C_CPI Integration Suite Development Practice Question
An integration developer must expose an integration flow as an HTTPS endpoint that a partner will call. The partner requires mutual TLS authentication, and only certificates issued by the partner's internal CA should be accepted. The developer has uploaded the partner's root CA certificate into the tenant keystore. Which additional configuration on the HTTPS sender adapter is required to enforce mutual TLS with that specific CA?
⚠ Common exam trap
Candidates often confuse keystore storage with trust configuration, when the CA must also be selected as the trusted issuer in the sender adapter's Client Certificate authorization settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Authorization option to 'Client Certificate' and select the partner's root CA certificate as the trusted issuer in the sender adapter's certificate configuration.
Mutual TLS on an HTTPS sender adapter is enabled by selecting Client Certificate authorization, which causes the runtime to request a client certificate during the TLS handshake. The trusted issuer list must include the partner's root CA so only certificates chaining to it are accepted. Role-based or None authorization does not validate client certificates, and merely storing the CA in the keystore without referencing it as a trusted issuer leaves the endpoint unauthenticated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the Authorization option to 'None' and rely on the partner's IP allowlist configured in the Cloud Integration tenant firewall settings.
Why it's wrong here
Setting authorization to None disables authentication entirely, so any caller reaching the endpoint is processed. An IP allowlist is a network-level control and does not satisfy a mutual TLS requirement, because it does not validate client certificates. This configuration would fail the partner's security requirement and expose the integration flow to unauthenticated calls from allowed addresses.
- ✗
Set the Authorization option to 'Role-Based' and add the partner's certificate to the tenant keystore under a new alias used only by this flow.
Why it's wrong here
Adding a certificate to the keystore does not by itself require clients to present it, and Role-Based authorization evaluates user roles rather than certificate chains. The endpoint would still accept requests without a client certificate, so mutual TLS would not be enforced. The keystore alias also does not map a specific incoming certificate to a trusted issuer for handshake validation.
- ✗
Set the Authorization option to 'User Role' and assign the partner's technical user to the ESBMessaging.send role.
Why it's wrong here
User Role authorization controls which authenticated users may invoke the endpoint through role assignment, but it does not perform certificate validation. Mutual TLS requires the server to request and validate a client certificate during the TLS handshake, which happens before any role check. This setting alone would leave the endpoint open to clients presenting any certificate, or to no certificate at all.
- ✓
Set the Authorization option to 'Client Certificate' and select the partner's root CA certificate as the trusted issuer in the sender adapter's certificate configuration.
Why this is correct
Choosing Client Certificate authorization makes the sender adapter request a client certificate during the TLS handshake and validate it against the configured trusted issuer. Selecting the partner's root CA as the trusted issuer restricts acceptance to certificates chaining to that CA, which is exactly the mutual TLS requirement described. This enforces both authentication and the CA restriction in one configuration.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.