We at Crack4sure are committed to giving students who are preparing for the SailPoint Identity-Security-Administrator Exam the most current and reliable questions . To help people study, we've made some of our SailPoint Certified Identity Security Administrator exam materials available for free to everyone. You can take the Free Identity-Security-Administrator Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.
An organization is considering purchasing an IGA tool. The manager asks the administrator to explain what compliance features the IGA tool provides for separation of duties, protecting personally identifying data and privileged access, and how the company can prove to the auditors that they comply with all laws and regulations.
Is this a good explanation of one of such features?
Proposed Solution / Statement:
"The vendor has provided proof that the tool complies with HIPAA, PCI-DSS, SoX, ISO 27002 and the GDPR. The fact that we use this IGA tool is sufficient legal proof for the auditors that we comply with all regulations."
Does this proposed solution meet the requirement / solve the scenario?
When reviewing accounts in a flat file source, some entitlements seem to be missing.
Is this a potential cause of this issue?
Proposed Solution / Statement:
The delimited file is not sorted by account ID. All entitlements for a single account ID must be listed together within the delimited file. Otherwise, only a partial subset of the entitlements will be added to the identity.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario for reviewing access requests in the approval management page?
Proposed Solution / Statement:
It is possible for an administrator to supersede an approver's cancellation of a request.
Does this proposed solution meet the requirement / solve the scenario?
Does this statement accurately describe the purpose of the Virtual Appliance (VA)?
Proposed Solution / Statement:
The VA eliminates the need for databases to store Personally Identifiable Information (PII).
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding uncorrelated accounts?
Proposed Solution / Statement:
Uncorrelated accounts can be correlated manually by downloading a correlation file, editing the file, and uploading it into the source configuration.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding attribute sync valid?
Proposed Solution / Statement:
Attribute sync can be enabled by going to Admin > Connections > Sources and selecting and editing the source.
Does this proposed solution meet the requirement / solve the scenario?
Reference the following search query:
created:[now-24h TO now] AND (@access(displayName:New_Hire_Access) OR @access(source.name:Acme_HRMS)) AND @entitlements(name:Manager_Access)
Is this statement true about the search query above?
Proposed Solution / Statement:
Searching for @entitlements(name:Manager_Access) will only return a list of access profiles that the entitlements are associated with.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Cloud tenant is configured to disable all source accounts for an identity that enters the terminated lifecycle state. A database administrator reports they have been noticing that employees who are terminated, still have their database accounts as "Active" in the source system.
Is this a valid troubleshooting option for the scenario above?
Proposed Solution / Statement:
On the Identity, validate that the Lifecycle State attribute value that is set for the affected users is "Terminated".
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid scenario where a Separation of Duties policy should be used?
Proposed Solution / Statement:
A user requests a major system configuration and approves the change.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement about entitlements valid?
Proposed Solution / Statement:
Entitlements are stored inside of the Virtual Appliance for quick indexing.
Does this proposed solution meet the requirement / solve the scenario?
Is the following statement regarding account deletion in Identity Security Cloud true?
Proposed Solution / Statement:
Once an account is deleted during aggregation, it cannot be re-aggregated or recreated in Identity Security Cloud.
Does this proposed solution meet the requirement / solve the scenario?
Test connection for the Active Directory source fails when Transport Layer Security (TLS) is on:
java.lang.Exception: [s0100] Failed to connect to server ...
PKIX path validation failed
sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Is this a valid step towards analyzing and resolving this issue?
Proposed Solution / Statement:
Upload the AD certificate into the TLS Settings page of the Active Directory source.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding the objects that represent access of systems managed by Identity Security Cloud?
Proposed Solution / Statement:
When criteria for automatic assignment of a Role are set to Identity List, the names of identities to include can be specified using wildcards, for example "John*".
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement regarding Identity Security Cloud (ISC) policies?
Proposed Solution / Statement:
Separation of duties policies help prevent users from gaining toxic combinations of access.
Does this proposed solution meet the requirement / solve the scenario?
Is this statement true regarding Identity Governance and Administration (IGA)?
Proposed Solution / Statement:
IGA enables security teams to gain access insight and visibility into how users access systems and apply policies and controls to ensure secure access.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about common authentication methods?
Proposed Solution / Statement:
The Identity Provider and Service Provider in a SAML setup trust each other based on public keys that have been exchanged as part of the configuration.
Does this proposed solution meet the requirement / solve the scenario?
An Identity Security Administrator notices that a Virtual Appliance (VA) is no longer communicating with Identity Security Cloud.
Is this an appropriate step to take to troubleshoot the issue?
Proposed Solution / Statement:
Test the connection with the VPN enabled and disabled to exclude it as the root cause of the issue.
Does this proposed solution meet the requirement / solve the scenario?
The security team has asked for a technical briefing on how authentication works with SailPoint.
Does the following statement correctly describe authentication methods in SailPoint and industry standards?
Proposed Solution / Statement:
When configuring SAML authentication in SailPoint, the Entity ID must exactly match the SAML metadata EntityID supplied by the identity provider for successful federation.
Does this proposed solution meet the requirement / solve the scenario?
Given the following scenario, is this a valid way to troubleshoot the issue?
A source shows this error during provisioning:
[ InvalidConfigurationException ] | Possible suggestions | You cannot initiate this action
because there are other pending or completed actions for the person that conflict with this one.
[ Error details ] Validation error occurred. Email addresses must be in the format of aaa.bbb@example.com
Proposed Solution / Statement:
Check the Create Account policy on the Source to ensure the email address is mapped correctly.
Does this proposed solution meet the requirement / solve the scenario?
An organization must maintain both production and sandbox tenants of Identity Security Cloud. The administrator needs to maintain consistent configurations across both environments, and backup and restore from previous configuration backups.
Does the following statement accurately describe how Configuration Hub functionality can help in this scenario?
Proposed Solution / Statement:
Configuration Hub allows one to create configuration templates that can be exported and imported across tenants.
Does this proposed solution meet the requirement / solve the scenario?
Assuming an access item's approval type is set to "reviewer," does the following statement accurately describe the approval flow behavior?
Proposed Solution / Statement:
When a user requests access for themselves and they are also in the approval chain, the approval flow will route to their manager instead to prevent a conflict of interest.
Does this proposed solution meet the requirement / solve the scenario?
A new employee's identity is not correctly created and shows in the Identity Exceptions report on the Identity Profile.
Is this a correct step towards analyzing and resolving the problem?
Proposed Solution / Statement:
Ensure the account attributes mapped to the identity attributes User Name (uid), Work Email (email), and Last Name are populated correctly.
Does this proposed solution meet the requirement / solve the scenario?
Below are the requirements for configuring user provisioning in an organization's Finance department.
Contractors in the organization MUST NOT be auto-provisioned with the default Office 365 license, as contractors in departments other than Finance have different license requirements.
Every Finance department user — whether employee or contractor — must be assigned one Office 365 E3 license.
No Finance employee or contractor should be provisioned more than one type of Office 365 license.
Is this a valid approach for the Identity Security Administrator to provide the necessary access?
Proposed Solution / Statement:
Create an ISC Role with membership criteria that includes all Finance department contractors. Assign an Access Profile associated with the default Office 365 license. Add these users to the Office 365 E3 license entitlement so they receive an account with the default Office 365 license and the required E3 license.
Does this proposed solution meet the requirement / solve the scenario?
Is this a valid statement about identity profile?
Proposed Solution / Statement:
Once users are assigned to an identity profile, administrators cannot modify or delete the identity profile.
Does this proposed solution meet the requirement / solve the scenario?
3 Months Free Update
3 Months Free Update
3 Months Free Update