C_CPI Integration Suite Development Practice Question
An integration developer is configuring a SOAP receiver adapter in SAP Cloud Integration to call an external SOAP service that requires WS-Security UsernameToken authentication. The developer must also ensure the message is signed. Which TWO actions must be performed to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is believing a Message Mapping or Groovy script can produce valid WS-Security headers, when only the SOAP receiver adapter's WS-Security settings generate the correct UsernameToken and XML signature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the WS-Security signing option in the SOAP receiver adapter and configure the keystore alias for the signing key.
Meeting both WS-Security UsernameToken authentication and message signing requires configuring the SOAP receiver adapter's WS-Security authentication option with secure credentials, and enabling the signing option with a keystore alias. These adapter settings generate the correct SOAP security headers and XML signature that the external service validates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the WS-Security signing option in the SOAP receiver adapter and configure the keystore alias for the signing key.
Why this is correct
The SOAP receiver adapter includes WS-Security settings where signing can be enabled. You must specify the keystore alias containing the private key and certificate used to sign the message. This ensures the SOAP message is signed as required by the external service.
- ✗
Create a PGP key pair in the tenant keystore and reference it in the SOAP receiver adapter's encryption settings.
Why it's wrong here
PGP keys are used for PGP-based encryption and signing of payloads, not for WS-Security XML signature in SOAP. The SOAP receiver adapter's WS-Security signing uses X.509 certificates and keys from the keystore, not PGP key pairs. Configuring PGP here would not produce the required WS-Security signature.
- ✗
Add a Message Mapping step that inserts a UsernameToken element into the SOAP header before the receiver call.
Why it's wrong here
Manually mapping a UsernameToken element does not produce a valid WS-Security header with the required namespace, nonce, and timestamp. The SOAP receiver adapter generates the proper WS-Security structures when the authentication option is selected. A mapping-based token would likely be rejected by the external service.
- ✗
Set the SOAP adapter's message exchange pattern to one-way and add a digital signature to the payload using a Groovy script.
Why it's wrong here
Changing the message exchange pattern affects synchronous versus asynchronous communication, not WS-Security. A Groovy script that signs the payload would not generate a proper WS-Security XML signature in the SOAP header. The external service expects WS-Security, so a payload-level signature would not satisfy the requirement.
- ✓
Configure the SOAP receiver adapter with the WS-Security UsernameToken authentication option and provide the user credentials in a secure parameter.
Why this is correct
The SOAP receiver adapter offers WS-Security UsernameToken as an authentication method. Selecting it and supplying the username and password through a secure parameter ensures the SOAP header carries the UsernameToken. This satisfies the authentication requirement without embedding credentials in the message payload.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.