C_CPI Integration Suite Development Practice Question
An integration developer needs to expose an integration flow in SAP Cloud Integration as an HTTPS endpoint that external partners can call. The partner requires mutual TLS authentication and the developer must ensure only authorized clients can invoke the flow. Which configuration should be applied to the HTTPS sender adapter?
⚠ Common exam trap
The trap here is equating any strong authentication method with mutual TLS, when only client certificate authentication actually requires the partner to present an X.509 certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the sender adapter with Client Certificate authentication and assign a role to the certificate
Mutual TLS requires the client to present a certificate during the handshake, which the HTTPS sender adapter supports through Client Certificate authentication. Mapping the certificate to a user and role ensures only authorized partners can invoke the flow. Token-based or password-based options do not provide the certificate handshake the partner demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the adapter to Basic authentication and store partner credentials in a User Credentials artifact
Why it's wrong here
Basic authentication transmits username and password, typically over TLS server authentication only. It does not require the client to present a certificate, so mutual TLS is not achieved. Storing credentials in a User Credentials artifact is suitable for outbound calls, not for enforcing certificate-based inbound authentication.
- ✓
Configure the sender adapter with Client Certificate authentication and assign a role to the certificate
Why this is correct
The HTTPS sender adapter supports client certificate authentication, where the partner presents an X.509 certificate during the TLS handshake. By mapping that certificate to a user and assigning an appropriate role, the tenant enforces mutual TLS and authorization. This directly satisfies both the mutual TLS and authorized-clients requirements.
- ✗
Enable CSRF protection and require a session cookie
Why it's wrong here
CSRF protection defends against cross-site request forgery in browser-based flows; it does not authenticate external partners or enforce mutual TLS. Requiring a session cookie would complicate stateless partner integrations and does not verify client certificates. This option does not meet the mutual TLS requirement.
- ✗
Use OAuth 2.0 client credentials with a generated client ID and secret
Why it's wrong here
OAuth 2.0 client credentials authenticate the calling application via tokens, not via client certificates. It does not provide mutual TLS, which the partner explicitly requires. While it can authorize clients, it does not satisfy the certificate-based handshake requirement, so it is the wrong mechanism for this scenario.
About these practice questions
One of 218 original C_CPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.