問題一覧
1
Rapid Setup is an implementation tool built into the current IdentityIQ product version to help with configuring IdentityIQ.
True
2
Groups which grant/identify user access on other systems (applications) and loaded into IdentityIQ through (account group) aggregation.
Account Group
3
What is a workflow case?
The object that represents a running instance of a workflow.
4
Certification Events can be automatically triggered by a wide range of data changes within IdentityIQ, such as changing departments. The Perform Maintenance task must run for the certification process to complete.
True
5
Which of these is the best definition of Policy?
Business rules that define user access conditions that are unwanted by the business
6
Once the spadmin password has been updated from the default, anyone who can authenticate into IdentityIQ can access the IdentityIQ console.
False
7
You can exclude certain users (such as executives) from a certification campaign by using _____________.
An exclusion rule
8
Password Policies must be defined for each application for which managing passwords is supported.
False
9
Group of IdentityIQ users defined through an Advanced Analytics query and used to define target of operation (e.g. task filter, report filter).
Population
10
By adding an identity to a workgroup, the identity inherits capabilities assigned to the workgroup.
True
11
In IdentityIQ, where and how are new Populations created?
In Advanced Analytics, using identity search criteria
12
The certifier in a certification campaign is always the current manager of each employee.
False
13
Roles can be configured to automatically be enabled at a specified future date.
True
14
What are Identities
IdentityIQ users and those with access to systems in your organization
15
Which type of IdentityIQ task checks for policy violations?
The Identity Refresh task
16
A best practice is to assign ownership of objects, such as applications, to workgroups.
True
17
Implementers can add custom business logic to IdentityIQ using what functionality?
Rules
18
You can use the Edit Identity Quicklink to modify an identity’s attributes and trigger attribute synchronization to other applications.
True
19
Account schemas define which account attributes to read from an application when aggregating accounts with IdentityIQ.
True
20
We discussed two ways to view your application data prior to aggregation. Preview only lists the first 10 records, while __________________ lists all records and more details.
CONNECTOR DEBUG
21
Accounts are correlated to existing Identity Cubes when the Prune Identity task is run.
False
22
Which statement best describes what happens when you click Save Identities as Population?
The list of identities in the population is saved
23
The Process Events option in an Identity Refresh task directs IdentityIQ to initiate the lifecycle event workflows.
True
24
The certification process can cause provisioning.
True
25
Group of IdentityIQ users based on shared value of a single identity attribute and used to define target of operation (e.g. task filter, report filter).
Group (factory)
26
Access requests cause the generation of a provisioning plan.
True
27
Which of these configurations is part of the Rapid Setup features?
Specifying what attribute identifies a locked account
28
When a serious system error occurs, and an incident code is displayed, where would an admin user go to see details of the error?
Advanced Analytics > Syslog Search
29
Which of the following is true of the Rapid Setup Termination process?
It has its own parallel configurations to the Rapid Setup Leaver options.
30
How does IdentityIQ communicate with target systems in your environment?
Through connectors and integration modules
31
Both methods can disallow users from deleting their accounts on connected systems: In the LCM Configuration, disallow the Delete option for the My Actions category of users and removing access to the Manage Accounts Quicklink for the Self Service Quicklink population.
True
32
You can use the Administrator Console to postpone a scheduled task.
True
33
On a per Quicklink population basis, a rule can be implemented to constrain what members can request.
True
34
After aggregating, entitlements are added to the Entitlement Catalog, but they are not fully promoted on Identity Cubes until a refresh task has been run.
True
35
In IdentityIQ, new account groups can be created and provisioned in a connected application by using the Add New Entitlement button located in the Entitlement Catalog.
True
36
It is a best practice to use Java println statements for logging.
False
37
In IdentityIQ, users can request changes to which of the following?
Roles, Password
38
All employees need to be issued an email address and membership in the DomainUsers group in Active Directory on day one of their employment.
Birthright
39
To be able to view the lifecycle event details under Track My Requests, you must:
Use a workflow that creates and updates the request record
40
Which role type supports this scenario: Mark is going to a conference and needs to be able to request access to purchase tickets and file expense reports.
Business
41
Which of the following is not an IdentityIQ module?
File Access Manager
42
The critical network performance zone is between the user’s browser and IdentityIQ. It requires a round trip latency of 3ms or less.
False
43
Which of the following log levels will provide the most detailed information?
Trace
44
IdentityIQ does not support multi-factor authentication.
False
45
Select all the objects that support extended attributes.
Identity Cubes, Applications, Entitlements
46
Through the Manage User Access Quicklink, a user can:
Request or remove entitlements and/or roles
47
Authoritative Identity Cubes are created for each account read from all applications.
False
48
Quicklink behavior can be configured per Quicklink population.
True
49
When an attribute is marked as "searchable", what does this mean?
