C_CPI Integration Suite Development Practice Question
Which TWO actions must be performed to securely connect an SAP Cloud Integration tenant to an on-premise system using the Cloud Connector? Choose exactly two answers.
⚠ Common exam trap
Candidates frequently forget the administrative registration step. They focus on the access control list but fail to realize the Cloud Connector must be actively registered to the subaccount via credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Cloud Connector access control list entry permitting access to the internal backend host and port
Connecting securely requires establishing a verified tunnel connection between the Cloud Connector and Cloud Integration using a technical user. Additionally, exposing the backend system resources by adding them to the Access Control list of the Cloud Connector is mandatory for authorization and routing purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a Cloud Connector access control list entry permitting access to the internal backend host and port
Why this is correct
The Cloud Connector strictly enforces an allowlist approach. Defining the internal backend system and accessible resources in the access control list is mandatory to permit secure inbound traffic from SAP Cloud Integration to reach the protected corporate network.
- ✗
Install a reverse proxy directly in front of the Cloud Integration tenant runtime node
Why it's wrong here
A reverse proxy in front of the tenant runtime does not participate in the Cloud Connector tunnel and adds no authentication or mapping. The Cloud Connector itself performs the reverse-proxy role on-premise. Such a proxy would be relevant only for exposing the tenant's own endpoints, not for reaching on-premise systems.
- ✓
Register the Cloud Connector instance with the respective subaccount using an administrative user credential
Why this is correct
Establishing trust and communication tunnels requires registering the Cloud Connector with the specific SAP BTP subaccount. This process uses valid administrator credentials to securely bind the connector instance to the designated subaccount landscape.
- ✗
Open inbound firewall ports on the corporate network to allow direct public internet traffic to the backend system
Why it's wrong here
The Cloud Connector establishes an outbound-only secure tunnel from the on-premise network, so no inbound public ports are opened. Direct internet exposure of the backend is what the Cloud Connector exists to eliminate. Inbound firewall rules would be relevant only for systems deliberately published to the internet.
- ✗
Store backend credentials permanently inside the integration flow script using plain text properties
Why it's wrong here
Plain-text credentials in scripts expose secrets to anyone reading the integration flow and breach secure-storage requirements. The Cloud Connector scenario expects credentials held in a Security Material artefact. Plain-text properties would only be acceptable for non-sensitive, non-authentication configuration values.
Visual reference
About these practice questions
Courseiva writes every C_CPI question from scratch — 218 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.