C_CPI Integration Suite Development Practice Question
You are designing an integration flow in SAP Cloud Integration that must call an external SOAP service. The service requires WS-Security with a username token and a timestamp. Which adapter should you use, and how should you configure security?
⚠ Common exam trap
The trap here is assuming that OAuth 2.0 or X.509 can substitute for WS-Security username token, but the service explicitly requires WS-Security with a username token and timestamp.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the SOAP adapter and configure WS-Security with 'Username Token' and 'Timestamp' in the adapter's security settings.
The SOAP adapter natively supports WS-Security, allowing you to configure a username token and timestamp. This directly fulfills the external service's security requirements. Other adapters or security mechanisms do not provide the same standards-compliant WS-Security features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the SOAP adapter and configure OAuth 2.0 authentication with a client credentials grant.
Why it's wrong here
OAuth 2.0 is not the same as WS-Security. The external service requires WS-Security with a username token and timestamp, not OAuth. Using OAuth would not satisfy the security requirements and would likely result in authentication failure. The SOAP adapter supports both, but you must choose the correct security policy.
- ✓
Use the SOAP adapter and configure WS-Security with 'Username Token' and 'Timestamp' in the adapter's security settings.
Why this is correct
The SOAP adapter in SAP Cloud Integration supports WS-Security policies. You can configure a username token and timestamp directly in the adapter's security settings. This is the standard way to secure SOAP calls with WS-Security, and it meets the external service's requirements without additional steps.
- ✗
Use the SOAP adapter and configure WS-Security with 'X.509 Token' and 'Timestamp'.
Why it's wrong here
X.509 token is used for certificate-based authentication, not username token. The scenario specifically requires a username token. While X.509 provides stronger security, it does not match the service's requirement. The SOAP adapter allows selection of the token type, so you must choose 'Username Token'.
- ✗
Use the HTTP adapter and add a SOAP header with the username and timestamp manually.
Why it's wrong here
The HTTP adapter does not provide built-in WS-Security support. Manually adding SOAP headers is error-prone and does not implement the WS-Security standard correctly, including proper encryption and signing. The SOAP adapter is specifically designed for SOAP services and offers native WS-Security configuration.
About these practice questions
Courseiva writes every C_CPI question from scratch — 218 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.