C_CPI Integration Suite Development Practice Question
An integration developer is tasked with encrypting a specific payload attribute containing Personally Identifiable Information (PII) before sending it to an external partner. The partner requires encryption using Pretty Good Privacy (PGP) standards with a specific public key stored in the tenant keystore. Which integration flow step should the developer configure to fulfill this requirement?
⚠ Common exam trap
Candidates often confuse the PGP Encryptor with the Content Modifier or general encryption steps. They fail to select the specific step that natively handles the PGP standard and keystore integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PGP Encryptor step referencing the partner's public key alias stored securely in the SAP Integration Suite Keystore.
The PGP Encryptor step is specifically engineered to sign and encrypt message payloads or specific attachments using keys managed within the tenant keystore. Using native PGP steps ensures compliance with corporate data privacy mandates and industry-standard cryptographic protocols without requiring custom script development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Content Modifier configured with SHA-256 hashing algorithms on the designated payload nodes.
Why it's wrong here
Hashing algorithms such as SHA-256 provide one-way data integrity verification rather than reversible encryption. Hashing makes it impossible for the external partner to decrypt and read the original PII attribute value upon receipt.
- ✗
Local Integration Process configured with XML Security signing options and private key bindings.
Why it's wrong here
XML Security steps are restricted strictly to XML digital signatures and XML encryption specifications. They cannot process arbitrary payloads, binary data, or non-XML formats using standard PGP cryptographic containers required by external partners.
- ✗
Script step executing custom Java Cryptography Architecture libraries to perform symmetric AES encryption.
Why it's wrong here
Writing custom cryptographic code in Groovy or Java introduces maintenance burdens and potential security vulnerabilities. SAP Integration Suite provides certified out-of-the-box PGP encryption steps that should always be preferred over custom cryptographic implementations.
- ✓
PGP Encryptor step referencing the partner's public key alias stored securely in the SAP Integration Suite Keystore.
Why this is correct
The PGP Encryptor step natively integrates with the tenant keystore to retrieve partner public keys and encrypt designated message segments. This configuration guarantees secure, standards-compliant transmission of sensitive PII data to external entities.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.