C_CPI Integration Suite Development Practice Question
An integration developer is configuring an integration flow that must call an external SOAP service over HTTPS. The service requires WS-Security UsernameToken authentication and the developer must also validate the service's certificate. Which TWO actions should the developer perform in SAP Cloud Integration? (Choose two.)
⚠ Common exam trap
The trap here is treating WS-Security UsernameToken as interchangeable with OAuth or manual header injection, when only the SOAP adapter's built-in WS-Security configuration properly generates the token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a WS-Security Username Token in the SOAP receiver adapter with a User Credentials artifact
WS-Security UsernameToken is configured in the SOAP receiver adapter using a User Credentials artifact, and validating the service's certificate requires the issuing CA in the tenant keystore. Together these satisfy both authentication and trust requirements. OAuth, manual header insertion, and on-premise proxy settings do not meet the stated needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a Content Modifier to insert the UsernameToken header manually into the SOAP envelope
Why it's wrong here
Manually inserting a WS-Security header via Content Modifier bypasses the adapter's built-in security handling and is error-prone, especially regarding timestamp and nonce generation. The SOAP adapter's WS-Security configuration handles these elements correctly. Manual insertion also risks exposing credentials in logs and does not integrate with the User Credentials artifact.
- ✓
Configure a WS-Security Username Token in the SOAP receiver adapter with a User Credentials artifact
Why this is correct
The SOAP receiver adapter supports WS-Security UsernameToken configuration, where the username and password are sourced from a deployed User Credentials artifact. This satisfies the service's authentication requirement without hardcoding secrets. It is the standard mechanism for UsernameToken in Cloud Integration and directly addresses the scenario.
- ✗
Enable OAuth 2.0 client credentials in the SOAP adapter's authentication settings
Why it's wrong here
OAuth 2.0 client credentials is a different authentication mechanism than WS-Security UsernameToken. The external service requires UsernameToken, so configuring OAuth would not satisfy its authentication expectations. Additionally, the SOAP adapter's WS-Security settings are separate from OAuth configuration, making this option both incorrect and unrelated to the requirement.
- ✓
Deploy the service's root CA certificate in the tenant keystore and reference it in the SOAP adapter's trust configuration
Why this is correct
To validate the external service's certificate, the issuing CA must be present in the tenant keystore so the TLS handshake can be verified. Deploying the root CA and referencing the keystore in the adapter's trust settings enables certificate validation. This is required for secure outbound HTTPS calls to a service with a non-public CA.
- ✗
Configure the SOAP adapter to use Proxy Type 'On-Premise' with a Cloud Connector location ID
Why it's wrong here
Proxy Type 'On-Premise' is used when the target service resides behind a Cloud Connector on the customer network. The scenario describes an external SOAP service reachable over the internet, so on-premise proxy settings are unnecessary and would misroute the call. This option does not address authentication or certificate validation.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.