C_CPI Integration Suite Development Practice Question
An integration developer is building an integration flow that must expose an HTTPS endpoint to a partner. The partner requires mutual TLS, and the developer needs to validate the partner's client certificate against a specific trust store. Which configuration should the developer apply on the HTTPS sender adapter?
⚠ Common exam trap
The trap here is equating any secure authentication option with mutual TLS, when only client certificate authentication actually validates the partner's X.509 certificate chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the sender adapter to use Client Certificate authentication and select the trust store containing the partner's root CA.
Mutual TLS means both sides present certificates and each validates the other. On an HTTPS sender adapter, selecting Client Certificate authentication and referencing the trust store that contains the partner's issuing root CA enables the tenant to validate the incoming client certificate. The other authentication modes rely on credentials or tokens and do not perform certificate chain validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the sender adapter to use Client Certificate authentication and select the trust store containing the partner's root CA.
Why this is correct
Mutual TLS requires the server side to validate the client certificate presented by the partner. Configuring Client Certificate authentication on the HTTPS sender adapter and pointing it to the trust store that holds the issuing root CA enables that validation, which directly satisfies the mutual TLS requirement.
- ✗
Set the sender adapter to use OAuth2 Client Credentials and register the partner as an OAuth client.
Why it's wrong here
OAuth2 client credentials authenticate an application by token issuance, not by exchanging and validating X.509 certificates. This mechanism cannot enforce mutual TLS, because it never inspects the partner's certificate chain, so it would not meet the stated security requirement.
- ✗
Set the sender adapter to use Basic authentication and store the partner's credentials in a User Credentials artifact.
Why it's wrong here
Basic authentication transmits a username and password, which is unrelated to certificate-based mutual authentication. Even when stored securely in a User Credentials artifact, this approach does not validate a client certificate, so it fails to deliver the mutual TLS behavior the partner demands.
- ✗
Set the sender adapter to use Role-Based authentication and assign the partner a role in the tenant.
Why it's wrong here
Role-Based authentication validates user credentials and authorizations rather than X.509 client certificates. It does not perform certificate chain validation, so it cannot satisfy a mutual TLS requirement where the partner presents a client certificate that must be checked against a trust store.
About these practice questions
One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.