for the admin on this VA, move onto the next one in the cluster.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding sources in Identity Security Cloud?
Proposed Solution / Statement:
A source is the Identity Security Cloud representation of a third-party application, database, or directory management system that maintains its own set of user accounts or personnel records.
Does this proposed solution meet the requirement / solve the scenario?
Reference the following search query:
created:[now-24h TO now] AND (@access(displayName:New_Hire_Access) OR @access(source.name:Acme_HRMS)) AND @entitlements(name:Manager_Access)
Is this statement true about the search query above?
Proposed Solution / Statement:
Removing the AND @entitlements(name:Manager_Access) from the query makes it valid, returning users who were created within the last 24 hours and either have access to the source Acme_HRMS or have the New_Hire_Access access profile assigned.
Does this proposed solution meet the requirement / solve the scenario?
When reviewing accounts in a flat file source, some entitlements seem to be missing.
Is this a potential cause of this issue?
Proposed Solution / Statement:
The delimited file is not sorted by account ID. All entitlements for a single account ID must be listed together within the delimited file. Otherwise, only a partial subset of the entitlements will be added to the identity.
Does this proposed solution meet the requirement / solve the scenario?
A newly created entitlement is not showing up in Identity Security Cloud. An aggregation issue is suspected. The administrator wants to verify what went wrong.
Is this the correct way to troubleshoot the issue?
Proposed Solution / Statement:
Wait for the next Identity refresh to run, as it will automatically generate the missing entitlement.
Does this proposed solution meet the requirement / solve the scenario?
Match the following options with their appropriate match.

Is this a valid statement about the creation of a PAT?
Proposed Solution / Statement:
If no scopes are selected, the scope sp:scopes:all will be assigned.
Does this proposed solution meet the requirement / solve the scenario?
Does the following event trigger the de-provisioning of a user's access?
Proposed Solution / Statement:
The department of a user changes, and the new department does not have access to an application that was previously assigned.
Does this proposed solution meet the requirement / solve the scenario?