Courseiva

C_CPI Integration Suite Development Practice Question

You are developing an integration flow in SAP Cloud Integration that processes messages from an AS2 sender. The partner sends signed and encrypted messages, and you must verify the signature and decrypt the payload. Which configuration steps must you perform in the AS2 sender adapter to achieve this?

⚠ Common exam trap

Candidates often confuse which keys are used for signature verification versus decryption; signature verification uses the sender's public key, while decryption uses the receiver's private key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Import the partner's public certificate for signature verification, import your private key for decryption, and enable both signature verification and decryption in the adapter.

For an AS2 sender adapter to verify a partner's signature and decrypt a message, you must import the partner's public certificate for signature verification and your own private key for decryption. Enabling both functions in the adapter ensures the message is authenticated and decrypted correctly. This setup aligns with the asymmetric cryptography principles underlying AS2 security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Import the partner's public certificate for signature verification, import your private key for decryption, and enable both signature verification and decryption in the adapter.

    Why this is correct

    The AS2 sender adapter requires the partner's public certificate to verify their digital signature, and your own private key to decrypt the message payload. Enabling both signature verification and decryption in the adapter configuration ensures the message is validated and decrypted correctly. This is the standard setup for secure AS2 communication where the partner signs and encrypts outgoing messages.

  • ✗

    Import your own private key for signature verification, import your own public certificate for decryption, and enable both signature verification and decryption in the adapter.

    Why it's wrong here

    Signature verification cannot use a private key; it requires the sender's public certificate. Your own private key is not the correct key for verifying the partner's signature. For decryption, your public certificate cannot decrypt a message encrypted with your public key; only your private key can. This configuration would result in both signature verification and decryption failures, causing the message to be rejected.

  • ✗

    Import your own public certificate for signature verification, import the partner's private key for decryption, and enable both signature verification and decryption in the adapter.

    Why it's wrong here

    Signature verification uses the sender's public certificate, not your own public certificate. The partner signs with their private key, so you need their public key to verify. Similarly, decryption requires your private key, not the partner's private key, because the message was encrypted with your public key. Using the wrong certificates will cause signature verification to fail and decryption to produce unreadable data.

  • ✗

    Import the partner's public certificate for signature verification, import the partner's public certificate for decryption, and enable both signature verification and decryption in the adapter.

    Why it's wrong here

    While the partner's public certificate is correct for signature verification, it cannot be used for decryption. Decryption requires your private key, which corresponds to the public key the partner used to encrypt the message. Using the partner's public certificate for decryption will fail because it does not contain the private key needed to decrypt the message. The adapter will reject the message due to decryption errors.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This C_CPI question is part of Courseiva's 218-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_CPI practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_CPI exam.