C_CPI Integration Suite Development Practice Question
An integration developer is configuring an HTTPS sender adapter in SAP Cloud Integration to receive messages from an external partner. The partner requires mutual TLS authentication and will present a client certificate. The developer must ensure that only certificates issued by the partner's specific Certificate Authority are accepted. Which configuration step achieves this requirement?
⚠ Common exam trap
It's easy for candidates to confuse server certificate validation with client certificate validation; the partner's server certificate is not relevant when the partner acts as the client presenting a certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Client Certificate Authentication' and upload the partner's CA certificate as a trusted certificate in the tenant's keystore.
Mutual TLS authentication in SAP Cloud Integration requires the sender adapter to be configured for client certificate authentication and the tenant keystore to trust the CA that issued the client certificate. Importing the partner's CA certificate ensures that any certificate signed by that CA is accepted, fulfilling the requirement without importing individual certificates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the sender adapter to use 'Role-Based Authentication' and assign the partner to a predefined role with certificate mapping.
Why it's wrong here
Role-based authentication is an authorization mechanism, not a transport-level authentication method. While roles can be used after authentication, they do not validate client certificates. Mutual TLS requires certificate validation at the transport layer, which this option does not provide.
- ✗
Upload the partner's server certificate to the tenant keystore as a trusted certificate and enable 'Client Certificate Authentication'.
Why it's wrong here
The partner presents a client certificate, not a server certificate. Uploading the partner's server certificate would not validate the client certificate chain. The correct approach is to import the CA certificate that issued the client certificate, not the server certificate itself.
- ✗
Configure OAuth 2.0 client credentials with the partner's client ID and secret in the sender adapter.
Why it's wrong here
OAuth 2.0 client credentials are used for token-based authentication, not mutual TLS. This scenario specifically requires client certificate validation, which OAuth does not provide. Using OAuth would not validate the partner's certificate chain against a specific CA.
- ✓
Enable 'Client Certificate Authentication' and upload the partner's CA certificate as a trusted certificate in the tenant's keystore.
Why this is correct
The HTTPS sender adapter supports client certificate authentication. By enabling this option and importing the partner's CA certificate into the tenant keystore as a trusted certificate, the tenant validates that the client certificate is signed by that CA, ensuring only authorized partners can connect.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.