Courseiva

C_CPI Integration Suite Development Practice Question

An integration developer is building an integration flow in SAP Cloud Integration that must call an external REST API. The API requires an API key sent in a custom HTTP header named X-API-Key. The developer wants to store the API key securely and reference it in the receiver channel without hardcoding it. Which approach should the developer use?

⚠ Common exam trap

The trap here is reaching for a security material type like OAuth2 or User Credentials when the API simply requires a static key in a custom header, which is best handled with a Secure Parameter and a Content Modifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Secure Parameter artifact, then reference it in a Content Modifier step that sets the X-API-Key header before the receiver call.

Secure Parameters are designed to store confidential values like API keys without exposing them in the integration flow. A Content Modifier step can reference the secure parameter and set the X-API-Key header before the receiver call. This keeps the secret out of the flow configuration and satisfies the external API's custom header requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Keystore artifact containing the API key as a certificate alias and reference it in the HTTP receiver adapter's SSL configuration.

    Why it's wrong here

    Keystore artifacts hold private keys and certificates for TLS and signing, not arbitrary API keys. Referencing a keystore in SSL configuration affects transport security, not custom HTTP headers. The external API expects X-API-Key as a header value, so a keystore entry would not deliver the key in the required form.

  • ✗

    Create a Security Material of type OAuth2 Client Credentials and reference it in the HTTP receiver adapter's authentication settings.

    Why it's wrong here

    OAuth2 Client Credentials security material is used for token-based authentication flows, not for static API keys in custom headers. The external API expects a plain X-API-Key header, so configuring OAuth2 would not produce the required header and authentication would fail. This material type is meant for obtaining access tokens, which is a different mechanism.

  • ✓

    Create a Secure Parameter artifact, then reference it in a Content Modifier step that sets the X-API-Key header before the receiver call.

    Why this is correct

    Secure Parameters store confidential values such as API keys and can be referenced using the secure parameter placeholder syntax in integration flow steps. A Content Modifier can set the X-API-Key header using that placeholder, so the key is not hardcoded. This approach securely injects the API key into the required custom header for the external REST API call.

  • ✗

    Create a User Credentials security material and reference it in the HTTP receiver adapter's authentication settings.

    Why it's wrong here

    User Credentials security material stores a username and password for Basic authentication, not an API key. Using it would send an Authorization header with Basic credentials, not the X-API-Key header the API requires. The API would reject the call because the expected custom header is missing.

About these practice questions

One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.