Prepare for the SailPoint Certified IdentityNow Engineer exam with our extensive collection of questions and answers. These practice Q&A are updated according to the latest syllabus, providing you with the tools needed to review and test your knowledge.
QA4Exam focus on the latest syllabus and exam objectives, our practice Q&A are designed to help you identify key topics and solidify your understanding. By focusing on the core curriculum, These Questions & Answers helps you cover all the essential topics, ensuring you're well-prepared for every section of the exam. Each question comes with a detailed explanation, offering valuable insights and helping you to learn from your mistakes. Whether you're looking to assess your progress or dive deeper into complex topics, our updated Q&A will provide the support you need to confidently approach the SailPoint IdentityNow-Engineer exam and achieve success.
An IdentityNow engineer has the following problem:
IdentityNow shows status failed on a virtual appliance (VA).
Is this one of the steps that should be taken troubleshoot the issue?
Solution: Log in to the console of the VA and verify that the VA has connectivity to the internet.
Yes, verifying that the Virtual Appliance (VA) has connectivity to the internet is a critical step when troubleshooting a 'failed' status in IdentityNow. The VA requires internet connectivity to communicate with SailPoint IdentityNow's cloud services for synchronization, updates, and other key functions. If the VA is unable to reach the internet, it can lead to a failed status. Logging in to the VA's console to test network connectivity (e.g., using ping or curl commands) is an important step in diagnosing the issue.
Key Reference from SailPoint Documentation:
VA Internet Connectivity Troubleshooting: SailPoint recommends checking the network connectivity as one of the first steps when the VA shows a failed status.
An IdentityNow engineer needs to find identities with disabled AD accounts by using IdentityNow's search features. Is this the correct search syntax to perform this task?
Solution:

No, the search syntax @accounts( source.name:'AD' AND disabled:true ) is incorrect for SailPoint IdentityNow because the attribute disabled may not be universally recognized or applicable for all sources in the system. Using the state:'disabled' condition (as in previous correct answers) is a more reliable and system-compliant approach to find disabled accounts.
Key Reference from SailPoint Documentation:
Standard Account State Search: The correct search syntax involves using state:'disabled' instead of disabled:true for querying disabled accounts.
A customer wants to configure a virtual appliance (VA) to use a static IP address. Does this file on the VA need to be modified to perform the configuration?
Solution: /home/sailpoint/config.yaml
The /home/sailpoint/config.yaml file is not used to configure the Virtual Appliance (VA) to use a static IP address. This file is generally used for other configuration purposes related to the SailPoint IdentityNow application settings, not for network configurations like setting static IP addresses. Network configurations are handled at the system or network service level within the VA's Linux environment.
SailPoint IdentityNow Virtual Appliance Configuration Guide.
SailPoint IdentityNow Networking Configuration Documentation.
Does the following use case accurately describe provisioning on a source that has provisioning disabled?
Solution: Provisioning is initialed by a process (e.g. Access Request Role Assignments). Provisioning instructions are calculated based on current access, and go through filtering and expansion processes. Provisioning is then assigned to a source for provisioning. A virtual appliance retries the provisioning request and carries out the provisioning via the connector. The results are communicated back to identityNow.
The provided use case incorrectly describes the provisioning process on a source that has provisioning disabled. If provisioning is disabled for a source, automated provisioning via the Virtual Appliance and connectors is not possible. The Virtual Appliance cannot retry or carry out the provisioning in this case, as the system explicitly prevents automated provisioning operations on sources marked as non-provisionable.
When a source has provisioning disabled, the system only supports manual provisioning, where a task is opened in IdentityNow for a person to manually execute the provisioning steps. The Virtual Appliance does not handle provisioning for disabled sources, so the described scenario where it retries the request and carries out provisioning is inaccurate.
SailPoint IdentityNow Provisioning Configuration Guide.
SailPoint IdentityNow Virtual Appliance and Connector Operations Documentation.
Does the following use case correctly describe passthrough authentication?
Solution: A user logs into identityNow via an identity provider's login. The identity provider exchanges information via federation.
The use case describes a user logging into IdentityNow via an external identity provider's login, where information is exchanged via federation. This correctly aligns with the concept of passthrough authentication.
Passthrough authentication often uses protocols like SAML (Security Assertion Markup Language) or OAuth for federation. In this case, the identity provider (IdP) handles the authentication and then passes the necessary authentication tokens or assertions back to SailPoint IdentityNow, granting the user access without directly requiring their password to be stored or authenticated by IdentityNow. This is a typical use case of federation and passthrough authentication.
SailPoint IdentityNow Documentation on SAML and OAuth Federation.
SailPoint IdentityNow Federation and Passthrough Authentication Configuration Guides.
Full Exam Access, Actual Exam Questions, Validated Answers, Anytime Anywhere, No Download Limits, No Practice Limits
Get All 108 Questions & Answers