C_CPI Integration Suite Development Practice Question
An integration developer is designing a Cloud Integration flow that must call an external REST API. The API requires a bearer token that expires every 30 minutes, and the flow is invoked frequently. The developer wants to avoid requesting a new token on every call. Which TWO measures should the developer implement? (Choose two.)
⚠ Common exam trap
The trap here is thinking that a fresh token must be requested for each call to be safe, when caching a valid token until near expiry is both secure and efficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the OAuth2 client credentials grant with a token cache enabled on the adapter so tokens are reused across calls.
To avoid requesting a token on every call, the developer should cache the token and reuse it until expiry. This can be done either by storing the token in a data store and refreshing near expiration, or by enabling the OAuth2 client credentials token cache on the adapter, which handles reuse and refresh automatically. Hard-coding, requesting infinite lifetime, or fetching a token per call all fail the efficiency and security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable token expiry validation on the external API by requesting a token with an infinite lifetime.
Why it's wrong here
The external API controls token lifetime, and a client cannot request an infinite expiry if the authorization server does not support it. Attempting to disable validation would require changing the API, which is outside the developer's control. This measure is not feasible and does not address the requirement to reuse tokens efficiently.
- ✓
Configure the OAuth2 client credentials grant with a token cache enabled on the adapter so tokens are reused across calls.
Why this is correct
The OAuth2 client credentials grant on the HTTP receiver adapter includes a token cache that automatically reuses valid tokens and refreshes them when they expire. Enabling this cache eliminates a token request per call without custom logic. It is the built-in mechanism for exactly this scenario and works with the 30-minute expiry by refreshing before the token becomes invalid.
- ✓
Store the token in a data store and reuse it until its expiry time, refreshing only when it is close to expiration.
Why this is correct
A data store persists the token across flow executions so that frequent invocations reuse the same token instead of requesting a new one each time. Checking the expiry before use and refreshing only when needed reduces token endpoint calls while ensuring the token remains valid. This is the standard caching approach for expiring bearer tokens in Cloud Integration.
- ✗
Call the token endpoint before every API request to guarantee a fresh token.
Why it's wrong here
Requesting a new token for every call directly contradicts the goal of avoiding a token request per invocation. It increases latency and load on the authorization server. While it would work functionally, it is inefficient and does not leverage caching, so it fails the stated objective of reducing token requests.
- ✗
Hard-code the bearer token in the integration flow configuration and update it manually before each expiry.
Why it's wrong here
Hard-coding a token is insecure and operationally fragile. Tokens expire every 30 minutes, so manual updates would be required continuously, and any missed update causes failures. It also exposes credentials in the flow configuration. This approach does not scale and contradicts security best practices, so it is not a valid measure.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.