Courseiva

C_CPI Integration Suite Development Practice Question

An integration developer is configuring an HTTPS sender adapter in SAP Cloud Integration to receive messages from an external partner. The partner will authenticate using client certificate authentication. The developer must ensure the partner's certificate is trusted and that the integration flow can be called securely. Which two actions must the developer perform? (Choose two.)

⚠ Common exam trap

The trap here is focusing only on the server trusting the client and forgetting that in mutual TLS the client must also trust the server, so both trust directions must be configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the partner's root or intermediate CA certificate to the SAP Cloud Integration Keystore under the appropriate certificate alias so the incoming client certificate can be validated.

Client certificate authentication requires mutual TLS trust. The tenant must trust the partner's certificate chain by adding the issuing CA to the Keystore, and the partner must trust the tenant's server certificate by receiving it or its CA. Together these actions enable the TLS handshake to succeed and the sender adapter to accept the partner's messages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an OAuth2 Client Credentials security material and reference it in the sender adapter's authentication settings.

    Why it's wrong here

    OAuth2 Client Credentials is a token-based authentication mechanism used for outbound calls or token issuance, not for client certificate authentication on an HTTPS sender. Configuring it here would not validate the partner's client certificate. The scenario explicitly requires client certificate authentication, so OAuth2 material is irrelevant and would not enable the intended handshake.

  • ✗

    Enable CSRF protection on the sender adapter so that the partner's certificate is checked on every request.

    Why it's wrong here

    CSRF protection prevents cross-site request forgery in browser-based scenarios by requiring a token; it does not validate client certificates. Enabling it would not establish trust for the partner's certificate and could interfere with the partner's calls. Certificate validation happens during the TLS handshake, not through CSRF settings, so this action is not applicable.

  • ✓

    Add the partner's root or intermediate CA certificate to the SAP Cloud Integration Keystore under the appropriate certificate alias so the incoming client certificate can be validated.

    Why this is correct

    For client certificate authentication, SAP Cloud Integration must validate the partner's certificate against a trusted CA. Adding the partner's root or intermediate CA certificate to the Keystore allows the runtime to build and verify the chain presented during the TLS handshake. Without this trust anchor, the sender adapter rejects the connection even if the client certificate itself is valid.

  • ✗

    Configure the HTTPS sender adapter to use Role-Based Access Control and assign the partner's certificate to a user with the required permissions.

    Why it's wrong here

    Client certificate authentication does not map a certificate to a user via RBAC in the sender adapter configuration. RBAC applies to user-based access, not to certificate-based authentication. The partner authenticates at the TLS layer, and authorization is handled separately, so this action does not establish trust for the incoming certificate.

  • ✓

    Download the SAP Cloud Integration tenant's server certificate and provide it to the partner so the partner can trust the server during the TLS handshake.

    Why this is correct

    In mutual TLS, the client must also trust the server. Providing the tenant's server certificate or its issuing CA to the partner allows the partner's client to validate the server certificate during the handshake. Without this, the partner's client may reject the connection even if the server trusts the client certificate, so it is a required step for successful mutual authentication.

About these practice questions

One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.