The attribute is stored in its own column for more efficient access for searching
50
Group of IdentityIQ users and used for assigning capabilities and scopes to set of users.
Workgroup
51
What is the term for writing access changes to applications within your enterprise?
Provisioning
52
What is the difference between a task and a business process (workflow)?
Tasks perform batch processing and can be scheduled; workflows interact with users and are activated in response to user action/data change.
53
What is the term for reading application data into IdentityIQ from external sources?
Aggregation
54
What is displayed on the My Reports tab?
Reports that you have configured and searches that have been saved as reports
55
Entitlements define which areas of the UI a user can access within IdentityIQ.
False
56
The Recommendation Engine can provide a recommendation for approving or denying a request for access.
True
57
When a policy violation is identified, a workflow can be initiated by IdentityIQ to address the violation.
True
58
What is the term for the process of reviewing an identity’s accounts and entitlements on the applications within your enterprise?
Certification
59
IdentityIQ can kick off a certification campaign for an identity when it detects a change in that person's account attributes.
True
60
When designating a batch host, a best practice is to add the host name to the Task ServiceDefinition object and the Request ServiceDefinition object.
True
61
SailPoint recommends use of multiple environments and a version control system as part of your deployment management strategy.
True
62
What are Entitlements
The type of access a user when logging into an application. Also called permission
63
Select the types of events that can trigger provisioning in IdentityIQ
A new employee, An employee retires, An employee moves from London to Toronto
64
What is the purpose of groups and populations?
To specify identities to include when performing an IdentityIQ activity, such as running a report.
65
Aggregation tasks are always partitioned and executed across multiple hosts.
False
66
Which of these is true of manual correlation?
It is not undone or overridden by a subsequent aggregation.
67
Identity search only allows you to search on the standard identity attributes that are pre-defined by IdentityIQ
False
68
What are batch requests typically used for within IdentityIQ?
Bulk loading identities or identity updates
69
What is an Application
Any resource you want to manage, such as operating systems, directories or databases
70
Rapid Setup Joiner runs for all new identity cubes created from any application.
True
71
Lifecycle Events, outside the Rapid Setup events, can only be used for situations other than joiner, mover, or leaver actions.
False
72
Manual correlation will link an account to an identity cube, but only until the next aggregation of that application.
False
73
An application connector can be forced to provision via IdentityIQ work items by removing “PROVISIONING” from the application features string.
True
74
Accounts are correlated to existing Identity Cubes when the Prune Identity task is run.
False
75
A policy definition disallows an identity to have both Admin and manager access on the Time Clock system. A user already has the Manager entitlement when she submits a request for Admin. IdentityIQ compares the access being requested and the user’s existing access to the policies. What kind of policy is this?
Preventive
76
It is impossible to have more than 20 extended attributes within IdentityIQ.
False
77
The Services Standard Build (SSB) is a deployment process provided by SailPoint that is required when deploying IdentityIQ.
False
78
IdentityIQ roles are required to ensure proper access security.
False
79
A group can be defined based on multiple attributes; a population is based on a single attribute.
False
80
Required relationships define the IT roles that are mandatory for any user who has a certain business role; while permitted relationships define the IT roles which a user is allowed to have, based on having a certain business role.
True
81
IdentityIQ can only monitor for password change requests originating from IdentityIQ.
False
82
The console commands export and import both provide the ability to strip dates and IDs from objects.
True
83
Certification must be part of Phase1 of any IdentityIQ implementation project.
False
84
If we want to add an entitlement to the entitlement catalog, what should we mark the corresponding account attribute as?
Managed
85
IdentityIQ supports both a delta aggregation and a delta refresh.
True
86
You can specify multiple triggers for the mover lifecycle event, for example, watching for changes in job title, department, or manager.
True
87
What is an Aggregation
Reding or collecting identity data from an enterprise application into IdentityIQ
88
While requesting access, you can search for entitlements using the extended attributes you’ve added to IdentityIQ.
True
89
The JDBC connector requires a provisioning rule to be written when provisioning to applications of this type.
True
90
Many IdentityIQ connectors include pre-defined account and group schemas.
True
91
IQService is used for provisioning to Active Directory and to LDAP.
False
92
When you add extended attributes that are not marked searchable to IdentityIQ, where are these new attributes stored by default?
In a CLOB
93
Roles can be manually requested by users and automatically assigned to users.
True
94
From the Administrator Console, you can view details about failed provisioning attempts and create a manual work item to complete the request.
True
95
The terms Identity Attributes and Account Attributes refer to the same thing.
False
96
The requestability of an entitlement is configured in the Entitlement Catalog.
True
97
Attachments can be added in which type of Quicklink process:
Manage User Access
98
A Quicklink population allows you to define a set of users who can make access requests for other sets of users.
True