Courseiva

C_CPI Integration Suite Development Practice Question

An integration developer is building an integration flow that must call an external REST endpoint. The endpoint requires OAuth 2.0 client credentials, and the client secret must not be stored in the integration flow configuration. The developer has already created an OAuth2 Client Credentials artifact in the Security Material monitor. Which step should be configured in the integration flow to obtain the access token before the HTTP receiver call?

⚠ Common exam trap

The trap here is thinking the HTTP adapter or a Content Modifier can perform the OAuth2 token exchange, when a separate OAuth2 Authorization step is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an OAuth2 Authorization step and reference the OAuth2 Client Credentials artifact to retrieve the access token.

The OAuth2 Authorization step is purpose-built to obtain tokens from an OAuth 2.0 authorization server using a configured OAuth2 Client Credentials artifact. It keeps the client secret in Security Material, retrieves the token at runtime, and stores it in a message header or property for the subsequent HTTP receiver to use. This satisfies both the functional and security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a Groovy Script step that reads the client secret from a local file and calls the token endpoint.

    Why it's wrong here

    Reading secrets from a local file is insecure and unsupported in the cloud runtime, where the file system is not a reliable secret store. This approach also bypasses the Security Material artifact and introduces custom code where a standard step exists, increasing maintenance and risk.

  • ✓

    Add an OAuth2 Authorization step and reference the OAuth2 Client Credentials artifact to retrieve the access token.

    Why this is correct

    The OAuth2 Authorization step is the built-in mechanism to obtain an access token using a configured OAuth2 Client Credentials artifact from Security Material. It performs the token request, stores the token, and makes it available for the subsequent HTTP receiver call without exposing the secret in the flow.

  • ✗

    Add a Content Modifier step and set the Authorization header to a hardcoded Bearer token.

    Why it's wrong here

    Hardcoding a Bearer token defeats the purpose of using OAuth 2.0 and will expire, causing failures. It also violates the requirement that the client secret not be stored in the integration flow configuration, and Content Modifier cannot perform the token exchange.

  • ✗

    Add a Request Reply step with the OAuth2 adapter and select the Client Credentials grant type.

    Why it's wrong here

    The Request Reply step uses adapters such as HTTP, SOAP, or OData, not an OAuth2 adapter for token retrieval. While the HTTP adapter can use OAuth2 authentication, it does not itself fetch a standalone token to be reused; the dedicated OAuth2 Authorization step is required for that.

About these practice questions

Courseiva writes every C_CPI question from scratch — 218 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.