C_CPI Integration Suite Development Practice Question
You are designing an integration flow in SAP Cloud Integration that must call an external SOAP service. The service requires WS-Security UsernameToken authentication with a password digest. Where do you configure the WS-Security settings so they are applied to the outbound SOAP request?
⚠ Common exam trap
The trap here is assuming that storing a User Credentials artifact in Security Material is sufficient for WS-Security, when the SOAP channel's WS-Security settings must also be enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
On the SOAP receiver channel under the WS-Security tab, selecting Username Token and Password Digest.
WS-Security UsernameToken with password digest is a native capability of the SOAP receiver adapter. Enabling Username Token and selecting Password Digest on the channel's WS-Security tab causes the adapter to generate the nonce, created timestamp, and digest, and to insert the correct security header into the outbound SOAP request, meeting the external service's authentication requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In a Content Modifier step that writes a SOAPAction header before the receiver channel.
Why it's wrong here
A Content Modifier can set headers and properties, but the WS-Security UsernameToken digest is a signed SOAP header element requiring nonce and timestamp generation, not a simple HTTP header. Writing a SOAPAction header only tells the endpoint which operation to invoke and does not authenticate the request. This approach cannot produce a valid WS-Security security header.
- ✓
On the SOAP receiver channel under the WS-Security tab, selecting Username Token and Password Digest.
Why this is correct
The SOAP receiver adapter exposes a WS-Security configuration area where you enable Username Token and choose the password digest option. This makes the adapter add the appropriate WS-Security header with a nonce and created timestamp to the outbound request, satisfying the external service's authentication requirement without any custom scripting.
- ✗
In a Groovy script step that manually builds the entire SOAP envelope including the security header.
Why it's wrong here
A Groovy script could theoretically construct a security header, but doing so requires manually implementing nonce generation, timestamp formatting, and digest computation, which is error-prone and unnecessary. The SOAP receiver adapter provides built-in WS-Security support that handles these details correctly. Choosing a script over the adapter's native capability adds complexity and risk without benefit.
- ✗
In the integration flow's runtime configuration artifact under Security Material, creating a User Credentials artifact only.
Why it's wrong here
A User Credentials artifact stores the username and password securely, but storing credentials alone does not add a WS-Security UsernameToken header to the SOAP message. The credential artifact supplies the secret; the SOAP receiver channel's WS-Security settings must still be enabled to generate the digest and insert the security header. Without that channel configuration, the request goes out unauthenticated.
About these practice questions
This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.