Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Is the following true about the web-services connector in IdentityNow?
Solution: The connector supports SAML authentication.
The Web Services connector in SailPoint IdentityNow does not support SAML authentication. SAML is primarily used for Single Sign-On (SSO) authentication for web applications, whereas the Web Services connector in IdentityNow typically supports Basic Authentication, OAuth, or custom header-based authentication for API-based integrations. SAML authentication is generally used for federated identity management rather than for API-based interactions.
SailPoint IdentityNow Web Services Connector Configuration Guide.
SailPoint IdentityNow Authentication Methods for Connectors.
Is the following description of an access profile correct?
Solution: It allows definition of an approval process.
Yes, an access profile allows the definition of an approval process. When an access profile is created, administrators can configure specific approval workflows that must be followed before the access is granted. This includes designating approvers or specifying multiple levels of approval, depending on the organization's policies. This capability is useful for ensuring that sensitive access requests are properly reviewed and approved.
SailPoint IdentityNow Access Request and Approval Workflow Guide.
SailPoint IdentityNow Access Profile Configuration Documentation.
In an IdentityNow environment, the source lest connection is failing with a timeout error.
Is this a step an identityNow engineer should take to troubleshoot the problem?
Solution: Test connectivity from the virtual appliance (VA) to the source.
Testing connectivity from the virtual appliance (VA) to the source is a crucial troubleshooting step when dealing with connection issues such as timeouts. This can be done by accessing the VA and performing network tests (e.g., ping, telnet, or curl commands) to verify that the VA can communicate with the source over the required network paths. Ensuring that the VA has network access to the source can help identify if the problem is related to network configuration or firewall restrictions.
Key Reference from SailPoint Documentation:
VA to Source Connectivity Testing: Verifying network connectivity between the VA and the source is a fundamental step in diagnosing connection issues, as outlined in SailPoint's troubleshooting guidelines.
Does this example accurately describe an IdentityNow data flow?
Solution:
1. An IdentityNow engineer clicks "start manual aggregation".
2. The IdentityNow tenant contacts the Active Directory domain controller.
3. The domain controller sends a list of accounts to the virtual appliance.
4. The virtual appliance masks sensitive information and sends a list of accounts to the IdentityNow tenant.
No, this example does not accurately describe an IdentityNow data flow. The step where the domain controller sends a list of accounts directly to the virtual appliance is incorrect. Instead, during manual aggregation, the virtual appliance is responsible for initiating the connection to the domain controller (or other authoritative source), retrieving account data, and then sending the results to the IdentityNow tenant. Sensitive information is masked before sending the data from the virtual appliance to the IdentityNow tenant, but the domain controller does not interact directly with the IdentityNow tenant.
SailPoint IdentityNow Aggregation Process Documentation.
SailPoint IdentityNow Virtual Appliance Data Flow Guide.
Is this statement true about certification campaigns?
Solution: A certification item can be reassigned multiple times.
Yes, a certification item can be reassigned multiple times during a certification campaign. If a reviewer is unable to certify an item or needs another individual to review the access, they can reassign the certification to a different reviewer. This reassignment functionality allows flexibility in handling access certifications and ensuring the right person evaluates the access. There are no limits on how many times an item can be reassigned, making it a versatile feature within the certification process.
SailPoint IdentityNow Certification Reassignment Feature Documentation.
SailPoint IdentityNow Certification Workflow Guide.
108 questions covering all exam domains, starting from $20
Exam domains verified against: Official SailPoint IdentityNow-Engineer exam guide, last checked September 2026.
This introductory section provides implementation engineers with essential knowledge about IdentityNow, focusing on key concepts necessary for effective identity security management. Learn the core architecture and foundational concepts of SailPoint's Identity Security Cloud platform.
Aimed at engineers and developers, this section covers identifying and modeling identity structures to ensure secure user access and adherence to regulatory standards. Understand how to design identity governance solutions using IdentityNow's configuration and modeling capabilities.
Targeted at engineers who specialize in provisioning, this part details the procedures for user onboarding and access control within the IdentityNow framework. Learn to implement provisioning workflows and manage user lifecycle processes effectively.
Designed for security engineers, this segment reviews search functionalities and compliance management within the platform. Master the tools for monitoring compliance status and searching identity data to support governance requirements.
Sample question from this domain above: Q1
This advanced topic is tailored for experienced engineers, delving into methods for customizing and enhancing the capabilities of IdentityNow. Learn to extend platform functionality through custom connectors, integrations, and advanced configurations.
Common questions about the exam itself