SailPoint Identity-Security-Administrator Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 2, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

SailPoint Identity-Security-Administrator Exam Details

Key details for this exam, checked against the published exam outline

99 Practice Questions (Our Bank)
120 minutes Exam Duration
USD 400 Exam Fee
Exam Code
Identity-Security-Administrator
Full Name
SailPoint Certified Identity Security Administrator
Issuing Body
SailPoint
Delivery
Online proctored through Examity, scheduled directly through SailPoint
Eligibility
Minimum 6 months of hands-on experience
Validity
2 years
Practice Questions

Free Identity-Security-Administrator Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our Identity-Security-Administrator exam preparation team, who also write the explanation shown with each one. How we research and review these pages

An identity security administrator is setting up an identity profile for the HR source and needs the identity's manager attribute to be automatically populated based on a value from the HR source account, while also allowing a fallback value if the source attribute is empty. Which mapping configuration should be used?

Correct Answer: A
Explanation

Identity attribute mappings in an identity profile can be configured using a transform, which allows administrators to reference a source attribute and apply logic (such as a default value or fallback) if the value is missing. Rule-based hardcoding is not scalable, manual entry defeats automation, and lifecycle states control access/provisioning, not attribute mapping defaults.

A compliance team wants to ensure that when an employee moves into a 'Leave of Absence' lifecycle state, their access to all applications is revoked automatically without deleting their accounts, so access can be restored quickly upon return. Which provisioning option within the lifecycle state configuration achieves this?

Correct Answer: A
Explanation

Lifecycle states allow administrators to configure account actions (enable, disable, or no action) per source when an identity transitions into that state. Disabling accounts revokes access while preserving the account for quick reinstatement, whereas deletion would remove the account entirely. Certification campaigns and identity profile changes are unrelated to this specific access revocation use case.

An administrator notices that a provisioning request to create a new account on an Active Directory source is stuck in a pending state, and the help desk wants to know where to look first to identify the root cause. Which object should the administrator search on in Identity Security Cloud to troubleshoot this provisioning error?

Correct Answer: A
Explanation

Account activity records track provisioning requests and their statuses (pending, completed, failed) and provide detailed error messages when a provisioning operation does not complete. Access profiles and identity profiles define configuration, not runtime provisioning status, and role membership criteria pertains to automated role assignment, not troubleshooting a stuck provisioning task.

A source owner reports that after a recent HR feed aggregation, several accounts that used to be linked to identities are now showing as uncorrelated. The administrator investigates and finds that the HR file's unique identifier column was renamed. In this scenario, what does 'uncorrelated' mean for these accounts?

Correct Answer: A
Explanation

Uncorrelated accounts are accounts discovered during aggregation that cannot be linked to an existing identity using the correlation rule or configuration, often because a key identifying attribute changed or is missing. This does not mean the account is disabled, deleted, or merged; it simply remains unlinked until correlation logic is corrected or manual correlation is performed.

A financial services organization must demonstrate to auditors that access to a sensitive application is reviewed periodically and that any inappropriate access is revoked in a timely manner, in line with regulatory requirements such as SOX. Which SailPoint Identity Security Cloud capability directly supports this compliance requirement?

Correct Answer: A
Explanation

Certification campaigns allow organizations to periodically review who has access to what, enabling reviewers to approve or revoke access, which directly satisfies compliance and audit requirements like SOX. Event triggers automate actions based on system events, workflow designer builds custom automations, and virtual appliance clustering relates to infrastructure availability, none of which specifically address periodic access review and compliance attestation.

Get Full Access

99 questions covering all exam domains, starting from $20

Study Guide

What the SailPoint Identity-Security-Administrator Exam Covers

Exam domains verified against: Official SailPoint Identity-Security-Administrator exam guide, last checked September 2026.

Domain 1: Platform

Covers valid search queries and results, scheduling search reports, REST API authentication, monitoring provisioning activity, security administration options, event triggers configuration, tenant authentication options, workflow components, and backup and restore procedures. Understanding these platform capabilities is essential for day-to-day administration of the Identity Security Cloud.

