Courseiva

C_CPI Integration Suite Development Practice Question

An integration developer must expose an integration flow in SAP Cloud Integration as an HTTPS endpoint that an external partner will call synchronously. The partner will authenticate using a client certificate (mutual TLS). Which configuration must the developer perform on the HTTPS sender adapter to accept and validate the partner's client certificate?

⚠ Common exam trap

A common mix-up: candidates confuse inbound client certificate authentication with outbound credential types, such as User Credentials, which cannot store certificates or establish mutual TLS trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the sender adapter's Authorization to 'Client Certificate' and reference a deployed Keystore artifact containing the partner's trusted root certificate.

Mutual TLS on an inbound HTTPS endpoint in Cloud Integration requires selecting Client Certificate authorization on the HTTPS sender adapter and referencing a Keystore artifact that holds the partner's trusted certificate chain. User Role authorization, User Credentials artifacts, and public access with IP allowlisting all fail to perform certificate-based client authentication, so only the Keystore-backed client certificate configuration meets the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the partner's client certificate as a 'User Credentials' security artifact and select it in the sender adapter.

    Why it's wrong here

    User Credentials artifacts store a username and password pair for outbound authentication. They cannot hold a certificate or establish trust for inbound client certificate validation. Selecting this artifact type on the HTTPS sender adapter does not configure mutual TLS, so the tenant would not request or validate the partner's client certificate during the TLS handshake.

  • ✗

    Set the sender adapter's Authorization to 'User Role' and assign the partner's user to the ESBMessaging.send role.

    Why it's wrong here

    User Role authorization validates the calling user's assigned roles after authentication, typically via OAuth or basic authentication. It does not perform mutual TLS certificate validation and therefore cannot accept a client certificate. The partner, expecting mutual TLS, would fail the handshake or be rejected because no client-certificate-based trust is configured on the sender adapter.

  • ✓

    Set the sender adapter's Authorization to 'Client Certificate' and reference a deployed Keystore artifact containing the partner's trusted root certificate.

    Why this is correct

    The HTTPS sender adapter supports client certificate authentication. Selecting 'Client Certificate' as the authorization method and referencing a Keystore artifact that contains the partner's trusted root or issuing certificate enables the tenant to validate the certificate presented during the TLS handshake. This is the standard configuration for mutual TLS on an inbound HTTPS endpoint in Cloud Integration.

  • ✗

    Enable 'Allow Public Access' on the sender adapter and rely on IP allowlisting for authentication.

    Why it's wrong here

    Allow Public Access removes authentication requirements entirely, which contradicts the requirement for client certificate authentication. IP allowlisting is not a substitute for mutual TLS and does not validate certificates. The partner's client certificate would be ignored, and any caller from an allowed IP could invoke the endpoint, failing the security requirement.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.