C_CPI Integration Suite Development Practice Question
An integration developer needs to expose an integration flow in SAP Cloud Integration so that an external partner can trigger it over HTTPS with a JSON payload, but the partner must not be able to reach any other tenant resource. Which sender adapter configuration is appropriate?
⚠ Common exam trap
The trap here is equating a valid authentication technology such as OAuth or WS-Security with least-privilege authorization, when the deciding factor is the scope of the role assigned to the partner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An HTTPS sender adapter with a dedicated address and a user role assigned only to the integration flow's runtime artifact.
Publishing an interface to an external partner requires an HTTPS sender adapter, which exposes the flow at a unique endpoint. Restricting the partner's credentials to a role assigned only to that runtime artifact limits them to invoking this single flow. Alternative adapters either change the protocol away from HTTPS JSON or grant overly broad roles that would expose other tenant resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An OData sender adapter with OAuth 2.0 and the ESBMessaging.send role assigned to the partner.
Why it's wrong here
OData senders are intended for OData-style interfaces, not arbitrary JSON posts, and ESBMessaging.send is a broad role that permits sending to many flows. The partner would gain more reach than intended, so this does not meet the isolation requirement even though OAuth itself is a valid authentication mechanism.
- ✗
An IDoc sender adapter with a partner-specific port and principal propagation enabled.
Why it's wrong here
IDoc senders handle SAP document exchange, not HTTPS JSON requests from external partners. Principal propagation is designed for user-context forwarding in specific adapter scenarios, not for granting a partner narrow HTTPS access, so this option fails on both protocol and authorization grounds.
- ✓
An HTTPS sender adapter with a dedicated address and a user role assigned only to the integration flow's runtime artifact.
Why this is correct
An HTTPS sender adapter publishes the flow at its own endpoint address, and authorization is enforced through the runtime artifact's role. Granting the partner a role scoped only to that artifact means the credentials can invoke this flow but nothing else, which satisfies the requirement to expose exactly one interface over HTTPS.
- ✗
A SOAP sender adapter with WS-Security and a tenant-wide security artifact administrator role.
Why it's wrong here
SOAP would force the partner to send XML envelopes rather than JSON, and a tenant-wide administrator role grants far more access than the single flow requires. Both the protocol and the over-broad authorization contradict the requirement, making this configuration unsuitable despite being technically functional.
About these practice questions
One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.