Domain 2: Virtual Appliances

Focuses on understanding virtual appliances, monitoring their health, and performing basic troubleshooting. Virtual appliances bridge on-premises environments with the cloud platform and require reliable monitoring and maintenance.

Domain 3: Identity and Lifecycle Management

Covers identity profiles, their authentication options, attribute mappings, mapping configuration options, lifecycle states and use cases, provisioning options within lifecycle states, and the cloud lifecycle state attribute. This domain forms the foundation for understanding how identities move through your system.

Sample questions from this domain above: Q1Q2

Domain 4: Provisioning

Addresses how provisioning is triggered, components of source provisioning, provisioning channels and their use cases, logging configuration and levels for specific connectors, and troubleshooting provisioning errors. Provisioning errors directly impact user access delivery and account management.

Sample question from this domain above: Q3

Domain 5: Access Management

Examines user level capabilities, entitlements basics, types of access supported, automated role assignments, and troubleshooting access management errors. Access management is where identity data translates into actual permissions and capabilities for users.

Domain 6: Supporting Governance

Covers access request steps, work reassignment, approval flows, certification lifecycle, certification types, and policy types in Identity Security Cloud. Governance functions ensure accountability and compliance across the identity and access lifecycle.

Sample question from this domain above: Q5

Domain 7: Sources

Focuses on aggregation types, processes for obtaining account and entitlement information, uncorrelated accounts, account deletion and its effect on aggregation, connector types, source error searching, and the purpose of sources. Sources are the starting point for all identity data flowing into the platform.

Sample question from this domain above: Q4

Domain 8: General knowledge for Identity Security Administrators

Covers IGA definition and understanding, compliance concepts, authentication versus authorization comparison, federation concepts, and authentication methods. This domain establishes the foundational concepts that inform all other administrator tasks.

FAQ

Identity-Security-Administrator Exam FAQ

Common questions about the exam itself

How much hands-on experience do I need before I can sit the Identity Security Administrator exam?
You need a minimum of 6 months of hands-on experience with the SailPoint Identity Security Cloud platform before attempting the exam. This experience helps ensure you understand real-world scenarios covered in the objectives.
How long does the Identity Security Administrator exam take?
The exam is 120 minutes long with 73 questions, which gives you approximately 98 seconds per question. However, scenario-based questions with longer framing text require you to read carefully before evaluating options.
What is the format of the Identity Security Administrator exam?
The exam is delivered online and proctored through Examity. You schedule it directly through SailPoint rather than through a third-party test center.
How much does the Identity Security Administrator exam cost?
The exam costs USD 400, and your enrollment includes two attempts. You have 364 days from registration to schedule and take both attempts.
What happens if I do not pass the Identity Security Administrator exam on my first attempt?
After your first attempt, your status shows as Not Complete. You have a second attempt included in your enrollment. After the second attempt, your final status updates to either Passed or Not Passed.
How long is the Identity Security Administrator certification valid?
The certification is valid for 2 years. SailPoint offers a formal recertification program that extends your credential for another 2 years without retaking the exam if you earn 80 recertification credits and pay a USD 200 recertification fee.
Which objective area is hardest in the Identity Security Administrator exam and how should I prepare for it?
Provisioning is typically the most challenging domain because it involves understanding multiple interconnected concepts like source provisioning components, provisioning channels, connector logging, and error troubleshooting. Study this domain last when you have solid foundational knowledge from Identity and Lifecycle Management and Sources.
How does the Identity Security Administrator certification relate to the other SailPoint certifications?
The Identity Security Administrator is the newest SailPoint certification, launched in February 2026, and serves as an entry-level option alongside the Identity Security Engineer certification. It focuses on administration and monitoring tasks, while the Engineer certification covers broader architecture and implementation skills.
How long should I spend preparing for the Identity Security Administrator exam?
Most candidates with the required 6 months of hands-on experience need 4 to 8 weeks of focused preparation, depending on their depth of experience with each objective area. SailPoint emphasizes that training alone without practical hands-on work does not prepare candidates to pass.
What is the passing score for the Identity Security Administrator exam?
SailPoint does not publish a percentage threshold for passing. The exam is graded as pass or fail, and your result updates after each of your two attempts.