Courseiva

C_CPI Integration Suite Development Practice Question

You are configuring a SAP Cloud Integration tenant to connect to an on-premise SAP S/4HANA system using the Cloud Connector. The connection must be secure and use principal propagation for user authentication. Which two configurations are required in the Cloud Connector to enable principal propagation? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse general trust setup (like certificates) with the specific Cloud Connector settings required for principal propagation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an access control list (ACL) for the on-premise system with the 'Principal Propagation' option enabled.

To enable principal propagation in the Cloud Connector, you must configure an access control list (ACL) for the on-premise system and enable the 'Principal Propagation' option within that ACL. Additionally, you must enable 'Principal Propagation' in the system mapping for that on-premise system. These two settings allow the Cloud Connector to accept the user identity from SAP Cloud Integration and propagate it to the on-premise system, ensuring that the correct user context is used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up a trust relationship between the Cloud Connector and the on-premise system's certificate authority (CA).

    Why it's wrong here

    While a trust relationship is important for secure communication, principal propagation specifically requires configuring the Cloud Connector to trust the SAP Cloud Integration tenant's certificate for user mapping. Setting up trust with the on-premise CA is part of the overall setup but is not the specific configuration for principal propagation. The key is to configure the Cloud Connector to accept the principal from the cloud and map it to an on-premise user.

  • ✗

    Install a client certificate on the Cloud Connector that is trusted by the on-premise system.

    Why it's wrong here

    While a client certificate may be used for secure communication, principal propagation primarily relies on the Cloud Connector's ability to forward the user identity. The Cloud Connector uses its own certificate to establish a secure tunnel, but the user identity is propagated via a separate mechanism, often SAML. Installing a client certificate is not the specific configuration for enabling principal propagation; it is part of the general trust setup.

  • ✗

    Configure the on-premise system to accept assertions from the Cloud Connector's certificate.

    Why it's wrong here

    The on-premise system must be configured to trust the Cloud Connector's certificate, but this is typically done as part of the overall trust setup. Principal propagation involves the Cloud Connector acting as a proxy and using the user's identity. The on-premise system must be configured to accept the propagated principal, but this is usually done via SAML or certificate-based authentication. The specific Cloud Connector configuration is the ACL and system mapping, not the on-premise system's assertion acceptance.

  • ✓

    Configure an access control list (ACL) for the on-premise system with the 'Principal Propagation' option enabled.

    Why this is correct

    In the Cloud Connector, you must define an access control list (ACL) for the on-premise system. Within the ACL, you enable the 'Principal Propagation' option to allow user identity to be passed through. This is a mandatory step to establish the trust relationship and permit principal propagation for the specified resources. Without this, the Cloud Connector will not forward the user identity.

  • ✓

    Enable 'Principal Propagation' in the Cloud Connector's system mapping for the on-premise system.

    Why this is correct

    In the Cloud Connector's system mapping, you must enable the 'Principal Propagation' checkbox. This tells the Cloud Connector to use the logged-in user's identity from SAP Cloud Integration and propagate it to the on-premise system. This setting is essential for principal propagation to work, as it activates the feature for that specific system mapping.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.