C_CPI Integration Suite Development Practice Question
An integration developer must expose an integration flow in SAP Cloud Integration as an HTTPS endpoint that an external business partner can call. The partner requires that the flow authenticate callers using client certificate authentication rather than basic credentials. Which TWO configuration actions must the developer perform to enable this? (Choose two.)
⚠ Common exam trap
The trap here is assuming that importing a certificate alone secures the endpoint, or that OAuth client credentials and client certificate authentication are interchangeable ways to authenticate an external caller.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the HTTPS sender adapter with the authorization option Client Certificate and select the appropriate role for the calling certificate.
Client certificate authentication at an HTTPS sender requires two coordinated actions: the sender adapter must be set to authorize by client certificate with a role assignment, and the tenant must trust the partner's certificate chain by importing the certificate or its issuing certificate authority and mapping it to a user or role. Together these enable mutual TLS validation and authorization without basic credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the HTTPS sender adapter with the authorization option Client Certificate and select the appropriate role for the calling certificate.
Why this is correct
The HTTPS sender adapter offers an authorization mode that validates the client certificate presented during the TLS handshake instead of a user and password. Selecting Client Certificate and assigning a role to the certificate subject maps the authenticated caller to an authorization role, allowing the partner to invoke the endpoint without transmitting basic credentials, which directly satisfies the stated requirement.
- ✓
Import the partner's trusted certificate or its issuing certificate authority into the tenant's keystore for certificate-to-user mapping.
Why this is correct
For client certificate authentication to succeed, the tenant must trust the certificate chain presented by the caller, which requires importing the partner certificate or the issuing certificate authority into the tenant keystore and mapping the certificate to a user or role. Without this trust anchor and mapping, the TLS handshake or the authorization check fails even if the sender adapter is set to Client Certificate.
- ✗
Enable the Principal Propagation option on the sender adapter so the partner's certificate is forwarded to the backend system.
Why it's wrong here
Principal propagation is a receiver-side concept used to forward the authenticated user identity to an on-premise or backend system, typically combined with Cloud Connector. It does not authenticate the incoming partner at the HTTPS sender; enabling it alone leaves the endpoint without client certificate validation and does not meet the authentication requirement.
- ✗
Create a service instance of the Process Integration Runtime plan and bind it to the integration flow's deployed artifact.
Why it's wrong here
Process Integration Runtime service instances grant OAuth-based access for runtime APIs and are used by external clients to call integration flows with OAuth tokens. They do not perform client certificate authentication at the sender and are not required for a partner that presents an X.509 certificate, so this action is irrelevant to the scenario.
- ✗
Deploy an OAuth 2.0 client credentials artifact and reference its token endpoint URL in the sender adapter configuration.
Why it's wrong here
OAuth 2.0 client credentials is a token-based authorization mechanism where the caller obtains an access token from a token endpoint, which is unrelated to mutual TLS client certificate authentication. Configuring it here would not validate the partner's certificate, and the sender adapter's client certificate option would remain unfulfilled, so this action does not satisfy the requirement.
About these practice questions
One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.