Courseiva

C_CPI Integration Suite Development Practice Question

An integration developer is building an integration flow that must call an external REST API protected by OAuth 2.0 client credentials. The API requires the client ID and client secret to be sent as HTTP Basic authentication to the token endpoint, and the resulting access token must be attached as a Bearer token to every subsequent request. The developer wants to avoid hardcoding the credentials in the integration flow and wants the token to be reused across multiple message exchanges until it expires. Which approach should the developer use?

⚠ Common exam trap

The trap here is assuming any security material that stores a secret can be used for OAuth 2.0, when only the OAuth2 Client Credentials artifact type supports the token endpoint flow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the HTTP receiver adapter with OAuth 2.0 Client Credentials authentication and select a Security Material of type OAuth2 Client Credentials that stores the client ID, client secret, and token service URL.

OAuth 2.0 client credentials flows require a security material that holds the client ID, client secret, and token service URL. SAP Cloud Integration provides the OAuth2 Client Credentials artifact type for exactly this purpose, and the HTTP receiver adapter uses it to fetch and cache the access token. This removes hardcoded secrets and avoids per-message token requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the client ID and client secret in a Partner Directory parameter and read them with a Groovy script that performs the token request on every message.

    Why it's wrong here

    A Partner Directory parameter can hold the credentials, but performing the token request on every message defeats the requirement to reuse the token until it expires. It also adds script complexity and does not leverage the built-in token caching that the OAuth2 Client Credentials security material provides.

  • ✗

    Configure the HTTP receiver adapter with OAuth 2.0 Client Credentials authentication and use a Keystore Monitor entry containing the client ID and client secret.

    Why it's wrong here

    Keystore Monitor entries store certificates and key pairs, not OAuth 2.0 client credentials. The HTTP receiver adapter cannot read a client ID and client secret from a keystore entry, so authentication against the token endpoint would fail. A dedicated OAuth2 Client Credentials security material is required.

  • ✓

    Configure the HTTP receiver adapter with OAuth 2.0 Client Credentials authentication and select a Security Material of type OAuth2 Client Credentials that stores the client ID, client secret, and token service URL.

    Why this is correct

    The OAuth2 Client Credentials security material stores the client ID, client secret, and token service URL, and the HTTP receiver adapter automatically requests, caches, and refreshes the access token. This avoids hardcoding credentials in the flow and reuses the token until it expires, which matches the requirement exactly.

  • ✗

    Create a User Credentials security material containing the client ID and client secret, then reference it from the HTTP receiver adapter using Basic authentication.

    Why it's wrong here

    User Credentials store a username and password for Basic authentication, not an OAuth 2.0 client ID and client secret pair. Using them with Basic authentication would send the credentials directly to the resource server, not obtain a Bearer token from the token endpoint, so the protected API would reject the call.

About these practice questions

Courseiva writes every C_CPI question from scratch — 218 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.